How to remove fcalloc.dll

fcalloc.dll

The module fcalloc.dll has been detected as Worm.Ramnit

fcalloc.dll

fcalloc.dll is a Windows file recorded in the ThreatInfo database. It is associated with Acronis Fomatik Memory Manager. The reported company name is Acronis. The current detection status is Worm.Ramnit, based on the latest analysis from 2021-01-06 08:02:50 (5 years ago).

If fcalloc.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Worm.Ramnit.

Product Name: Acronis Fomatik Memory Manager
Company Name: Acronis
MD5: 1ec2cdf1a3e9b62d661647c5c035fa34
Size: 99 KB
First Published: 2021-01-06 08:02:50 (5 years ago)
Latest Published: 2021-01-06 08:02:50 (5 years ago)
Status: Worm.Ramnit (on last analysis)
Analysis Date: 2021-01-06 08:02:50 (5 years ago)
%commondir%\acronis

ThreatInfo has observed fcalloc.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Philippines with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 7 100.0%

The most common operating system signal for fcalloc.dll is Windows 7 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

fcalloc.dll is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x10000000
Entry Address: 0x00006000

PE Sections:

Name Size of data MD5
.text 3584 5ad5551a45816d135c5642cefbfa1b3a
.rdata 2048 26aa313840dd29077e48fcee2f79d491
.data 512 1c8c4939b1e2230181c964b5644c2699
.rsrc 1024 9204a4b63b2b38c137433d30559e74f8
.reloc 1536 ff949e212d4284a7135e74503ff14be0
.text 91648 fd9289849b891eb4e033b2e2c6db208a

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for fcalloc.dll