How to remove $R8LOBS0.exe

$R8LOBS0.exe

The module $R8LOBS0.exe has been detected as Risk.CoinMiner

$R8LOBS0.exe
Product Name:

NiceHashMinerLegacy

Company Name:

NiceHash

MD5: ba01f3e7791863a4aaab27e2cf505033
Size: 1 MB
First Published: 2018-10-27 04:08:03 (6 years ago)
Latest Published: 2018-11-17 13:19:27 (6 years ago)
Status: Risk.CoinMiner (on last analysis)
Analysis Date: 2018-11-17 13:19:27 (6 years ago)
%desktop%
%sysdrive%\$recycle.bin
%sysdrive%\$recycle.bin\s-1-5-21-77113414-1841730795-1489145725-1001
%programfiles%
%programfiles%\nhm
%localappdata%\packages\microsoft.microsoftedge_8wekyb3d8bbwe\ac\#!001\microsoftedge\cache\49dxwgeg
%profile%\downloads
%profile%\downloads\nhmwin1907
%sysdrive%
%profile%\downloads\compressed\bitcoin
NiceHashMinerLegacy.exe
$R8LOBS0.exe
$RF4HJDH.exe
42.1%
15.8%
10.5%
10.5%
10.5%
5.3%
5.3%
Windows 10 89.5%
Windows 8.1 10.5%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00121db6

.NET Info:

MVID: 693fa405-5b1b-4f46-9c88-e5c741c94c72

PE Sections:

Name Size of data MD5
.text 1179648 103f44ea623e20c57bd44d5903598b65
.rsrc 287744 759ab42f507e9f56ecb52aa32ae0743e
.reloc 512 ec173a67268eb2969d951045fd1f0f3b

More information:

Download GridinSoft Anti-Malware - Removal tool for $R8LOBS0.exe