How to remove check_decryption_id.exe
- File Details
- Overview
- Analysis
check_decryption_id.exe
The module check_decryption_id.exe has been detected as Ransom.Wacatac
File Details
Product Name: |
|
Company Name: |
|
MD5: |
c45ab63ac8fe1ba4a266ee5187fb9bd3 |
Size: |
5 MB |
First Published: |
2024-05-13 23:06:41 (11 months ago) |
Latest Published: |
2025-03-31 23:01:14 (4 days ago) |
Status: |
Ransom.Wacatac (on last analysis) |
|
Analysis Date: |
2025-03-31 23:01:14 (4 days ago) |
%profile%\downloads\decryption_checker_for_lockbit |
%desktop% |
Windows 10 |
50.0% |
|
Windows 7 |
50.0% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x0000c23c |
Name |
Size of data |
MD5 |
.text |
133120 |
e6f859e740c0accbd4da65d858a45523 |
.rdata |
60416 |
a85408d4e8740ddc162c95a1bb13901f |
.data |
3072 |
e22e6b38ad006a74933f79e538bfb2e1 |
.pdata |
6656 |
70e4cdb79d1892bbf6d2987fda4d1285 |
_RDATA |
512 |
c1ef5e9c6a299e7026a89d21dad2eeee |
.rsrc |
5716480 |
0f7460f52c7939f2ad68e90bfb26f612 |
.reloc |
2048 |
f5f9986a8fbc030246b297b4e4664ae9 |