Threat Database Potentially Unwanted Programs PUP.YAC (Yet Another Cleaner)

PUP.YAC (Yet Another Cleaner)

Threat Scorecard

Ranking: 1,524
Threat Level: 10 % (Normal)
Infected Computers: 218,633
First Seen: December 27, 2013
Last Seen: May 1, 2024
OS(es) Affected: Windows

File System Details

PUP.YAC (Yet Another Cleaner) may create the following file(s):
# File Name MD5 Detections
1. aerdl.dll 0750556e1471fc9d823c30bc99b77a38 3,054
2. aedroid.dll b2987d8a627afce56302498d912161f7 1,460
3. aeheur.dll edf1ff20c2277e9af3778757c987d14c 1,153
4. aescript.dll 9a639617aeeb415832e659714053fcab 1,075
5. aeoffice.dll 223b886130b8e2e03a3702dc92efe5a4 1,059
6. aeexp.dll 16652e6d9b7d961e9f1ca93c94fcecb0 889
7. bas.dat 46721a65cc7400788bf58072f5ff70a6 792
8. adb.dat d08eb2854b761c9ec1e36d590790f776 736
9. rms.dat 649172d71d4aca8496fba5e53fe940bc 731
10. nlu.dat b6b096e15554281027b0ffe59e94a0b9 644
11. mic.dat bf771c93b7f109934054742a262573e5 642
12. stu.dat 3c13507f1e9bf138714daa4e04d98cfd 564
13. uis.dat 0744e7ed95e05352e420f290614ddf3d 563
14. aescn.dll 7a09731d5c7c6c6c97cb01ced6544e2b 522
15. bwd.dat 21c4dd4e2c6f525aff8cb2f14deed567 218
16. aeheur.dll 76b976f396c89864b9882716fc7bcca4 154
17. aeheur.dll 8b6d7491e84612e8d41960c7d947c559 125
18. aeoffice.dll 4d3ddfdb2cc71137a953f4600acbdfa2 76
19. aescript.dll 7c7e2283049f3f69925fef29d3f5927b 76
20. aescript.dll 6bcaf7c0efa7e81ad45b1b5cdaa8badc 67
21. aeoffice.dll e1425ddb4f01ba16112e2dbbcad0a0b5 62
22. aescript.dll c7df4253d7a5820e0df791e3bbc26564 56
23. aeoffice.dll fa3300cf1ea41d8f295d5d1cfed351f6 52
24. aegen.dll 266b1c726a11c338b3d30e5759ad9cb5 46
25. A0023360.dll d8e6dff3afe4138bd9b040af30f85918 26
26. aescript.dll 83477e6b6db2ee55b95392c5cafc5f4f 24
27. aeoffice.dll 3851287dde16dd1c612788094ad917d4 16
28. aescript.dll e7b644bce09e7cf797a90ef8cae4e72b 16
29. eas.dat 7c0ce536cb12533f3d54cd23f56c1dad 3
30. yac_setup.exe 1a126b528993fd081e9a1cda4ca2a96a 1
More files

Registry Details

PUP.YAC (Yet Another Cleaner) may create the following registry entry or registry entries:
CLSID
{0EB9B9FE-3CEF-43E1-882A-853FC80021CE}
{5411D116-5A37-47D4-B154-5F7FCD9062F0}
File name without path
YAC.lnk
Regexp file mask
%AppData%\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Depth clean up junk files.lnk
%WINDIR%\System32\drivers\iSafeKrnlBoot.sys
%WINDIR%\System32\drivers\iSafeNetFilter.sys
%WinDir%\System32\log\iSafeKrnlCall.log
*\shellex\ContextMenuHandlers\iSafeRKScan
CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shell\iSafeRKScan
CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\iSafeRKScan
Directory\shellex\ContextMenuHandlers\iSafeRKScan
Folder\ShellEx\ContextMenuHandlers\iSafeRKScan
lnkfile\shellex\ContextMenuHandlers\iSafeRKScan
SOFTWARE\Classes\*\shellex\ContextMenuHandlers\iSafeRKScan
SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shell\iSafeRKScan
SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\iSafeRKScan
SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\iSafeRKScan
SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\iSafeRKScan
SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\iSafeRKScan
SOFTWARE\Elex-tech
SOFTWARE\iSafe
SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0EB9B9FE-3CEF-43E1-882A-853FC80021CE}
SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5411D116-5A37-47D4-B154-5F7FCD9062F0}
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iSafe
SOFTWARE\Wow6432Node\Elex-tech
SOFTWARE\Wow6432Node\iSafe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iSafe
SYSTEM\ControlSet001\Control\iSafeKrnlBoot
SYSTEM\ControlSet001\Enum\Root\LEGACY_ISAFEKRNL
SYSTEM\ControlSet001\Enum\Root\LEGACY_ISAFEKRNLKIT
SYSTEM\ControlSet001\Enum\Root\LEGACY_ISAFEKRNLR3
SYSTEM\ControlSet001\Enum\Root\LEGACY_ISAFENETFILTER
SYSTEM\ControlSet001\services\iSafeKrnl
SYSTEM\ControlSet001\services\iSafeKrnlBoot
SYSTEM\ControlSet001\services\iSafeKrnlKit
SYSTEM\ControlSet001\services\iSafeKrnlR3
SYSTEM\ControlSet001\services\iSafeNetFilter
SYSTEM\ControlSet001\services\iSafeService
SYSTEM\ControlSet002\Control\iSafeKrnlBoot
SYSTEM\ControlSet002\Enum\Root\LEGACY_ISAFEKRNL
SYSTEM\ControlSet002\Enum\Root\LEGACY_ISAFEKRNLKIT
SYSTEM\ControlSet002\Enum\Root\LEGACY_ISAFEKRNLR3
SYSTEM\ControlSet002\Enum\Root\LEGACY_ISAFENETFILTER
SYSTEM\ControlSet002\services\iSafeKrnl
SYSTEM\ControlSet002\services\iSafeKrnlBoot
SYSTEM\ControlSet002\services\iSafeKrnlKit
SYSTEM\ControlSet002\services\iSafeKrnlR3
SYSTEM\ControlSet002\services\iSafeNetFilter
SYSTEM\ControlSet002\services\iSafeService
SYSTEM\CurrentControlSet\Control\iSafeKrnlBoot
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ISAFEKRNL
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ISAFEKRNLKIT
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ISAFEKRNLR3
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ISAFENETFILTER
SYSTEM\CurrentControlSet\services\iSafeKrnl
SYSTEM\CurrentControlSet\services\iSafeKrnlBoot
SYSTEM\CurrentControlSet\services\iSafeKrnlKit
SYSTEM\CurrentControlSet\services\iSafeKrnlR3
SYSTEM\CurrentControlSet\services\iSafeNetFilter
SYSTEM\CurrentControlSet\services\iSafeService

Directories

PUP.YAC (Yet Another Cleaner) may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\YAC
%APPDATA%\Elex-tech
%AppData%\eCyber
%AppData%\iSafe
%PROGRAMFILES%\Elex-tech
%PROGRAMFILES%\iSafe
%PROGRAMFILES(x86)%\Elex-tech
%PROGRAMFILES(x86)%\iSafe
%TEMP%\iSafeRightKeyScan

Trending

Most Viewed

Loading...