How to remove tp_Fade.dll
- File Details
- Overview
- Analysis
tp_Fade.dll
The module tp_Fade.dll has been detected as Worm.Ramnit
File Details
Product Name: |
|
MD5: |
8e624ec2b93c205b8bb6aafff36d4c2c |
Size: |
251 KB |
First Published: |
2018-04-15 08:11:43 (6 years ago) |
Latest Published: |
2018-04-15 08:11:43 (6 years ago) |
Status: |
Worm.Ramnit (on last analysis) |
|
Analysis Date: |
2018-04-15 08:11:43 (6 years ago) |
%sysdrive%\งานกู้ 240658\root\program files\wondershare\video editor |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x10000000 |
Entry Address: |
0x0001b000 |
Name |
Size of data |
MD5 |
.text |
61440 |
af5f8b020008361523d014be5d53e1a5 |
.rdata |
13312 |
9e3cb075f73f4fbacc72332504ec2212 |
.data |
7168 |
8f23d58234f9ce7e6adc1953cbef0dca |
.rsrc |
1536 |
63dc3829a95336fb94ac5091a0c89c09 |
.reloc |
6144 |
940cdbfdb6f9317c26d18a263802069e |
.text |
166400 |
6208de3d0e7c5d720b9177edd206fca6 |