How to remove PSCP.EXE

PSCP.EXE

The module PSCP.EXE has been detected as Trojan.Emotet

PSCP.EXE
Product Name:

PuTTY suite

Company Name:

Simon Tatham

MD5: b3135736bcfdab27f891dbe4009a8c80
Size: 350 KB
First Published: 2018-08-03 16:12:52 (6 years ago)
Latest Published: 2018-08-07 06:10:51 (6 years ago)
Status: Trojan.Emotet (on last analysis)
Analysis Date: 2018-08-07 06:10:51 (6 years ago)
Signed By: Simon Tatham
Status: Valid
%programfiles%\matlab\r2017a\toolbox\idelink\foundation
%sysdrive%\torrent\mydisc\defence\puttyportable\app
%programfiles%
%programfiles%\veeam\backup and replication\console
%programfiles%\veeam\backup and replication\backup
%sysdrive%\wkprogramfiles\putty
%sysdrive%\wkprogramfiles
pscp.exe
PSCP.EXE
44.4%
22.2%
11.1%
11.1%
11.1%
Windows 10 55.6%
Windows 7 22.2%
Windows Server 2012 R2 22.2%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x000370ed

PE Sections:

Name Size of data MD5
.text 253952 c3989da3558eea92cb8da5f910592877
.rdata 77824 1e9ef13028384594848359c51918027d
.data 8192 f80f74c998ac1a844fbe0ee428b6427c
.rsrc 8192 0533f72ec211169e19f96440da800e28

More information:

Download GridinSoft Anti-Malware - Removal tool for PSCP.EXE