How to remove $R7MBTGA.exe

$R7MBTGA.exe

The module $R7MBTGA.exe has been detected as Adware.ELEX

$R7MBTGA.exe
Product Name:

Firefox

Company Name:

Mozilla Corporation

MD5: 891206505ee398cf379d4ffa85123b7a
Size: 150 KB
First Published: 2017-05-24 11:10:30 (6 years ago)
Latest Published: 2019-10-12 19:31:27 (4 years ago)
Status: Adware.ELEX (on last analysis)
Analysis Date: 2019-10-12 19:31:27 (4 years ago)
Signed By: Mengmeng Wang
Status: Valid
%programfiles%\firefox
%sysdrive%\adwcleaner\quarantine\files\rszejbxwtcmauudlsqitlujsdrmndwbk
%sysdrive%\$recycle.bin\s-1-5-21-1515912927-174380303-3839714098-1001\$ray0gxo
%sysdrive%\$recycle.bin\s-1-5-21-3737494481-1270847105-2955528620-1000
%programfiles%\59268ba6_jumpeasy\sdirec
%programfiles%\592555f9_jumpeasy\sdirec
%sysdrive%\adwcleaner\quarantine\files\tpcysuvkwihevhehjjthgqodwqcmcura
%sysdrive%\adwcleaner\quarantine\files\pdtyxugckxueyuxrhshgxdjblezsdqrw
%sysdrive%\adwcleaner\quarantine\files\mjxftjlavkjfpqywfokrhiyzuuxwsoxt
%sysdrive%\quarantine_mzk\folders\201705258450847\firefox. 9.15.57.25
maintenanceservice_installer.exe
$R7MBTGA.exe
29.5%
12.8%
11.4%
8.1%
6.7%
5.4%
4.0%
2.7%
2.0%
2.0%
2.0%
1.3%
1.3%
1.3%
1.3%
1.3%
1.3%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
0.7%
Windows 7 48.0%
Windows 10 40.0%
Windows 8.1 9.3%
Windows 8 2.0%
Windows Server 2012 R2 0.7%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0000322e

PE Sections:

Name Size of data MD5
.text 25088 9dca43f07e072b6ab5b47217e8148626
.rdata 5632 0aa2dc336f7337ed3785ee2afeacae36
.data 1536 25a0547494fc1187f1c34d41f766d083
.ndata 0 00000000000000000000000000000000
.rsrc 29696 ae5c992826e26bda776ce051e1c704a5

More information:

Download GridinSoft Anti-Malware - Removal tool for $R7MBTGA.exe