What is rsh.exe?
rsh.exe is a legitimate process file popularly known as TCP/IP Remote Shell Command. It belongs to the Windows Operating System, developed by Microsoft Corporation. It is located in C:\Windows\System32 by default. Malware programmers write virus files with malicious scripts and save them as rsh.exe with an intention to spread virus on the internet.
Affected Platforms: Windows OS
How to determine if your computer is infected with rsh.exe malware?
Look out for the these symptoms to check if your PC is infected with rsh.exe malware:
- Unstable internet connection
- rsh.exe occupies extra CPU space
- PC processing speed slows down
- Browser often redirects to irrelevant websites
- Browser is bombarded with hordes of popup ads
- Computer screen freezes repeatedly
Take the following steps to diagnose your PC for possible rsh.exe malware attack:
Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.
Step 2: If you notice the file located outside C:\Windows\System32, perform an antivirus scan to get rid of the malware.
How to remove rsh.exe malware from system using Comodo Antivirus?
Step 1: Download our award-winning Free Antivirus.
Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.
Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.
Step 4: Restart your PC after the installation gets over.
Step 5: Wait for Comodo Internet Security to update the antivirus.
Step 6: Proceed with the quick scan that automatically begins after the update.
Step 7: If threats are found during the scanning, you will be notified through an alert screen.
Step 8: Comodo Antivirus will remove rsh.exe malware from your computer including all other malwares!
| No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Microsoft Corporation | Executable | 9477ca1d13404933 c644bc5a28c35541 76482eb1 |
a8ebee48df0d4869 6eb70f02513dc372 |
Virus.Win32. Parite.gen |
No | 5.1.2600.2 180 (xpsp_sp2_ rtm.040803 -2158) |
5.1.2600.2 180 |
Turkey |
N/A |
| 2 | Корпорация Майкрософт | Executable | d2eb66f5bbd2503c 7559a363a5c6e8cd 685bb80f |
033f7d28a94e58a9 706dee1979fa8e91 |
Virus.Win32. Expiro.R0 |
No | 5.1.2600.5 512 (xpsp.0804 13-0852) |
5.1.2600.5 512 |
Ukraine |
N/A |
| 3 | Microsoft Corporation | Executable | 5213f1f27cc4702a 250b1afe7b8721e6 12e483ec |
01014be755def953 37cee53843ddda0e |
Virus.Win32. Virut.Ce |
No | 5.1.2600.5 512 (xpsp.0804 13-0852) |
5.1.2600.5 512 |
10.224.1.116/32 |
N/A |
| 4 | Microsoft Corporation | Executable | 9d8e1b544c2c2da2 8bceee522499954f 34425bee |
ef1b23f968f9cd9e 9ddc300ad3dbe8d6 |
Virus.Win32. Parite.gen |
No | 5.1.2600.2 180 (xpsp_sp2_ rtm.040803 -2158) |
5.1.2600.2 180 |
Turkey |
N/A |
| No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
|---|---|---|---|---|---|---|---|---|
| 1 | N/A | Executable | b340ab516d230b57 5091bc86141332c4 7ee58785 |
5f897a7366bdafee fe7de053134ad7ed |
No | N/A | N/A | United States |
| 2 | N/A | Executable | 82f4f8d9cde82a4a 96080b24949746b8 b3f4e98c |
8bb29c716b340a65 2a374becab384389 |
No | N/A | N/A | United States |
| 3 | N/A | Non-executable | 58af749bbd5b41b0 d987d7fe3ef7948b 7f67451a |
91e98537de24c771 1d705811901a7523 |
No | N/A | N/A | 104.238.128.144/32 |
| 4 | N/A | Executable | 78a272d1ecd1fe06 87fa411ef1bd9804 162a8e63 |
063c886278125f2e 37f106ba9b62be10 |
No | N/A | N/A | United States |

Turkey
Ukraine
10.224.1.116/32
United States
Russian Federation
Trinidad and Tobago
Bulgaria
Egypt
Vietnam
Italy
Taiwan
Germany
China
Mexico
India
Canada
