How to remove pythonw.exe.q_Quarantine_2EEE7899_q

pythonw.exe.q_Quarantine_2EEE7899_q

The module pythonw.exe.q_Quarantine_2EEE7899_q has been detected as Trojan.CoinMiner

pythonw.exe.q_Quarantine_2EEE7899_q
Product Name:

Python

Company Name:

Python Software Foundation

MD5: 09e1729b0917b448f60e9520f8b6c844
Size: 94 KB
First Published: 2017-08-23 11:07:42 (7 years ago)
Latest Published: 2020-12-07 15:08:19 (4 years ago)
Status: Trojan.CoinMiner (on last analysis)
Analysis Date: 2020-12-07 15:08:19 (4 years ago)
Signed By: Python Software Foundation
Status: Valid
%appdata%\vksaver\python
%appdata%\gastproffite\python
%appdata%\bestsalesprofit\python
%appdata%\chcgfdgbopcgplldemnkhcgngckmhbdf\python
%appdata%\jpfkljhgkiobbgppiaombggpadkdehgo\python
%appdata%\setupsk_upd\python
%appdata%\setupsk\python
%appdata%\setups~1\python
%appdata%\setupsk_upd\python\python
%appdata%\currencyconvertor\python
pythonw.exe
pythonw.exe.q_Quarantine_2EEE7899_q
pythonw.exe.q_Quarantine_2AFB7899_q
pyw.exe
sfsdfs.txt.exe
60.0%
20.3%
3.0%
2.6%
1.9%
1.6%
1.5%
1.5%
1.3%
0.8%
0.7%
0.7%
0.6%
0.5%
0.4%
0.3%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
Windows 10 60.4%
Windows 7 30.2%
Windows 8.1 8.3%
Windows 8 0.9%
Windows XP 0.1%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x1d000000
Entry Address: 0x00001299

PE Sections:

Name Size of data MD5
.text 4608 951955b6c39cf008bc821e9eb4f07443
.rdata 3072 6c5d7b12a045ed4ae6360ab4b621b96e
.data 512 550b6d19eefd3a6f89a89a9be78fdbaf
.gfids 512 6452981ac31dd4560d40db77ffcb7c7f
.rsrc 79360 dd83343515865e24860a8ed9b0f582f3
.reloc 512 529c62fb1c8e7f51e1d99da85c6a77b1

More information:

Download GridinSoft Anti-Malware - Removal tool for pythonw.exe.q_Quarantine_2EEE7899_q