How to remove ps.exe

ps.exe

The module ps.exe has been detected as Ransom.Wacatac

ps.exe
Product Name:

Punto Switcher

Company Name:

ООО Яндекс

MD5: 504ef85343be74d746c4f97891875373
Size: 2 MB
First Published: 2018-02-01 20:07:48 (6 years ago)
Latest Published: 2022-03-31 23:59:06 (2 years ago)
Status: Ransom.Wacatac (on last analysis)
Analysis Date: 2022-03-31 23:59:06 (2 years ago)
%programfiles%\total commander\utils
%sysdrive%\!distrib\total commander 704a\utils
%sysdrive%\программы\диск win xp sp 3 и доп проги\grtmpvol_ru\mcpe\commander\utils
%programfiles%\total commander\utils
71.4%
28.6%
Windows 7 100.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00001abb

PE Sections:

Name Size of data MD5
.text 7168 2232dbd9bb1e146a0a0084ef5b518b91
.res 16656 f441ea7e637552cabd6bb17f4d9e0c7e

More information:

Download GridinSoft Anti-Malware - Removal tool for ps.exe