How to remove xmrig.gh
xmrig.gh
The module xmrig.gh has been detected as Risk.CoinMiner
File Details
| Product Name: | XMRig |
| Company Name: | www.xmrig.com |
| MD5: | 09adbc6b276efd090270b432dfb24014 |
| Size: | 3 MB |
| First Published: | 2019-03-18 14:08:45 (6 years ago) |
| Latest Published: | 2021-01-05 14:54:02 (4 years ago) |
| Status: | Risk.CoinMiner (on last analysis) | |
| Analysis Date: | 2021-01-05 14:54:02 (4 years ago) |
Common Places:
| %localappdata%\gamerhash\miners |
| %localappdata%\gamerhash\miners |
| %localappdata%\shortestminer\miners |
| %localappdata%\shortestminer\miners |
| %appdata% |
| %appdata% |
| %localappdata%\gamerhash\miners |
| %localappdata%\shortestminer\miners |
| %appdata% |
Geography:
| 33.3% | ||
| 25.0% | ||
| 16.7% | ||
| 16.7% | ||
| 8.3% |
OS Version:
| Windows 10 | 91.7% | |
| Windows 7 | 8.3% |
Analysis
| Subsystem: | Windows CUI |
| PE Type: | pe |
| OS Bitness: | 64 |
| Image Base: | 0x0000000140000000 |
| Entry Address: | 0x001bdfa8 |
PE Sections:
| Name | Size of data | MD5 |
| .text | 2263552 | ba6d8416e8219a02d47f8d99e2d52361 |
| .rdata | 765952 | 793b67fcaa921970ec0acd4cf9036fac |
| .data | 57856 | a5e9906464458c5b28b415c089b1f16a |
| .pdata | 95232 | 03461605e207522862eda81baeba6ce0 |
| _TEXT_CN | 4096 | 9b77d6f2b2faabee6debd71c56bc63a3 |
| _TEXT_CN | 7680 | dec60b287d8c7286bba42dcdb02ed14a |
| .rsrc | 23040 | 42e0c5395d48673e3f4ea37dc8ba74fb |
| .reloc | 30208 | 225bc58bd7de9977c96e36ec337370ed |
More information:
Download GridinSoft
Anti-Malware - Removal tool for xmrig.gh