How to remove yeadesktop.exe
- File Details
- Overview
- Analysis
yeadesktop.exe
The module yeadesktop.exe has been detected as Adware.Eszjuxuan
File Details
Product Name: |
|
Company Name: |
|
MD5: |
48f761125c63aa44a55fb2e79eb6e085 |
Size: |
2 MB |
First Published: |
2017-07-28 10:03:19 (7 years ago) |
Latest Published: |
2019-09-13 13:31:16 (5 years ago) |
Status: |
Adware.Eszjuxuan (on last analysis) |
|
Analysis Date: |
2019-09-13 13:31:16 (5 years ago) |
%temp%\1196046 |
%localappdata%\temp |
%temp%\22915062 |
%temp%\471703 |
%temp%\4449671 |
%temp%\5156691 |
%temp%\3c7f4a53a8744dcead086e8da6438feb |
%temp%\63fdc255a44b434f9d45a00018813ae4 |
%temp%\3e81108c598d4148a43cc29fe43e6b4f |
%temp%\63151451 |
ic-0.724cbabadf63d4.exe |
yeadesktop.exe |
ic-0.0e9f6735dc0234.exe |
ic-0.f2d609ba361f8.exe |
ic-0.9ad4b9e089363.exe |
ic-0.e324069cc6625.exe |
yeadesktop2.exe |
ic-0.68812ac423a18c.exe |
Yeadesktop.exe |
ic-0.064ca4425f78c.exe |
ic-0.e96b02ba10f5c.exe |
ic-0.97f4e618bd149.exe |
ic-0.1367b49c0fb154.exe |
ic-0.9cf452b82f181.exe |
ic-0.e499a5a20cf1c.exe |
ic-0.e0ed27742c76f8.exe |
ic-0.5b9fbbb2081c94.exe |
ic-0.1404c819ebd024.exe |
ic-0.c54ac5db861bb.exe |
ic-0.4b429992cf17ac.exe |
|
23.9% |
|
|
15.5% |
|
|
12.7% |
|
|
12.7% |
|
|
5.6% |
|
|
4.2% |
|
|
4.2% |
|
|
2.8% |
|
|
2.8% |
|
|
2.8% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
Windows 10 |
39.4% |
|
Windows 7 |
35.2% |
|
Windows 8.1 |
18.3% |
|
Windows 8 |
4.2% |
|
Windows Vista |
2.8% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00009c14 |
Name |
Size of data |
MD5 |
CODE |
37888 |
0f1e58bee0e7f7b353de3dde9de0259d |
DATA |
1024 |
1afd2a5d0373792e0d1942b295194e3c |
BSS |
0 |
00000000000000000000000000000000 |
.idata |
2560 |
bb5485bf968b970e5ea81292af2acdba |
.tls |
0 |
00000000000000000000000000000000 |
.rdata |
512 |
9ba824905bf9c7922b6fc87a38b74366 |
.reloc |
0 |
00000000000000000000000000000000 |
.rsrc |
11264 |
781b77cfabb648413d805876f79707da |