HEUR.Trojan script miner gen malware

meetdilip

Computer Addict
A very simple solution for you. Take it to the nearest laptop repair, tell the problem, ask them if they can fix it. If they say ok, leave it with them, collect it once fixed. All you have to do is shell some money.
 

SaiyanGoku

kamehameha!!
A very simple solution for you. Take it to the nearest laptop repair, tell the problem, ask them if they can fix it. If they say ok, leave it with them, collect it once fixed. All you have to do is shell some money.
Yeah, wait till they install some old version of windows which they didn't download from microsoft directly and who knows what other bloatware they'll install.
 
Last edited:

meetdilip

Computer Addict
There are many people other than us who know how to do their work. Most PC repair guys would know how to fix this.
 

sling-shot

Wise Old Owl
Yeah, wait till they install some old version of windows which they didn't download from microsoft directly and who knows what other bloatware they'll install.
Just saw a pristine RTM copy of Windows 10 installed after wiping a factory installation in another guy's laptop last week!
 

SaiyanGoku

kamehameha!!
Just saw a pristine RTM copy of Windows 10 installed after wiping a factory installation in another guy's laptop last week!
Most of the local repair shops do not bother with downloading latest version. Some are lazy enough to install cracked Windows 10 1703 build (in 2019) Home Single Language 32 bit on a laptop with 8GB ram :facepalm:
The only place to get an untouched iso is from the OEM or Microsoft directly.
 

meetdilip

Computer Addict
If I saw the other threads correctly, OP is at a point where he is about to buy a new laptop. It is much easier to get it repaired through a reputed service centre.
 
Last edited:
OP
A

andy_65_in

Padawan
Thankful to whitestar who took the effort to connect with my pc( anydesk) and identify the coin hive issue..its still there...the IE directs me to coinhive ...which can be noted in the network mode when IE used in private browsing....surprisingly this coinhive not visible in networking when i use 4 g network...im otherwise using a unlimited paid broadband connection....???
 
OP
A

andy_65_in

Padawan
see attached files for the coinhive behaviour both in http and https protocol as pointed out by whitestar..also enclosed is screenshot of the coinhive warning in windows defender
 

Attachments

  • coinhive proof 01.pdf
    109.9 KB · Views: 170
  • coinhive proof 02(clean).pdf
    141.4 KB · Views: 169
  • Screenshot (20).png
    Screenshot (20).png
    244 KB · Views: 128
OP
A

andy_65_in

Padawan
sorry for uploading a off topic reply but from the attached file can my pc ki battery life be predicted..the hp battery check tool recommends replacement which i want to avoid in such a old computer..
 

Attachments

  • battery.pdf
    312.9 KB · Views: 186

whitestar_999

Super Moderator
Staff member
nothing..hes clear theres nothing wrong with his network..apparently nobody else using it complaining
Nobody will complain if they don't look for it,only option remaining now is to do this same test at some friend/relative pc in their house using same net provider connection in your area.

sorry for uploading a off topic reply but from the attached file can my pc ki battery life be predicted..the hp battery check tool recommends replacement which i want to avoid in such a old computer..
As long as laptop battery can give a backup of 45 min,it is fine.With time & usage all laptop battery capacity goes down & it depends on you when to replace it(e.g.if you are happy with even a 30 min backup then you can replace it later compared to someone who is not happy with even a 40 min backup because he wants at least 1 hour backup).
 
OP
A

andy_65_in

Padawan
thanks both Saiyan and whitestar for the advice..please tell me..with the laptop running ok so far on Defender and free walla Malwarebytes should I

1. install a paid antivirus(which may then start fingering my browsing because of cojnhive..my guesss).

2. download all my stored data in googledrive on my lappie back(if its clr after a virus scan)
 

whitestar_999

Super Moderator
Staff member
Have you tried this?:
Remove CoinHive In-Browser Miner
I checked his pc via remote session.The thing is that I can see coinhive entries being loaded into any http webpage & source of these entries is not some server but rather cache.I already cleaned browser cache earlier so it could only mean that cache here refers to his isp network server because I tried the same with his laptop connected via 4g mobile network & it didn't happen.Also https sites too are unaffected by this because https traffic cannot be intercepted & modified during transit.All this led me to believe that his ISP network itself is infected & any http traffic passing through is being intercepted to load these coinhive entries from isp server cache.

P.S. check the attached pdf proof above
 

SaiyanGoku

kamehameha!!
I checked his pc via remote session.The thing is that I can see coinhive entries being loaded into any http webpage & source of these entries is not some server but rather cache.I already cleaned browser cache earlier so it could only mean that cache here refers to his isp network server because I tried the same with his laptop connected via 4g mobile network & it didn't happen.Also https sites too are unaffected by this because https traffic cannot be intercepted & modified during transit.All this led me to believe that his ISP network itself is infected & any http traffic passing through is being intercepted to load these coinhive entries from isp server cache.

P.S. check the attached pdf proof above
Can't check the pdf in office.
Would setting dns to 1.1.1.1, 8.8.8.8 and using https everywhere, ublock origin extensions combined with Brave Browser (Secure, Fast & Private Web Browser with Adblocker | Brave Browser) or Opera with VPN connected help in this situation?
 
Top