How to remove whoami.exe

whoami.exe

The module whoami.exe has been detected as Spy.Zbot

whoami.exe
Product Name:

CoreUtils

Company Name:

GNU <www.gnu.org>

MD5: 06fc28d73dcff0efe7786c2d902ca51e
Size: 24 KB
First Published: 2018-05-12 01:03:42 (6 years ago)
Latest Published: 2018-06-11 12:09:14 (6 years ago)
Status: Spy.Zbot (on last analysis)
Analysis Date: 2018-06-11 12:09:14 (6 years ago)
%programfiles%\microchip\mplabx\v4.05\gnubins\gnuwin32
%programfiles%\microchip\mplabx\v3.15\gnubins\gnuwin32
%programfiles%\microchip\mplabx\gnubins\gnuwin32
%programfiles%\microchip\mplabx\v3.50\gnubins\gnuwin32
%programfiles%\microchip\mplabx\v4.01\gnubins\gnuwin32
%sysdrive%\xilinx\14.7\ise_ds\edk\gnuwin
%sysdrive%\xmplab\gnubins\gnuwin32
%programfiles%\microchip\mplabx\v3.20\gnubins\gnuwin32
25.0%
16.7%
8.3%
8.3%
8.3%
8.3%
8.3%
8.3%
8.3%
Windows 7 58.3%
Windows 10 33.3%
Windows 8.1 8.3%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00001000

PE Sections:

Name Size of data MD5
.text 17408 6ea033bbe5755f178cf9ce2d6ffadb48
.data 512 9d0d5960aa5a64448dba442d6aaf55fb
.bss 0 00000000000000000000000000000000
.idata 1536 cbcf84f73355024acf3cef141ca99e05
.rsrc 4096 831105ba51496e93b7fc3f3a6368270f

More information:

Download GridinSoft Anti-Malware - Removal tool for whoami.exe