Skip to content

Latest commit

 

History

History
12 lines (12 loc) · 523 Bytes

README.md

File metadata and controls

12 lines (12 loc) · 523 Bytes

WindowsCryptoMinerRemoval

Run the script with Administrator privileges

This script is built to remove the most prevalent cryptominers affecting Windows devices. We have identified some IOCs of the miners and automated the removal.
The IOC's include scheduled tasks, firewall rules, dropped files, established network connections, registry edits, and running processes.
This works for malware related to any of the following keywords:

  1. XMrig
  2. Monero
  3. PCastle
  4. Mysa
  5. SDNS
  6. Powershell bypass -e