Author Topic: Malware JS:Miner-C  (Read 3296 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Malware JS:Miner-C
« on: February 19, 2018, 12:12:11 PM »
Ive Recently encountred this while i was browsing heres my questions

1) Ive Checked my computer with MalwareBytes and Avast and it says it clean but im not so sure should i take another steps bare in mind i didnt check it in safe mode

2) This Pops Up So does it mean im already infected and also when i open chest ive found nothing its empty


is the Chest Normal To Be Empty?

3)Based on the searches that i take on the web many Antiviruses say its a Trojan but the name refers to a Miner so which one is true and which one is more dangerous?

4)Ive Checked it on Virus Total it says clean but avast says it has the miner so which one is probably correct?

5)The Website that was said by Avast to Contain the JS:Miner-C  (xxiyoutube.com) check it twice to be sure maybe?

Please if you got the time answer this questions Thanks in Advance

REDACTED

  • Guest
Re: Malware JS:Miner-C
« Reply #1 on: February 19, 2018, 02:03:19 PM »
An update Avast just found it and i already remove and delete it but should i check further?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Malware JS:Miner-C
« Reply #2 on: February 19, 2018, 02:15:27 PM »
as avast say it aborted connection, no file was downloaded so chest is empty

virustotal does not scan websites for infections, it is a blacklist check

JS:Miner-C [trj]
JS = java script
miner = miner script (written in java)
[trj] = trojan


URL contain minerscript  >>  https://sitecheck.sucuri.net/results/xxiyoutube.com

HTML scan
https://www.virustotal.com/#/file/cc48a987cfc023a6baba4f7b27dde9c885dd0723d4353cac2d7df131669e8654/detection

https://www.virustotal.com/#/file/4dfde456a8876ff4218a484df7d1fcf10a9d702a454a7c30caa6a022dfefdde3/detection

Blacklisted by Norton  >>  https://safeweb.norton.com/report/show?url=xxiyoutube.com



Quote
1) Ive Checked my computer with MalwareBytes and Avast and it says it clean but im not so sure should i take another steps bare in mind i didnt check it in safe mode
Malwarebytes does not target script / doc / mediafiles ... only executable files


Quote
1) Ive Checked my computer with MalwareBytes and Avast and it says it clean but im not so sure should i take another steps bare in mind i didnt check it in safe mode
and you dont have to. safe mode does not give any better detection, in fact it may be worse. Malware that is detected by behaviour may not run
Malwarebytes is not designed to be run in safemode, it will run (crippled) but all drivers are not loaded



« Last Edit: February 19, 2018, 02:52:43 PM by Pondus »

REDACTED

  • Guest
Re: Malware JS:Miner-C
« Reply #3 on: February 19, 2018, 03:39:07 PM »
as avast say it aborted connection, no file was downloaded so chest is empty

virustotal does not scan websites for infections, it is a blacklist check

JS:Miner-C [trj]
JS = java script
miner = miner script (written in java)
[trj] = trojan


URL contain minerscript  >>  https://sitecheck.sucuri.net/results/xxiyoutube.com

HTML scan
https://www.virustotal.com/#/file/cc48a987cfc023a6baba4f7b27dde9c885dd0723d4353cac2d7df131669e8654/detection

https://www.virustotal.com/#/file/4dfde456a8876ff4218a484df7d1fcf10a9d702a454a7c30caa6a022dfefdde3/detection

Blacklisted by Norton  >>  https://safeweb.norton.com/report/show?url=xxiyoutube.com



Quote
1) Ive Checked my computer with MalwareBytes and Avast and it says it clean but im not so sure should i take another steps bare in mind i didnt check it in safe mode
Malwarebytes does not target script / doc / mediafiles ... only executable files


Quote
1) Ive Checked my computer with MalwareBytes and Avast and it says it clean but im not so sure should i take another steps bare in mind i didnt check it in safe mode
and you dont have to. safe mode does not give any better detection, in fact it may be worse. Malware that is detected by behaviour may not run
Malwarebytes is not designed to be run in safemode, it will run (crippled) but all drivers are not loaded

May i ask if you read reply update from me? because avast says aborted but it still found the file how should i know if its safe and should i take precautions? your advice?
« Last Edit: February 19, 2018, 03:44:11 PM by Sempak2 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Malware JS:Miner-C
« Reply #4 on: February 19, 2018, 04:19:46 PM »
Quote
because avast says aborted but it still found the file how should i know if its safe and should i take precautions?
Do you mean it happens when not doing anything?

Does it only happen when surfing that website?   website is infected and only the website owner can clean it


« Last Edit: February 19, 2018, 04:23:09 PM by Pondus »

REDACTED

  • Guest
Re: Malware JS:Miner-C
« Reply #5 on: February 21, 2018, 04:13:18 PM »
Quote
because avast says aborted but it still found the file how should i know if its safe and should i take precautions?
Do you mean it happens when not doing anything?

Does it only happen when surfing that website?   website is infected and only the website owner can clean it

No i meant when i ran a full virus scan even though avast says its aborted it stills found the .exe and zip files of the miner in my computer thats why im a bit skeptical about the abort notification  and the emptiness of the chest if avast says its aborted but still find the files in my pc then thats alarming thats why im asking for further advice should i check further?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Malware JS:Miner-C
« Reply #6 on: February 21, 2018, 04:20:24 PM »
post a screenshot of the message avast give after scan so experts can see what and where

then follow instructions here  >>  https://forum.avast.com/index.php?topic=194892.0

attach requested logs and a malware expert will assist you


REDACTED

  • Guest
Re: Malware JS:Miner-C
« Reply #7 on: February 22, 2018, 01:01:32 PM »
post a screenshot of the message avast give after scan so experts can see what and where

then follow instructions here  >>  https://forum.avast.com/index.php?topic=194892.0

attach requested logs and a malware expert will assist you

So my second check here on normal boot setup after the first check resulted in avast finding the Miner Script,Zip and .exe which i remove and delete it from the virus chest and delete some caches that was linked to this file. Now the second check Avast says no issues so should i continue with the advance assistant from an Expert?

Heres the Second Check



Thanks for all the Help so Far