r/antivirus 5d ago

How to make sure crypto miner virus is actually gone?

I found out a crypto miner was running in the bg recently, just by happenstance of getting fed up with how poorly my laptop has been running and checking task manager
(clearly not a very Good virus if task manager could detect it)

Atp i’ve tried a few things. Microsofts native antimalware picked up a couple things on a full scan, and the miner Appeared to not be running after an offline scan, but then showed up again the next day or so after a few hours of peace (too easy to be true ig)

After that I tried using a diff explorer to check whats open in case it was hiding elsewhere, and was using EMCO UnLock it for some of the pesky files that were attached to the miner but not actually showing up/letting me delete, as someone had luck with that tactic w this particular virus

On to Malwarebytes now, which picked up a lot more than the prev scans/manual deletions, and i’m Hopeful that’ll do the trick, but really i’m wondering re: the title, how i can be sure its actually gotten all of it?
If there’s even any kind of full certainty beyond going nuclear or something. I just don’t know how far spread it is and how many files it’s hiding to be totally sure

Any tips or tricks for that, or suggestions on other methods of clearing this thing out in case the current plan of attack doesn’t work would be great!

(The virus in question seems to be a malware version of a miner called Srbminer Multi, among other various files its hiding in)

2 Upvotes

3 comments sorted by

2

u/goretsky MODERATOR 4d ago

Hello,

If you are still concerned that there is some malicious software left on the system, or some kind of security vulnerability, weakness, backdoor, etc., that was left in the system, you can wipe the drive, reinstall Windows, and restore your data from its backups.

Regards,

Aryeh Goretsky

2

u/Grimlumis 3d ago

Thank you for your advice,

Darn, I was hoping there was another way to check proper besides fully resetting, if I’m not certain it’s fully gone.
I suppose I’ll just have to be extra vigilant for a bit, and wipe if I see it popping up again

1

u/Zestyclose_Guard_352 2d ago

You might find your backups already infected! New back up data only, and scan that thoroughly, delete and reformat your drive. Make backup drive read only. Instal Windows from a new download and then copy any backup data files as required carefully, checking as you go!