How to remove winDecrypt,2.exe
- File Details
- Overview
- Analysis
winDecrypt,2.exe
The module winDecrypt,2.exe has been detected as Trojan.Agent
File Details
Product Name: |
|
Company Name: |
|
MD5: |
7e91b2802a2bc5185cee4cf7aef637fd |
Size: |
300 KB |
First Published: |
2020-04-22 00:17:26 (5 years ago) |
Latest Published: |
2024-05-04 23:01:35 (a year ago) |
Status: |
Trojan.Agent (on last analysis) |
|
Analysis Date: |
2024-05-04 23:01:35 (a year ago) |
%sysdrive%\! software\~ office\portable.pdf.password.remover.3.1 |
%sysdrive%\! software\~ office\portable.pdf.password.remover.3.1 |
%programfiles% |
%sysdrive%\! software\~ office\portable.pdf.password.remover.3.1 |
%sysdrive%\! software\~ office\portable.pdf.password.remover.3.1 |
%programfiles% |
%programfiles% |
%programfiles% |
%programfiles% |
%programfiles% |
|
27.3% |
|
|
13.6% |
|
|
9.1% |
|
|
9.1% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
Windows 10 |
72.7% |
|
Windows 7 |
18.2% |
|
Windows 8.1 |
9.1% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000cac20 |
Name |
Size of data |
MD5 |
|
0 |
00000000000000000000000000000000 |
|
298496 |
60592f2bc31e7bef62256e3dd386721c |
.rsrc |
8192 |
3217725ac19aadc35326f18e957a9e79 |