How to remove $RQ1LCRV.exe
- File Details
- Overview
- Analysis
$RQ1LCRV.exe
The module $RQ1LCRV.exe has been detected as Risk.RemoteAdmin
File Details
Product Name: |
|
Company Name: |
|
MD5: |
20a8c3a12f4d3390623b3219129fa3e9 |
Size: |
1 MB |
First Published: |
2017-08-14 13:14:21 (7 years ago) |
Latest Published: |
2018-08-15 02:11:32 (6 years ago) |
Status: |
Risk.RemoteAdmin (on last analysis) |
|
Analysis Date: |
2018-08-15 02:11:32 (6 years ago) |
Overview
%programfiles%\ultravnc |
%sysdrive%\ubcd4win\plugin\network\ultravnc\files |
%sysdrive%\$recycle.bin\s-1-5-21-2087035277-3798034300-3097854789-1002 |
%sysdrive%\ubcd4win\plugin\network\ultravnc |
%desktop%\backup\recovered data 09-12-2016 at 22_05_51\ntfs 0\ubcd4win\plugin\network\ultravnc |
%desktop%\backup\recovered data 09-13-2016 at 11_22_46\ntfs 0\ubcd4win1\plugin\network\ultravnc |
%desktop%\backup\recovered data 09-12-2016 at 22_05_51\ntfs 0\ubcd4win1\plugin\network\ultravnc |
%desktop%\backup\recovered data 09-13-2016 at 11_22_46\ntfs 0\ubcd4win\plugin\network\ultravnc |
%programfiles% |
%sysdrive%\$recycle.bin\s-1-5-21-1902188588-496605031-3941538261-1000\$ru2w0n8\plugin\network\ultravnc |
vncviewer.exe |
$RQ1LCRV.exe |
|
52.9% |
|
|
17.6% |
|
|
11.8% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
Windows 10 |
58.8% |
|
Windows 7 |
23.5% |
|
Windows Vista |
11.8% |
|
Windows 8 |
5.9% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0003eafb |
Name |
Size of data |
MD5 |
.text |
653824 |
3331f0331c6918eb8c39fe75add28e3c |
.rdata |
102400 |
62e1a76c1e2ec04fd880926e031f0492 |
.data |
10240 |
b16b1e12c3649406ab99cb0d47a5f5bf |
.rsrc |
781312 |
fd6ba26d978be413262cd8217df87d16 |