How to remove psftp.exe
psftp.exe
The module psftp.exe has been detected as Trojan.Emotet
File Details
Product Name: | PuTTY suite |
Company Name: | Simon Tatham |
MD5: | c2d629c167248dbb99f4aa8e036f9f31 |
Size: | 628 KB |
First Published: | 2018-08-03 13:07:27 (6 years ago) |
Latest Published: | 2018-08-07 04:12:27 (6 years ago) |
Status: | Trojan.Emotet (on last analysis) | |
Analysis Date: | 2018-08-07 04:12:27 (6 years ago) |
Overview
Signed By: | Simon Tatham |
Status: | Valid |
Common Places:
%programfiles% |
%programfiles%\wscc3\other utilities |
%sysdrive% |
Geography:
22.0% | ||
17.1% | ||
7.3% | ||
4.9% | ||
4.9% | ||
4.9% | ||
4.9% | ||
4.9% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% | ||
2.4% |
OS Version:
Windows 10 | 70.5% | |
Windows 7 | 25.0% | |
Windows 8.1 | 4.5% |
Analysis
Subsystem: | Windows CUI |
PE Type: | pe |
OS Bitness: | 64 |
Image Base: | 0x0000000140000000 |
Entry Address: | 0x000781d0 |
PE Sections:
Name | Size of data | MD5 |
.00cfg | 512 | 242c61d6c86ff1c7658f416a6a4db66b |
.rdata | 130560 | 071f55e8bad711237456d86d740a9772 |
.bss | 0 | 00000000000000000000000000000000 |
.data | 4608 | 354d4456bcd5dc5dfc6b916b37e7cc54 |
.gfids | 512 | febdae1c5b761f9706b15389b01943b2 |
.pdata | 17920 | 4602143ceb89db1b8bf9d38932bebf8b |
.rsrc | 5632 | 2d6c1c91bfe138b7b7ef077e34813dbc |
.text | 437248 | 224c81fe9b97f2019a0580217fc28f5f |
.xdata | 23040 | dfffde99cb6af5a3dd49ca26a64c7f35 |
.idata | 5632 | 117b3eb5f0ba0183ad78ff7a4fa08334 |
.reloc | 4096 | 44d4ad65556ec8883c136377edf23b29 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for psftp.exe