How to remove xmrigServer.exe
- File Details
- Overview
- Analysis
xmrigServer.exe
The module xmrigServer.exe has been detected as Trojan.CoinMiner
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
9e21b2a7012377294867e4c489e37e98 |
| Size: |
3 MB |
| First Published: |
2021-01-06 10:30:05 (4 years ago) |
| Latest Published: |
2021-01-06 10:32:00 (4 years ago) |
| Status: |
Trojan.CoinMiner (on last analysis) |
|
| Analysis Date: |
2021-01-06 10:32:00 (4 years ago) |
| %sysdrive%\$recycle.bin\s-1-5-21-2649899950-350314689-1133762106-1000\$rcmy3u6 |
| %sysdrive%\$recycle.bin\s-1-5-21-2649899950-350314689-1133762106-1000\$rcmy3u6\xmrigcc-2.8.0-with_tls_and_gzip-mvc-win64.zip |
| %sysdrive%\$recycle.bin\s-1-5-21-2649899950-350314689-1133762106-1000 |
Analysis
| Subsystem: |
Windows CUI |
| PE Type: |
pe |
| OS Bitness: |
64 |
| Image Base: |
0x0000000140000000 |
| Entry Address: |
0x001a5b18 |
| Name |
Size of data |
MD5 |
| .text |
2054144 |
1472366c19295f24092d03123a02e442 |
| .rdata |
826368 |
2212ab5e2188d9d29edece63e513b745 |
| .data |
44032 |
3155f0db90aa6d041fd5382a2414d867 |
| .pdata |
102400 |
c477df466bc573d7810091f7fa00a9df |
| .rsrc |
130048 |
ead8057d02c21b301dbc05b91fe61b23 |
| .reloc |
30720 |
a93d85e3ae845b1e4087c170b3209abe |