How to remove $RIY8YKJ.exe

$RIY8YKJ.exe

The module $RIY8YKJ.exe has been detected as Trojan.CoinMiner

$RIY8YKJ.exe
Product Name:

中华办公模板

Company Name:

北京华网智讯信息有限公司

MD5: 5ecd13028d847b164743825b92d134b6
Size: 846 KB
First Published: 2020-11-19 08:59:03 (3 years ago)
Latest Published: 2020-11-19 08:59:03 (3 years ago)
Status: Trojan.CoinMiner (on last analysis)
Analysis Date: 2020-11-19 08:59:03 (3 years ago)
Signed By: 北京华网智讯信息有限公司
Status: Valid
%sysdrive%\$recycle.bin
100.0%
Windows 10 100.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00010b84

PE Sections:

Name Size of data MD5
.text 522752 35f5100705765c6b7c02458be6874e32
.rdata 114688 e6744835d0c74a469cbb556ec4070957
.data 5120 95395782023a2919143b2aaefd92d632
.gfids 1024 4bcfc82a4cb7645ab488cc5303ef4eca
.tls 512 1f354d76203061bfdd5a53dae48d5435
.rsrc 182272 77a506ff5f9c15bb37be6b51bfea7f71
.reloc 23552 1444b0f69dee64ca1af556d69973700f

More information:

Download GridinSoft Anti-Malware - Removal tool for $RIY8YKJ.exe