How to remove xmrig.exe
xmrig.exe
The module xmrig.exe has been detected as Risk.CoinMiner

File Details
Product Name: | XMRig |
Company Name: | www.xmrig.com |
MD5: | 0e2431a09f5aae6d9f436e62eb41ed69 |
Size: | 1 MB |
First Published: | 2021-10-16 20:12:33 (3 years ago) |
Latest Published: | 2024-12-04 23:01:51 (6 months ago) |
Status: | Risk.CoinMiner (on last analysis) | |
Analysis Date: | 2024-12-04 23:01:51 (6 months ago) |
Overview
Signed By: | Cudo Ventures Ltd |
Status: | Valid |
Common Places:
%commonappdata%\cudo miner\registry |
%sysdrive%\$recycle.bin\s-1-5-21-613876456-3037896169-1960079061-1001\$rxon21l\registry |
%sysdrive%\$recycle.bin\s-1-5-21-2400453414-84194822-421123232-1001\$r9hi94u\registry |
%commonappdata%\cudo miner\registry |
%commonappdata%\cudo miner\registry |
Geography:
20.0% | ||
20.0% | ||
20.0% | ||
20.0% | ||
20.0% |
OS Version:
Windows 10 | 100.0% |
Analysis
Subsystem: | Windows CUI |
PE Type: | pe |
OS Bitness: | 64 |
Image Base: | 0x0000000140000000 |
Entry Address: | 0x0012ddc8 |
PE Sections:
Name | Size of data | MD5 |
.text | 1567232 | fcb8adf7d1543012d59bc19889bcf045 |
.rdata | 297472 | 74b3a981d9f1e6cd9d5725d4b8688d13 |
.data | 23552 | fc915cc852d326c176c0c51f5fd3e9ff |
.pdata | 58368 | 6e7a17e05c9cd09319e69a0333751b44 |
_RANDOMX | 3072 | 2d064068efaf1cce84dfd050ac9137d1 |
_TEXT_CN | 6656 | 6a7f77e47f77f65bef85036ae5a71106 |
_TEXT_CN | 4608 | 409bf3f918f2402291cb56c2e9354b47 |
_RDATA | 512 | cbac2042f09e889feea06050064c46d7 |
.rsrc | 23040 | 75792f794d5b9eb77cce464903fd5bb0 |
.reloc | 9216 | 404977587a1e05152cb23e57d5c4e2b3 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for xmrig.exe
