Stránka 1 z 1

Windows defender hlási Trojan:coinMiner

Napsal: 12 pro 2018 17:10
od meli
Dobrý deň,

Windows defender hlási že objavil Trojan:Win32/CoinMinerC!cl a že to robí zmeny v súbore systemcall. Problém je taký že v poslednej dobe mi pc z ničoho nič začne fučať a systém je vyťažený na 50-70% aplikáciou systemcall. Defender nedokáže odstrániť tento problém, respektíve ho ani nevie nájsť, zaznamená ho len ako história útokov s aktuálnym dátumom. Taktiež sa mi nedá zapnúť ochrana v realnom čase a občas mi nejde zapnúť ani windows defender - vypisuje mi že aplikácia je spravovaná IT správcom.... musím ho následovne ručne vypnúť a reštartovať.

Re: Windows defender hlási Trojan:coinMiner

Napsal: 12 pro 2018 18:01
od Rudy
Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Windows defender hlási Trojan:coinMiner

Napsal: 12 pro 2018 19:00
od meli
Dobrý deň,

Pripínam výsledok.

# -------------------------------
# Malwarebytes AdwCleaner 7.2.5.0
# -------------------------------
# Build: 11-26-2018
# Database: 2018-12-07.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 12-12-2018
# Duration: 00:00:03
# OS: Windows 10 Home
# Cleaned: 22
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Users\melek\AppData\Roaming\DRPSu

***** [ Files ] *****

Deleted C:\Windows\Reimage.ini

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
Deleted C:\Users\melek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\drpsu
Deleted HKLM\Software\Wow6432Node\drpsu
Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\update.drp.su
Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\drp.su
Deleted HKLM\Software\Wow6432Node\Classes\AppID\REI_AxControl.DLL
Deleted HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
Deleted HKLM\Software\Wow6432Node\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Deleted HKLM\Software\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted HKLM\Software\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted HKLM\Software\Wow6432Node\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted HKLM\Software\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted HKLM\Software\Wow6432Node\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted HKLM\Software\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted HKCU\Software\Reimage
Deleted HKLM\Software\Reimage
Deleted HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [3203 octets] - [12/12/2018 18:57:19]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: Windows defender hlási Trojan:coinMiner

Napsal: 12 pro 2018 19:02
od meli
Stále mi windows defender hlási hrozby

Re: Windows defender hlási Trojan:coinMiner

Napsal: 12 pro 2018 19:15
od JaRon

Re: Windows defender hlási Trojan:coinMiner

Napsal: 12 pro 2018 19:51
od Rudy
meli píše:Stále mi windows defender hlási hrozby
Pochopitelně, ještě jsme nedokončili čištění. Zatím udělejte ten sken, jak píše kolega a pak dejte nové logy FRST+Addition.