How to remove $RNMYHCI.exe
- File Details
- Overview
- Analysis
$RNMYHCI.exe
The module $RNMYHCI.exe has been detected as Adware.OpenCandy
File Details
| Product Name: |
|
| MD5: |
767dd2101015ca7b626cafd870a92c77 |
| Size: |
2 MB |
| First Published: |
2017-05-30 20:03:24 (8 years ago) |
| Latest Published: |
2023-09-01 23:22:00 (2 years ago) |
| Status: |
Adware.OpenCandy (on last analysis) |
|
| Analysis Date: |
2023-09-01 23:22:00 (2 years ago) |
| %desktop%\desktop\gamle download |
| %profile%\downloads\programs |
| %profile% |
| %sysdrive%\彰化縣政府 |
| %sysdrive%\program\_w_i_n_r_a_r_\ipod repair.rar |
| %profile%\downloads |
| %sysdrive%\windows.old.000\fknrocknout\documents x\jd stuff\iphone hacks |
| %profile% |
| %sysdrive%\ايفوننننننننننننننننننننننننننننننن\ws_icloud_backup |
| %sysdrive% |
| tinyumbrella_windows_8_2_0_60_InstalledJRE.exe |
| $RNMYHCI.exe |
| tinyumbrella_windows_8_2_0_60_InstalledJRE (1).exe |
| tinyumbrella_windows_8_2_0_60_InstalledJRE (2016_01_01 18_39_28 UTC).exe |
|
30.8% |
|
|
15.4% |
|
|
11.5% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
| Windows 7 |
53.8% |
|
| Windows 10 |
42.3% |
|
| Windows 8.1 |
3.8% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x0001b114 |
| Name |
Size of data |
MD5 |
| .text |
184832 |
934c77ae73e8b270f809b7df411369dc |
| .rdata |
48128 |
c4473f98314d34ce1ae39c4e9fbebe5c |
| .data |
7680 |
5298456a70cf054677855f75363b8ea3 |
| .rsrc |
32768 |
4755ac462a906b852b11dcc96d7800e7 |
| .reloc |
12288 |
a906fec4303a0015448220e037000697 |