How to remove Windows__Update.exe
- File Details
- Overview
- Analysis
Windows__Update.exe
The module Windows__Update.exe has been detected as Ransom.Bladabindi
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
8e5514ac044ea28251f86403aed679e8 |
| Size: |
428 KB |
| First Published: |
2022-03-20 23:29:47 (3 years ago) |
| Latest Published: |
2022-03-21 23:24:57 (3 years ago) |
| Status: |
Ransom.Bladabindi (on last analysis) |
|
| Analysis Date: |
2022-03-21 23:24:57 (3 years ago) |
| %sysdrive%\windows.old\program files (x86) |
| %programfiles% |
| %programfiles% |
| %programfiles% |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x00050a3e |
| MVID: |
fe65e55c-7e1b-4383-8712-5379b8ace20c |
| Typelib ID: |
f7cccbec-9f68-4aae-81a0-f34df456d67e |
| Name |
Size of data |
MD5 |
| .text |
322560 |
6a54386d9244da1ee9b354d1028d4a81 |
| .sdata |
1024 |
f78062365faa11035c39a9fea836a8c7 |
| .rsrc |
113664 |
f36edf1ae948d90c7dd5f46d65918714 |
| .reloc |
512 |
b892298af29b474698147aab6b4bdf9c |