How to remove Futytiwuzhy.exe

Futytiwuzhy.exe

The module Futytiwuzhy.exe has been detected as Ransom.Sabsik

Futytiwuzhy.exe

Futytiwuzhy.exe is a Windows file recorded in the ThreatInfo database. It is associated with monitor_software_GXvrDN73S8NaTKhD_system_utilities. The reported company name is monitor_software_GXvrDN73S8NaTKhD_system_utilities. The current detection status is Ransom.Sabsik, based on the latest analysis from 2021-12-08 21:11:03 (4 years ago).

If Futytiwuzhy.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Ransom.Sabsik.

Product Name: monitor_software_GXvrDN73S8NaTKhD_system_utilities
Company Name: monitor_software_GXvrDN73S8NaTKhD_system_utilities
MD5: 7fc8fd28d0ff2a056326f26bc2b2da85
Size: 349 KB
First Published: 2021-12-06 21:09:35 (4 years ago)
Latest Published: 2021-12-08 21:11:03 (4 years ago)
Status: Ransom.Sabsik (on last analysis)
Analysis Date: 2021-12-08 21:11:03 (4 years ago)
%temp%
%temp%
%temp%
%temp%
%temp%

ThreatInfo has observed Futytiwuzhy.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

60.0%
40.0%

The strongest geographic signal for this file is Peru with 60.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 66.7%
Windows 7 33.3%

The most common operating system signal for Futytiwuzhy.exe is Windows 10 with 66.7% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

Futytiwuzhy.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0005508e

.NET Info:

MVID: 6e71b352-9091-4214-af7c-8eb5dd827d68
Typelib ID: 4f30169f-941f-40b2-baf7-b5b854e7edda

PE Sections:

Name Size of data MD5
.text 340480 a34b94999da510d8bd6f8094fecff990
.sdata 1024 a3403a82a8d77358d39e09b73e997cdf
.rsrc 14336 b865688836bed6c52d806f02ebadfc2b
.reloc 512 320542d4ba8316619ee0837c3cf6f666

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for Futytiwuzhy.exe