Jump to content

Please help me remove a bitcoin miner virus.


Recommended Posts

Hi!

So I have a Bitcoin miner virus in my computer.

I made a topic about that here: https://forums.malwarebytes.org/index.php?showtopic=146431#entry817421

So there was cracked software on my computer.

I couldn't remove all of them individually so I ran ESET Online Scanner but kept the 'remove found threats' check box checked.

After it found the 67 virus files (there were 70 before) it sent them all to quarantine and I deleted them from quarantine.

 

The virus is still present in my computer.

I ran MBAM, FarBar and RogueKiller again.

The logs are below.

Please help.

Thanks!

mbam.txt

FRST.txt

RKreport0_S_04212014_154205.txt

Link to post
Share on other sites

  • Root Admin

Please go ahead and run through the following steps and post back the logs when ready.

STEP 03
Please download Malwarebytes Anti-Rootkit from here

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder... mbar-log.txt and system-log.txt

STEP 04
Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Right click over JRT.exe and select Run as administrator on Windows Vista or Windows 7, double-click on XP.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next reply message
  • When completed make sure to re-enable your antivirus



STEP 05
Lets clean out any adware now: (this will require a reboot so save all your work)

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you may want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted:
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.



STEP 06
Please open Malwarebytes Anti-Malware and from the Dashboard please Check for Updates by clicking the Update Now... link
Open up Malwarebytes > Settings > Detection and Protection > Under Non Malware Protection set both PUP and PUM to Treat detections as malware.
Click on the SCAN button and run a Threat Scan with Malwarebytes Anti-Malware by clicking the Scan Now>> button.
Once completed please click on the History > Application Logs and find your scan log and open it and then click on the "copy to clipboard" button and post back the results on your next reply.


STEP 07
button_eos.gif

Please go here to run the online antivirus scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology

    [*]Click Scan [*]Wait for the scan to finish [*]If any threats were found, click the 'List of found threats' , then click Export to text file.... [*]Save it to your desktop, then please copy and paste that log as a reply to this topic.



STEP 08
Please download the Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press the Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it also makes another log (Addition.txt). Please attach it to your reply as well.


 

Link to post
Share on other sites

Hi!

Thanks for replying.

I may have made a few changes to my computer so I ran MBAM (mbam.txt), FarBar (FRST.txt), RogueKiller (RKreport[0]_S_04242014_104413.txt) and the logs are below!

 

RogueKiller finds 2 registry malware files. I tried removing them using RogueKiller and manually but they reappear after rebooting.

 

MBAR found nothing (again)! (mbar-log-2014-04-24 (10-47-15).txt) and (system-log.txt)

JRT worked fine (JRT.txt)

I cleaned everything using AdwCleaner (AdwCleaner[s1].txt)

I ran MBAM again as you said (mbam2.txt)

ESET Online Scanner found nothing as:

 

 

So there was cracked software on my computer.

I couldn't remove all of them individually so I ran ESET Online Scanner but kept the 'remove found threats' check box checked.

After it found the 67 virus files (there were 70 before) it sent them all to quarantine and I deleted them from quarantine.

 

No log file was created.

I ran FRST again (FRST2.txt)

 

Thank you! :)

Link to post
Share on other sites

  • Root Admin

Due to abuse by others we have to set post editing to 100 posts before you're allowed to edit.

 

Please read the following and make sure your data is backed up and then proceed with running the tool.

 

Please visit this webpage and read the ComboFix User's Guide:

  • Once you've read the article and are ready to use the program you can download it directly from the link below.
  • Important! - Please make sure you save combofix to your desktop and do not run it from your browser
  • Direct download link for: ComboFix.exe
  • Please make sure you disable your security applications before running ComboFix.
  • Once Combofix has completed it will produce and open a log file.  Please be patient as it can take some time to load.
  • Please attach that log file to your next reply.
  • If needed the file can be located here:  C:\combofix.txt
  • NOTE: If you receive the message "illegal operation has been attempted on a registry key that has been marked for deletion", just reboot the computer.


 

Link to post
Share on other sites

Hi!

Thank you soo much.

I ran ComboFix (from the desktop) and it worked. It deleted some files and registry keys but in the log file I couldn't file the registry keys that RogueKiller displayed.

The virus doesn't seem to be gone. My computer is still hot. It may have gone though.

What should I do next?

 

Note: Can you please tell me why do we have to run ComboFix from the desktop? Sorry but I'm curious.

