How to remove y_advisor.exe

y_advisor.exe

The module y_advisor.exe has been detected as PUP.Presenoker

y_advisor.exe
Product Name:

Yandex Sovetnik

Company Name:

Yandex.Market LLC

MD5: a8ea292a24743b69f671fd6ccc63b33e
Size: 2 MB
First Published: 2020-04-10 04:56:05 (5 years ago)
Latest Published: 2022-01-01 21:39:38 (3 years ago)
Status: PUP.Presenoker (on last analysis)
Analysis Date: 2022-01-01 21:39:38 (3 years ago)
Signed By: YANDEX EUROPE AG
Status: Valid
%temp%
%localappdata%\microsoft\windows\temporary internet files\content.ie5
%temp%
%profile%\downloads
%temp%
%localappdata%\microsoft\windows\inetcache\ie
83.3%
16.7%
Windows 7 50.0%
Windows 10 50.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0001181c

PE Sections:

Name Size of data MD5
.text 62464 0da5d73ffbc41792fa65a09058a91476
.itext 4096 2eb275566563c3f1d0099a0da7345b74
.data 3584 73b859e23f5fd17e00c08db2e0e73dfe
.bss 0 00000000000000000000000000000000
.idata 4096 e9b9c0328fd9628ad4d6ab8283dcb20e
.tls 0 00000000000000000000000000000000
.rdata 512 3dffc444ccc131c9dcee18db49ee6403
.rsrc 45568 006c4fa6435ada2609ea251a9e840c5a

More information:

Download GridinSoft Anti-Malware - Removal tool for y_advisor.exe