Avast WEBforum

Other => Viruses and worms => Topic started by: pandamerah on September 11, 2013, 06:13:30 AM

Title: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 06:13:30 AM
Dear Experts,

Please help with the removal of this trojan.
It has been a day since the first warning of this trojan from avast.
I first try the TFC, and so far (2 hours after i ran it) there isn't any trojan activities appear from avast.
Please find attached the logs.
Thank you so much.
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: Pondus on September 11, 2013, 06:20:01 AM
removers are notified...
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 06:24:10 AM
One more log.
Please help, thank you so much :)
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: Pondus on September 11, 2013, 06:49:16 AM
it may take some hours before any removal specialist arrive so be patient.    ;)

Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 07:05:30 AM
Yes, Pondus.
Thank you for your friendliness :)
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 08:33:43 AM
Hi, I will be working on your Malware issues.

Re-run OTL.exe.

Code: [Select]

:OTL
O4 - HKU\S-1-5-21-969727876-1222006065-2701588059-1000..\Run: [tsiVideo] C:\Windows\SysWOW64\rundll32.exe C:\Users\SUGIXI~1\AppData\Local\Temp\\tsiVi132.dll,start File not found
O33 - MountPoints2\{c8986139-d43c-11e2-87c9-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c8986139-d43c-11e2-87c9-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun\AutoRunX\AutoRunX.exe
O33 - MountPoints2\{e6ceaed1-d43b-11e2-ba24-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e6ceaed1-d43b-11e2-ba24-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe

:commands
[CREATERESTOREPOINT]
[emptytemp]


If the log doesn't appear, it can be found here:

c:\_OTL\MovedFiles\mmddyyyy_hhmmss.log
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 11:04:31 AM
I run the command, like the pic attached, but the program is not responding and i have to hard reset it.
Did i do it wrong?
Please advise :)
Thank you
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 11:20:25 AM

Please download zoek.zip ((http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png)) from here (http://hijackthis.nl/smeenk) or here (http://home.kpn.nl/stefsmeenk/zoek.exe) and save it to your Desktop.
Unpack the archive...
Code: [Select]
filesrcm;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 11:37:22 AM
Dear Argus,

I downloaded zoek.zip, extracted it in desktop, closed the browser, disabled antivirus, ran zoek.exe, copied and ran the script like the pic attached.
Please find the log attached also. Is everything OK now?
Thank you  :)
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 11:53:03 AM
Not showing it zoek..

Please turn off Malwarebytes and run again OTL fix.

Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 11:58:41 AM
I didn't run Malwarebytes. And I don't find it in processes.
Where can I find it?
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 12:10:16 PM
Code: [Select]
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
Startup  ;)


Uninstall Malwarebytes and run fix.
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 12:26:16 PM
Dear Argus,

I'm sorry but i don't really understand hahaha..
I uninstalled the Malwarebytes after reading your last post, then i opened OTL and clicked Run Fix but it said, "No fix has been provided".
What is it actually am i supposed to do?
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 12:35:22 PM
Quote
Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Do you do this??

See my first post.
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 12:40:05 PM
Dear Argus,

I think i made mistake, i have just tried the command and here's the result.
Should i install Malwarebytes again and run the command on OTL?
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 12:43:25 PM
Hi, I will be working on your Malware issues.

Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]

:OTL
O4 - HKU\S-1-5-21-969727876-1222006065-2701588059-1000..\Run: [tsiVideo] C:\Windows\SysWOW64\rundll32.exe C:\Users\SUGIXI~1\AppData\Local\Temp\\tsiVi132.dll,start File not found
O33 - MountPoints2\{c8986139-d43c-11e2-87c9-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c8986139-d43c-11e2-87c9-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun\AutoRunX\AutoRunX.exe
O33 - MountPoints2\{e6ceaed1-d43b-11e2-ba24-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e6ceaed1-d43b-11e2-ba24-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe

:commands
[CREATERESTOREPOINT]
[emptytemp]


  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
If the log doesn't appear, it can be found here:

c:\_OTL\MovedFiles\mmddyyyy_hhmmss.log
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 01:00:13 PM
Dear Argus,

I run the command and here is the result.
Is it okay?
Thank you so much
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 01:06:30 PM
Another check


Re-run OTL and click Run scan

Attach here log. (OTL.txt)
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 01:35:42 PM
Dear Argus,

I ran the scan just like http://forum.avast.com/index.php?topic=53253.0
minus the command on Custom Scans/Fixes.
Here's the log, thank you
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 01:47:12 PM
OK, system is clean.



Please download  DelFix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix) by "Xplode" to your Desktop.

Run the tool and check the following boxes below;

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 01:55:30 PM
Dear Argus,

Thank you so much for guiding me to clean up things. You are awesome   :)
However i still have adwcleaner, aswmbr, mbam-setup 1.75.0.1300, OTL, TFC, and all the log reports (but not the DelFix).
Probably because i move it (not on desktop). Do i need to delete them all?
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 02:06:08 PM
Quote
Do i need to delete them all?

Yes.
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: Pondus on September 11, 2013, 02:11:03 PM
if you want..... recomended programs to keep

Malwarebytes .... works great as extra scanner alongside avast

MCShield   http://www.mcshield.net/    protect you from USB infections

Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: argus on September 11, 2013, 02:13:45 PM
if you want..... recomended programs to keep

Malwarebytes .... works great as extra scanner alongside avast

MCShield   http://www.mcshield.net/    protect you from USB infections

Like  :)
Title: Re: Please help with Win32:BitCoinMiner-CA[Trj]
Post by: pandamerah on September 11, 2013, 02:33:22 PM
Dear Argus and Pondus,

Thank you so much for everything. You guys rocks  :)