How to remove PSCP.EXE
PSCP.EXE
The module PSCP.EXE has been detected as Trojan.Emotet
File Details
Product Name: | PuTTY suite |
Company Name: | Simon Tatham |
MD5: | 0d523eb45150009f2b8b3758c4ffbb6a |
Size: | 542 KB |
First Published: | 2018-08-03 16:12:05 (6 years ago) |
Latest Published: | 2018-08-07 05:05:35 (6 years ago) |
Status: | Trojan.Emotet (on last analysis) | |
Analysis Date: | 2018-08-07 05:05:35 (6 years ago) |
Overview
Signed By: | Simon Tatham |
Status: | Valid |
Common Places:
%programfiles% |
%programfiles%\wscc3\other utilities |
%desktop%\portable\122_portable_prog\portableapps\puttyportable\app |
File Names:
pscp.exe |
PSCP.EXE |
Geography:
20.0% | ||
20.0% | ||
10.0% | ||
10.0% | ||
10.0% | ||
10.0% | ||
10.0% | ||
10.0% |
OS Version:
Windows 10 | 60.0% | |
Windows 7 | 40.0% |
Analysis
Subsystem: | Windows CUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x000651bd |
PE Sections:
Name | Size of data | MD5 |
.00cfg | 512 | 32368be28c4ebc4ec03e63746e953288 |
.rdata | 109568 | c741bb3940f7253f5a419b895e39237b |
.bss | 0 | 00000000000000000000000000000000 |
.data | 3072 | 7b6af43d528a126674b3a8263ff1367f |
.gfids | 512 | c8bf52aae712f35c902ec5b86607a0c1 |
.rsrc | 5632 | 322b630d87e64f19063a165fb87a8421 |
.text | 398336 | 28c533393fbae452c93f012173ac3a14 |
.xdata | 2048 | 5d7fc2c15affe077daad83feafdfe2e3 |
.idata | 4096 | 8c4530ffb24549eb3f7c5b004b2a6c11 |
.reloc | 17920 | aa27307af8d435354b5090b3b492f04f |
More information:
Download GridinSoft
Anti-Malware - Removal tool for PSCP.EXE