WechatVideoSniffer Trojan Wacatac Analysis

Trojan Wacatac
Updated on 2024-07-03 (2 days ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.181.174
DB Version:2024-07-03 04:00:26

Ransom.Win32.Wacatac.oa!s1

Wacatac is a type of malware that falls under the wide category of computer viruses. It is known for its malicious capabilities, which include data theft, system compromise, and the execution of additional malicious payloads on the infected system like ransomware.

FileWechatVideoSniffer
Checked2024-07-03 02:06:04
MD5cc67e72cfa52b8050aa35a249d351674
SHA175ae30b15bdb3c0d244a9c7f2ef12af0401fec91
SHA256b7c81ebeab46a9cb61ec2fe30475aff39ffbd804d05a8ce166dcd0456797c156
SHA512c0436356c019b320f2c30497de593379a8652686326259a9495253385cbaf4c443fd755cada7bad4fb88433d40d66049cf7936d1af2e4d8c3dfa98b8e267ab01
Imphashb73463e2c02bcc27c18c5f758c7fc511
File Size4274688 bytes

Ransom.Win32.Wacatac.oa!s1 Removal

Ransom.Win32.Wacatac.oa!s1 Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win32.Wacatac.oa!s1 without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

CompanyName单位名称
FileDescriptionWechatVideoSniffer
FileVersion0.0.0.7
InternalNameWechatVideoSniffer
LegalCopyrightCopyright (C) 作者 2022
OriginalFilenameWechatVideoSniffer.exe
ProductNameWechatVideoSniffer
ProductVersion0.0.0.7
Translation0x0009 0x04b0

Portable Executable Info

0304a765b7d1981a90d07ce1b4f8148c
00f093ca5233c12c497c0f3fc1557273
909280a2a280a2a0
Image Base:0x00400000
Entry Point:0x0046f1ee
Compilation:2022-12-21 16:51:43
Checksum:0x00000000 (Actual: 0x00417c1c)
OS Version:4.1
PEiD:PE32 executable (GUI) Intel 80386, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:4
Imports: KERNEL32, USER32, ole32, SHLWAPI, GDI32, ADVAPI32, SHELL32, OLEAUT32,
Exports: 0
Resources:90

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x000922c2 0x00092400 f87af54c87c8760b49f0c4c587e06086 6.66
.rdata 0x00094000 0x0001a946 0x0001aa00 4e6d0aa1e99c1792f2a817b35d126fb6 6.15
.data 0x000af000 0x00004ab8 0x00002600 41b0bbace0709f7b462c7c745275d11b 4.70
.rsrc 0x000b4000 0x003640d0 0x00364200 5eae88d1caadb340d52f8188662a8392 5.64

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware