HEUR.Trojan script miner gen malware

OP
A

andy_65_in

Padawan
Post screenshots of warnings here along with files giving warnings.Also install avira free just for now & update it to scan whole pc.you can remove it afterwards if no threats found.
Cant post screenshot...but i get this...remediation incomplete..threat trojan js counhive..affected items...a long file in c drive..ruffly called c/users/app data/locsl/temp...but when i scan using malwarebytes and zamana..no threat
 
OP
A

andy_65_in

Padawan
Scanned now using avira free...all clear...im now going mad....what should i do...format this laptop again...and sell the dam thing
 

meetdilip

Computer Addict
Any free type of this av

Looks like Malwarebytes has some expertise in it

Cryptojacking definition – What is it, and how can you prevent it?

I have seen those only in paid modules. All I can say now is scan your data with your AV and Malwarebytes and then use your system until there is some malware warning. Most people like us do not have anything precious on our PC to steal.
 

whitestar_999

Super Moderator
Staff member
Cant post screenshot...but i get this...remediation incomplete..threat trojan js counhive..affected items...a long file in c drive..ruffly called c/users/app data/locsl/temp...but when i scan using malwarebytes and zamana..no threat

Scanned now using avira free...all clear...im now going mad....what should i do...format this laptop again...and sell the dam thing
It seems like a temporary internet webpage file created(& probably active only) inside a browser while being connected to net.If system is not connected to net then it should show no threat.Also this file can be created by simply vising some affected website.Delete everything inside the temp folder where this file is located then connect to net & browse some sites you usually visit using the browsers you generally use while letting avira free run in background.If you get no warning then everything is fine.Next time onwards,whenever you visit a site infected with such malware then avira will block it giving you a similar warning "coinhive.js.. detected & quarantined".
 
OP
A

andy_65_in

Padawan
It seems like a temporary internet webpage file created(& probably active only) inside a browser while being connected to net.If system is not connected to net then it should show no threat.Also this file can be created by simply vising some affected website.Delete everything inside the temp folder where this file is located then connect to net & browse some sites you usually visit using the browsers you generally use while letting avira free run in background.If you get no warning then everything is fine.Next time onwards,whenever you visit a site infected with such malware then avira will block it giving you a similar warning "coinhive.js.. detected & quarantined".
did what you said...surfing is normal..no warnings..including while installing google chrome finally...so so ar looks good...am running avira,malwarebytes and zemana all free versions and all are CLEAR so far...fingers crossed for some time...wondering net banking use karen or not..or wait for day...in the meanwhile updating windows
 
OP
A

andy_65_in

Padawan
Getting pua crypotiminer gen alerts in my avira free every minute as i use mozilla(i removed chrome)...this crap then goes into quarantine where i delete it..is this mslware...btw scans by hitmanpro,zemana,malwarebytes,window defender show no threats....what should i do...stick to IEonly
 

pkkumarcool

Game & anime Lover
Getting pua crypotiminer gen alerts in my avira free every minute as i use mozilla(i removed chrome)...this crap then goes into quarantine where i delete it..is this mslware...btw scans by hitmanpro,zemana,malwarebytes,window defender show no threats....what should i do...stick to IEonly

Have you fresh installed windows?


Sent from my iPhone using Tapatalk
 
OP
A

andy_65_in

Padawan
Trojan coin hive is back....as per win defender....dont dont what the hell is wroong with my machine...best is to reformat it again and sell it...its already 7 years old
 
OP
A

andy_65_in

Padawan
Trojan hive also confirmed by newly added avast...wiill reformat and try selling this pc...im im surprised the hdd looks compromised even after reformat....avast prompts to buy paid version
 

meetdilip

Computer Addict
Did you use an existing installer of Chrome or Firefox? That could be the compromised part.

Do a clean wipe of HDD, download the latest Windows 10 ISO and do an install. Then download all installer new, no matter Chrome, Firefox, MS Office etc,

I know this is a lot of work. But I don't see any other way of being certain.
 

whitestar_999

Super Moderator
Staff member
Seems like you are installing something infected(I hope you are not using firefox/chrome setup files from earlier/backup instead of fresh downloading again from their official sites).
 

meetdilip

Computer Addict
Another possibility is that it is coming from your network. It can come even from an infected phone if not an infected PC.
 
Top Bottom