How to remove winvnc.exe
winvnc.exe
The module winvnc.exe has been detected as Risk.RemoteAdmin
File Details
Product Name: | AT@amp;T Research Labs Cambridge - WinVNC |
Company Name: | AT@amp;T Research Labs Cambridge |
MD5: | f58f2f89a111b08a26ead3a8fd56b65c |
Size: | 463 KB |
First Published: | 2017-09-08 08:04:37 (7 years ago) |
Latest Published: | 2020-09-16 06:20:08 (4 years ago) |
Status: | Risk.RemoteAdmin (on last analysis) | |
Analysis Date: | 2020-09-16 06:20:08 (4 years ago) |
Common Places:
%sysdrive%\iso @amp; app\programlar\graphic\cadlink signlab 7.0 revision 1\cadlink signlab 7.0 revision 1\sl7rev1build2 |
%sysdrive%\iso @amp; app\programlar\graphic\signlab_7.7z\cadlink signlab 7.0 revision 1\cadlink signlab 7.0 revision 1\sl7rev1build2 |
%sysdrive%\cadlink |
%sysdrive%\selım flash bellek\111-dosyalar\signlab_7.7z\cadlink signlab 7.0 revision 1\cadlink signlab 7.0 revision 1\sl7rev1build2 |
%sysdrive%\willy\endesarrollo\oficina backup\willy\nueva carpeta\cadlink |
%programfiles% |
%sysdrive%\200 |
%desktop%\stuff\flashdrive backup\software |
%sysdrive%\wintools |
%sysdrive%\恒昶公司\自由時報台北krause裝機及教學影片\krause_training\tiffblaster\install cd 032012\htdocs\jet peformance easy\c\tiffblaster |
File Names:
remote.dll |
winvnc.exe |
WinVNC.exe |
Geography:
67.8% | ||
8.5% | ||
6.8% | ||
3.4% | ||
3.4% | ||
1.7% | ||
1.7% | ||
1.7% | ||
1.7% | ||
1.7% | ||
1.7% |
OS Version:
Windows 10 | 89.7% | |
Windows 7 | 10.3% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00001000 |
PE Sections:
Name | Size of data | MD5 |
.text | 239104 | 3f8e03fccd86375991254b9eff9d5e5d |
.data | 55296 | 2c5a732f04e87e05cd887bf9539a54e2 |
.tls | 512 | bf619eac0cdf3f68d496ea9344137e8b |
.rdata | 512 | b60a016938708380eaca374770939d5c |
.idata | 6656 | 965d296f8866e48ebd65ff5383436954 |
.edata | 512 | 4a09cbc585b7447b3e6bc2294d72553c |
.rsrc | 170496 | b3d382cfbf97aaa61a3b25b81b19aac6 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for winvnc.exe