logo elektroda
logo elektroda
X
logo elektroda

Persistent BitcoinMiner Virus Infection: Resistance to Antivirus Deletion

rhimo 5688 15
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 16717387
    rhimo
    Level 8  
    Posts: 22
    Hello everyone
    I think I caught the BitcoinMiner virus. I don't want to be removed by antivirus. A moment after I delete infected files, the virus notification pops up again. Over and over again...
    Could the virus get into your computer through pop-up ads?
    I paste logs from OTL. Help.
    Attachments:
    • Extras.Txt (93.27 KB) You must be logged in to download this attachment.
    • OTL.Txt (93.58 KB) You must be logged in to download this attachment.
  • ADVERTISEMENT
  • ADVERTISEMENT
  • #3 16717434
    rhimo
    Level 8  
    Posts: 22
    Thank you for your help.
    I attach files.
    Attachments:
    • FRST.txt (66.96 KB) You must be logged in to download this attachment.
    • Addition.txt (49.3 KB) You must be logged in to download this attachment.
  • ADVERTISEMENT
  • Helpful post
    #4 16717495
    krzychupar
    Level 43  
    Posts: 6807
    Help: 1490
    Rate: 633
    Otwórz notatnik systemowy i wklej:
    Task: {03F41391-F3A5-4B02-AB73-7B3CBA3D1843} - System32\Tasks\{D1FE52A9-941D-4BA2-8DBF-0A554E29E712} => C:\Windows\system32\pcalua.exe -a G:\Setup.exe -d G:\
    Task: {1A4556E8-189F-4D48-B88B-81A8BD8F76B2} - System32\Tasks\{3C8C6182-6779-4122-8260-432D2DCD485F} => C:\Windows\system32\pcalua.exe -a J:\programy\Nero6\nero63117.exe -d J:\programy\Nero6
    Task: {AAFA5047-E278-4184-901D-582CB0528EC9} - System32\Tasks\{8CB37EEB-C815-49A3-BC6F-C2B9C705745F} => "c:\program files\internet explorer\iexplore.exe" hxxps://ui.skype.com/ui/0/7.33.0.104/pl/abandoninstall?page=tsProgressBar
    Task: {CECCEC79-C10E-45DB-B7CB-17103E7C25DF} - System32\Tasks\{EB9E77B6-FEF0-4208-865D-D52AA12BD830} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\TeamSpeak 3 Client\plugins\ts3overlay\InstallHook.exe" -d "C:\Program Files\TeamSpeak 3 Client\plugins\ts3overlay\" -c ts3overlay_hook_win32.dll 10001
    Task: {FD8C8BE5-4BD8-4D2A-A4EC-CCEAB92B2F31} - System32\Tasks\{5156CA6C-1CAC-48A5-83A9-BB7A1EE57AFC} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\F-Secure\Uninstall\fsuninst.exe" -c /UninstRegKey:"F-Secure Anti-Virus"
    Task: {FFB59619-2318-48AE-9180-A98C6237F209} - System32\Tasks\{8D2E57E1-E8D1-4F32-9A8D-12766AF9C297} => C:\Windows\system32\pcalua.exe -a "C:\Users\Garvi\Desktop\Nowy folder\KD MAX DEMO pliki instalacyjne\setup.exe" -d "C:\Users\Garvi\Desktop\Nowy folder\KD MAX DEMO pliki instalacyjne"
    Hosts:
    HKLM-x32\...\Run: [] => [X]
    HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    HKU\S-1-5-21-1555414959-3566746135-1843529842-1000\...\MountPoints2: F - F:\Setup.exe
    HKU\S-1-5-21-1555414959-3566746135-1843529842-1000\...\MountPoints2: {67049dea-fc6d-11e4-b51e-b870f4b068b2} - I:\Startme.exe
    HKU\S-1-5-21-1555414959-3566746135-1843529842-1000\...\MountPoints2: {c85c6f19-f6a0-11e3-83c8-ccaf7806b24a} - "F:\WD SmartWare.exe" autoplay=true
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    HKU\S-1-5-21-1555414959-3566746135-1843529842-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => nie znaleziono
    CHR HomePage: Default -> amazon.com/websearch/?ie=UTF8__PARAM__
    CHR DefaultSearchURL: Default -> hxxps://www.amazon.com/websearch/?ie=UTF8__PARAM__&query={searchTerms}
    CHR DefaultSearchKeyword: Default -> amazon
    2017-09-24 10:38 - 2017-09-24 10:38 - 000095510 _____ C:\Users\Garvi\Desktop\Extras.Txt
    2017-09-24 10:38 - 2017-09-24 10:38 - 000000000 ____D C:\Users\Garvi\Downloads\FRST-OlderVersion
    2017-09-24 10:58 - 2017-09-24 10:58 - 002399744 _____ (Farbar) C:\Users\Garvi\Downloads\FRST64 (1).exe
    2017-09-24 10:27 - 2017-09-24 10:27 - 000095826 _____ C:\Users\Garvi\Desktop\OTL.Txt
    2017-09-24 10:26 - 2017-09-24 10:26 - 000095510 _____ C:\Users\Garvi\Downloads\Extras.Txt
    2017-09-24 10:25 - 2017-09-24 10:25 - 000095826 _____ C:\Users\Garvi\Downloads\OTL.Txt
    2017-09-24 10:04 - 2017-09-24 10:04 - 000602112 _____ (OldTimer Tools) C:\Users\Garvi\Downloads\OTL_[www.programosy.pl].exe
    2017-09-17 21:02 - 2017-09-17 21:03 - 000000000 ____D C:\b74d18fcac5d7b886d60ab66ae23fece
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść w folderze obok FRST.exe.
    Uruchom FRST i kliknij w Fix/Napraw.
  • Helpful post
    #5 16717541
    Kolobos
    IT specialist
    Posts: 85164
    Help: 17165
    Rate: 10442
    Napiszesz co dokladnie wykrywa antywirus i gdzie? Podaj pelna sciezke oraz nazwy plikow.


