How to remove ps.exe
ps.exe
The module ps.exe has been detected as Ransom.Wacatac
File Details
| Product Name: | Punto Switcher |
| Company Name: | ООО Яндекс |
| MD5: | 504ef85343be74d746c4f97891875373 |
| Size: | 2 MB |
| First Published: | 2018-02-01 20:07:48 (7 years ago) |
| Latest Published: | 2022-03-31 23:59:06 (3 years ago) |
| Status: | Ransom.Wacatac (on last analysis) | |
| Analysis Date: | 2022-03-31 23:59:06 (3 years ago) |
Common Places:
| %programfiles%\total commander\utils |
| %sysdrive%\!distrib\total commander 704a\utils |
| %sysdrive%\программы\диск win xp sp 3 и доп проги\grtmpvol_ru\mcpe\commander\utils |
| %programfiles%\total commander\utils |
Geography:
| 71.4% | ||
| 28.6% |
OS Version:
| Windows 7 | 100.0% |
Analysis
| Subsystem: | Windows GUI |
| PE Type: | pe |
| OS Bitness: | 32 |
| Image Base: | 0x00400000 |
| Entry Address: | 0x00001abb |
PE Sections:
| Name | Size of data | MD5 |
| .text | 7168 | 2232dbd9bb1e146a0a0084ef5b518b91 |
| .res | 16656 | f441ea7e637552cabd6bb17f4d9e0c7e |
More information:
Download GridinSoft
Anti-Malware - Removal tool for ps.exe