Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

MobaXterm created `xwin_mobax.exe` or it is a virus? [closed]

Tags:

mobaxterm

Using Personal Edition v20.2 of MobaXterm at Windows 10...

No problem to remove a strange file like C:\Users\USERNAME\Documents\MobaXterm\slash\bin\xwin_mobax.exe ?

PS: this page say that xwin_mobax.exe is a virus, and windows asking about pemission (I cancel).

like image 391
Peter Krauss Avatar asked Oct 26 '25 10:10

Peter Krauss


2 Answers

The page link that you mentioned in your post describes about checking running processes associated with MobaXterm program and if you find those suspicious then it can be dangerous but they are not categorizing as threat since it is tool for SSH and as you know for that it reads keystrokes and mouse inputs.

So simple answer is NOT currently but if you monitor some unusual behavior by its process then it can be.

like image 167
darth vader Avatar answered Oct 29 '25 06:10

darth vader


Did you check this?

1 Antivirus labeled it as Trojan.Heur

The most significant indicator is an Anti-VM trick

(You can also check here and here)


Conclusions:

  • You can continue using your "Personal Edition v20.2 of MobaXterm", but

  • You can to delete as precautionary, but it is only 2.5% (1 of 40 detector-engines) as metadefender report YnpJd01EUXdNWEo1YUhSSmFEQXRSRlVyMWlGMkNidzg. Seems that will not affect MobaXterm functions

like image 36
aga Avatar answered Oct 29 '25 06:10

aga



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!