Suggestions on removing a stubborn mining virus?

mildewman

Member
Feb 8, 2017
25
2
71
Im infected - Realtemp shows load at 30%, if i open task manager load drops to normal 2-5%, close task manager and system load immediately goes back to 30%. (Windows 10 x64 latest public version)

I have run Trend Online scan, Malwarebytes, Kaspersky, AVP2019 and Windows defender but no success.

When windows starts i can see a dos box opening then minimizing just before desktop opens. No odd additions to installed apps list in windows, no odd additions to startup apps list in windows. What should my next step be for removing this virus?
 
Last edited:

UsandThem

Elite Member
May 4, 2000
16,068
7,380
146
Back up your documents, nuke your partitions, full format, and then a clean OS install.
 
  • Like
Reactions: KeithP

mildewman

Member
Feb 8, 2017
25
2
71
My recording software uses a LOT of plugins. A system rebuild takes many hours.

I ran Malwarebytes beta of its specialized rootkit fixing software (https://www.malwarebytes.com/antirootkit/), and it turned out my soundmixer.exe had been infected. Same file as the last mining virus i got about a year ago.

System load now back down to 2-3% but i still have this suss dosbox opening just before desktop comes up at boot. Now to uninstall all the random antivirus software ive added in the last few hours and start using malwarebytes instead of windows defender. And the moral is of course, never install software you found on piratebay !!!
 

UsandThem

Elite Member
May 4, 2000
16,068
7,380
146
And the moral is of course, never install software you found on piratebay !!!

I don't want to be "that guy", but in this case I'm going to. ;)

1m81ah.jpg
 

balloonshark

Diamond Member
Jun 5, 2008
6,322
2,726
136
I could never trust a computer that was infected. Making regularly created known clean images and then restoring them if and when you're infected or have issues is the only way to go.
 
  • Like
Reactions: UsandThem

jameny5

Senior member
Aug 7, 2018
300
77
101
Download RKILL at www.cnet.com. Install it. Then RUN it. At the RUN command type RKILL. Let it run it's diagnostics and see if it finds the problem.
 

WilliamM2

Platinum Member
Jun 14, 2012
2,372
479
136
I would restore my computer to an image created before it was infected. Takes less than 10 minutes.

If you don't have one, do a clean install, and this time create one.

As you said, it takes a long time to fully configure your computer the way you like it.
 

corkyg

Elite Member | Peripherals
Super Moderator
Mar 4, 2000
27,370
238
106
That is why I have duplicate drives that are mounted in a mobile rack. I rotate them every Sunday morning. If one ever gets corrupted, I simply go to the other drive, and clone it to the contaminated one. That way I always have an ace in the hole.
 
  • Like
Reactions: VeryCharBroiled

Modular

Diamond Member
Jul 1, 2005
5,027
67
91
I could never trust a computer that was infected. Making regularly created known clean images and then restoring them if and when you're infected or have issues is the only way to go.
I would restore my computer to an image created before it was infected. Takes less than 10 minutes.

If you don't have one, do a clean install, and this time create one.

As you said, it takes a long time to fully configure your computer the way you like it.
That is why I have duplicate drives that are mounted in a mobile rack. I rotate them every Sunday morning. If one ever gets corrupted, I simply go to the other drive, and clone it to the contaminated one. That way I always have an ace in the hole.


What software do you all use to make clean images?
 

corkyg

Elite Member | Peripherals
Super Moderator
Mar 4, 2000
27,370
238
106
I use Acronis TI created Rescue Media.
 

Modular

Diamond Member
Jul 1, 2005
5,027
67
91
I use Macrium Reflect Free. You can check out the comparison chart to see if it will fit your needs. https://www.macrium.com/reflectfree
Thanks!

I use the built in utility in Windows. It's never failed me yet. Go to control panel, and look for "backup and restore".
Excellent, I think I'm going to give this a shot. I've been using Acronis TrueImage, but it's pretty clumsy IMO. I don't have the time to research 100 different options. I just need something simple.

I use Acronis TI created Rescue Media.

Thanks, I've been using their full version with incremental backups and some other settings, but I never feel confident that it's going to work when I need it. I guess that I should try and do a restore to a spare HDD and see how it goes.

Back on topic - sorry for the thread derailment.
 

corkyg

Elite Member | Peripherals
Super Moderator
Mar 4, 2000
27,370
238
106
I use the clone function offline with TI bootable media/ Never has failed me in the last 20 years or so. :)