How to remove mimidrv.sys
- File Details
- Overview
- Analysis
mimidrv.sys
The module mimidrv.sys has been detected as Hack.Mimikatz
File Details
Product Name: |
|
Company Name: |
|
MD5: |
5be61a24f50eb4c94d98b8a82ef58dcf |
Size: |
36 KB |
First Published: |
2018-07-16 15:15:33 (6 years ago) |
Latest Published: |
2020-11-25 23:22:54 (4 years ago) |
Status: |
Hack.Mimikatz (on last analysis) |
|
Analysis Date: |
2020-11-25 23:22:54 (4 years ago) |
Overview
%localappdata%\packages\kalilinux.54290c8133fee_ey8k8hqnwqnmg\localstate\rootfs\usr\share\mimikatz |
%desktop%\zrtfg |
%desktop%\aaaaaa\m |
%sysdrive%\$recycle.bin\s-1-5-21-4002530241-252803949-4081733239-1001\$r0x0u0a |
%sysdrive%\$recycle.bin\s-1-5-21-4002530241-252803949-4081733239-1001\$ruk6czp |
%sysdrive%\bcert 19-02\encryption exercise\mimikatz_trunk.zip |
Windows 10 |
33.3% |
|
Windows 8.1 |
33.3% |
|
Windows Server 2008 R2 |
16.7% |
|
Windows Server 2012 R2 |
16.7% |
|
Analysis
Subsystem: |
Native |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000000010000 |
Entry Address: |
0x0000b064 |
Name |
Size of data |
MD5 |
.text |
12800 |
b0ff3faa16c74306f92153b1c48cb7f5 |
.rdata |
5120 |
70101e456d9d26e9acb830d94adc9357 |
.data |
5632 |
2db401347bf58464e7d5b4b4559f7649 |
.pdata |
512 |
b04990936e5aa0b5e6449b3450beddc2 |
PAGE |
1024 |
8b0684505ef2968c82786401708e2579 |
INIT |
1536 |
6ba44e961efadd26bd07cdf50e02f977 |
.rsrc |
1536 |
d30a5ae8c6b8615ded3d921feda2bbbf |
.reloc |
1024 |
d1acd4353a27bfa9c1fbfd6852a1f1ed |