RemoveWAT.exe

RemoveWAT

Product:
RemoveWAT

Version:
1.5.0.0

MD5:
45deff8b03e81491892e9b00af41e485

SHA-1:
aef2d12d266e32f2cb12a4bd632a200b8d8df8a0

SHA-256:
354d3cb3b18960839fc5028cb51867b21d8186eed09bfdf39db103c2f82f1d34

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 12:39:18 PM UTC  (today)

File size:
1.4 MB (1,422,336 bytes)

Product version:
1.5.0.0

Original file name:
RemoveWAT.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\removewat.exe

File PE Metadata
Compilation timestamp:
10/24/2009 2:43:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:FSXISXhzmx3+ea/03J4fH8tJomCy3/WLY:SHh6xOeTZ4fcPom1Y

Entry address:
0x12FA0E

Entry point:
60, 01, EE, C1, D6, 65, 47, E8, 0A, 00, 00, 00, 64, 8D, F6, 19, E2, DB, 5F, B2, 84, 04, 6A, 8A, 6A, 74, E8, 90, 16, 00, 00, 58, 5B, 33, DD, 0F, A5, F7, 5B, 33, EE, 0F, CF, FF, C1, 72, 0E, 31, F5, 0F, B7, FD, 0F, C1, C8, C7, C1, 84, 37, 1E, 69, 81, C3, F6, 23, 4B, 00, 84, EC, 41, 8D, 3D, 34, 27, 4E, D9, 0F, BE, C6, 41, 81, EB, 10, 3E, 49, 00, FF, C1, 0F, C1, C8, 8B, C3, 89, F9, F3, FF, C1, 8B, CF, 50, 3B, C2, F3, 0F, A5, C1, B9, C9, 68, 8B, 22, 73, 17, 52, C7, C1, 01, C0, 83, 3A, 18, D6, 0F, BA, E5, B5, 58...
 
[+]

Entropy:
5.7586

Code size:
1.2 MB (1,235,968 bytes)

The file RemoveWAT.exe has been seen being distributed by the following URL.

Scan RemoveWAT.exe - Powered by Reason Core Security