How to remove sihost.exe

sihost.exe

The module sihost.exe has been detected as Ransom.Wacatac

sihost.exe
MD5: 8f31073871dcdf2abd3cc0c57928038f
Size: 66 KB
First Published: 2020-08-06 20:46:14 (3 years ago)
Latest Published: 2020-11-27 18:43:44 (3 years ago)
Status: Ransom.Wacatac (on last analysis)
Analysis Date: 2020-11-27 18:43:44 (3 years ago)
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
%appdata%
21.1%
10.5%
10.5%
10.5%
5.3%
5.3%
5.3%
5.3%
5.3%
5.3%
5.3%
5.3%
5.3%
Windows 10 76.2%
Windows 7 19.0%
Windows 8.1 4.8%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0001115e

.NET Info:

MVID: cc1703bd-8c3e-4df7-934e-7f93047db09a
Typelib ID: 25560858-c3cf-451f-90d2-0d9fff806ed0

PE Sections:

Name Size of data MD5
.text 61952 089585b059952f1e2575e3253359bb1f
.sdata 1024 d3f2e01571c1f854e20d47d2050a1b9b
.rsrc 3584 f5bfd92b3b8567647717f4996d67b35b
.reloc 512 8993c54d6301729b6144a7bdb9422080

More information:

Download GridinSoft Anti-Malware - Removal tool for sihost.exe