    Zmien Adobe Reader 9.1 MUI na najnowsza wersje AR lub Foxit -> http://ninite.com/foxit/

    Odinstaluj SpyBot.

    Wykonaj Fixlist.txt dla FRST:
    Task: {03F41391-F3A5-4B02-AB73-7B3CBA3D1843} - System32\Tasks\{D1FE52A9-941D-4BA2-8DBF-0A554E29E712} => C:\Windows\system32\pcalua.exe -a G:\Setup.exe -d G:\
    Task: {1A4556E8-189F-4D48-B88B-81A8BD8F76B2} - System32\Tasks\{3C8C6182-6779-4122-8260-432D2DCD485F} => C:\Windows\system32\pcalua.exe -a J:\programy\Nero6\nero63117.exe -d J:\programy\Nero6
    Task: {AAFA5047-E278-4184-901D-582CB0528EC9} - System32\Tasks\{8CB37EEB-C815-49A3-BC6F-C2B9C705745F} => "c:\program files\internet explorer\iexplore.exe" hxxps://ui.skype.com/ui/0/7.33.0.104/pl/abandoninstall?page=tsProgressBar
    Task: {CECCEC79-C10E-45DB-B7CB-17103E7C25DF} - System32\Tasks\{EB9E77B6-FEF0-4208-865D-D52AA12BD830} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\TeamSpeak 3 Client\plugins\ts3overlay\InstallHook.exe" -d "C:\Program Files\TeamSpeak 3 Client\plugins\ts3overlay\" -c ts3overlay_hook_win32.dll 10001
    Task: {FD8C8BE5-4BD8-4D2A-A4EC-CCEAB92B2F31} - System32\Tasks\{5156CA6C-1CAC-48A5-83A9-BB7A1EE57AFC} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\F-Secure\Uninstall\fsuninst.exe" -c /UninstRegKey:"F-Secure Anti-Virus"
    Task: {FFB59619-2318-48AE-9180-A98C6237F209} - System32\Tasks\{8D2E57E1-E8D1-4F32-9A8D-12766AF9C297} => C:\Windows\system32\pcalua.exe -a "C:\Users\Garvi\Desktop\Nowy folder\KD MAX DEMO pliki instalacyjne\setup.exe" -d "C:\Users\Garvi\Desktop\Nowy folder\KD MAX DEMO pliki instalacyjne"
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [NeroFilterCheck] => C:\Windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
    HKU\S-1-5-21-1555414959-3566746135-1843529842-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
    HKU\S-1-5-21-1555414959-3566746135-1843529842-1000\...\MountPoints2: F - F:\Setup.exe
    HKU\S-1-5-21-1555414959-3566746135-1843529842-1000\...\MountPoints2: {67049dea-fc6d-11e4-b51e-b870f4b068b2} - I:\Startme.exe
    HKU\S-1-5-21-1555414959-3566746135-1843529842-1000\...\MountPoints2: {c85c6f19-f6a0-11e3-83c8-ccaf7806b24a} - "F:\WD SmartWare.exe" autoplay=true
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk [2014-07-09]
    ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\Windows\SysWOW64\C2MP\UpdateChecker.exe ()
    2017-09-24 10:38 - 2017-09-24 10:38 - 000000000 ____D C:\Users\Garvi\Downloads\FRST-OlderVersion
    2017-09-24 10:27 - 2017-09-24 10:27 - 000095826 _____ C:\Users\Garvi\Desktop\OTL.Txt
    2017-09-24 10:26 - 2017-09-24 10:26 - 000095510 _____ C:\Users\Garvi\Downloads\Extras.Txt
    2017-09-24 10:25 - 2017-09-24 10:25 - 000095826 _____ C:\Users\Garvi\Downloads\OTL.Txt
    2017-09-24 10:04 - 2017-09-24 10:04 - 000602112 _____ (OldTimer Tools) C:\Users\Garvi\Downloads\OTL_[www.programosy.pl].exe
  • ADVERTISEMENT
  • #6 16717595
    rhimo
    Level 8  
    Posts: 22
    I did as written by krzychupar. I don't know enough to tell if everything is alright, that's why I paste FRST files.
    Is everything ok now?

