How to remove k5GUHWm1FTW3RX9IPRyP8mGI.exe
- File Details
- Overview
- Analysis
k5GUHWm1FTW3RX9IPRyP8mGI.exe
The module k5GUHWm1FTW3RX9IPRyP8mGI.exe has been detected as Ransom.STOP
File Details
| Product Name: |
|
| MD5: |
e9ad6f92f270e2e2cd26482eb475fef8 |
| Size: |
4 MB |
| First Published: |
2024-04-08 23:00:56 (2 years ago) |
| Latest Published: |
2024-04-08 23:01:28 (2 years ago) |
| Status: |
Ransom.STOP (on last analysis) |
|
| Analysis Date: |
2024-04-08 23:01:28 (2 years ago) |
Overview
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x00004251 |
| Name |
Size of data |
MD5 |
| .text |
69120 |
5fdf926e025464ac215038e859a5b2fd |
| .rdata |
36864 |
7d03ffc4c20a5d48bcf626855ca12eb6 |
| .data |
4185088 |
57c401552d6c5dbac67972c874c072b6 |
| .rsrc |
24576 |
8b0116d16ad3dcba6e60b9e7fac8fe35 |