Share via

Malware Extension keeps reinstalling itself on Edge!

Anonymous
2022-09-18T16:33:25+00:00

Hi I have a bitcoin miner trojan or something that keeps popping up on Malwarebytes every time i reset pc. It has to be hiding as a fake Microsoft task program or something.. I delete and quarantine but they keep coming back? any suggestions?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

19 answers

Sort by: Most helpful
  1. _AW_ 67,676 Reputation points Volunteer Moderator
    2022-09-19T02:45:05+00:00

    Delete the task named - \Microsoft\Windows\Chkdsk\SyspartRepairLLzFp

    Restart the PC

    Delete the file - C:\Windows\System32\0D8BBDCC-E597-45AB-B53F-A1D6233ED904.ps1

    Delete the extension

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-09-19T02:48:26+00:00

    Excellent. Then if you've completed all steps including running the scans twice it should be fixed.

    But if not then we need to find specific removal steps for the Miner which I'd need ot know the name of to help you with that.

    Keep me posted on your progress as I will be here to help until the case is resolved.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-09-18T17:38:53+00:00

    HI Dank. I'm Greg, 10 years awarded Windows MVP, here to help you.

    Do you know the name? If so you can google a removal tool, but you have to sort it out from the ads promoting sneaky paid scanners. So I can help you find it. Meanwhile try this regimen which will remove almost any infection using the industry's best tools. I include Malwarebytes since you may not have enabled Rootkits and that is essential:

    To check most thoroughly for infection and any resulting System damage, Download, install and run a full scan with the most powerful on-demand free scanner Malwarebytes:

    https://www.malwarebytes.com/mwb-download/ Make sure to only choose the Free version.

    In the Malwarebytes Settings (gear icon) > Security tab set it to include scanning for Rootkits.

    If necessary run it in Safe Mode with Networking (to have internet), or Safe Mode accessed by one of these methods: https://www.digitalcitizen.life/4-ways-boot-saf.... These require a password and not PIN to access.

    Clean up anything found, restart PC and then run again until it comes up clean.

    Then download, install and run a full scan with AdwCleaner:

    http://www.bleepingcomputer.com/download/adwcle...

    Remove whatever it finds.

    Check for anything found but is still left over in Settings > Apps > Apps & Features, and C:\Program Files and C:\Program Files(86) to uninstall or delete them. I can guide you how to do this if there are problems.

    Also in each of your browser's Extensions, Home Page settings, Search service or Add-On's as shown here: https://www.computerhope.com/issues/ch001411.htm

    to disable anything you didn't add yourself and are sure you need. Ask back if in doubt.

    Then check for damaged System files by running System File Checker and DISM from Step 10 in this checklist:

    https://answers.microsoft.com/en-us/windows/for...

    If completing all of Step 10 in above Checklist doesn't fix it then run a Repair Install which reinstalls WIndows while keeping your files, programs and most settings in place, by installing the Media Creation Tool from this link: https://www.microsoft.com/en-US/software-downlo..., open the tool and choose Upgrade This PC Now. This will solve most problems and also bring it up to the latest version which you need anyway and by the most stable method.

    If you want to keep Malwarebytes as an on-demand scanner then you can turn off its Real Time trial version using the slider buttons on it's front panel. I recommend it as the #1 tool for your toolbox. For best WIndows performance, use built-in Defender which gives adequate real-time protection.

    If nothing will clean it up, then you may need to back up your files to quarantine (scan twice with each above) then wipe the drive with Clean Command and do this gold standard Clean Install that compiles the best possible Install of Windows which will stay that way as long as you stick with the tools and methods given, has zero reported problems, and is better than any amount of money could buy: http://answers.microsoft.com/en-us/windows/wiki....

    At second screen of bootable media access Command Prompt via Repair Your Computer > Advanced Troubleshooting to Clean drive:

    https://www.tenforums.com/tutorials/85819-erase...

    Feel free to ask back any questions. Report back results for more steps if necessary.

    ______________________________________________

    Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2022-09-18T20:44:48+00:00

    would resetting my pc to like factory state fix it?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2022-09-18T19:37:30+00:00

    after running cmd sfc scan i got back "windows resource protection found corrupt files but was unable to fix some of them." any idea to fix them?

    The files keep reappering in users/appdata/microsoft/edge/extensions i believe. even after deleting edge folder they still come back.

    Was this answer helpful?

    0 comments No comments