How to remove mspass.exe
mspass.exe
The module mspass.exe has been detected as Ransom.Zbot
File Details
| Product Name: | MessenPass |
| Company Name: | NirSoft |
| MD5: | b1483a77f4c0041edbf2504be20083c9 |
| Size: | 123 KB |
| First Published: | 2017-09-03 00:09:06 (8 years ago) |
| Latest Published: | 2023-02-09 23:20:02 (2 years ago) |
| Status: | Ransom.Zbot (on last analysis) | |
| Analysis Date: | 2023-02-09 23:20:02 (2 years ago) |
Common Places:
| %profile%\downloads\compressed\passreccommandline |
| %desktop%\passwordfox |
| %desktop%\xd\..3\usb hack |
| %sysdrive%\windows_repair_toolbox\downloads |
| %desktop%\windows_repair_toolbox\downloads |
| %sysdrive%\backup |
| %sysdrive%\應用程式\usb hack |
| %sysdrive%\usb hack |
| %sysdrive%\downloads |
| %desktop% |
Geography:
| 26.1% | ||
| 13.0% | ||
| 8.7% | ||
| 8.7% | ||
| 8.7% | ||
| 4.3% | ||
| 4.3% | ||
| 4.3% | ||
| 4.3% | ||
| 4.3% | ||
| 4.3% | ||
| 4.3% | ||
| 4.3% |
OS Version:
| Windows 10 | 69.6% | |
| Windows 7 | 30.4% |
Analysis
| Subsystem: | Windows GUI |
| PE Type: | pe |
| OS Bitness: | 32 |
| Image Base: | 0x00400000 |
| Entry Address: | 0x00013e10 |
PE Sections:
| Name | Size of data | MD5 |
| .text | 78336 | f55b357354f2a2edda4c62cb84993c39 |
| .rdata | 23552 | 712ce6b612690f3b1786e05b36563b4f |
| .data | 11264 | 5414ea3141fe886c11ca229ab9648a09 |
| .rsrc | 11776 | 0f43fbdf10b0f617122a684fae256bb3 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for mspass.exe