My server had infected with CoinMiner "fuckyoumm_consumer and fuckyoumm2_consumer". I have tried all sugguestions follow the links:
It was easy to remove all worm. But the result wasn't as expected. After server restart, all "fuckyoumm" came back again, even tried in safemode.
Have anyone can help me to completely clear these worms?
Hello a b15,
this isn't an XG Firewall question, is it? Could you please tell which Sophos product (on-premise SESC, Central/Intercept X) you are using and the server's OS version. Is this the only machine affected? Do you still get alerts from Sophos, if so, please provide the SAV.txt log..
But as the threat persisted it's better to raise a Support Case as mentioned in the Recommended Actions.
I am sorry about posted on wrong thread. I am using Sophos Endpoint Agent and Malwarebytes. The Sophos have no alert, even full scanning, but when I scan with Malwarebytes, it showed worms, then I did quarantine all with Malwarebytes. I have also delete worm from Autorun. But after restart the server, all came back again.
as said, you should raise a case with Support, did you already do so?Sophos Endpoint Agent suggests Central/Intercept X but you didn't specify. Anyway, without details it's impossible to suggest a solution. If neither Sophos nor Malwarebytes nor both together can get rid of it and you've carried out all the steps in the articles an in-depth analysis is necessary.