Gridinsoft Logo

Patch.exe Trojan Wacatac Analysis

Trojan Wacatac
Updated on 2024-07-02 (3 months ago)
Checked by Online Virus Scanner
Online Virus Checker v.1.0.181.174
DB Version: 2024-07-02 00:00:16

Ransom.Win32.Wacatac.sa

Wacatac is a type of malware that falls under the wide category of computer viruses. It is known for its malicious capabilities, which include data theft, system compromise, and the execution of additional malicious payloads on the infected system like ransomware.

File Patch.exe
Checked 2024-07-01 22:03:25
MD5 b26a4b5fb6fc09689ffcc83ad1635c17
SHA1 7c047e6d2fb7a55f583d41ec6484b62300a2a683
SHA256 52104d3d55eea30c34424fc7df94bea2df81d0ace2a579f814bcd743ae345841
SHA512 5478673949ec1b4d9d1dcb4cffa48433613b27539c5b1bf5641e8a5371300215fb0a884ba614fab198173b17f18779ff49de69a4565e2a880fc1e39f1e4a63d3
Imphash f998c3a833cca013c7d8886746579fb5
File Size 33625088 bytes

Ransom.Win32.Wacatac.sa Removal

Ransom.Win32.Wacatac.sa Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win32.Wacatac.sa without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

Portable Executable Info

790085edb50eeff302202bce64fd72da
13ffa692814b8b2839341948a9a9213e
80e0709a5e5a5910
Image Base: 0x00400000
Entry Point: 0x00401000
Compilation: 2011-02-22 19:44:08
Checksum: 0x00000000 (Actual: 0x02012318)
OS Version: 4.0
PEiD: PE32 executable (GUI) Intel 80386, for MS Windows
Sign: The PE file does not contain a certificate table.
Sections: 6
Imports: kernel32, user32, shell32, gdi32, advapi32, comdlg32, oleaut32,
Exports: 0
Resources: 46

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
0x00001000 0x00009000 0x00003400 81997c85f2bbecd57c62e0e8acde9d13 7.99
0x0000a000 0x00001000 0x00000e00 8b117b1599d328f3f8b5cc2684895035 7.94
0x0000b000 0x00014000 0x00000400 f1bc9f25bbadf6999475662feea8aecb 7.81
.rsrc 0x0001f000 0x021c1000 0x01fbe800 1842ac0e47281baaab85ef98b1523dfc 8.00
.data 0x021e0000 0x0004f000 0x0004e200 0883180b217233c1938b07492f402f20 7.75
.adata 0x0222f000 0x00001000 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00

1 comment(s)

AL
aldo
🕓 Feb 24, 2024

the best

Leave a comment *

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware