How to remove ytaia.exe
ytaia.exe
The module ytaia.exe has been detected as Adware.Crossrider

File Details
MD5: | f1792abe5220c825c23c612236dab5b2 |
Size: | 792 KB |
First Published: | 2017-06-09 10:03:06 (7 years ago) |
Latest Published: | 2019-03-25 14:27:01 (6 years ago) |
Status: | Adware.Crossrider (on last analysis) | |
Analysis Date: | 2019-03-25 14:27:01 (6 years ago) |
Overview
Signed By: | Goobzo LTD |
Status: | Valid |
Common Places:
%localappdata%\installer\install_16586 |
%localappdata%\installer\install_14594 |
%localappdata%\installer\install_4797 |
%localappdata%\installer\install_20790 |
%localappdata%\installer\install_12727 |
%localappdata%\installer\install_3309 |
%localappdata%\installer\install_24931 |
%localappdata%\installer\install_7026 |
%localappdata%\installer |
%sysdrive%\windows.old\users\cliente\appdata\local\temp |
File Names:
ytaib.exe |
ytaia.exe |
ytai.exe |
Geography:
30.0% | ||
10.0% | ||
10.0% | ||
10.0% | ||
5.0% | ||
5.0% | ||
5.0% | ||
5.0% | ||
5.0% | ||
5.0% | ||
5.0% | ||
5.0% |
OS Version:
Windows 7 | 60.0% | |
Windows 10 | 40.0% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x000423e0 |
PE Sections:
Name | Size of data | MD5 |
.text | 405504 | 81d5596e3a87533ee73b41e1b4333e78 |
.rdata | 168960 | bc4bfa63c0923eb28dae5aab75a95767 |
.data | 12288 | 0e0cfe9cacb8d7e2c571b5c535e32437 |
.rsrc | 185344 | df406303a94f96928675bf69bcd7269c |
.reloc | 31744 | 1c7c8e7859d46c555b2e52a1cba0a1a3 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for ytaia.exe