    EDIT
    Kolobos:
    Antivirus detects infected files in: C: \ Users \ Garvi \ AppData \ Local \ Chromium \ User Data \ f_008d3. After each scan, the file (f_008d3) the antivirus displayed a different name for the infected file; they were names like: f_008d4, f_008d38 etc. In an alert he said that this file is in the archive (like zip) and cannot delete it. I found files with similar names in the Ceche folder, but the target file was not there. That's why I deleted the entire Ceche folder. But it gave nothing. Over and over - an infection notification popped up -> I deleted the entire Ceche folder. After some time the infection window popped up again, so I deleted Ceche.
    After some time, I guessed that the virus may be associated with pop-up ads on the alltuve.tv website or with the alltube.tv website itself ... After opening it on a second computer, the fun with Bitcoin file infection began. Now I have the same on the other device ...
    Returning to the subject - can I not worry about this topic here yet, is the virus still lurking somewhere?

    I merged. RADU23
    Attachments:
    • FRST.txt (65.36 KB) You must be logged in to download this attachment.
    • Addition.txt (46.82 KB) You must be logged in to download this attachment.
  • #7 16718136
    Kolobos
    IT specialist
    Posts: 85164
    Help: 17165
    Rate: 10442
    You go to the site where Bitcoin Miner is, that's why the files are still being created.
  • #8 16718206
    rhimo
    Level 8  
    Posts: 22
    I thought so, thanks :)
    Is your computer free of BitcoinMiner now?
  • Helpful post
    #9 16718222
    Kolobos
    IT specialist
    Posts: 85164
    Help: 17165
    Rate: 10442
    It looks like this, such excavators work only when they enter the site, they do not infect the computer. Therefore, the file is detected in the cache.
  • #10 16718227
    rhimo
    Level 8  
    Posts: 22
    I ask because I wasn't sure. Thank you for your help.
    When I got infected with a second BitcoinMiner computer, I scanned it with anti-virus, but (as before on the previous device) it did not delete the files. I deleted them manually, but the browser is still mussels and consumes up to 99% of memory when used. I think the virus is still in the computer. I put files from FRST below, please check that everything is OK.
    Attachments:
    • FRST_02.txt (26.95 KB) You must be logged in to download this attachment.
    • Addition_02.txt (31.28 KB) You must be logged in to download this attachment.
  • Helpful post
    #11 16718243
    Kolobos
    IT specialist
    Posts: 85164
    Help: 17165
    Rate: 10442
    W logach widac, ze antywirus wykryl:
    Error: (09/24/2017 01:03:52 PM) (Source: F-Secure Anti-Virus) (EventID: 103) (User: )
    Description: 2 2017-09-24 13:03:52+02:00    \misio F-Secure Anti-Virus
    Spyware detected:
    Type: riskware
    Family:
    Name: Application.BitCoinMiner.SX
    Object: C:\Documents and Settings\misio\Local Settings\Application Data\Chromium\User Data\Default\Cache\f_00006c

    Error: (09/24/2017 01:03:52 PM) (Source: F-Secure Anti-Virus) (EventID: 103) (User: )
    Description: 1 2017-09-24 13:03:52+02:00    \misio F-Secure Anti-Virus
    Spyware detected:
    Type: riskware
    Family:
    Name: Application.BitCoinMiner.SX
    Object: C:\Documents and Settings\misio\Local Settings\Application Data\Chromium\User Data\Default\Cache\f_00006a

    Zapewne usunal.

