How to remove nqqchtkypz.exe
- File Details
- Overview
- Analysis
nqqchtkypz.exe
The module nqqchtkypz.exe has been detected as Ransom.Cerber
File Details
Product Name: |
|
Company Name: |
|
MD5: |
81d6af74652be2a7245a2a36ed4ca613 |
Size: |
159 KB |
First Published: |
2017-05-26 14:11:19 (7 years ago) |
Latest Published: |
2020-07-01 12:35:14 (4 years ago) |
Status: |
Ransom.Cerber (on last analysis) |
|
Analysis Date: |
2020-07-01 12:35:14 (4 years ago) |
%localappdata%\temp |
%sysdrive%\temp |
alaxkixsga.exe |
nqqchtkypz.exe |
wxyynwdear.exe |
iqmkmrsybe.exe |
xyfuklzska.exe |
zxlhrfbqie.exe |
khuhgrbrfj.exe |
Windows 7 |
95.8% |
|
Windows 10 |
4.2% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000032a0 |
Name |
Size of data |
MD5 |
.text |
25600 |
4219bc0ba21196c40804cc23644c3170 |
.rdata |
5632 |
d6b0bc2db2de2a3dd996fda6539cef0e |
.data |
1536 |
2aa587c909999ca52be17d0f1ffbd186 |
.ndata |
0 |
00000000000000000000000000000000 |
.rsrc |
36352 |
d38f32c2208bb3b652891047d8651fb2 |