Jump to content

Coinhive script got onto my pc somehow


Recommended Posts

It seems to only happen when I open firefox, it looks like it is trying to run a script even if I am just opening up my homepage. (Also as far as the article is concerned, this is not happening because I visit the website, It happens when I open the program.)

 

Edited by LegacyNovus
Link to post
Share on other sites

Alright. Follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.

  • Download the right version of FRST for your system:
    • FRST 32-bit
    • FRST 64-bit
      Note: Only the right version will run on your system, the other will throw an error message. So if you don't know what your system's version is, simply download both of them, and the one that works is the one you should be using.
  • Move the executable (FRST.exe or FRST64.exe) on your Desktop
  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds
  • Make sure the Addition.txt box is checked
  • Click on the Scan button
    KSJwAxg.png
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply

Link to post
Share on other sites

I don't see anything suspicious in your Mozilla Firefox settings. Let's try to clear the history and cache and see if that works.

3DPGbxe.pngTemp File Cleaner (TFC)

  • Download Temp File Cleaner (TFC) and move it to your Desktop
  • Right-click on TFC.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Simply click on Start to launch the clean-up and wait until it completes
    s5yB2E8.png
  • Depending on which processes are running, all your programs will be closed and explorer.exe (your Windows shell) will be killed, it will however be relaunched shortly after so do not panic
  • There's no log to give for this tool

Link to post
Share on other sites

Update: Uninstalling normally did not get rid of it, perhaps there is something else we could do to track it back to the source file? Since Malewarebytes is blocking it is there a way to trace it when it tries to be nasty?

Edit: Oh yes, I also took some initiative and ran ADWcleaner which promptly gave me nada.

Edited by LegacyNovus
Link to post
Share on other sites

Let's see if RogueKiller detects anything.

RQKuhw1.pngRogueKiller

  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.