How to remove k5GUHWm1FTW3RX9IPRyP8mGI.exe
- File Details
- Overview
- Analysis
k5GUHWm1FTW3RX9IPRyP8mGI.exe
The module k5GUHWm1FTW3RX9IPRyP8mGI.exe has been detected as Ransom.STOP
File Details
Product Name: |
|
MD5: |
e9ad6f92f270e2e2cd26482eb475fef8 |
Size: |
4 MB |
First Published: |
2024-04-08 23:00:56 (a year ago) |
Latest Published: |
2024-04-08 23:01:28 (a year ago) |
Status: |
Ransom.STOP (on last analysis) |
|
Analysis Date: |
2024-04-08 23:01:28 (a year ago) |
Overview
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00004251 |
Name |
Size of data |
MD5 |
.text |
69120 |
5fdf926e025464ac215038e859a5b2fd |
.rdata |
36864 |
7d03ffc4c20a5d48bcf626855ca12eb6 |
.data |
4185088 |
57c401552d6c5dbac67972c874c072b6 |
.rsrc |
24576 |
8b0116d16ad3dcba6e60b9e7fac8fe35 |