How to remove xmrig.exe
xmrig.exe
The module xmrig.exe has been detected as Risk.CoinMiner
File Details
Product Name: | XMRig |
Company Name: | www.xmrig.com |
MD5: | 32017257aac633c9689a615b68973a4a |
Size: | 1 MB |
First Published: | 2020-01-13 11:35:14 (5 years ago) |
Latest Published: | 2020-09-19 19:49:49 (4 years ago) |
Status: | Risk.CoinMiner (on last analysis) | |
Analysis Date: | 2020-09-19 19:49:49 (4 years ago) |
Overview
Signed By: | Cudo Ventures Ltd |
Status: | Valid |
Common Places:
%appdata%\cudo miner\workloads |
%appdata%\cudo miner\workloads |
%appdata%\cudo miner\workloads |
%commonappdata%\cudo miner\registry |
%commonappdata%\cudo miner\registry |
%commonappdata%\cudo miner\registry |
%commonappdata%\cudo miner\registry |
Geography:
28.6% | ||
14.3% | ||
14.3% | ||
14.3% | ||
14.3% | ||
14.3% |
OS Version:
Windows 10 | 100.0% |
Analysis
Subsystem: | Windows CUI |
PE Type: | pe |
OS Bitness: | 64 |
Image Base: | 0x0000000140000000 |
Entry Address: | 0x000f1764 |
PE Sections:
Name | Size of data | MD5 |
.text | 1280000 | c63db6429c7f01b1284716cb0be3d3b8 |
.rdata | 307200 | 19160d0b131277df0bcd60fe02604797 |
.data | 236032 | 80ebed2327796166122f5c998aa9cade |
.pdata | 49664 | 7f44dd2f3c1139ab4cf3b6b0ae1f48af |
_RANDOMX | 1536 | ef4c348a62790a9f11b1f28733313416 |
_TEXT_CN | 6656 | 6a7f77e47f77f65bef85036ae5a71106 |
_TEXT_CN | 4608 | 409bf3f918f2402291cb56c2e9354b47 |
.rsrc | 23040 | c9dd870459ec5ab6f6db56273b195cd7 |
.reloc | 9216 | 6441428f55810d4bdb1e473284cfcfb4 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for xmrig.exe