How to remove p0state.exe

p0state.exe

The module p0state.exe has been detected as Risk.CoinMiner

p0state.exe
Product Name:

nvidiasetp0state

MD5: 0e3a32475a9df59a1984038fceed2f42
Size: 15 KB
First Published: 2017-05-27 03:08:01 (6 years ago)
Latest Published: 2020-12-27 07:23:15 (3 years ago)
Status: Risk.CoinMiner (on last analysis)
Analysis Date: 2020-12-27 07:23:15 (3 years ago)
Signed By: H-BIT d.o.o.
Status: Valid
%localappdata%\programs\nhm2\utils
%profile%\downloads\mining\nicehashminer_v1.7.5.7\nicehashminer_v1.7.5.7
%desktop%\nicehashminer_v1.7.5.12
%profile%\downloads\nicehashminer_v1.7.5.12
%profile%\downloads\nicehashminer_v1.7.5.13\nicehashminer_v1.7.5.13
%sysdrive%\nicehash\nicehashminer_v1.7.5.13
%desktop%\nicehashminer_v1.7.5.13
%desktop%\nicehash miner_v1.7.5.13\nicehashminer_v1.7.5.13
%profile%\downloads\programs\nicehashminer_v1.7.5.13
%desktop%\nicehashminer_v1.7.5.13\nicehashminer_v1.7.5.13
nvidiasetp0state.exe
p0state.exe
17.7%
14.9%
13.9%
11.5%
4.9%
3.8%
3.1%
2.1%
2.1%
2.1%
1.7%
1.7%
1.7%
1.7%
1.7%
1.4%
1.4%
1.0%
1.0%
1.0%
1.0%
1.0%
0.7%
0.7%
0.7%
0.7%
0.7%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
Windows 10 66.0%
Windows 7 23.7%
Windows 8.1 8.2%
Windows Server 2008 R2 1.7%
Windows 8 0.3%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x000033be

.NET Info:

MVID: 4725267d-7499-4a41-bc3f-fbed454bee37
Typelib ID: f6fe2e1f-c25f-4d1d-85a9-eb0c91400988

PE Sections:

Name Size of data MD5
.text 5120 ffb3e4c54a7c36ebba0208ab0a3b8a30
.rsrc 4096 41667b067011ca6a41107bbd1ff7d6ed
.reloc 512 5287762b971a1259d99f6dcebf3e6c48

More information:

Download GridinSoft Anti-Malware - Removal tool for p0state.exe