#XMRig Miner Virus Problem

83 messages · Page 1 of 1 (latest)

spiral robin
#

xmrig is a legit program lol, how tf did you get a virus version of it

frail jewel
spiral robin
#

I've used it many times myself to mine monero

frail jewel
#

Yeah I used it on another computer a while ago too. This time went to a virus thing lol

frail jewel
spiral robin
#

Did you download it from the correct site? How did you even get this virus

frail jewel
spiral robin
#

Wow damn, someone got a botnet out there using it

frail jewel
#

i'm very careful about what I download or do on the internet in general, very rare from myself to get infected but this time, maybe I didn't pay enough atention

spiral robin
#

Are you able to go to the source directory of the .exe files

frail jewel
#

and the 2 files are there

#

I can delete it if I use Rkill to kill the process (also detects that these two are malware )

#

but will come back in a few hours or tomorrow or in 2 days maximum

spiral robin
#

Another script must be hiding somewhere to load them back in

frail jewel
#

So yeah, something is clearly hiding but what...

spiral robin
#

Do you know what program you downloaded that might have contained the virus

frail jewel
#

Do you know how I could check what scripts goes on when I start windows? and which doesn't if I go to Safe mode?

spiral robin
#

In powershell run Get-Process

#

It should list stuff

frail jewel
spiral robin
#

The thing is a smart virus would disguise itself as a normal process

frail jewel
#

Yeah.. So here I opened task manager before running powershell and DlHost & svshost wasn't appearing bc it hides when I open it. Now, when closed, I can see them

#

As I showed when I close the task manager, processhacker tells me that a service was created and it's called WinRing0_1_2_0

spiral robin
#

Does this work Get-Process | Select-Object Name, StartTime

#

Shows the processes in order of which they started

frail jewel
spiral robin
#

Try this maybe Get-Process | Sort-Object StartTime | Select-Object Name, StartTime

frail jewel
spiral robin
#

Coz im thinking if you get the start times, delete the virues in the windows folder, wait for them to start up again you might be able to see the script that starts it up

frail jewel
#

but some doenst have time

frail jewel
spiral robin
#

Hmm

frail jewel
#

now that I closed task manager, it lists me DlHost and svshost (the viruses) at the bottom of the list

#

so something is still running that means it can make them work, right?

#

bc in safe mode they didn't even start x)

spiral robin
#

You could compare the list from safemode and normal mode

frail jewel
#

the very first thing that launched first is this

#

svchost, and svshost doesn't even exist, it's like it tries to fake svchost

frail jewel
#

also is there anyway to save this list?

spiral robin
#

Get-Process | Select-Object Name, StartTime >> C:/processes.txt

#

Or just get-process

#

Whatever command you are using lol

frail jewel
#

So now I have my 2 lists

frail jewel
#

@spiral robin Once I restarted my computer, I went instantly to Processhacker. I saw a Powershell window quickly appearing (couldn't see anything) and instantly closed, then the viruses appeared

#

is there anyway to check what was started ?

polar ice
#

Have you removed the malware?

frail jewel
polar ice
frail jewel
polar ice
#

I see it still comes back. Does it come back even with a good antivirus such as malwarebytes installed?

frail jewel
#

that's why I was here asking for help lol

polar ice
#

What antivirus do you have right now?

frail jewel
#

but no one couldn't so, someone else helped me

#

Windows Defender x)

polar ice
#

Was that someone anothergame?

#

Wondering if you came into contact with him, hes good at this stuff

frail jewel
#

No, not from this server

polar ice
#

also Why would you keep the normal useless (mind you..TRASH) antivirus? Could you maybe install kasperksy or avast one to scan your network and keep logs? Feels like a router malware, not sure.

frail jewel
#

I will in the future

polar ice
#

I had a malware keep coming back even when I reset my PC. It was a router infestation.

frail jewel
#

Now it's gone, the guy who helped me was a pro at it. We went very deep to remove it so I think it should have comeback now but it hasnt

polar ice
frail jewel
polar ice
#

ah alr

#

hes a friend of mine

#

was wondering if you knew him

frail jewel
#

That's cool

#

No :/

polar ice
#

alr

#

well

#

if it comes back again, please install kaspersky

frail jewel
#

i will

polar ice
#

it keeps logs on scripts from the internet trying to download malware

#

and block them

#

anyways good day