Windows 10: Did I just find crypto-malware on my PC?

Discus and support Did I just find crypto-malware on my PC? in Windows 10 Ask Insider to solve the problem; I left my PC alone with Task Manager open, and I noticed 3 processes, called ".NET Runtime Optimization Service", sitting at the top (when sorting by... Discussion in 'Windows 10 Ask Insider' started by /u/GLIBG10B, Jan 24, 2021.

  1. Did I just find crypto-malware on my PC?


    I left my PC alone with Task Manager open, and I noticed 3 processes, called ".NET Runtime Optimization Service", sitting at the top (when sorting by CPU). I sat down at my PC, and as soon as I started using it, they started to move down the list and separate. After waiting for 10 seconds, they quickly found their way back to the top. Very considerate, but still a nuisance.

    So, naturally, I fired up Process Explorer to take a look. This is what I found: C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe -restart 0 -pool us1.ethermine.org:4444 -pool2 us2.ethermine.org:4444 -wal 0x2C87A020b716276D37FF52BFab90286C71A28Ed9.MyRig -proto 3 C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe -restart 0 -pool us1.ethermine.org:4444 -pool2 us2.ethermine.org:4444 -wal 0x2C87A020b716276D37FF52BFab90286C71A28Ed9.MyRig -proto 3 C:\Windows\Microsoft.NET\Framework\v3.5\mscorsvw.exe -restart 0 -pool us1.ethermine.org:4444 -pool2 us2.ethermine.org:4444 -wal 0x2C87A020b716276D37FF52BFab90286C71A28Ed9.MyRig -proto 3

    The command-line arguments for all three processes contain "ethermine", which I assume is an Ethereum miner. Cool, so I've been lending my processing power this whole time, and Windows Defender didn't have anything to say about it?

    So, I have a few questions: 1. This is crypto-mining malware, right? 2. How do I get rid of it? 3. How do I get rid of all traces of it? 4. Has anyone else here encountered this before? 5. How can I check my PC for malware like this, without using antivirus (for personal reasons)?

    Thanks in advance!

    submitted by /u/GLIBG10B
    [link] [comments]

    :)
     
    /u/GLIBG10B, Jan 24, 2021
    #1

  2. How crypto ransomware spreads... is it decryptable...should I pay the ransom

    Crypto malware ransomware typically propagates itself as a
    Trojan Horse
    which the developers use to target a wide audience for financial gain rather than a specific individual. Numerous

    variants of encrypting ransomware
    have been reported between 2013 and 2016.

    A repository listing of Crypto malware Information and ransomware topics can be found in this index.

     
    quietman7 - MVP, Jan 24, 2021
    #2
  3. Does Windows 10 File History protect against crypto malware

    Is the saved data generated by Windows 10's file history feature isolated from users and administrators? I'm asking this after reading of the recent crypto attack against OSX machines where time machine backups were safe because the files are only accessible to a special user and even with access to the drive the malware wasn't able to encrypt time machine's data store.

    I was wondering if Windows 10's feature provides similar protection. There is a similar question to this but the answers simply suggest different backup strategies and don't actually answer the question.

    note: I realize that the most secure solution involves backing up to drives that are physically disconnected, there's no need to suggest that - I'm only looking for a specific answer to this question
     
    George Kendros, Jan 24, 2021
    #3
  4. Did I just find crypto-malware on my PC?

    How crypto ransomware spreads... is it decryptable...should I pay the ransom

    Crypto malware typically will scan and encrypt whatever data files it finds on computers connected in the same network with a drive letter including removable drives, network shares, and even DropBox mappings...if there is a drive letter on your
    computer it will be scanned for data files and encrypt them
    . Some crypto malware will scan all of the drive letters that match certain file extensions and when it finds a match, it encrypts them. Other crypto malware utilize a white list and will
    encrypt all files unless it has certain excluded extensions or is located at a certain area on the system.
     
    quietman7 - MVP, Jan 24, 2021
    #4
Thema:

Did I just find crypto-malware on my PC?

Loading...
  1. Did I just find crypto-malware on my PC? - Similar Threads - Did find crypto

  2. Powershell hogging ram/cpu crypto malware

    in Windows 10 Gaming
    Powershell hogging ram/cpu crypto malware: Since i've got that issue and got it fixed with a good person named _AW_ in this community. i got it again and noticed a lot of people are having same issue. he told me in this thread to make a thread so he reply me....
  3. Powershell hogging ram/cpu crypto malware

    in Windows 10 Software and Apps
    Powershell hogging ram/cpu crypto malware: Since i've got that issue and got it fixed with a good person named _AW_ in this community. i got it again and noticed a lot of people are having same issue. he told me in this thread to make a thread so he reply me....
  4. Powershell hogging ram/cpu crypto malware

    in AntiVirus, Firewalls and System Security
    Powershell hogging ram/cpu crypto malware: Since i've got that issue and got it fixed with a good person named _AW_ in this community. i got it again and noticed a lot of people are having same issue. he told me in this thread to make a thread so he reply me....
  5. Malware did not destroy my PC

    in AntiVirus, Firewalls and System Security
    Malware did not destroy my PC: Recently I downloaded wannacrypt ransomware and install it on my old PC just for fun. Windows 10 pro 64-bitBut instead of encrypt my file and demand me to give it money, it runs some command on terminal and just... vanished. My PC remains untouched.I even download the malware...
  6. I believe there is malware in my PC

    in AntiVirus, Firewalls and System Security
    I believe there is malware in my PC: So at random times the command prompt will open up and close really fast and its from a file called ptxas.exe, is there any way to get rid of it or just make it stop opening up? and I also unable to reset my pc there is a image down there please look into it. i have tried...
  7. I believe there is malware in my PC

    in AntiVirus, Firewalls and System Security
    I believe there is malware in my PC: So at random times the command prompt will open up and close really fast and its from a file called ptxas.exe, is there any way to get rid of it or just make it stop opening up?[Original Title: Maybe Virus]...
  8. my pc is infected with unremovable crypto mining malware

    in AntiVirus, Firewalls and System Security
    my pc is infected with unremovable crypto mining malware: there is a process that has no name with a settings symbol, and when i click on open file location it brings me to svchost in system32, i cant end the task or the pc will bsod, malwarebytes shows nothing, windows defender shows nothing, and it uses about 50% of my cpu and 80...
  9. I think my computer has a Crypto mining malware

    in AntiVirus, Firewalls and System Security
    I think my computer has a Crypto mining malware: Hello, so when I open task manager everything freezes for 1 second and CPU usage is at 100% then everything goes back to normal, I think my pc has a bitcoin miner, what to do ?[ATTACH], this is from AVG internet security antivirus quarantine selection, I deleted it from there...
  10. Did Windows 10 just Break My PC?

    in Windows 10 Support
    Did Windows 10 just Break My PC?: *MadEver since install..all 3 pc's have been acting weird....won't sleep or shut down properly, random crashes, go away 30 min. and when I come back, all my icons are huge...???? and just now my Desk Top just powered off and it's completely DEAD!!!. No lights on the MB,...