TeamViewer is removing the miner files

Malware name: Application.BitCoinMiner.PD
Malware file path: c:\zcash\miner.exe
Detection time: 20-Nov-2017 09:10:19 UTC
Additional information / action: File deleted

Malware name: Generic.Malware.SL!dld.EA6C6D66
Malware file path: C:\WINDOWS\INSTALLDIR\SERVER.EXE\SOFTWARE\WOW6432NODE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS{5460C4DF-B266-909E-CB58-E32B79832EB2}\StubPath
Detection time: 20-Nov-2017 09:09:09 UTC
Additional information / action: File deleted

Malware name: Gen:Trojan.Heur.LShot.1
Malware file path: C:\Users\Rig\Downloads\Zcash Vaid\guardian.ps1
Detection time: 20-Nov-2017 09:16:06 UTC
Additional information / action: Moved to quarantine

So teamviewer basically removed my mining files and stopped mining… Has this happened with anyone else ?

It wasnt teamviewer, it was your antivirus. And it has happened yes. I kept the .rar file next to the ewbf miner folder untill i got my Avira antivirus configured and ignore the miner.exe file (unrarred the miner.exe again). Thats the zcash miner.exe file that got removed. Not sure about the zcash vaid folder and the guardian.ps1 file … no clue what they are.

1 Like

Teamviewer is a remote desktop software. It doesn’t scan for viruses or malware. It was whichever anti-virus or anti-malware software you have running.

Haha @project beat me to it :wink:

So the new team viewer aperantly has its own antimalware and security… that’s why it removed the files… That antimalware is from itbrains.com or something… I disabled it and reverted the files and it’s back online now…

Guardian is my own script to keep the process up and running… cheers

1 Like

Ahh. That makes sense. ITbrain has been a round a bit but it’s only available to pro accounts. I just assumed you were using the free version of Teamviewer. :slight_smile:

1 Like