How to remove mfencrk.sys
- File Details
- Overview
- Analysis
mfencrk.sys
The module mfencrk.sys has been detected as Virtool.ShadowBrokers
File Details
Product Name: |
|
Company Name: |
|
MD5: |
0a07fc7d6fad10c9fbf152a7a1b0d830 |
Size: |
104 KB |
First Published: |
2019-11-12 17:23:35 (5 years ago) |
Latest Published: |
2019-11-12 17:23:35 (5 years ago) |
Status: |
Virtool.ShadowBrokers (on last analysis) |
|
Analysis Date: |
2019-11-12 17:23:35 (5 years ago) |
Overview
Analysis
Subsystem: |
Native |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x00001130 |
Name |
Size of data |
MD5 |
.text |
61440 |
0076ea5e194b93592c8fa027a27fc63e |
.rdata |
10752 |
595cb6fe15ee25f39ab11c004de61a8d |
.data |
512 |
fd05ed983208d982b536d2da3b81db19 |
.pdata |
4096 |
a9c40c6384be7eb65dce96cee51a1404 |
.CRT |
512 |
7825c6c16249c231313044b1afb8d72d |
.bldvar |
512 |
07321e0c0aa8344971c4d0511fe02c04 |
PAGE |
1024 |
7d1beef61b8ccf7c6510be2c1fc6784f |
INIT |
2560 |
2cbfe26084393d391802ea734f1438c1 |
.rsrc |
1024 |
18258a79017e8648784ee0a76625ea30 |
.reloc |
512 |
fa781c55e30a1290479d5ae16f548b6b |