How to remove wmiproviderhost.exe

wmiproviderhost.exe

The module wmiproviderhost.exe has been detected as Trojan.CoinMiner

wmiproviderhost.exe
Product Name:

WMI Provider Host

MD5: 77207356a5d75aef7238dde0d4ca2a54
Size: 100 KB
First Published: 2021-10-05 20:21:39 (3 years ago)
Latest Published: 2021-10-05 20:21:39 (3 years ago)
Status: Trojan.CoinMiner (on last analysis)
Analysis Date: 2021-10-05 20:21:39 (3 years ago)
%appdata%
100.0%
Windows Server 2016 100.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0000b022

.NET Info:

MVID: 9aa22b28-b61e-4e83-b280-6edc48425dba
Typelib ID: d887d189-371b-4764-a3a5-f07b33e8fee8

PE Sections:

Name Size of data MD5
.text 37376 464394197bf2a29779d2448492000088
.rsrc 64000 d5be18e4c125d6b3307b6f1e75cd9089
.reloc 512 fafc247655ce923415f1185741540ac8

More information:

Download GridinSoft Anti-Malware - Removal tool for wmiproviderhost.exe