• Status: Solved
  • Priority: Low
  • Security: Public
  • Views: 76
  • Last Modified:

BitCoinMiner help

Can anyone explain how the Coinminer trojan infects a machine?  Our web server keeps getting re-infected.
We have AVG File Server edition and CCleaner running on it, plus Malwarebytes(free version only at this stage).
AVG and Malwarebytes keep picking up the infection and remove it, but within a day it's back.
  • 2
2 Solutions
Dr. KlahnPrincipal Software EngineerCommented:
Sounds like you have a polymorphic virus there.  These are exceedingly clever viruses that hide all over a machine using methods that make them undetectable by virus scanners.  

If that is the case, the only solution will be to restore the machine from the last full backup that was uncorrupted ... or reload it from scratch.

Then open the case and disconnect the USB sockets on the front of the machine, as this is likely how it was infected in the first place.
Shaun VermaakTechnical Specialist/DeveloperCommented:
Someone keeps visiting a site that does in browser mining. The site does not even need to be malicious. For example, this site asks for concent and mines for the user.
I would also go to the expense of a Better AV solution - Symantec, McAfee, Ksperksy...  While AVG do produce a server product its not one I'd use on any production server
Dr. KlahnPrincipal Software EngineerCommented:
Points split among contributors who addressed the problem at hand.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now