How to remove ctsbldm.exe
- File Details
- Overview
- Analysis
ctsbldm.exe
The module ctsbldm.exe has been detected as Ransom.Exp
File Details
Product Name: |
|
Company Name: |
|
MD5: |
2c45b9f0a398d44a7303655c68d42bd5 |
Size: |
1 MB |
First Published: |
2021-01-05 10:37:59 (4 years ago) |
Latest Published: |
2021-01-10 00:33:27 (4 years ago) |
Status: |
Ransom.Exp (on last analysis) |
|
Analysis Date: |
2021-01-10 00:33:27 (4 years ago) |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
Windows Server 2016 |
100.0% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000f7962 |
Name |
Size of data |
MD5 |
.text |
1469952 |
a3818fd98fcee5f17907a93883fc185e |
.rdata |
79360 |
f0bf0bf142c8f4cb8ba6dd50ebb1d32b |
.data |
112640 |
0ac68c38f66432bddfbdc8cc7b71f8db |
.idata |
4608 |
0c4d3b72b2897cb2e1c532c3c78d845e |
.rsrc |
2048 |
a564160520fa7a512f4d23f855a894e4 |
.reloc |
39936 |
3fd44167e26b3f207f3bc33bc3696cc5 |