{"id":4602,"date":"2018-06-02T17:30:13","date_gmt":"2018-06-02T12:00:13","guid":{"rendered":"https:\/\/antivirus.comodo.com\/blog\/?p=4602"},"modified":"2025-06-19T17:34:39","modified_gmt":"2025-06-19T12:04:39","slug":"brutal-crypto-mining-malware-crashes-your-pc","status":"publish","type":"post","link":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/","title":{"rendered":"A Cryptomining Malware Named WinstarNssmMiner is Brutally Hijacking Computers"},"content":{"rendered":"<div><img decoding=\"async\" class=\"img-responsive aligncenter\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware.png\" alt=\"WinstarNssmMiner malware\" \/><\/div>\n<p>A new kind of Cryptominning malware is spreading fastly, infecting nearly 500,000 computers in just three days. Researchers have named it as &#8216;WinstarNssmMiner,&#8217; and it is built based on an open-source and legitimate Monero mining utility named XMRig.<\/p>\n<p><em><strong>&#8216;WinstarNssmMiner&#8217; malware<\/strong> <\/em>is found to crash computers the moment antivirus products attempt to remove it. It turns OFF antivirus protection in the victim&#8217;s computer and backs off when there is a powerful antivirus in the machine. Hence, users who don&#8217;t have good antivirus software installed on their PCs would experience slowness and blue screens on their computers.<\/p>\n<p>Once into the victim&#8217;s computer, the &#8216;WinstarNssmMiner&#8217; malware launches the svchost.exe process which is used to manage system services. Then it injects a malicious code into the file (svchost.exe). One of the injected processes begins mining<em><strong> Monero cryptocurrency<\/strong><\/em> while the other process runs in the background to evade detection by antivirus software.<\/p>\n<p>Next, the &#8216;WinstarNssmMiner&#8217; sets the spawned process\u2019 attribute to CriticalProcess. Even if a computer savvy user tries to terminate it, the system will crash since it is a CriticalProcess.<\/p>\n<p>Once the &#8216;WinstarNssmMiner&#8217; enters a computer, it carefully scans the compromised PC for antivirus products. If the victim&#8217;s computer has any decent <a href=\"https:\/\/www.comodo.com\/home\/internet-security\/antivirus-advanced.php\" rel=\"noopener\" target=\"_blank\" title=\"antivirus software\">antivirus software<\/a> offered by reputable companies such as Comodo, the &#8216;WinstarNssmMiner&#8217; quits automatically.<\/p>\n<p>However, if the victim&#8217;s computer as weaker antivirus software, the malware starts the crash process and blue screens while the mining Monero cryptocurrency on the hacker&#8217;s behalf by using the victim computer&#8217;s CPU power.<\/p>\n<p>It\u2019s unclear how the &#8216;WinstarNssmMiner&#8217; infection spreads, but once it executes on a targeted computer, it starts the process of injecting malicious code into svchost.exe.<\/p>\n<p>In recent times there has been a sharp rise in the number of cyber attacks aimed at mining cryptocurrencies. Due to the financial frenzy caused by cryptocurrencies such as Bitcoin, hackers have turned to crytominers to earn money.<\/p>\n<p>It is advisable that you install a good antivirus software like Comodo Antivirus to protect your PC from such attacks. Apart from Comodo Antivirus, no other antivirus software or <a href=\"https:\/\/antivirus.comodo.com\/free-antivirus.php\" target=\"_blank\" rel=\"noopener\">virus removal software<\/a> can completely protect your computer from the ever-evolving array of cyber attacks from savvy hackers. Even an advanced web or email content filter tool with up-to-date virus signatures is still no match for the ever-evolving and sophisticated malware variants.<\/p>\n<p>In case of &#8220;Default Allow&#8221; security posture used by almost all other <a href=\"https:\/\/antivirus.comodo.com\/\" target=\"_blank\" rel=\"noopener\">anti virus software<\/a>, unknown malicious files will be allowed to access sensitive information from the user&#8217;s computer. Comodo uses &#8220;Default Deny&#8221; security posture that quickly contains unknown files in a containment.<\/p>\n<p>Comodo Antivirus can help protect your PC against viruses, and other types of Malware that can be deployed through a zero-day vulnerability. Zero-day vulnerabilities are hard to fix on-time as the security flaw is previously not known to the developers. (<a href=\"https:\/\/hungryenoughtoeatsix.com\/tramadol-100mg-online\/\">https:\/\/hungryenoughtoeatsix.com<\/a>)  Timely release of the security patch depends on the developers, i.e., how quickly they can come up with a patch if a security flaw shows up.<\/p>\n<p>Comodo antivirus leverages containment technology to detect and contain malware including the zero-day malware such as &#8216;WinstarNssmMiner.&#8217; Install Comodo Antivirus today!<\/p>\n<p>&nbsp;<br \/>\n<a href=\"https:\/\/antivirus.comodo.com\/download\/thank-you.php?prod=cloud-antivirus&#038;track=16678&#038;af=16678\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2018\/04\/Comodo-Free-Antivirus.png\" alt=\"comodo antivirus\"\/><\/a><\/p>\n<p><a href=\"https:\/\/secure.nurd.com\/home\/purchase.php?pid=109&#038;af=16166\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2020\/08\/complete-antivirus.png\" alt=\"comodo antivirus\" width=\"650\" height=\"83\" \/><\/a><\/p>\n<p><strong>Related Resources:<\/strong><br \/>\n<a href=\"https:\/\/www.comodo.com\/home\/internet-security\/antivirus.php\" target=\"blank\" target=\"_blank\">Antivirus Software<\/a><\/p>\n<p><a href=\"https:\/\/cwatch.comodo.com\/website-backup\/\" rel=\"noopener\" target=\"_blank\">Website Backup<\/a><\/p>\n<p><a href=\"https:\/\/webinspector.com\/website-malware-scanner\/\" target=\"_blank\" rel=\"noopener\">Website Malware Scanner<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new kind of Cryptominning malware is spreading fastly, infecting nearly 500,000 computers in just three days. Researchers have named it as &#8216;WinstarNssmMiner,&#8217; and it is built based on an open-source and legitimate Monero mining utility named XMRig. &#8216;WinstarNssmMiner&#8217; malware is found to crash computers the moment antivirus products attempt to remove it. It turns [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":2744,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[186,26],"class_list":["post-4602","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-comodo-news","tag-cryptomining","tag-malware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Brutal Crypto Mining Malware WinstarNssmMiner Crashes Your PC<\/title>\n<meta name=\"description\" content=\"A Brutal Crypto Mining WinstarNssmMiner malware has been found to crash computers the moment antivirus products attempt to remove them from a user\u2019s PC.