How to remove ctflvrfy.exe
            
        
    
    
    
    
    
        
            
                
                    
                    - File Details
- Overview
- Analysis
 
            
                ctflvrfy.exe
                
                The module ctflvrfy.exe has been detected as Ransom.Exp
                
                
                
                
                File Details
                
                
                    
                        
                            
                            
                        
                        
                        
                            | Product Name: |  | 
                        
                        
                        
                            | Company Name: |  | 
                        
                        
                            | MD5: | 00e44eb733d07e6b41873598cf0de8d3 | 
                        
                        
                        
                            | Size: | 1 MB | 
                        
                        
                            | First Published: | 2021-01-05 10:38:48 (4 years ago) | 
                        
                            | Latest Published: | 2021-01-10 00:34:00 (4 years ago) | 
                    
                 
                
                
                    
                        
                            
                            
                        
                        
                            | Status: | Ransom.Exp (on last analysis) |  | 
                        
                            | Analysis Date: | 2021-01-10 00:34:00 (4 years ago) | 
                    
                 
                
                
                
                
                    
                        
                        
                            
                                | %sysdrive%\schuyler\faircom\win32\tools\cmdline\utils | 
                        
                        
                            
                                | %desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils | 
                        
                        
                            
                                | %desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils | 
                        
                        
                            
                                | %sysdrive%\schuyler\faircom\win32\tools\cmdline\utils | 
                        
                        
                            
                                | %desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils | 
                        
                        
                            
                                | %sysdrive%\schuyler\faircom\win32\tools\cmdline\utils | 
                        
                    
                 
                
                
                
                
                
                
                
                
                
                
                
                    
                        
                        
                            | Windows Server 2016 | 100.0% |  | 
                        
                    
                 
                
                
                
                
                Analysis
                
                
                
                    
                        
                            
                            
                        
                        
                        
                            | Subsystem: | Windows CUI | 
                        
                            | PE Type: | pe | 
                        
                            | OS Bitness: | 32 | 
                        
                        
                            | Image Base: | 0x00400000 | 
                        
                            | Entry Address: | 0x000f8a78 | 
                    
                 
                
                
                
                
                
                    
                        
                            
                            
                            
                        
                        
                            | Name | Size of data | MD5 | 
                        
                        
                            | .text | 1474560 | 420d2934949b466bf2db3c6e58e63f1a | 
                        
                        
                            | .rdata | 79872 | fdf55530d0d4bb25eb6d7861e8d814b7 | 
                        
                        
                            | .data | 116224 | 52a23e00bc81eb9ce51e5475a2fab310 | 
                        
                        
                            | .idata | 4608 | 7c600b723556dc691e4e3aad203a556d | 
                        
                        
                            | .rsrc | 2048 | 73eb0b767e93be8ae73e1ed248955641 | 
                        
                        
                            | .reloc | 40448 | cc240df994447482f07fc7aeef9404b6 |