    Zmien Adobe Reader 9.5.0 - Polish na najnowsza wersje AR lub na Foxit: http://ninite.com/foxit/

    Odinstaluj:
    mks_vir Skaner Online
    Spybot - Search & Destroy

    Wpisow z tej modyfikowanej wersji Chrome i tak nie widac w logach, wiec sa zbedne.

    Fixlist.txt dla FRST:
    HKLM\...\Run: [] => [X]
    Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
    HKU\S-1-5-21-2052111302-725345543-682003330-1004\...\Run: [CW] => [X]
    HKU\S-1-5-21-2052111302-725345543-682003330-1004\...\MountPoints2: {169f3d68-b7bc-11e5-832f-00166f916797} - "F:\WD SmartWare.exe" autoplay=true
    HKU\S-1-5-21-2052111302-725345543-682003330-1004\...\MountPoints2: {5a043882-33d6-11e7-8417-00166f916797} - F:\HiSuiteDownLoader.exe
    IFEO\Your Image File Name Here without a path: [Debugger]
    BootExecute: autocheck autochk * sdnclean.exe
    CHR HKLM\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-2052111302-725345543-682003330-1004\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
    2017-09-02 13:02 - 2017-09-02 13:27 - 000002432 _____ C:\Documents and Settings\misio\Local Settings\Tempfo1596.html
    2017-09-02 13:02 - 2017-09-02 13:27 - 000002089 _____ C:\Documents and Settings\misio\Local Settings\TempyH1596.html
    2017-09-24 10:51 - 2017-08-02 18:55 - 000000602 _____ C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
    2017-01-14 13:37 - 2017-01-14 13:37 - 002174976 _____ (Advanced Micro Devices Inc.) C:\Program Files\Common Files\atimpenc.dll
    2016-01-10 21:11 - 2016-01-10 21:11 - 000000038 __SHC () C:\Documents and Settings\misio\Local Settings\Application Data\69ff07055291669bb2b218.72821112



    Zawsze mozesz tez usunac przegladarke razem z katalogiem profilu C:\Documents and Settings\misio\Local Settings\Application Data\Chromium\ i zainstalowac ponownie.
    Wczesniej zrob kopie zakladek itp. o ile sa potrzebne.
  • #12 16718350
    rhimo
    Level 8  
    Posts: 22
    I'll uninstall Adobe and Spybot in a moment. Thank you for your help. Did I get rid of the virus on the other device?
    Attachments:
    • FRST.txt (25.4 KB) You must be logged in to download this attachment.
    • Addition.txt (30.96 KB) You must be logged in to download this attachment.
  • #13 16718597
    Kolobos
    IT specialist
    Posts: 85164
    Help: 17165
    Rate: 10442
    You've already posted logs from this computer in the previous post to which I wrote back.
  • #14 16718934
    rhimo
    Level 8  
    Posts: 22
    I pasted FRST files after changing fixlist.txt (as you described at 16:16).
  • #15 16718950
    Kolobos
    IT specialist
    Posts: 85164
    Help: 17165
    Rate: 10442
    Why did I write to you that the contents of the cache and entries from this browser can not be seen in the logs? What I've provided is just a few unnecessary entries, you don't have to post logs.
  • #16 16718963
    rhimo
    Level 8  
    Posts: 22
    Approx. Thank you for your help and best regards. Subject to close.

Topic summary

✨ The discussion revolves around a persistent BitcoinMiner virus infection that resists deletion by antivirus software. The user reports repeated notifications of the virus after attempting to delete infected files, particularly in the cache of the Chromium browser. Several participants suggest using the Farbar Recovery Scan Tool (FRST) instead of the OTL program for better log analysis. They recommend updating software like Adobe Reader and uninstalling unnecessary programs such as SpyBot. The conversation highlights the importance of clearing the browser cache and the potential for the virus to be linked to specific websites, particularly those displaying pop-up ads. Users share logs indicating the detection of the BitcoinMiner virus and discuss methods to ensure complete removal.
Generated by the language model.

FAQ

TL;DR: Antivirus logged 2 detections in Chromium cache; “Spyware detected: Application.BitCoinMiner.SX.” These miners run from sites, not as a resident virus. Clear cache, update software, or reset the browser profile using FRST-guided cleanup. [Elektroda, Kolobos, post #16718243]

Why it matters: This FAQ helps Windows users fix recurring BitcoinMiner alerts that reappear after deletion and slow the browser.

