Xmrig.exe Risk B Analysis

Risk B
Updated on 2024-04-20 (22 days ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.172.174
DB Version:2024-04-20 13:00:34

Risk.CoinMiner.B.vl!yf

Filexmrig.exe
Checked2024-04-20 13:23:19
MD572061021a062ab5f5985635eb6dbd510
SHA1ba71f867fa785f4709e988d62e47d7c5b1e40836
SHA25660ad648c1e48af06869573320bc25d824c10d141e4f919d1e45aa4992445db85
SHA51270e0cbad9c93a6220a8622c43d4cad07268964f5b16915a3a9e9b1cfa819299f8d32865dbc369faabd452ba6fac31dee6ab818bb24f700324550280222418467
Imphashd27adcc63481fa934ef3ba9e672732b2
File Size9507840 bytes

Risk.CoinMiner.B.vl!yf Removal

Risk.CoinMiner.B.vl!yf Removal

Gridinsoft has the capability to identify and eliminate Risk.CoinMiner.B.vl!yf without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation0x0000 0x04b0
Comments*Description*
CompanyNameD7YJ2A2Q22S2
FileDescriptionK6E6P
FileVersion3.1.4.6
InternalNameX8IF523W57C2.exe
LegalCopyrightEYGE7U546FR4
LegalTrademarksX8IF523W57C2
OriginalFilenameX8IF523W57C2.exe
ProductNameUTJY4E424LI4
ProductVersion3.1.4.6
Assembly Version6.3.1.5
CompanyNamewww.xmrig.com
FileDescriptionXMRig miner
FileVersion6.21.2
LegalCopyrightCopyright (C) 2016-2024 xmrig.com
OriginalFilenamexmrig.exe
ProductNameXMRig
ProductVersion6.21.2
Translation0x0000 0x04b0

Portable Executable Info

4d7f8487110b81d4a3ea3eab06140b06
3b5d3c7d207e37dceeedd301e35e2e58
0000000000000000
Image Base:0x140000000
Entry Point:0x1400013f0
Compilation:2024-03-23 06:42:51
Checksum:0x0091f74a (Actual: 0x009164fa)
OS Version:4.0
PEiD:PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:11
Imports: ADVAPI32, CRYPT32, dbghelp, IPHLPAPI, KERNEL32, msvcrt, ole32, SHELL32, USER32, USERENV, WS2_32,
Exports: 0
Resources:10

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x006c85f0 0x006c8600 af7194cc1211cb2589f1d591fd763810 6.49
.data 0x006ca000 0x00010f20 0x00011000 01188a4af98f169c876a9c1a560b71be 3.26
.rdata 0x006db000 0x001a09d0 0x001a0a00 7bbed45385f0bef4e928c6bb77642880 6.08
.pdata 0x0087c000 0x00039d44 0x00039e00 324278a2f676474bbbad3209450b303d 6.41
.xdata 0x008b6000 0x00044bac 0x00044c00 4127c4c8faf99066866d71f16310f6f8 4.90
.bss 0x008fb000 0x0031f770 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.idata 0x00c1b000 0x000048f4 0x00004a00 bc8a38fe7bbe081bd6ee259ebf9a5389 4.75
.CRT 0x00c20000 0x00000068 0x00000200 47ecdc2c29eedae9067863b81868f3a4 0.41
.tls 0x00c21000 0x00000010 0x00000200 bf619eac0cdf3f68d496ea9344137e8b 0.00
.rsrc 0x00c22000 0x00007158 0x00007200 9c280ce53efae7baea9646e232e7e8da 5.16
.reloc 0x00c2a000 0x0000c5f8 0x0000c600 d778e1d7e6657fd18c843c23b4e3c045 5.46

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware