How to remove $R6PS4OU.exe

$R6PS4OU.exe

The module $R6PS4OU.exe has been detected as Adware.Montiera

$R6PS4OU.exe
Product Name:

Company Name:

Pay By Ads LTD

MD5: ba73d8dc5dd1cf3e558c2152c3d969ad
Size: 522 KB
First Published: 2017-08-09 23:09:54 (6 years ago)
Latest Published: 2020-12-24 15:33:37 (3 years ago)
Status: Adware.Montiera (on last analysis)
Analysis Date: 2020-12-24 15:33:37 (3 years ago)
Signed By: Pay-by-Ads Ltd
Status: Valid
%localappdata%\temp
%localappdata%\pay-by-ads\yahoo! search\1.3.8.2
%sysdrive%\adwcleaner\quarantine\files\bodlsbrtzqghikfydlheiliuqthtncsa\yahoo! search
%sysdrive%\back up\users\wow\appdata\local\pay-by-ads\yahoo! search
%sysdrive%\$recycle.bin
%localappdata%\pay-by-ads\yahoo! search
%localappdata%\pay-by-ads\yahoo! search
dsrlte.exe
$R6PS4OU.exe
20.0%
10.0%
10.0%
10.0%
10.0%
10.0%
10.0%
10.0%
10.0%
Windows 7 50.0%
Windows 8.1 30.0%
Windows 10 10.0%
Windows 8 10.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0003d316

PE Sections:

Name Size of data MD5
.text 328192 e1f2d1290040a617efd1430cfdec3945
.rdata 66048 07a8b20b33a00f1d653ee61cc8cbd355
.data 12800 ce52f046f435f350d07413242dce119f
.rsrc 92672 814eb8f0107709322d0211e5662e1fed
.reloc 28672 af39983d636f1ceebf06d3cfb1b7b5f5

More information:

Download GridinSoft Anti-Malware - Removal tool for $R6PS4OU.exe