How to remove ctupdpad.exe
- File Details
- Overview
- Analysis
ctupdpad.exe
The module ctupdpad.exe has been detected as Ransom.Exp
File Details
Product Name: |
|
Company Name: |
|
MD5: |
48bf8d50f73ba3168d8eaed490f15f82 |
Size: |
1 MB |
First Published: |
2021-01-05 10:37:51 (4 years ago) |
Latest Published: |
2021-01-10 00:34:12 (4 years ago) |
Status: |
Ransom.Exp (on last analysis) |
|
Analysis Date: |
2021-01-10 00:34:12 (4 years ago) |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
%desktop%\dbfilesfromrecyc\schuyler\faircom\win32\tools\cmdline\utils |
%sysdrive%\schuyler\faircom\win32\tools\cmdline\utils |
Windows Server 2016 |
100.0% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000f82a3 |
Name |
Size of data |
MD5 |
.text |
1471488 |
0347c16502957c7b3e4ef7a5e04944e2 |
.rdata |
79360 |
4852401f21855769f11e761488cb6465 |
.data |
113664 |
ad27c16d6a71fc74cf170fd82bb31694 |
.idata |
4608 |
776ee27924e1966b80c069817b4cb1d6 |
.rsrc |
2048 |
2c322f03d2aed6346f9758ae7c3a2c11 |
.reloc |
39936 |
7622ba53ed00d73a462c0a4d55697ebe |