How to remove xmrig.exe
xmrig.exe
The module xmrig.exe has been detected as Risk.CoinMiner
File Details
Product Name: | XMRig |
Company Name: | www.xmrig.com |
MD5: | d71fadd7cfa547da853cf79d1f5e0c5e |
Size: | 2 MB |
First Published: | 2020-03-21 14:40:07 (4 years ago) |
Latest Published: | 2020-11-21 18:17:36 (4 years ago) |
Status: | Risk.CoinMiner (on last analysis) | |
Analysis Date: | 2020-11-21 18:17:36 (4 years ago) |
Overview
Signed By: | Cudo Ventures Ltd |
Status: | Valid |
Common Places:
%commonappdata%\cudo miner\registry |
%commonappdata%\cudo miner\registry |
%commonappdata%\cudo miner\registry |
%commonappdata%\cudo miner\registry |
%sysdrive%\$recycle.bin\s-1-5-21-1593340925-1448411556-465868952-1001\$rlzbevw\registry |
Geography:
33.3% | ||
33.3% | ||
16.7% | ||
16.7% |
OS Version:
Windows 10 | 100.0% |
Analysis
Subsystem: | Windows CUI |
PE Type: | pe |
OS Bitness: | 64 |
Image Base: | 0x0000000140000000 |
Entry Address: | 0x001408e4 |
PE Sections:
Name | Size of data | MD5 |
.text | 1609728 | 56700e263d8fca394338ab4e40c79b07 |
.rdata | 344064 | c6c420b9da4a78ac7edcc844b83273a3 |
.data | 274432 | a2795238265139cf470948d077228b5d |
.pdata | 55296 | ceb12a8c2a5b62c73c8e0b1131ccbaed |
_RANDOMX | 2048 | 4c9ad32e381e3b0d5fe17bbaafaae2bf |
_TEXT_CN | 6656 | 6a7f77e47f77f65bef85036ae5a71106 |
_TEXT_CN | 4608 | 409bf3f918f2402291cb56c2e9354b47 |
.rsrc | 23040 | 12e466b060587f4ac4fdd84170ad6500 |
.reloc | 9728 | 0aedfff563f1ef10ea957e24c8ea6454 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for xmrig.exe