How to remove 505040.exe
505040.exe
The module 505040.exe has been detected as Backdoor.DarkKomet
![Remove Backdoor.DarkKomet 505040.exe](/screens/screen-61a89ffcdf0b19b4ff0651de8cb898c7.png)
File Details
Product Name: | VirtualDub |
MD5: | 61a89ffcdf0b19b4ff0651de8cb898c7 |
Size: | 174 KB |
First Published: | 2017-07-21 23:11:14 (7 years ago) |
Latest Published: | 2018-07-23 07:10:49 (6 years ago) |
Status: | Backdoor.DarkKomet (on last analysis) | |
Analysis Date: | 2018-07-23 07:10:49 (6 years ago) |
Common Places:
%sysdrive% |
%windir% |
File Names:
windrv.exe |
505040.exe |
winmgr.exe |
Geography:
66.7% | ||
33.3% |
OS Version:
Windows 7 | 100.0% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00003217 |
PE Sections:
Name | Size of data | MD5 |
.text | 23552 | 92032f5e50e74fe0fe80a33ba4ca92db |
.rdata | 4608 | 5801d712ecba58aa87d1e7d1aa24f3aa |
.data | 1024 | f2470ac8847791744aff280e7e2f5353 |
.ndata | 0 | 00000000000000000000000000000000 |
.rsrc | 111104 | ba554fbbedf5e0d94019cb7a47955e66 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for 505040.exe
![copyright for information about 505040.exe](/images/copyright.png)