How to remove MSVC.exe
MSVC.exe
The module MSVC.exe has been detected as Risk.CoinMiner
File Details
Product Name: | XMRig |
Company Name: | www.xmrig.com |
MD5: | f91ba4d9fa68cf7c578fb80a125139f5 |
Size: | 396 KB |
First Published: | 2017-06-22 03:08:32 (7 years ago) |
Latest Published: | 2020-06-03 06:26:47 (4 years ago) |
Status: | Risk.CoinMiner (on last analysis) | |
Analysis Date: | 2020-06-03 06:26:47 (4 years ago) |
Common Places:
%appdata%\msvc |
%appdata%\ieserv |
%appdata%\runspeed |
%appdata%\fixmix |
%appdata%\ieservise |
%appdata%\ielast |
%appdata%\testservice |
%appdata%\smotri2 |
%appdata%\taloce |
%appdata%\smoti2 |
File Names:
MSVCCPU64.exe |
MSVC.exe |
v.exe |
li1ew.exe |
llkq.exe |
kota.exe |
BITE255.tmp |
BITF0B7.tmp |
ptica.exe |
vorox.exe |
BITCF32.tmp |
liew.exe |
moloko.exe |
MVIC.exe |
BITAEF8.tmp |
BIT4B17.tmp |
BIT3C3B.tmp |
BITCCC5.tmp |
BITB6C6.tmp |
BITD6E1.tmp |
BIT797B.tmp |
BITD5E7.tmp |
BITF328.tmp |
llkq.exe.DEL.del |
MSVC64.exe |
BIT5578.tmp |
xmrig.exe |
BIT7CD5.tmp |
BIT45C7.tmp |
BITB995.tmp |
kvas.exe |
LI1EW.del |
BITA0AE.tmp |
Geography:
15.6% | ||
10.7% | ||
7.7% | ||
6.8% | ||
5.5% | ||
5.5% | ||
4.9% | ||
3.8% | ||
3.8% | ||
3.6% | ||
3.0% | ||
3.0% | ||
2.7% | ||
2.7% | ||
2.5% | ||
1.9% | ||
1.6% | ||
1.4% | ||
1.1% | ||
1.1% | ||
1.1% | ||
1.1% | ||
0.8% | ||
0.8% | ||
0.5% | ||
0.5% | ||
0.5% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% | ||
0.3% |
OS Version:
Windows 7 | 58.5% | |
Windows 10 | 32.5% | |
Windows 8.1 | 6.3% | |
Windows 8 | 2.7% |
Analysis
Subsystem: | Windows CUI |
PE Type: | pe |
OS Bitness: | 64 |
Image Base: | 0x0000000140000000 |
Entry Address: | 0x00011f8c |
PE Sections:
Name | Size of data | MD5 |
.text | 278016 | 0429edb605a813c57763a04ff49baa6c |
.rdata | 87040 | f81594e443cb510ba191518f72ee4e41 |
.data | 6656 | 8a647fbcbefe7423e6583398348d7593 |
.pdata | 13824 | 08b9f1958f6971d00916af9a11cbaf84 |
.rsrc | 16896 | a8b5de20d5035cc6dc62cfdd9809eb5f |
.reloc | 2560 | 568c020daa6df32f68afdcc7bc7b703c |
More information:
Download GridinSoft
Anti-Malware - Removal tool for MSVC.exe