How to remove check_decryption_id.exe

check_decryption_id.exe

The module check_decryption_id.exe has been detected as Ransom.Wacatac

check_decryption_id.exe
Product Name:

check_decryption_id

Company Name:

nomoreransom

MD5: c45ab63ac8fe1ba4a266ee5187fb9bd3
Size: 5 MB
First Published: 2024-05-13 23:06:41 (11 months ago)
Latest Published: 2025-03-31 23:01:14 (4 days ago)
Status: Ransom.Wacatac (on last analysis)
Analysis Date: 2025-03-31 23:01:14 (4 days ago)
%profile%\downloads\decryption_checker_for_lockbit
%desktop%
Brazil 100.0%
Windows 10 50.0%
Windows 7 50.0%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x0000c23c

PE Sections:

Name Size of data MD5
.text 133120 e6f859e740c0accbd4da65d858a45523
.rdata 60416 a85408d4e8740ddc162c95a1bb13901f
.data 3072 e22e6b38ad006a74933f79e538bfb2e1
.pdata 6656 70e4cdb79d1892bbf6d2987fda4d1285
_RDATA 512 c1ef5e9c6a299e7026a89d21dad2eeee
.rsrc 5716480 0f7460f52c7939f2ad68e90bfb26f612
.reloc 2048 f5f9986a8fbc030246b297b4e4664ae9

More information:

Download GridinSoft Anti-Malware - Removal tool for check_decryption_id.exe
­