How to remove $RQ2B0S3.exe

$RQ2B0S3.exe

The module $RQ2B0S3.exe has been detected as Trojan.CoinMiner

$RQ2B0S3.exe
Product Name:

Main Services

Company Name:

System Native

MD5: d117bcec836985e708099b7fb123aa84
Size: 558 KB
First Published: 2018-01-12 06:08:48 (7 years ago)
Latest Published: 2018-07-18 09:17:42 (6 years ago)
Status: Trojan.CoinMiner (on last analysis)
Analysis Date: 2018-07-18 09:17:42 (6 years ago)
Signed By: Garry Lachman
Status: Valid
%programfiles%\system native
%windir%\temp
%sysdrive%\$recycle.bin
%sysdrive%\$recycle.bin\s-1-5-21-617333665-1130277085-2315668691-1001\$r9weqnj
updater.exe
$RQ2B0S3.exe
13.9%
13.4%
10.2%
9.6%
8.0%
5.9%
3.2%
3.2%
2.7%
2.7%
2.1%
2.1%
2.1%
2.1%
2.1%
2.1%
2.1%
1.6%
1.6%
1.1%
1.1%
1.1%
1.1%
1.1%
1.1%
0.5%
0.5%
0.5%
0.5%
0.5%
Windows 7 47.1%
Windows 10 45.5%
Windows 8.1 4.8%
Windows 8 2.7%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0003cc73

PE Sections:

Name Size of data MD5
.text 369664 a0afd883bf5b51471fb96b53aad5a9ec
.rdata 112128 fc950a3e7af62207b3c078c2df85a24c
.data 4096 d914976d80d650f9b8112756fe9dddf2
.rsrc 55808 de51c8105bac414270c78987ff5673a6
.reloc 21504 4ab5b1d9a7de96dd11722b785d8303ef

More information:

Download GridinSoft Anti-Malware - Removal tool for $RQ2B0S3.exe