How to Remove “rsmui.exe”

What is rsmui.exe?

rsmui.exe is a legitimate process file popularly known as Removable Storage UI Layer. It is associated with Windows Operating System, developed by Microsoft Corporation. It is located in C:\Windows\System32 by default.
Malware programmers write virus files with malicious scripts and save them as rsmui.exe with an intention to spread virus on the internet.

Affected Platforms: Windows OS

How to determine if your computer is infected with rsmui.exe malware?

Look out for these symptoms to check if your PC is infected with rsmui.exe malware:

  • Unstable internet connection
  • rsmui.exe occupies extra CPU space
  • PC processing speed slows down
  • Browser often redirects to irrelevant websites
  • Browser is bombarded with hordes of popup ads
  • Computer screen freezes repeatedly

Take the following steps to diagnose your PC for possible rsmui.exe malware attack:

Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.

Step 2: If you notice the file located outside C:\Windows\System32, perform an antivirus scan to get rid of the malware.

How to remove rsmui.exe malware from system using Comodo Antivirus?

Step 1: Download our award-winning Free Antivirus

Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.

Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.

Step 4: Restart your PC after the installation gets over.

Step 5: Wait for Comodo Internet Security to update the antivirus.

Step 6: Proceed with the quick scan that automatically begins after the update.

Step 7: If threats are found during the scanning, you will be notified through an alert screen.

Step 8: Comodo Antivirus will remove rsmui.exe malware from your computer including all other malwares!

27

Malware Entries

First Seen: 05 June 2008 at 11:27 am
No. Company File Type SHA1 MD5 Malware
Name
Digitally
Signed
File
Version
Product
Version
Submitted
From
Malware Behavior
1 Microsoft Corporation Executable 2e7156966da8c19e
a992973647019fdd
93cf8bff
035d19af18cc56df
e9f534634586b2c0
Virus.Win32.
Virut.CE
No 5.1.2400.1 5.1.2400.1 Internal Submission N/A
2 N/A Executable 6e3042557fd20daf
abaae263ca92f620
618b4f63
abc6078781708ad1
2edf1fe4202e693c
Win32.Neshta
.A
No N/A N/A Romania N/A
3 Microsoft Corporation Executable 112e6fe93a14e22b
596176ac05939fa1
7caacf0a
9d2c1fedf80efca6
5af7302a09b2d0fa
Virus.Win32.
Virut.CE
No 5.1.2400.1 5.1.2400.1 Indonesia N/A
4 Microsoft Corporation Executable c755f0fdb314f6a6
d53544d174aa9263
54b40f81
N/A Virus.Win32.
Virut.n
No 5.1.2400.1 5.1.2400.1 Vietnam N/A
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
24

Safe Entries

First Seen: 03 June 2008 at 5:51 pm
No. Company File Type SHA1 MD5 Digitally
Signed
File
Version
Product
Version
Submitted
From
1 Microsoft Corporation Executable 5c500db9569df457
71cb3b55dd8da69a
b094d388
694b3beede3d5d7a
ab05154b0cab6c75
No 5.1.2400.1 5.1.2400.1 Chile
2 Microsoft Corporation Executable df219c2d7daffc03
e094b1405d609c6b
107de82d
8237813b35b76649
553be1050db9d931
No 5.2.3790.3
959
(srv03_sp2
_rtm.07021
6-1710)
5.2.3790.3
959
Internal Submission
3 N/A Executable cf5bf791e89ea61e
7739de93d7e51642
07e390e2
58ebcbc59a3e752a
34e8d0ff9f635b11
No N/A N/A Internal Submission
4 Microsoft Corporation Executable b59edf58a9de0128
bb0250db6ff020bd
690c419a
27837fd125524f5d
77d2d6f0eba55e91
No 5.2.3790.3
959
(srv03_sp2
_rtm.07021
6-1710)
5.2.3790.3
959
Japan
Display 4 items per page
  • 4 items per page
  • 8 items per page
  • 16 items per page
  • 32 items per page
 
Exclusive Offer
Get Free Endpoint Protection
Get Advanced
Endpoint
Protection

Award-Winning Security to Protect Your Clients from Cyber Attacks

Comodo Internet Security Pro

Free Antivirus protection from hackers! Get the ultimate Antivirus solution to keep your PC clean and to remove viruses from a slow or infected PC. Improve the PC performance at home or use it on-the-go!

Get Comodo Internet Security Comodo Internet Security