How to remove xmrig.exe

xmrig.exe

The module xmrig.exe has been detected as Trojan.CoinMiner

xmrig.exe
Product Name:

XMRig

Company Name:

www.xmrig.com

MD5: 96bcc7e38525dab8032c0ae0c6055bbf
Size: 4 MB
First Published: 2020-10-22 09:30:30 (4 years ago)
Latest Published: 2024-12-16 23:02:08 (6 months ago)
Status: Trojan.CoinMiner (on last analysis)
Analysis Date: 2024-12-16 23:02:08 (6 months ago)
%localappdata%\programs\nicehash miner\miner_plugins\0e0a7320-94ec-11ea-a64d-17be303ea466\bins\11.3
%sysdrive%\$recycle.bin\s-1-5-21-3417231984-1246498483-569619165-1001\$rmapa6m\miner_plugins\0e0a7320-94ec-11ea-a64d-17be303ea466\bins\11.3
%localappdata%\programs\nicehash miner\miner_plugins\0e0a7320-94ec-11ea-a64d-17be303ea466\bins\11.3
%desktop%\new folder (3)\miner_plugins\0e0a7320-94ec-11ea-a64d-17be303ea466\bins\11.3
%localappdata%\programs\nicehash miner\miner_plugins\0e0a7320-94ec-11ea-a64d-17be303ea466\bins\11.3
%programfiles%\betterhash\cores
%programfiles%\betterhash\cores
%programfiles%\betterhash\cores
%programfiles%\betterhash\cores
%localappdata%\programs\nicehash miner\miner_plugins\0e0a7320-94ec-11ea-a64d-17be303ea466\bins\11.3
29.4%
17.6%
11.8%
11.8%
5.9%
5.9%
5.9%
5.9%
5.9%
Windows 10 100.0%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x0029e988

PE Sections:

Name Size of data MD5
.text 3084288 af00931ecaeed47ec68aa2e2e0b5dca3
.rdata 1188864 6a4d9a0d41287d06b2a301045d80bedb
.data 69120 013895112a40cfd8c9dcf5ae10d348bd
.pdata 125440 f80ab3438aafcef769f00310574eb796
_RANDOMX 2048 b182bf6976fc56dcc30743b1e5cbdaae
_SHA3_25 2560 c14f9aad5e95192cd7523ba6675549fd
_TEXT_CN 6656 6a7f77e47f77f65bef85036ae5a71106
_TEXT_CN 4608 409bf3f918f2402291cb56c2e9354b47
_RDATA 512 bf79d49ef528cf2dc966a057342577ad
.rsrc 23040 2873c1dbc4ef5eb291fd5aee42cb2d59
.reloc 34304 4851e907c12920fbc7bfc9208ce73ae3

More information:

Download GridinSoft Anti-Malware - Removal tool for xmrig.exe