Use offline scanning tools like Windows Defender Offline, Malwarebytes, or ESET SysRescue. These have specific signatures for known superadminexe variants.
superadminexe.tmp was quarantined and hashed shared with threat intel platforms.Use Windows Defender Application Control (WDAC) or AppLocker to whitelist only approved executables. Block execution from %AppData%, %Temp%, and C:\Users\Public. superadminexe