PUB.bitminer Malware

Anyone every had to deal with this before? I can’t get rid of this fucker and usually can get most stuff.

Still runs in safe mode. MWB/MSE/some other thing/rkill don’t seem to touch it.

It plays random audio clips all the time which is annoying as hell. I’m sure its doing other crap I don’t want. I scan and find it, can remove it, but then its back as soon as I restart, even if I run rkill, reboot in safe mode, all of that normal stuff.

Google just mostly turns up people asking for help and no real solutions, any suggestions appreciated.

Thanks

can you get to the internet on that computer? if so i have found the norton power eraser works on some weird infections that other programs don’t.

you could also try running combofix

In for replies as I’ve not heard anything about this one yet. Modern day malware I don’t bother removing myself, I backup the profile data and do a fresh OS install. I know most don’t agree with just wiping but that’s my preference.

Yes.

Will try both of those tonight.

---------- Post added at 02:37 PM ---------- Previous post was at 02:35 PM ----------

Yea, I had a long streak of not having any issues (see LZ’s protection thread). Don’t know what happened here, but as he pointed out, probably some exploit I left opened more than going to a weird website or download. I don’t have any system restore points so… I’ll keep plugging at it for a bit. Then I’ll back up my important data and just go clean.

http://www.sophos.com/en-us/products/free-tools/sophos-anti-rootkit.aspx

http://www.gmer.net/

http://blog.teesupport.com/pup-bitminer-wont-go-away-how-to-manually-remove-pup-bitminer-completely/

---------- Post added at 02:50 PM ---------- Previous post was at 02:42 PM ----------

Or you can paypal me money and I can do some reverse analysis on the malware sample :slight_smile:

Thanks, will try the first two. I tried the third yesterday without too much luck. Was unable to figure out (or find) all of the files it was referencing.

Format. If its a rootkit, you will be pulling your hair out trying to get rid of it and still may leave holes for future command and control software loads.

On a side note, it would be entertaining as hell if a malware producer managed to make their own virus, then, flooded google with “removal” articles which were actually ways to get more infected. Muhahahahha. Profit?!

I think it’s pretty sweet someone wrote some malware that mines for bitcoin :lol:

The sophos stuff works pretty well. If all else fails, ComboFix that bitch.

bleh, still no luck. lots of “i can find it but I can’t get rid of it” grrr

Do you know when it got infected?

Boot off another distro search by creation date and look for dlls and exes that shouldn’t be

Even combofix? does anything show the file location?

At this point it will probably be faster/easier to back up, format, and re-install

I want to punch this thing in the face.

I’m going to format and reinstall later, just don’t have time to bother these days… look for a thread asking about a NAS recommendation

I’ve wasted countless hours on newer malware/virus/trojans only to opt for the format method. It’s often quicker than doing the several scans with different products and in the end you know for sure you’re drive is clean. Fresh registry etc… usually speeds you up as a side reward for your efforts. :slight_smile:

I had something like this a few years ago, never found it/fixed it so I just formatted

They should have called it PIITB.bitminer

combofix seems to have gotten it finally, annoying, but seems clear for the moment. Still reformatting this weekend.

You should work on figuring out how you got it in the first place.