Help with Coinminer


Hi.


A few days ago, my bitdefender antivirus started detecting a threat named: application.coinminer.ge. The folder where the virus is located is C:\Users\USER\AppData\Local\Microsoft\Windows\INetCache\Low\IE. In this folder, the threat creates a folder with a file in it named stat[1].htm. - note the 1 is replaced by 2, then 3 and so on after each deletion by bitdefender. (I couldn't find out anything about this online, there was also nothing on the bitdefender website about this threat).


I ran a malwarebytes scan but it didn't find anything, i even activated my 14 day free trial just in case it were to pick it up again, but it didn't.


I also ran spyhunter5, which found some vulnerabilities but not this one.


It keeps popping up about 5-10 times a day, at random times.


I tried deleting everything in the folder as well as uninstalling internet explorer, which didn't help.


I am not sure if this is a false positive or a real miner, so i would like to receive some advice and help.


Thanks.


 


PS: Here is a pic of the threat detection message: https://gyazo.com/36ce6742c84a6c18ed7f562c14753710


Software Info:


- Bitdefender Antivirus Free Edition 1.0.16.152


- Antimalware Engine 7.83750


- i am not sure where to find the logs in the free version.

Comments


  • The same is happening to me. 


    I would like to find out where it comes from and who or what loads is to prevent it. 


    Is it a website I am visiting, or does it come from a certain software of maybe a chrome-extension?

  • FlexxFlexx ✭✭✭✭

    HI There,

    Kindly let me know if the issue still persists.

    If not, then kindly select agree.

    Regards

    Flex

Leave a Comment

Rich Text Editor. To edit a paragraph's style, hit tab to get to the paragraph menu. From there you will be able to pick one style. Nothing defaults to paragraph. An inline formatting menu will show up when you select text. Hit tab to get into that menu. Some elements, such as rich link embeds, images, loading indicators, and error messages may get inserted into the editor. You may navigate to these using the arrow keys inside of the editor and delete them with the delete or backspace key.