How to remove $RTC79WN.exe

$RTC79WN.exe

The module $RTC79WN.exe has been detected as Trojan.Agent

$RTC79WN.exe
MD5: ac64a4f2426a765c35e82ca6a82a410f
Size: 2 MB
First Published: 2017-05-25 15:06:11 (6 years ago)
Latest Published: 2020-12-11 06:44:26 (3 years ago)
Status: Trojan.Agent (on last analysis)
Analysis Date: 2020-12-11 06:44:26 (3 years ago)
Signed By: 长沙聚丰网络科技有限公司
Status: Valid
%sysdrive%\$recycle.bin\s-1-5-21-1627889186-2833423570-876032702-1002\$r2v0n2n\chengjisihan4clybl
%desktop%\sango heroes 7
%sysdrive%\新增資料夾\華夏風雲特別版\san11huaxiafy
%sysdrive%\新增資料夾\春秋戰國志\sgz11cqzgz
%profile%\downloads\daisenryakuperfect30\daisenryakuperfect30
%profile%\downloads\fengyunsanguo273
%profile%\downloads\qikan16bei1.3
%sysdrive%\$recycle.bin\s-1-5-21-1550666763-1375613775-4263545339-1000\$ryq5sj6\sanguoshaguiying
%sysdrive%\shanluanshenlesnmdzmcn
%profile%\downloads\xianjianqixiazhuan2v105
PlayGame.exe
$RTC79WN.exe
62.9%
20.0%
7.1%
5.7%
1.4%
1.4%
1.4%
Windows 7 57.1%
Windows 10 40.0%
Windows 8.1 2.9%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00377001

PE Sections:

Name Size of data MD5
CODE 415744 4ee20345a7744f65648920458b9b136b
DATA 6144 d7396cb0b4a6507076524b256f4956d6
BSS 0 00000000000000000000000000000000
.idata 4608 130d8b5c33818ca30072cabaf1e665cd
.tls 0 00000000000000000000000000000000
.rdata 512 90000e41e87803ef9e2934ef7d1d27ab
.reloc 0 00000000000000000000000000000000
.rsrc 1993728 ebfcb8331b06d7281981493b2efc615a
.aspack 99328 dd828b629538d238c1c7180b1dfc2124
.adata 0 00000000000000000000000000000000

More information:

Download GridinSoft Anti-Malware - Removal tool for $RTC79WN.exe