What is rsh.exe?
rsh.exe is a legitimate process file popularly known as TCP/IP Remote Shell Command. It belongs to the Windows Operating System, developed by Microsoft Corporation. It is located in C:\Windows\System32 by default. Malware programmers write virus files with malicious scripts and save them as rsh.exe with an intention to spread virus on the internet.
Affected Platforms: Windows OS
How to determine if your computer is infected with rsh.exe malware?
Look out for the these symptoms to check if your PC is infected with rsh.exe malware:
- Unstable internet connection
- rsh.exe occupies extra CPU space
- PC processing speed slows down
- Browser often redirects to irrelevant websites
- Browser is bombarded with hordes of popup ads
- Computer screen freezes repeatedly
Take the following steps to diagnose your PC for possible rsh.exe malware attack:
Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.
Step 2: If you notice the file located outside C:\Windows\System32, perform an antivirus scan to get rid of the malware.
How to remove rsh.exe malware from system using Comodo Antivirus?
Step 1: Download our award-winning Free Antivirus.
Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.
Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.
Step 4: Restart your PC after the installation gets over.
Step 5: Wait for Comodo Internet Security to update the antivirus.
Step 6: Proceed with the quick scan that automatically begins after the update.
Step 7: If threats are found during the scanning, you will be notified through an alert screen.
Step 8: Comodo Antivirus will remove rsh.exe malware from your computer including all other malwares!
No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
---|---|---|---|---|---|---|---|---|---|---|
1 | Microsoft Corporation | Executable | 9477ca1d13404933 c644bc5a28c35541 76482eb1 |
a8ebee48df0d4869 6eb70f02513dc372 |
Virus.Win32. Parite.gen |
No | 5.1.2600.2 180 (xpsp_sp2_ rtm.040803 -2158) |
5.1.2600.2 180 |
![]() |
N/A |
2 | Корпорация Майкрософт | Executable | d2eb66f5bbd2503c 7559a363a5c6e8cd 685bb80f |
033f7d28a94e58a9 706dee1979fa8e91 |
Virus.Win32. Expiro.R0 |
No | 5.1.2600.5 512 (xpsp.0804 13-0852) |
5.1.2600.5 512 |
![]() |
N/A |
3 | Microsoft Corporation | Executable | 5213f1f27cc4702a 250b1afe7b8721e6 12e483ec |
01014be755def953 37cee53843ddda0e |
Virus.Win32. Virut.Ce |
No | 5.1.2600.5 512 (xpsp.0804 13-0852) |
5.1.2600.5 512 |
![]() |
N/A |
4 | Microsoft Corporation | Executable | 9d8e1b544c2c2da2 8bceee522499954f 34425bee |
ef1b23f968f9cd9e 9ddc300ad3dbe8d6 |
Virus.Win32. Parite.gen |
No | 5.1.2600.2 180 (xpsp_sp2_ rtm.040803 -2158) |
5.1.2600.2 180 |
![]() |
N/A |
No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
---|---|---|---|---|---|---|---|---|
1 | N/A | Executable | b340ab516d230b57 5091bc86141332c4 7ee58785 |
5f897a7366bdafee fe7de053134ad7ed |
No | N/A | N/A | ![]() |
2 | N/A | Executable | 82f4f8d9cde82a4a 96080b24949746b8 b3f4e98c |
8bb29c716b340a65 2a374becab384389 |
No | N/A | N/A | ![]() |
3 | N/A | Non-executable | 717c5b52bf0e2f00 ba32e63bddc901e6 8998c6de |
8c408c41d87ce4d7 754a382f4c94e1b9 |
No | N/A | N/A | ![]() |
4 | N/A | Non-executable | 58af749bbd5b41b0 d987d7fe3ef7948b 7f67451a |
91e98537de24c771 1d705811901a7523 |
No | N/A | N/A | ![]() |