Quick Facts

Is this a real infection or just a browser-based miner?

It’s a browser-based miner triggered by the site you visit. The files land in the browser cache and do not install a resident virus. The expert explains these “work only when they enter the site,” which is why antivirus flags cache items rather than system binaries. Close the site and clean the cache to stop activity. [Elektroda, Kolobos, post #16718222]

Why does my antivirus keep detecting BitcoinMiner in f_00xxx files?

Your antivirus is inspecting Chromium’s cache. It finds items like f_00006a and f_00006c that came from the webpage. These are artifacts, not installed programs. Deleting cache reduces repeat alerts unless you revisit the same site. One log shows two alerts on those cache objects. [Elektroda, Kolobos, post #16718243]

Can pop-up ads or a streaming site cause this?

Yes. Visiting certain streaming or pop-up-heavy sites can deliver in-browser mining scripts. The activity persists while the tab stays open and leaves cache traces. Closing the site and clearing the cache ends the mining session. [Elektroda, Kolobos, post #16718136]

How do I stop the constant reappearance after I delete files?

Stop visiting the offending site, then clear the Chromium cache. If alerts return, reset or reinstall the browser profile. Avoid using the same site again to prevent re-creation. The expert notes files reappear because you go back to the miner site. [Elektroda, Kolobos, post #16718136]

What quick steps should I follow to clean up?

  1. Clear Chromium’s cache and close suspicious tabs.
  2. Generate FRST (FRST.txt and Addition.txt) and apply the provided fixlist.
  3. Uninstall outdated tools, then reset or reinstall the Chromium profile if needed. These steps removed detections in the discussed case. [Elektroda, Kolobos, post #16718243]

What is FRST and why not OTL?

FRST (Farbar Recovery Scan Tool) creates modern diagnostic logs and applies a custom fixlist. OTL is outdated and not supported in this workflow. Helpers requested FRST logs and supplied a fixlist tailored to entries found. [Elektroda, krzychupar, post #16717420]

Why can’t the antivirus delete the file if it’s in an archive?

Some detections reside inside compressed cache objects, so the antivirus reports the item but cannot remove it directly. Clearing the browser cache or deleting the profile removes the underlying file. The user observed the alert stating it was in an archive. [Elektroda, rhimo, post #16717595]

My browser now uses 99% memory—am I still infected?

High memory or CPU during browsing often follows visiting miner-laced sites. If FRST cleanup is done and only cache items were flagged, the system is not persistently infected. Reset the browser profile to stop resource spikes from leftover extensions or settings. [Elektroda, rhimo, post #16718227]

What did the logs actually show?

Event logs showed two detections labeled Application.BitCoinMiner.SX in Chromium’s cache. The expert concluded antivirus likely removed what it could and advised software updates and profile cleanup. This indicates transient, site-driven artifacts, not a resident trojan. [Elektroda, Kolobos, post #16718243]

Should I remove Spybot and old Adobe Reader?

Yes. The helper advised uninstalling Spybot and replacing old Adobe Reader with a current reader. This reduces conflicts and closes security gaps before reinstalling or resetting the browser. [Elektroda, Kolobos, post #16718243]

How do I fully reset the Chromium profile safely?

Back up bookmarks first. Uninstall the browser, then delete the profile folder at the specified user path. Reinstall Chromium, restore bookmarks, and avoid the problem site. “Always remove the browser together with the profile directory,” the helper noted. [Elektroda, Kolobos, post #16718243]

What is ‘riskware’ in this context?

Riskware means software or scripts that may be used for unwanted actions like cryptomining. The alert labeled the detection as riskware and named Application.BitCoinMiner.SX. It’s unwanted but not a classic self-installing virus. [Elektroda, Kolobos, post #16718243]

Edge case: What if I still get alerts after cleanup without visiting bad sites?

Extensions or startup tabs can reopen the miner page. Remove suspicious extensions, then reset the profile. As a fallback, reinstall the browser and profile. If alerts name cache files again, they originate from browsing activity. [Elektroda, Kolobos, post #16718243]

Can I ignore the detections if they’re only in cache?

Do not ignore them. Clear the cache and stop visiting the source site. Apply the fixlist and security updates. The expert emphasized cache-based nature but still advised cleanup and software hygiene steps. [Elektroda, Kolobos, post #16718243]
Generated by the language model.
ADVERTISEMENT