How to remove $RNHS9FD.exe

$RNHS9FD.exe

The module $RNHS9FD.exe has been detected as Adware.ELEX

$RNHS9FD.exe
Product Name:

Firefox

Company Name:

Mozilla Corporation

MD5: bb1460a86eced733d22923aa9aaf673a
Size: 155 KB
First Published: 2017-05-21 04:03:36 (6 years ago)
Latest Published: 2019-04-10 02:37:36 (5 years ago)
Status: Adware.ELEX (on last analysis)
Analysis Date: 2019-04-10 02:37:36 (5 years ago)
Signed By: Mengmeng Wang
Status: Valid
%programfiles%\firefox
%sysdrive%\adwcleaner\quarantine\files\elpsmjvvmbctzuzgymreqtfnlrfefdyb
%profile%\dropbox\farina\backup c\adwcleaner\quarantine\files\elpsmjvvmbctzuzgymreqtfnlrfefdyb
%sysdrive%\$recycle.bin\s-1-5-21-1992274373-2149420621-907573384-1000
%sysdrive%\adwcleaner\quarantine\files\qivticfbhplowovmvofwbvcmqdkrzqie
%sysdrive%\adwcleaner\quarantine\files\brtzueofziatokksflqoyuuhpwqqkxer
%sysdrive%\adwcleaner\quarantine\files\ukyiiewribfnwsfajtujlibnuipogenb
%programfiles%\5901eb50_jumpeasy\sdirec
%programfiles%
%programfiles%\5901c7ea_jumpeasy
plugin-container.exe
$RNHS9FD.exe
17.9%
14.3%
10.7%
10.7%
10.7%
10.7%
7.1%
3.6%
3.6%
3.6%
3.6%
3.6%
Windows 7 46.4%
Windows 10 39.3%
Windows XP 10.7%
Windows 8 3.6%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0000ee9b

PE Sections:

Name Size of data MD5
.text 61440 42a72cce5be7cdaf12548f94766150d8
.rdata 82944 0f65ecd6e143ab2c7813a26b6d66f6ac
.data 512 4bed3374e3e440ec88fa6059a173afc8
.gfids 512 6a9c72a06ef22efefe9f6ba9932b2e4d
.rsrc 3072 34e0b2b3dd00f89ec7c811ebd11cc324
.reloc 4096 3b2740cdc4288e13a20e2550dc6b1bac

More information:

Download GridinSoft Anti-Malware - Removal tool for $RNHS9FD.exe