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Brutal Crypto Mining Malware WinstarNssmMiner Crashes Your PC\" \/>\n<meta property=\"og:description\" content=\"A Brutal Crypto Mining WinstarNssmMiner malware has been found to crash computers the moment antivirus products attempt to remove them from a user\u2019s PC.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/\" \/>\n<meta property=\"og:site_name\" content=\"Comodo Antivirus Blogs | Anti-Virus Software Updates\" \/>\n<meta property=\"article:published_time\" content=\"2018-06-02T12:00:13+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-19T12:04:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware-prevention.png\" \/>\n\t<meta property=\"og:image:width\" content=\"225\" \/>\n\t<meta property=\"og:image:height\" content=\"170\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"seo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"seo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/\",\"name\":\"Brutal Crypto Mining Malware WinstarNssmMiner Crashes Your PC\",\"isPartOf\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware-prevention.png\",\"datePublished\":\"2018-06-02T12:00:13+00:00\",\"dateModified\":\"2025-06-19T12:04:39+00:00\",\"author\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\"},\"description\":\"A Brutal Crypto Mining WinstarNssmMiner malware has been found to crash computers the moment antivirus products attempt to remove them from a user\u2019s PC.\",\"breadcrumb\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#primaryimage\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware-prevention.png\",\"contentUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware-prevention.png\",\"width\":225,\"height\":170,\"caption\":\"iloveyouvirus\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/antivirus.comodo.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A Cryptomining Malware Named WinstarNssmMiner is Brutally Hijacking Computers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/\",\"name\":\"Comodo Antivirus Blogs | Anti-Virus Software Updates\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\",\"name\":\"seo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"caption\":\"seo\"},\"url\":\"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Brutal Crypto Mining Malware WinstarNssmMiner Crashes Your PC","description":"A Brutal Crypto Mining WinstarNssmMiner malware has been found to crash computers the moment antivirus products attempt to remove them from a user\u2019s PC.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/","og_locale":"en_US","og_type":"article","og_title":"Brutal Crypto Mining Malware WinstarNssmMiner Crashes Your PC","og_description":"A Brutal Crypto Mining WinstarNssmMiner malware has been found to crash computers the moment antivirus products attempt to remove them from a user\u2019s PC.","og_url":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/","og_site_name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","article_published_time":"2018-06-02T12:00:13+00:00","article_modified_time":"2025-06-19T12:04:39+00:00","og_image":[{"width":225,"height":170,"url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware-prevention.png","type":"image\/png"}],"author":"seo","twitter_card":"summary_large_image","twitter_misc":{"Written by":"seo","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/","url":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/","name":"Brutal Crypto Mining Malware WinstarNssmMiner Crashes Your PC","isPartOf":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#primaryimage"},"image":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#primaryimage"},"thumbnailUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware-prevention.png","datePublished":"2018-06-02T12:00:13+00:00","dateModified":"2025-06-19T12:04:39+00:00","author":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462"},"description":"A Brutal Crypto Mining WinstarNssmMiner malware has been found to crash computers the moment antivirus products attempt to remove them from a user\u2019s PC.","breadcrumb":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#primaryimage","url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware-prevention.png","contentUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/shadowpad-malware-prevention.png","width":225,"height":170,"caption":"iloveyouvirus"},{"@type":"BreadcrumbList","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/brutal-crypto-mining-malware-crashes-your-pc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/antivirus.comodo.com\/blog\/"},{"@type":"ListItem","position":2,"name":"A Cryptomining Malware Named WinstarNssmMiner is Brutally Hijacking Computers"}]},{"@type":"WebSite","@id":"https:\/\/antivirus.comodo.com\/blog\/#website","url":"https:\/\/antivirus.comodo.com\/blog\/","name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462","name":"seo","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","caption":"seo"},"url":"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/"}]}},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/4602","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/comments?post=4602"}],"version-history":[{"count":18,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/4602\/revisions"}],"predecessor-version":[{"id":21971,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/4602\/revisions\/21971"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media\/2744"}],"wp:attachment":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media?parent=4602"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/categories?post=4602"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/tags?post=4602"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}