How to remove accelera.sys

accelera.sys

The module accelera.sys has been detected as Adware.Agent

accelera.sys

accelera.sys is a Windows file recorded in the ThreatInfo database. It is associated with Accelera. The reported company name is He Fei Yun Biao Xin Xi Ke Ji You Xian Gong Si. The current detection status is Adware.Agent, based on the latest analysis from 2021-03-07 04:19:52 (5 years ago).

If accelera.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Adware.Agent.

Product Name: Accelera
Company Name: He Fei Yun Biao Xin Xi Ke Ji You Xian Gong Si
MD5: 9c46150a9467938a0151864e2be8d0bb
Size: 1 MB
First Published: 2021-03-06 04:22:09 (5 years ago)
Latest Published: 2021-03-07 04:19:52 (5 years ago)
Status: Adware.Agent (on last analysis)
Analysis Date: 2021-03-07 04:19:52 (5 years ago)

The signature on accelera.sys is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%localappdata%\zippercloud\acce
%localappdata%\zippercloud\acce

ThreatInfo has observed accelera.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

50.0%
50.0%

The strongest geographic signal for this file is China with 50.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows Server 2012 R2 50.0%
Windows 7 50.0%

The most common operating system signal for accelera.sys is Windows Server 2012 R2 with 50.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

accelera.sys is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000000010000
Entry Address: 0x00115064

PE Sections:

Name Size of data MD5
.text 5120 eaddb3cc0424aa51721fb2843c994195
.rdata 1024 8c31f36f4903fe4e319fdd1dfac3a7f9
.data 1111552 37c457fcf5c3daf18e4f3a478f8a8ba4
.pdata 512 baebe4acebcca9e15cc147ee6cf5676a
INIT 1024 574ad8246c05f2bdc1d5a9b8e6bd89ce
.rsrc 1024 1f384c0acc8f004b03aa571a2d797faf

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for accelera.sys