ComboFix.txt

Link to post
Share on other sites

  • Root Admin

The tool is designed to be run from the desktop so that it can read certain variables.

Please go into Control Panel, Add/Remove and uninstall ALL versions of Java.
Then run the following

Please download JavaRa-1.16 and save it to your computer.

  • Double click to open the zip file and then select all and choose Copy.
  • Create a new folder on your Desktop named RemoveJava and paste the files into this new folder.
  • Quit all browsers and other running applications.
  • Right-click on JavaRa.exe in RemoveJava folder and choose Run as administrator to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location and post it in your next reply.

Then restart the computer.

After the restart please run the following.
 
Please Run TFC by OldTimer to clear temporary files:

  • Download TFC from here and save it to your desktop.
  • http://oldtimer.geekstogo.com/TFC.exe
  • Close any open programs and Internet browsers.
  • Double click TFC.exe to run it on XP (for Vista and Windows 7 right click and choose "Run as administrator") and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning.
  • Please be patient as clearing out temp files may take a while.
  • Once it completes you may be prompted to restart your computer, please do so.
  • Once it's finished you may delete TFC.exe from your desktop or save it for later use for the cleaning of temporary files.

 

Now restart the computer one more time.

 

Next, Please download the following scanner from Kaspersky and save it to your computer: TDSSkiller

Then watch the following video on how to use the tool and make sure to temporarily disable your security applications before running TDSSkiller.



If any infection is found please make sure to choose SKIP and post back the log in case of a False Positive detection.

Once the tool has completed scanning make sure to re-enable your other security applications.
 
Link to post
Share on other sites

JavaRa and TFC worked fine.

TDSSKiller worked fine too I guess. I ticked everything in Change Parameters but it still didn't find anything.

Logs are below.

 

TDSSKiller log is the 2nd one.

The JavaRa log won't upload due to some reason. (I also tried renaming it from .log to .txt but it still didn't work)

 

Screenshots of the JavaRa log problem and the JavaRa log are also below.

 

Thanks! :)

 

Also, some unusual  from Chrome for a while (4 days maybe). If Google Chrome is windowed (not fullscreen) the browser is like a rectangle with more height than width. If I change it, it will remain so till I close my browser. If I open Chrome again it returns to that same rectangular shape, not the one I set. Maybe related to the virus?

TDSSKiller.3.0.0.33_25.04.2014_14.15.46_log.txt

post-159564-0-04725500-1398416954_thumb.

post-159564-0-34108300-1398416962_thumb.

Link to post
Share on other sites

  • Root Admin

Well something still going on as not all the Java entries have been removed as they should have been.

 

Please restart the computer again.  Then run FRST again but make sure you post back a NEW  Addition.txt log file as well.

Then we'll do some manual fixes if need be.

Link to post
Share on other sites

  • Root Admin

You can uninstall the Pando Networks\Media Booster as that is only used to download the game initially and then seed your box files for other users to download and thus using your bandwidth

 

Please download the attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST or FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system.

Run FRST or FRST64 and press the Fix button just once and wait.
If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach or post it to your next reply.

Note: If the tool warned you about an outdated version please download and run the updated version.
 

fixlist.txt

Link to post
Share on other sites

  • Root Admin

Well I need a bit more than that to indicate that you're infected.  The latest logs are not showing an infection.  Let's try this again.

 

Please download the following scanner from Kaspersky and save it to your computer: TDSSkiller

Then watch the following video on how to use the tool and make sure to temporarily disable your security applications before running TDSSkiller.



If any infection is found please make sure to choose SKIP and post back the log in case of a False Positive detection.

Once the tool has completed scanning make sure to re-enable your other security applications.
 
Link to post
Share on other sites

Well it gets hot ONLY when my mouse is not moving.

Hot air out of the air vents and higher sound of fan when the mouse is not moving.

My fan had got spoilt before but now it only speeds up when the mouse isn't moving.

I have to keep moving my mouse while playing a game to avoid overheating.

My laptop screen works only on specific angles because of the overheating.

I will give it in for repairing as soon as the problem is eliminated or it might get spoilt again.

Link to post
Share on other sites

Ran it using default settings but the fan keeps whirring.

I ought to get my fan checked out and I will do it before the screen repair.

My laptop's fan had got spoilt but after the virus had infected.

Videos don't stop or lag now (few weeks) and I think the virus is gone.

But the fan of the computer only speeds up when I'm NOT moving the mouse which is very peculiar.

What do you suggest to do?

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.