How to remove $RDMM2VN.exe
- File Details
- Overview
- Analysis
$RDMM2VN.exe
The module $RDMM2VN.exe has been detected as Adware.Babylon
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
cf5a1d1a6b12962b47a832654d821214 |
| Size: |
148 KB |
| First Published: |
2017-12-27 13:02:27 (8 years ago) |
| Latest Published: |
2021-01-12 16:38:22 (5 years ago) |
| Status: |
Adware.Babylon (on last analysis) |
|
| Analysis Date: |
2021-01-12 16:38:22 (5 years ago) |
Overview
| %programfiles%\babylon |
| %appdata%\zhp\quarantine\babylon |
| %sysdrive%\office\babylon |
| %sysdrive%\$recycle.bin |
| %appdata%\zhp\quarantine\zhpcleaner\babylon |
| %programfiles%\babylon |
| %programfiles%\babylon |
| %programfiles%\babylon |
| %programfiles%\babylon |
| %programfiles%\babylon |
| BabylonHelper64.exe |
| $RDMM2VN.exe |
|
24.8% |
|
|
9.9% |
|
|
9.2% |
|
|
7.1% |
|
|
2.8% |
|
|
2.8% |
|
|
2.8% |
|
|
2.8% |
|
|
2.1% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
| Windows 10 |
74.1% |
|
| Windows 7 |
23.1% |
|
| Windows 8.1 |
2.1% |
|
| Windows Server 2016 |
0.7% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
64 |
| Image Base: |
0x0000000140000000 |
| Entry Address: |
0x000079b8 |
| Name |
Size of data |
MD5 |
| .text |
76288 |
a110d684ac2e1f45db9320dda2e67949 |
| .rdata |
52736 |
271cfeb05c8a5b366905e43ba58fd1f5 |
| .data |
4608 |
de03663345fcd753b942dfcd5822eea2 |
| .pdata |
5632 |
6023dbec4c42e12b4127f9ff2cb2332a |
| .tls |
512 |
1f354d76203061bfdd5a53dae48d5435 |
| .gfids |
512 |
fe74de2ec18723d65cc64246abd42e6c |
| .rsrc |
2048 |
4c3f29cbf57d9eb6cf88fa5b06e271ba |
| .reloc |
2048 |
1e3291bd4eaa930c27aa29c9efc3848a |