Windows 10: How do I find a task I believe is related to coinminer malware?

Discus and support How do I find a task I believe is related to coinminer malware? in AntiVirus, Firewalls and System Security to solve the problem; I am having an odd problem that I think may be related to malware. A few days ago Windows Defender stopped working. I also use Comodo AV. Comodo AV... Discussion in 'AntiVirus, Firewalls and System Security' started by PlatypusKnight, Mar 31, 2019.

  1. How do I find a task I believe is related to coinminer malware?


    I am having an odd problem that I think may be related to malware.

    A few days ago Windows Defender stopped working. I also use Comodo AV. Comodo AV was disabled from the system tray but it was apparently still able to run. It ran a scheduled scan and discovered a miner.

    For some time I had noticed that every time I boot C:\Windows\Temp\signtool.exe wants to connect to the web.

    However no such file exists on my machine.

    This got me to thinking that there must be a task somewhere that is running signtool.exe from the temp folder. And then deleting that file.

    I started logging tasks with Task Scheduler.

    I have identified two tasks I think are suspicious. Signtool.exe attempted to connect to the web 2 mins after one of these tasks ran.



    How do I find a task I believe is related to coinminer malware? [​IMG]



    However I can't interact with the task at all because Task Scheduler doesn't allow you to open tasks from the Task Status box. How can I find out more information about this task?



    I am not sure but I think this is the first stage of the malware process. Signtool will connect to the internet, and then download the payload, and then the miner will start again. The miner will disable Microsoft Security Center, will disable updates, and then start doing the mining.


    Or maybe I am being paranoid and signtool.exe is a legitimate process and I am being paranoid. However, I use the same programs on multiple machines and never seen this signtool.exe on any other machine.

    I will also note that startupchecklibrary.dll has returned to my machine, although I deleted this file as part of malware removal efforts.

    Any help, any information is appreciated.

    At this point I am trying to determine

    1. If I am overreacting and signtool.exe is legitimate
    2. Why signtool.exe seeks to the connect to the internet at boot, and then at scheduled intervals
    3. What these strange tasks are and how I can find them

    :)
     
    PlatypusKnight, Mar 31, 2019
    #1
  2. Brink Win User

    XBash malware combines ransomware, coinminer, botnet, & worm features


    Read more:
     
    Brink, Mar 31, 2019
    #2
  3. Le Boule Win User
    Le Boule, Mar 31, 2019
    #3
  4. How do I find a task I believe is related to coinminer malware?

    My pc takes for ever to shut down when i restart

    Suggest cleaning up your startup list .There may be many services / Apps you can remove on startup which is not needed on boot or during shutdown.
    Before you shutdown the Pc check what is running in Task Manager as a program or service in not killing the process on shutdown

    Would suggest cleaning up running apps and services -Autoruns, StartupMonitor,HighjackThis,
    Malware Scan - Malwarebytes,ADWcleaner, Combofix
     
    SnakeDoctor, Mar 31, 2019
    #4
Thema:

How do I find a task I believe is related to coinminer malware?

Loading...
  1. How do I find a task I believe is related to coinminer malware? - Similar Threads - find task believe

  2. How do I disband a family Malware related

    in Windows 10 Gaming
    How do I disband a family Malware related: I recently uninstalled some malware botnet related, ad clickers that created a "remote administrator account." I cannot remove myself from the family group, I think, because of this, I cannot remove myself from the family. I do not see another account listed anywhere on the...
  3. How do I disband a family Malware related

    in Windows 10 Software and Apps
    How do I disband a family Malware related: I recently uninstalled some malware botnet related, ad clickers that created a "remote administrator account." I cannot remove myself from the family group, I think, because of this, I cannot remove myself from the family. I do not see another account listed anywhere on the...
  4. How can I delete this CoinMiner Malware that keeps reinstalling after removal?

    in Windows 10 Gaming
    How can I delete this CoinMiner Malware that keeps reinstalling after removal?: Windows Defender alerts malware CoinMiner.I on reboot stating it was been deleted. I am assuming it's reinstalling from another process and have been trying to track it down. This is the alert that I am getting.Detected: Behavior:Win32/CoinMiner.IStatus: RemovedA threat or...
  5. How can I delete this CoinMiner Malware that keeps reinstalling after removal?

    in Windows 10 Software and Apps
    How can I delete this CoinMiner Malware that keeps reinstalling after removal?: Windows Defender alerts malware CoinMiner.I on reboot stating it was been deleted. I am assuming it's reinstalling from another process and have been trying to track it down. This is the alert that I am getting.Detected: Behavior:Win32/CoinMiner.IStatus: RemovedA threat or...
  6. Malware related

    in Windows 10 Gaming
    Malware related: I want to inform you that I recently download a cracked game and defender detects some malware and I remove them by defender. And now the game running very smoothly and my computer does not detect any defect. Should I uninstall the game or I can play this...
  7. Malware related

    in Windows 10 Software and Apps
    Malware related: I want to inform you that I recently download a cracked game and defender detects some malware and I remove them by defender. And now the game running very smoothly and my computer does not detect any defect. Should I uninstall the game or I can play this...
  8. I am facing 2 issues on relating security I believe

    in Windows 10 Gaming
    I am facing 2 issues on relating security I believe: 1. the security setting which shows the error is - local security authority protection. it remains on but the line that windows restart is required is stuck on it in yellow color on top of it.2. My web browsers namely edge and google are being managed by an organization that...
  9. I believe there is malware in my PC

    in AntiVirus, Firewalls and System Security
    I believe there is malware in my PC: So at random times the command prompt will open up and close really fast and its from a file called ptxas.exe, is there any way to get rid of it or just make it stop opening up? and I also unable to reset my pc there is a image down there please look into it. i have tried...
  10. I believe there is malware in my PC

    in AntiVirus, Firewalls and System Security
    I believe there is malware in my PC: So at random times the command prompt will open up and close really fast and its from a file called ptxas.exe, is there any way to get rid of it or just make it stop opening up?[Original Title: Maybe Virus]...