How to remove sihost.exe
sihost.exe
The module sihost.exe has been detected as Ransom.Wacatac
File Details
MD5: | 8f31073871dcdf2abd3cc0c57928038f |
Size: | 66 KB |
First Published: | 2020-08-06 20:46:14 (3 years ago) |
Latest Published: | 2020-11-27 18:43:44 (3 years ago) |
Status: | Ransom.Wacatac (on last analysis) | |
Analysis Date: | 2020-11-27 18:43:44 (3 years ago) |
Common Places:
%appdata% |
%appdata% |
%appdata% |
%appdata% |
%appdata% |
%appdata% |
%appdata% |
%appdata% |
%appdata% |
%appdata% |
Geography:
21.1% | ||
10.5% | ||
10.5% | ||
10.5% | ||
5.3% | ||
5.3% | ||
5.3% | ||
5.3% | ||
5.3% | ||
5.3% | ||
5.3% | ||
5.3% | ||
5.3% |
OS Version:
Windows 10 | 76.2% | |
Windows 7 | 19.0% | |
Windows 8.1 | 4.8% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x0001115e |
.NET Info:
MVID: | cc1703bd-8c3e-4df7-934e-7f93047db09a |
Typelib ID: | 25560858-c3cf-451f-90d2-0d9fff806ed0 |
PE Sections:
Name | Size of data | MD5 |
.text | 61952 | 089585b059952f1e2575e3253359bb1f |
.sdata | 1024 | d3f2e01571c1f854e20d47d2050a1b9b |
.rsrc | 3584 | f5bfd92b3b8567647717f4996d67b35b |
.reloc | 512 | 8993c54d6301729b6144a7bdb9422080 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for sihost.exe