How to remove confserv.exe
- File Details
- Overview
- Analysis
confserv.exe
The module confserv.exe has been detected as Trojan.Heur!
File Details
Product Name: |
|
Company Name: |
|
MD5: |
d49de130155cefb029c32977d8756da6 |
Size: |
9 MB |
First Published: |
2020-08-14 22:22:02 (4 years ago) |
Latest Published: |
2021-01-11 15:26:30 (4 years ago) |
Status: |
Trojan.Heur! (on last analysis) |
|
Analysis Date: |
2021-01-11 15:26:30 (4 years ago) |
%sysdrive%\gcti |
%sysdrive%\gcti |
%sysdrive%\gcti |
%sysdrive%\gcti |
%sysdrive%\gcti |
%sysdrive%\gcti |
Windows Server 2012 |
100.0% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x00118a10 |
Name |
Size of data |
MD5 |
.text |
6386176 |
6175b264a6058d1242559acf50e85284 |
fipstx |
218112 |
3deca3ba0f4eba29a43525b30aeaa77f |
.textidx |
859648 |
eb31348e3eb7b7d89c682229619069fa |
.rdata |
1576960 |
19370bff684e241c94a7c9f35a9ec339 |
.data |
346624 |
c7cc5e1e80b908c239c245637049dec4 |
.pdata |
348672 |
7598f7852e35bea8b5eb5dab6a415fc2 |
fipsrd |
13824 |
2463e6671bd0ba7c3391ec6521a3a09d |
fipsda |
6656 |
aa43ceb5b3a541703975f918fbaa895e |
fipsro |
45568 |
ea3c99719436193e4bf30fe7a953b9eb |
.rsrc |
2560 |
f3299ae257d06061cb1364aceed6ae43 |