Jump to content

Need help removing SvcMiner.A Trojan


RainDreamer

Recommended Posts

So I did some stupid things and apparently my computer is infected with SvcMiner.A - learning my lesson already, now I gotta deal with the consequences. My antivirus (just microsoft security essential) detected it and removing it every time it emerges, but still, even though I have removed all suspicious files and take the computer off the internet, it still emerge to be caught again by the antivirus from time to time, which means there is something else in here releasing them. I need some help going to the root of the problem and get rid of it. The guides I found from googling are dubious and ask me to install stuff, which I have once again painfully learned to distrust.

At least I can trust people here a little more. So, anyone got something for me to go with?

Link to comment
Share on other sites

You need a good anti-virus, obviously. AVG or Avast are free and sufficient. But, first, removing the bugs, start with Malwarebytes - let it scan and clean, then load up SpyBot - scan and immunize your system and keep it updated. All of these things are free, and they work... so does smart browsing. ;)

Link to comment
Share on other sites

The "miner" part suggests it's a just a hidden bitcoin miner. Stuff like this is usually packaged inside installers for completely different (and maybe even legit) programs.

Using MSE, look at the threat and scroll down in the information box and it will have it's origin and/or location.

ME3WL.jpg

You can then remove the program it's embedded in.

Link to comment
Share on other sites

Eset also makes NOD32... quite familiar with it. It is a Georgian company (Republic of Georgia). NOD32 is 'ok', but I've found it lacking. IMO, the two best free to be had in the Windows realm are either AVG or AVAST ..... I have proven track records with both (for many many people) since the late 80's early 90's.

You really should look into Malwarebytes and SpyBot.

Link to comment
Share on other sites

Really, all that antivirus crud will slow your system down as much as the BitCoin miner service.

Just get something like http://clonezilla.org/, partition your windows drive to something like 15->20GB, and keep all the programs and junk off of it, use mklink or other; ~10min at most to restore to a clean version of whatever os you use while (if you get your user data [not the user registry though] off the main drive) having near zero effect. Some things will complain (like microsoft office) and would have to be installed before the backup.

Eitherway, easy reverts is so much nicer than loading down on crazy antivirus trash that you'll only need to clean the infection... and getting infected is utterly rare so just revert every now and then for the fun of it. Antivirus for the lazy :)

Link to comment
Share on other sites

Thanks people, I managed to get rid of a rootkit that was deploying those things. I used this thing: http://www.eset.com/us/online-scanner/ and it managed to catch it.

Lesson now learned and I am going to run suspicious things in sandboxie on a different computer first now...

I might also suggest you run a scan of EVERY item you download to ensure that there are no hidden viruses in them.

Edited by Sampa
Link to comment
Share on other sites

Lesson now learned and I am going to run suspicious things in sandboxie on a different computer first now...

It might sound pretty obvious, but the best thing is not to run suspicious things at all. You might also consider installing Windows from scratch after disinfecting, because you never know what damage any malware has done. You just do not want to find out something like a keylogger was left after two years, or when you bank account turns out to be empty.

Link to comment
Share on other sites

It might sound pretty obvious, but the best thing is not to run suspicious things at all. You might also consider installing Windows from scratch after disinfecting, because you never know what damage any malware has done. You just do not want to find out something like a keylogger was left after two years, or when you bank account turns out to be empty.

Yup, go here. Make sure your system is clean before getting on with your cyberlife.

Best free tech support I ever got. Great community. Be polite and respectful, and you will likely get expert help.

Link to comment
Share on other sites

First off: AVG is NOT a good anti-virus, due to some bug in it's programing it will actually lock you out of your computer, the only way to get back in is some safe-mode registry editing. Second: When performing a Malwarebytes scan make sure you use a custom scan and tick ever box, this will give you a complete scan of your entre computer, threat scan will not do this, also check it's history folder and delete everything, otherwise it is still on your PC. Thirdly: Security essentials is a decent AV, not the best certainly, but good for a free AV. If you want a AV that has a low system impact use Bitdefener's free version.

Link to comment
Share on other sites

No, toss AVG and Avast out the door. Sure they are free, but remember this... you get what you pay for. Since I'm a 20+ year IT Consultant, not only do I use Malwarebytes, I use Clamwin, and SuperAntiSpyware Portable to get rid of infected files. Now, as far as day to day AV, I trust none other than Vipre Antivirus, by GFI. It's government certified, and I've never once had any infections since.

Sure, its going to cost you 49.95 per PC, but it has a small footprint, active scanning, and will stop web pages from loading if it thinks they have any viruses embedded in them. Great program.

Link to comment
Share on other sites

for me I use Norton(say what you must say about it) but it plus malware bytes has kept my computer clean. Keep in mind,if I remember correctly, i get Norton for free since my father works with the air force, plus (for me anyways) it does not slow down my computer.

Link to comment
Share on other sites

This thread is quite old. Please consider starting a new thread rather than reviving this one.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...