How to remove $RDAQHEW.dll
- File Details
- Overview
- Analysis
$RDAQHEW.dll
The module $RDAQHEW.dll has been detected as Risk.RemoteAdmin
File Details
Product Name: |
|
Company Name: |
|
MD5: |
bfbc65b145b14299353b0d05af55da13 |
Size: |
25 KB |
First Published: |
2017-08-20 12:09:43 (7 years ago) |
Latest Published: |
2018-09-12 05:03:57 (6 years ago) |
Status: |
Risk.RemoteAdmin (on last analysis) |
|
Analysis Date: |
2018-09-12 05:03:57 (6 years ago) |
Overview
%programfiles%\opiekunnet\konsola\vnc\driver\vista64\driver |
%windir%\system32 |
%system%\driverstore\filerepository\mv2.inf_amd64_neutral_33f6848fb0f6ad6d |
%sysdrive%\$recycle.bin\s-1-5-21-3440705321-3869224375-2206127129-1001 |
%programfiles%\ultravnc\driver\vista64\driver |
%programfiles%\izex\nethelper client v7.0 x64 |
%system% |
%programfiles%\ultravnc\driver\vista64 |
%sysdrive%\vnc\drivers\vista64 |
%programfiles%\izex |
mv2.dll |
$RDAQHEW.dll |
vista_mv2.dll |
|
47.8% |
|
|
28.3% |
|
|
13.0% |
|
|
4.3% |
|
|
4.3% |
|
|
2.2% |
|
Windows 7 |
73.9% |
|
Windows 10 |
23.9% |
|
Windows Server 2008 R2 |
2.2% |
|
Analysis
Subsystem: |
Native |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000000010000 |
Entry Address: |
0x000037a0 |
Name |
Size of data |
MD5 |
.text |
11776 |
fe6a22b0809da2819363b47c63767981 |
.rdata |
1536 |
fe4e265f4149446724617cf4177603d4 |
.data |
1536 |
b929baa99d75603f419d355cb0a67d0a |
.pdata |
512 |
29cb4af2995ab1f887393ca4473ce100 |
INIT |
1024 |
2f721197e8566a5eb1129b127ab0ee1a |
.rsrc |
1024 |
f3d98a0f0fa3d469c0a94d3648275690 |
.reloc |
512 |
68abe6381d8adc22b5cd740f481d38fa |