How to remove pythonw.exe
- File Details
- Overview
- Analysis
pythonw.exe
The module pythonw.exe has been detected as Ransom.Wacatac
File Details
MD5: |
c31d7c4ec546f7eb90a669a605a6987b |
Size: |
98 KB |
First Published: |
2024-02-15 23:10:44 (10 months ago) |
Latest Published: |
2024-11-15 23:01:16 (3 weeks ago) |
Status: |
Ransom.Wacatac (on last analysis) |
|
Analysis Date: |
2024-11-15 23:01:16 (3 weeks ago) |
%programfiles%\steam\steamapps\common\projekt passion\lib |
%sysdrive%\games\projektpassion-0.10-pc_rus\lib |
%sysdrive%\riot games\assets\dreams.of.desire.definitive.edition.v1.0.3.multi5-gog\lib |
%sysdrive%\steam\steamapps\common\projekt passion\lib |
%sysdrive%\hh\games\ahouseintherift-0.7.4r2-pc\lib |
%appdata%\itch\apps\monster-girl-dreams\mongirldreams-alpha-v25.9b-pc\lib |
%sysdrive%\a-house-in-the-rift-pc_hi-res\ahouseintherift-0.7.8r2-pc\lib |
%mydoc%\jeux\projektpassion-0.12-pc\lib |
%sysdrive%\steam\steamapps\common\projekt passion\lib |
%sysdrive%\jeux\d\d\dreams.of.desire.definitive.edition\lib |
|
16.7% |
|
|
8.3% |
|
|
8.3% |
|
|
8.3% |
|
|
8.3% |
|
|
8.3% |
|
|
8.3% |
|
|
8.3% |
|
|
8.3% |
|
|
8.3% |
|
|
8.3% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00001110 |
Name |
Size of data |
MD5 |
.text |
5632 |
5f5fa4cf8d7ca8756f554a0aecfe77cb |
.rdata |
3072 |
96baf569363210b5ac165318ae88dca0 |
.buildid |
512 |
6d28c3c0302e13ce6e7eb8b3ecd94ad3 |
.data |
512 |
2abec3235e0ab2707922a439e6213836 |
.tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.rsrc |
89088 |
2e6e200e217dcc2a90567478f076377c |