How to remove $RYFTGAA.exe

$RYFTGAA.exe

The module $RYFTGAA.exe has been detected as Adware.OpenCandy

$RYFTGAA.exe
Product Name:

Youtube Downloader HD

Company Name:

YoutubeDownloaderHD.com

MD5: 9efd88fa206200bdc586dd132f8a29e9
Size: 9 MB
First Published: 2017-08-10 07:09:22 (6 years ago)
Latest Published: 2019-09-26 21:44:47 (4 years ago)
Status: Adware.OpenCandy (on last analysis)
Analysis Date: 2019-09-26 21:44:47 (4 years ago)
Signed By: Egor Chernyshev
Status: Valid
%profile%\downloads
%sysdrive%\my documents
%sysdrive%\$recycle.bin
%desktop%\my shared folder\c
%profile%
%sysdrive%\mysoftware\network\影音下載
%sysdrive%
%sysdrive%\utiles
%desktop%\utiles
%profile%\oucef\mes documents
youtube_downloader_hd_setup.exe
$RYFTGAA.exe
youtubedownloaderhd_2.9.9.13.exe
youtube-downloader-hd_2-9-9-13_fr_24719.exe
youtube_downloader_hd_setup (2016_05_16 12_36_48 UTC).exe
youube-downloader_2-9-9-13_fr_75502.exe
youube-downloader_2-9-9-13_fr_75502 (1).exe
16.3%
11.6%
9.3%
7.0%
7.0%
7.0%
4.7%
4.7%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
2.3%
Windows 10 58.1%
Windows 7 32.6%
Windows 8 4.7%
Windows Vista 2.3%
Windows 8.1 2.3%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00009c40

PE Sections:

Name Size of data MD5
CODE 37888 0d7ac17dafcd52a9b3ea353c32256c1d
DATA 1024 e8f82382eefca31b62f6a8c8a52ff421
BSS 0 00000000000000000000000000000000
.idata 2560 bb5485bf968b970e5ea81292af2acdba
.tls 0 00000000000000000000000000000000
.rdata 512 9ba824905bf9c7922b6fc87a38b74366
.reloc 0 00000000000000000000000000000000
.rsrc 376832 fcea36048d04f97b730d4039e0aca0d2

More information:

Download GridinSoft Anti-Malware - Removal tool for $RYFTGAA.exe