How to remove $RPS0YNH.tmp
- File Details
- Overview
- Analysis
$RPS0YNH.tmp
The module $RPS0YNH.tmp has been detected as Adware.ELEX
File Details
Product Name: |
|
Company Name: |
|
MD5: |
3d403b96bcd9e68077b2b701f5d9b04d |
Size: |
275 KB |
First Published: |
2017-05-21 04:03:04 (7 years ago) |
Latest Published: |
2023-09-27 23:25:42 (a year ago) |
Status: |
Adware.ELEX (on last analysis) |
|
Analysis Date: |
2023-09-27 23:25:42 (a year ago) |
Overview
%programfiles%\elex-tech\yac |
%temp%\istca6f.tmp |
%temp%\ist4161.tmp |
%sysdrive%\$recycle.bin\s-1-5-21-1515912927-174380303-3839714098-1001 |
%temp%\istdc68.tmp |
%sysdrive%\adwcleaner\quarantine\files\hnejfgjgzqgwsaagtcjzctwkxkwixhhr\yac |
%sysdrive%\adwcleaner\quarantine\files\ttrzbiwbftrphsyswotxgiymvycbwfok\yac |
%temp%\isteda.tmp |
%temp%\ist955b.tmp |
%sysdrive%\adwcleaner\quarantine\files\ocujcckwzviwpgdpvbimylqvtkgncirf\yac |
ssleay32.dll |
$RPS0YNH.tmp |
A0422241.dll |
A0432640.dll |
_@8229.tmp |
A0244112.dll |
A0096125.dll |
_@11.tmp |
|
16.3% |
|
|
16.0% |
|
|
14.2% |
|
|
9.0% |
|
|
6.9% |
|
|
5.7% |
|
|
4.5% |
|
|
4.1% |
|
|
3.5% |
|
|
2.3% |
|
|
1.9% |
|
|
1.4% |
|
|
1.4% |
|
|
1.1% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 7 |
56.9% |
|
Windows 10 |
33.0% |
|
Windows 8.1 |
4.4% |
|
Windows XP |
3.4% |
|
Windows 8 |
2.2% |
|
Windows Vista |
0.1% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x10000000 |
Entry Address: |
0x0003213f |
Name |
Size of data |
MD5 |
.text |
202752 |
f1a3eed346f714867a82970b0fa54452 |
.rdata |
46080 |
329ab3620480db67cb16b48603bf5194 |
.data |
12288 |
dfc45cdac0d35ff5bf284ea1c68662d0 |
.rsrc |
1536 |
41ff55d2f27629e0760820c031fcf9bb |
.reloc |
9728 |
da8232cf925305392d305d1aa6ad9a84 |