How to remove nekopara_vol0.exe
- File Details
- Overview
- Analysis
nekopara_vol0.exe
The module nekopara_vol0.exe has been detected as Worm.Ramnit
File Details
Product Name: |
|
MD5: |
6932608d31b134c5fc24a263817e5add |
Size: |
4 MB |
First Published: |
2018-05-10 18:04:16 (7 years ago) |
Latest Published: |
2018-05-10 18:04:16 (7 years ago) |
Status: |
Worm.Ramnit (on last analysis) |
|
Analysis Date: |
2018-05-10 18:04:16 (7 years ago) |
%sysdrive%\do not enter zzzz\hmm\vn |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x004ef000 |
Name |
Size of data |
MD5 |
.text |
2846208 |
aeaab6a59adc118f03524f99df97b993 |
.adata |
1536 |
2793ef729adc8c9147cf8d55cc0b471a |
.rdata |
963584 |
d1419ff10cddc3b6046e29b43b73992f |
.data |
41472 |
8ffb9c1f60dcf45ef0d474174af341f3 |
.rsrc |
291840 |
9eb684df290dae43a9922d7b0b387549 |
.reloc |
193024 |
97e4fe944d243e55471528ba52693962 |
.rmnet |
158208 |
62c55595cc27330f8496e709081032c4 |
.text |
99840 |
dc386d7640d75063750582d32ee4827b |