How to remove WindowsBootManager.exe
- File Details
- Overview
- Analysis
WindowsBootManager.exe
The module WindowsBootManager.exe has been detected as Trojan.Heur!
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
6d582ad6377f23e6ded3fbe114cdebef |
| Size: |
139 MB |
| First Published: |
2023-03-03 23:12:49 (2 years ago) |
| Latest Published: |
2023-03-03 23:27:52 (2 years ago) |
| Status: |
Trojan.Heur! (on last analysis) |
|
| Analysis Date: |
2023-03-03 23:27:52 (2 years ago) |
| %temp%\nsebcb9.tmp |
| %temp%\nsi6863.tmp |
| %temp%\nsh682c.tmp |
| %temp% |
| %temp%\nsxc412.tmp |
| %temp%\nsyd2f1.tmp |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
64 |
| Image Base: |
0x0000000140000000 |
| Entry Address: |
0x03ba23b0 |
| Name |
Size of data |
MD5 |
| .text |
119330304 |
b4e4b0335fed30a90281db9899050ffc |
| .rdata |
21858816 |
815b7e9166d7af9e7f0a5629c6f540b5 |
| .data |
520704 |
cd41b085c694cfe02da06197f05b75f4 |
| .pdata |
3830272 |
646429366759067a4871c72b3b45c067 |
| .00cfg |
512 |
fbd6948dc06937aade885dffe1e04500 |
| .retplne |
512 |
7a1b7754bbb5658c6826035106303d20 |
| .rodata |
4608 |
ab87d2e8f7e7a40ee320b1ce20d19e20 |
| .tls |
1024 |
e54b3a6ef03b79d65232703b172114dc |
| CPADinfo |
512 |
60d3ea61d541c9be2e845d2787fb9574 |
| _RDATA |
512 |
1cac896d03323d088225e8d65326c4fa |
| malloc_h |
512 |
582ba43437976a7a0a0250c3ee9e500e |
| .rsrc |
99328 |
d4193d5858985cfed113aba88a0163cd |
| .reloc |
952832 |
3a5f66e52f674250767145811d8b4b69 |