Yuuki 0 Posted October 6, 2017 Share Posted October 6, 2017 (edited) I just got this virus called "CoinMiner" today. Eset window threat reminder starting showing up almost 20messages. until Eset asked me to Reboot Scan. So I rebooted it, the action shows "Contained Infected Files". and no more showing threat reminder. I also checked the location of the malware "SMSS.EXE/CoinMiner" the location is "C:\Users\Yunho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" and the malware no longer there. but I just want to know if the malware is completely removed. Thank you. --Sorry for my English. Edited October 6, 2017 by Yuuki Update Link to comment Share on other sites More sharing options...
Administrators Marcos 5,257 Posted October 7, 2017 Administrators Share Posted October 7, 2017 If the suspicious files in the startup folder are still there and are not detected, submit them to samples[at]eset.com in an archive encrypted with the password "infected". However, it could be just simple vbs/lnk files that run/open a specific file or website so they themselves may not pose a risk if the target doesn't exist any more. Link to comment Share on other sites More sharing options...
tmuster2k 22 Posted October 9, 2017 Share Posted October 9, 2017 Marcos. Do you have any specifics on the detection >> "Contained Infected Files" . I looked on the online support guide and could not find. thank you. Link to comment Share on other sites More sharing options...
Administrators Marcos 5,257 Posted October 9, 2017 Administrators Share Posted October 9, 2017 "Contained infected files" is reported when an action was taken on a child object. I reckon that double-clicking such record would display more detailed information. Link to comment Share on other sites More sharing options...
Recommended Posts