How to remove TeamViewerQS.exe

TeamViewerQS.exe

The module TeamViewerQS.exe has been detected as Trojan.CoinMiner

TeamViewerQS.exe
MD5: e86b65f86bfa762d02d43f7db5d56bad
Size: 2 MB
First Published: 2017-09-15 02:07:21 (7 years ago)
Latest Published: 2021-01-07 13:17:24 (4 years ago)
Status: Trojan.CoinMiner (on last analysis)
Analysis Date: 2021-01-07 13:17:24 (4 years ago)
Signed By: TeamViewer GmbH
Status: Valid
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017\misa remote support
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017
%appdata%\temp\misa.sme2019\winroot\misa jsc\misa sme.net 2019
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017
%appdata%\temp\misa.sme.net 2017 installer\winroot\misa jsc\misa sme.net 2017
98.9%
0.6%
0.6%
Windows 10 47.2%
Windows 7 38.2%
Windows 8.1 9.6%
Windows Server 2012 R2 3.4%
Windows 8 0.6%
Windows Server 2008 R2 0.6%
Windows Server 2016 0.6%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x000030cb

PE Sections:

Name Size of data MD5
.text 23040 c69726ed422d3dcfdec9731986daa752
.rdata 4608 a2c7710fa66fcbb43c7ef0ab9eea5e9a
.data 1024 e59cdcb732e4bfbc84cc61dd68354f78
.ndata 0 00000000000000000000000000000000
.rsrc 24576 9892c0a36f91c179d279c9aa8a0220fc

More information:

Download GridinSoft Anti-Malware - Removal tool for TeamViewerQS.exe