木馬病毒

挖礦木馬: 如何徹底去除?

Today I found my CPU being used more than usual. I checked on that and noticed one of the svchost.exe processes running continuously at around 20% CPU. As this seemed a little suspicious, I downloaded Malwarebytes and ran a scan. It found a pack of Trojan.Downloader and Trojan.MalPack files are located in subfolders of my C:\Users\Appdata\Local\Temp folder.

I put them in quarantine. Unfortunately, Malwarebytes still reports the reoccurrence and blocking of a file called C:\ProgramData\ndfbaljqaqzm\dckuybanmlgp.exe. I did some research and this seems to be a CoinMiner so I suspect I did not get rid of the whole problem. The file is continuously recreated and quarantined.Reddit User

Malwarebytes Detect CoinMiner Trojan

Malwarebytes Detect CoinMiner Trojan

When persistent malware like Trojans and CoinMiners evade removal from standard tools like Malwarebytes, it might be time to employ a more robust solution. Gridinsoft Anti-Malware offers a powerful alternative, designed to eliminate these stubborn infections. Follow this guide to clean your system effectively using Gridinsoft Anti-Malware.

Initial Steps for Detection and Removal

  1. Install Gridinsoft Anti-Malware: Download and install Gridinsoft Anti-Malware from the official website. Ensure you have the latest version to take advantage of the most recent updates and malware definitions.
  2. Run a Full Scan: Launch Gridinsoft Anti-Malware and perform a full system scan to detect any hidden malware or remnants of infections. The comprehensive scanning algorithm will help pinpoint even the most elusive threats.

Remove CoinMiner with Gridinsoft Anti-Malware

從那時起我們就一直在我們的系統上使用這個軟體, 而且在檢測病毒方面一直很成功. It has blocked the most common Trojans as 從我們的測試中可以看出 與軟體, and we assure you that it can remove CoinMiner as well as other malware hiding on your computer.

Gridinsoft 反惡意軟體 - 主螢幕

使用 Gridinsoft 刪除惡意威脅, 請依照以下步驟操作:

1. 首先下載 Gridinsoft Anti-Malware, 透過下面的藍色按鈕或直接從官方網站訪問 網格軟體.

2.一旦 Gridinsoft 安裝文件 (安裝-gridinsoft-fix.exe) 已下載, 透過點擊該檔案來執行它. Follow the installation setup wizard's instructions diligently.

Gridinsoft 設定精靈

3. 訪問 "掃描選項卡" on the application's start screen and launch a comprehensive "全碟掃描" 檢查您的整台計算機. 這種包容性掃描涵蓋了內存, 啟動項, 註冊表, 服務, 司機, 和所有文件, 確保它檢測到隱藏在所有可能位置的惡意軟體.

Scan for CoinMiner Trojans

要有耐心, as the scan duration depends on the number of files and your computer's hardware capabilities. 利用這段時間放鬆或處理其他任務.

4. 完成後, 反惡意軟體將提供一份詳細報告,其中包含您 PC 上偵測到的所有惡意專案和威脅.

The CoinMiner was Found

5. 從報告中選擇所有已識別的項目,然後放心地單擊 "立即清潔" 按鈕. 此操作將從您的電腦中安全地刪除惡意文件, 將它們轉移到反惡意軟體程式的安全隔離區,以防止任何進一步的有害行為.

The CoinMiner has been removed

6. 如果出現提示, 重新啟動電腦以完成完整的系統掃描過程. 此步驟對於確保徹底消除任何剩餘威脅至關重要. 重啟後, Gridinsoft Anti-Malware 將會開啟並顯示一則訊息,確認 掃描完成.

請記住 Gridinsoft 提供 6 天免費試用. 這意味著您可以免費利用試用期體驗軟體的全部優勢,並防止您的系統將來受到任何惡意軟體感染. Embrace this opportunity to fortify your computer's security without any financial commitment.

Stopping Recurrent Malware

  1. Identify and Delete Malicious Processes: Monitor your system’s resource usage via Task Manager to identify any suspicious processes that consume a high percentage of CPU. Right-click on the process and select ‘Open file location’. Delete the files if they are in unusual or temporary directories like Temp or ProgramData.
  2. Disable Startup Entries: Use the System Configuration tool (msconfig) or Task Manager to disable startup items that are linked to the malicious software.
  3. Clean Temporary Files: Clear out your Temp folder using the Disk Cleanup tool or manually delete the contents to remove any executables or payloads left by the malware.
  4. Delete Registry Entries: Malware often creates registry entries to ensure persistence. Use the Registry Editor (regedit) with caution to locate and delete any suspicious entries. Look for entries under ‘RUNsections within ‘HKEY_CURRENT_USERand ‘HKEY_LOCAL_MACHINE’.

Prevent Future Infections

  1. Enhance Browser Security: Install ad blockers and script blockers to prevent malicious scripts from executing while browsing.
  2. Update Regularly: Keep your operating system, browsers, and all installed software updated to protect against vulnerabilities used by malware.
  3. Practice Safe Browsing: Be cautious with email attachments and downloads from untrusted sources. Avoid clicking on suspicious links.

By diligently following these steps, you can effectively remove persistent malware such as Trojans and CoinMiners from your PC and take preventive measures to safeguard against future infections. For complex cases, consider consulting with a professional cybersecurity expert.

GridinSoft 反惡意軟體審查
最好是預防, 而不是修復和悔改!
當我們談論不熟悉的程式侵入您的電腦工作時, 諺語「凡事有預謀」盡可能準確地描述了情況. Gridinsoft Anti-Malware 正是您軍械庫中始終有用的工具: 快速地, 高效率的, 最新. 一旦懷疑有輕微感染,可將其用作緊急求助.
Gridinsoft Anti-Malware 提供 6 天試用版.
最終用戶許可協議 | 隱私權政策 | 10% 優惠券

Using Gridinsoft Anti-Malware to remove persistent Trojans and CoinMiners ensures your PC is thoroughly cleaned and protected against future infections. Staying proactive with regular scans and updates is crucial for maintaining a secure system.

關於作者

布倫丹·史密斯

I'm Brendan Smith, 一位充滿熱情的記者, 研究員, 和網頁內容開發人員. 對電腦科技和安全有濃厚的興趣, 我專注於提供高品質的內容,教育讀者並幫助他們駕馭數位景觀.

專注於電腦技術和安全, 我致力於分享我的知識和見解,幫助個人和組織在數位時代保護自己. 我在網路安全原則方面的專業知識, 資料隱私, 最佳實踐使我能夠提供實用的技巧和建議,讀者可以實施以增強他們的線上安全.

發表評論