How to remove ctsqlmgr.exe
- File Details
- Overview
- Analysis
ctsqlmgr.exe
The module ctsqlmgr.exe has been detected as Ransom.Exp
File Details
Product Name: |
|
Company Name: |
|
MD5: |
8117956e6a48c5a8cebbdafa87846e31 |
Size: |
1 MB |
First Published: |
2021-01-05 10:38:46 (4 years ago) |
Latest Published: |
2021-01-10 00:35:04 (4 years ago) |
Status: |
Ransom.Exp (on last analysis) |
|
Analysis Date: |
2021-01-10 00:35:04 (4 years ago) |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
Windows Server 2016 |
100.0% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000f9613 |
Name |
Size of data |
MD5 |
.text |
1474560 |
7c81afdb9e0907a5712b06049395e108 |
.rdata |
79360 |
ebf8b73d163205b5e8adbdc571b8584a |
.data |
113152 |
21af49f69541cb6f5147f2f08bac25dc |
.idata |
4608 |
59ee672cf8ca766e634db25b17fa4f02 |
.rsrc |
2048 |
ae832f0dfe6df5d9a697c50a4d4e70cf |
.reloc |
39936 |
381fe1e06f7f150d6912aa89cca02529 |