How to remove cp[1].exe
cp[1].exe
The module cp[1].exe has been detected as Ransom.Sabsik
File Details
| Product Name: | QlikView |
| Company Name: | QlikTech International AB |
| MD5: | a47cecc3d3d5445ff24766a9835b545a |
| Size: | 5 MB |
| First Published: | 2023-11-19 23:49:05 (2 years ago) |
| Latest Published: | 2023-12-03 23:03:58 (2 years ago) |
| Status: | Ransom.Sabsik (on last analysis) | |
| Analysis Date: | 2023-12-03 23:03:58 (2 years ago) |
Overview
| Signed By: | Sony SEL-55210 55-210mm F4.5-6.3 |
| Status: | Valid |
Common Places:
| %localappdata%\microsoft\windows\inetcache\ie |
| %temp% |
Geography:
| 50.0% | ||
| 50.0% |
OS Version:
| Windows 10 | 100.0% |
Analysis
| Subsystem: | Windows GUI |
| PE Type: | pe |
| OS Bitness: | 32 |
| Image Base: | 0x00400000 |
| Entry Address: | 0x00d272ae |
PE Sections:
| Name | Size of data | MD5 |
| 0 | d41d8cd98f00b204e9800998ecf8427e | |
| 0 | d41d8cd98f00b204e9800998ecf8427e | |
| 0 | d41d8cd98f00b204e9800998ecf8427e | |
| 0 | d41d8cd98f00b204e9800998ecf8427e | |
| 0 | d41d8cd98f00b204e9800998ecf8427e | |
| .imports | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .|Tracer | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .themida | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .boot | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .|Tracer | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .*IPTV*0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .*IPTV*1 | 1024 | 7e671e2cea530b89b021bfe10ffaf273 |
| .*IPTV*2 | 5459456 | 2fb4feb30c37b3dda175735d2d56264c |
| .reloc | 7168 | b19489b762cd556536cccf76e1dd2754 |
| .rsrc | 124928 | e187038b2211cd588f80a412b949cb25 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for cp[1].exe