Securing Wowza Streaming Engine Manager from Backdoors

Before you delete the files you have some debugging to do. Otherwise you will have the same problem again in no time.

  • Did you secure your windows server? installing with the basic settings is not enough.
  • Windows defender is not suitable for servers (in my opinion).
  • Get server monitoring (zabbix or some sort).
  • Close down all the ports you dont need
  • is your Java up-to-date?
  • Did you patch your Wowza with the log4j patch?
    UPDATE: FIX RELEASED FOR BOTH CVE-2021-44228 or CVE-2021-45046/ log4j2

You have to find the source first and close that down. Close the leak first then you can delete the files.
Edit: Am i right you already found the source?

If you have an annual license you could also ask wowza for support. I don’t think they help you with removing the trojan, but they can advise you on your Windows setup.