Jump to content

Urgent: XMR coin miner malware


Go to solution Solved by Marcos,

Recommended Posts

Posted

Hi all,

I have some windows servers 2012 standard effected XMR coin miner malware, when I view with processxp

C:\Windows\System32\svchost.exe -o pool.supportxmr.com:443 -u 44bwTAxAcX7Q99bCLnawEQW55LrCqEUfT1D8pnzz9f1LXSSwp3AXD1K829xt7xKoFdUfdxneZGCmi6BfyHVbQy73UN7GQMJ -k --tls -p 054

My servers has ESET Antivirus 7.x for windows but it cannot detect and remove this malware, please help, let me know if you need more information, thank you very much.

Posted

After update windows, restart , block all traffic in/out from/to pool.supportxmr.com , the malware process stil running but it doesn't consume CPU anymore , is it safe to delete C:\Windows\System32\XblGameUpdateTask.exe ?

Capture.PNG

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...