Author Topic: Win32:BitCoinMiner-CA trojan  (Read 7679 times)

0 Members and 1 Guest are viewing this topic.

Harry86

  • Guest
Win32:BitCoinMiner-CA trojan
« on: May 25, 2013, 11:54:51 PM »
Hi. I have exactly the same problem with this guy here http://forum.avast.com/index.php?topic=124164.0
I've already tried mbam and mbar with no result. Here is a screen of avast blocking the trojan horse
http://img716.imageshack.us/img716/4271/trojann.png

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:BitCoinMiner-CA trojan
« Reply #1 on: May 26, 2013, 12:00:17 AM »
Could you follow the steps here please http://forum.avast.com/index.php?topic=53253.0

Harry86

  • Guest
Re: Win32:BitCoinMiner-CA trojan
« Reply #2 on: May 26, 2013, 12:47:03 AM »
Here are my logs

Harry86

  • Guest
Re: Win32:BitCoinMiner-CA trojan
« Reply #3 on: May 26, 2013, 12:49:13 AM »
..and aswMBR.txt

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37586
  • Not a avast user
Re: Win32:BitCoinMiner-CA trojan
« Reply #4 on: May 26, 2013, 01:44:39 AM »
essexboy is notified....
you are a bit late, so essexboy is on bed now, check back tomorrow.   :)


Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Win32:BitCoinMiner-CA trojan
« Reply #5 on: May 26, 2013, 09:06:33 AM »
post_edit:

Ups, just now I saw colleague essexboy has already taken over this case. :)
« Last Edit: May 26, 2013, 09:14:33 AM by magna86 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:BitCoinMiner-CA trojan
« Reply #6 on: May 26, 2013, 11:33:15 AM »
:)  Hi lets get at it

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Harry86

  • Guest
Re: Win32:BitCoinMiner-CA trojan
« Reply #7 on: May 26, 2013, 03:45:42 PM »
I got an error while Combofix was running (PEV.exe Error) however the scan completed.
I think nothing changed, the trojan is still there.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:BitCoinMiner-CA trojan
« Reply #8 on: May 26, 2013, 04:45:03 PM »
OK I can see the reason for that

Download the latest version of TDSSKiller from here and save it to your Desktop.
 
 
  • Doubleclick on TDSSKiller.exe to run the application


  • Then click on Change parameters.
     

     
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
     
  • Click the Start Scan button.
     
     
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
     

     
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

  • Get the report by selecting Reports

 
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
Please copy and paste its contents on your next reply.

Harry86

  • Guest
Re: Win32:BitCoinMiner-CA trojan
« Reply #9 on: May 26, 2013, 04:52:53 PM »
3 threats found but without cure button.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:BitCoinMiner-CA trojan
« Reply #10 on: May 26, 2013, 05:01:15 PM »
OK lets see if we can find a spare copy of Atapi.sys

Please run OTL and paste the following in the custom scans and fixes box

/md5start
atapi.*
/md5stop


Then press Run Scan
Attach the resultant log please

Harry86

  • Guest
Re: Win32:BitCoinMiner-CA trojan
« Reply #11 on: May 26, 2013, 05:57:26 PM »
Do you need extras log? I didn't find it.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37586
  • Not a avast user
Re: Win32:BitCoinMiner-CA trojan
« Reply #12 on: May 26, 2013, 06:16:06 PM »
Do you need extras log? I didn't find it.
it is only created at first OTL run and is only extra tech info and usually not needed

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:BitCoinMiner-CA trojan
« Reply #13 on: May 26, 2013, 06:32:40 PM »
Intriguing Combofix reports that Atapi is infected however, both TDSSKiller and OTL MD5 scan report no problems

Please delete the current copy of combofix from your desktop
Then download and run a fresh copy please

Link 1
Link 2
 

ComputerRepairTech

  • Guest
Re: Win32:BitCoinMiner-CA trojan
« Reply #14 on: May 26, 2013, 07:24:34 PM »
Forum virus removal is not my field and this is essexboys show here..I just glanced over those txt files..



Sometimes when you are dealing with an undetectable rootkit you may find that you've been fooled and you aren't dealing with a rootkit at all just an amateur virus that you missed because you were searching so hard for a rootkit.  I could be way off base here