yam.dll

JProof LLC

The module yam.dll by JProof has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program EpicScale Application by EpicScale, Inc.. The file has been seen being downloaded from epicscale.r.worldssl.net.
Publisher:
JProof LLC  (signed and verified)

MD5:
4a34b6cd4c8c494ae7f0505293caf46d

SHA-1:
35217f54a2512325e31850b319cad2a0bec94783

SHA-256:
e70151552eabfab12194f5c72688a5fb15c7ff3ef5050ae563f959d26353259a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/27/2024 1:54:48 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.EpicScale.JProof (M)
15.6.26.14

File size:
3.5 MB (3,671,144 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\ProgramData\application data\epicscale\0\99.32.in.am.generic\yam.dll

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
10/4/2014 5:00:00 PM

Valid to:
10/11/2017 5:00:00 AM

Subject:
CN=JProof LLC, O=JProof LLC, L=Washington, S=New Jersey, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
010A6723CC9454568F41F9221A61B586

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.24

CTPH (ssdeep):
98304:HH2658d4+tN2FU8KlmAOUBBOee617AnDr8:HH26JC8FU8KllOUBBOee6N68

Entry address:
0x1420

Entry point:
83, EC, 1C, 8B, 54, 24, 24, C7, 05, 0C, BC, 6A, 6D, 00, 00, 00, 00, 83, FA, 01, 74, 1A, 8B, 4C, 24, 28, 8B, 44, 24, 20, E8, 1D, FE, FF, FF, 83, C4, 1C, C2, 0C, 00, 8D, B4, 26, 00, 00, 00, 00, 89, 54, 24, 0C, E8, C7, 41, 06, 00, 8B, 54, 24, 0C, EB, D7, 90, 55, 89, E5, 56, 53, 83, EC, 10, 8B, 1D, 30, E4, 6A, 6D, C7, 04, 24, 00, E0, 5E, 6D, FF, D3, 89, C6, 83, EC, 04, B8, F0, A3, 3A, 6D, 85, F6, 74, 29, C7, 04, 24, 00, E0, 5E, 6D, FF, 15, 74, E4, 6A, 6D, 83, EC, 04, A3, 88, C9, 6A, 6D, C7, 44, 24, 04, 13, E0...
 
[+]

Entropy:
6.5681

Code size:
2.6 MB (2,765,312 bytes)

The file yam.dll has been discovered within the following program.

EpicScale Application  by EpicScale, Inc.
About 8% of users remove it
 
Powered by Should I Remove It?

The file yam.dll has been seen being distributed by the following URL.

Remove yam.dll - Powered by Reason Core Security