How to remove pro-zipper.exe
- File Details
- Overview
- Analysis
pro-zipper.exe
The module pro-zipper.exe has been detected as Ransom.Wacatac
File Details
Product Name: |
|
Company Name: |
|
MD5: |
277aef6225feab2a6bf61971992d80a3 |
Size: |
460 KB |
First Published: |
2020-07-04 19:04:06 (4 years ago) |
Latest Published: |
2020-07-11 03:14:13 (4 years ago) |
Status: |
Ransom.Wacatac (on last analysis) |
|
Analysis Date: |
2020-07-11 03:14:13 (4 years ago) |
%temp% |
%temp% |
%localappdata%\microsoft\windows\inetcache\ie |
%temp% |
%temp% |
%temp% |
%temp% |
%temp% |
%temp% |
%temp% |
|
30.4% |
|
|
13.0% |
|
|
8.7% |
|
|
8.7% |
|
|
8.7% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
Windows 10 |
91.3% |
|
Windows 8.1 |
4.3% |
|
Windows 7 |
4.3% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000a5f8 |
Name |
Size of data |
MD5 |
CODE |
40448 |
611a4d7a24dd9b18a256468a5d7453f5 |
DATA |
1024 |
2f7f9f859c8b4b133abf78cebd99cc90 |
BSS |
0 |
00000000000000000000000000000000 |
.idata |
2560 |
bb5485bf968b970e5ea81292af2acdba |
.tls |
0 |
00000000000000000000000000000000 |
.rdata |
512 |
9ba824905bf9c7922b6fc87a38b74366 |
.reloc |
0 |
00000000000000000000000000000000 |
.rsrc |
74240 |
8cfa669481e3f8ebd978a811c0b98d66 |