Weird, that address does not look like it's been mining at nicehash according to their dashboard lookup and looking at an explorer, the last time it received funds was January of last year.
Most of the infected miners that I have seen / heard about mined to a common address.
Are all 3 pools in the config set to poolin?
-Dave