How to remove aida64_All.exe
- File Details
- Overview
- Analysis
aida64_All.exe
The module aida64_All.exe has been detected as Ransom.WannaCrypt
File Details
Product Name: |
|
Company Name: |
|
MD5: |
7f6a26e038dfda380310fb4312cbfcff |
Size: |
25 MB |
First Published: |
2018-07-03 19:02:04 (6 years ago) |
Latest Published: |
2019-10-03 05:20:25 (5 years ago) |
Status: |
Ransom.WannaCrypt (on last analysis) |
|
Analysis Date: |
2019-10-03 05:20:25 (5 years ago) |
%sysdrive%\sstr\minst |
%sysdrive%\efi\paravis\strelec\minst |
%sysdrive%\obraz\winpe 10-8 sergei strelec x86_x64_native x86 2018.02.07\winpe10_8_sergei_strelec_x86_x64_2018.02.07_russian\sstr\minst |
Windows 10 |
87.5% |
|
Windows 7 |
12.5% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00015cbf |
Name |
Size of data |
MD5 |
.text |
87040 |
3ec934cc436d7b64c1d6b75a6b7b1156 |
.rdata |
13312 |
b7ca18a7adbe2e37497203064a96d994 |
.data |
2048 |
e25c694b4e1f6a6310362c4fe77c745a |
.rsrc |
119296 |
ca6932d329841d4f322aeeafe5590efc |