How to remove $RW5FY1F.dll
- File Details
- Overview
- Analysis
$RW5FY1F.dll
The module $RW5FY1F.dll has been detected as Risk.RemoteAdmin
File Details
Product Name: |
|
Company Name: |
|
MD5: |
b309f4ee61e3f4c31cff648f31af5b06 |
Size: |
127 KB |
First Published: |
2017-08-14 13:14:21 (7 years ago) |
Latest Published: |
2018-09-20 00:08:29 (6 years ago) |
Status: |
Risk.RemoteAdmin (on last analysis) |
|
Analysis Date: |
2018-09-20 00:08:29 (6 years ago) |
Overview
%programfiles%\ultravnc |
%sysdrive%\ubcd4win\plugin\network\ultravnc\files |
%sysdrive%\$recycle.bin\s-1-5-21-2087035277-3798034300-3097854789-1002 |
%sysdrive%\ubcd4win\plugin\network\ultravnc |
%desktop%\backup\recovered data 09-13-2016 at 11_22_46\ntfs 0\ubcd4win\plugin\network\ultravnc |
%desktop%\backup\recovered data 09-12-2016 at 22_05_51\ntfs 0\ubcd4win\plugin\network\ultravnc |
%desktop%\backup\recovered data 09-12-2016 at 22_05_51\ntfs 0\ubcd4win1\plugin\network\ultravnc |
%desktop%\backup\recovered data 09-13-2016 at 11_22_46\ntfs 0\ubcd4win1\plugin\network\ultravnc |
%programfiles% |
%commonappdata%\cadent\alignsupport |
vnchooks.dll |
$RW5FY1F.dll |
|
47.8% |
|
|
17.4% |
|
|
8.7% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
Windows 10 |
56.5% |
|
Windows 7 |
39.1% |
|
Windows 8 |
4.3% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x10000000 |
Entry Address: |
0x000027d8 |
Name |
Size of data |
MD5 |
.text |
96768 |
48cc158c6d9e984983406f277a7b948d |
.rdata |
15360 |
62918fe6ea9c205719bbdd1958e31cce |
.data |
3584 |
1167f95de1c26975d3d57b41e05be61b |
.SharedD |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.rsrc |
2048 |
8a2a52adfdbeee13bcfe2a282adf186f |
.reloc |
5632 |
4b760348850d2ae218a1ccbfe5fecd34 |