Windows 10: How to delete Trojan:HTML/CoinMiner?

Discus and support How to delete Trojan:HTML/CoinMiner? in AntiVirus, Firewalls and System Security to solve the problem; How do I fully delete Trojan:HTML/CoinMiner? The Microsoft Safety Scanner only "partially removed" it.... Discussion in 'AntiVirus, Firewalls and System Security' started by ThompsonJohn1, May 15, 2020.

  1. How to delete Trojan:HTML/CoinMiner?


    How do I fully delete Trojan:HTML/CoinMiner? The Microsoft Safety Scanner only "partially removed" it.

    :)
     
    ThompsonJohn1, May 15, 2020
    #1
  2. Bruce Hagen, May 15, 2020
    #2
  3. Moirty Win User
    Trojan Found and Deleted....but it Returns (Trojan: HTML/Phish.AB!MSR)

    Windows defender periodically finds a Trojan in a .htm file in my Windows Communications appdata area (see attachment). You will notice that the file is in the Attachments folder. Windows defender seems to delete this threat but after a few days or a couple
    weeks, the threat will return in the exact same location.

    I have no evidence that the Trojan is actually running on my computer. I believe it is just sitting in the file waiting to be executed. I have not knowingly run this file and am usually careful about phishing attacks.

    Only Microsoft Defender will find it. I tried using Malwarebytes, Bitdefender and Microsoft Safety Scanner. None of these even finds it.

    MS-Defender says that it is successful at removing it and a scan immediately after the clean will not find the Trojan.

    A few troubleshooting actions to date:

    • Have removed the threat and immediately opened all known Microsoft communications programs (Outlook, Windows Calendar/Mail, Skype, Skype-Biz, Teams). I then reran a scan but did not find the Trojan. Nevertheless, it did return a couple weeks later.
    • I have started my computer in Safe Mode and deleted the entire package folder. After rebooting, the Trojan is no longer found by Defender. However, the folder and its content is eventually recreated along with the Trojan threat.
    • I had a case opened at Microsoft (who more-or-less had me repeat everything I had already done). MS ultimately recommended that I rebuild/refresh my entire computer. I am not adverse to doing this but I am worried that since the Trojan appears to be in
      an attachment within Windows communications, it will simply return. I do not want to waste my time.

    I currently run a daily scan of the appdata\package folder so that I can identify when the file returns.

    MS-Surface Pro i7/16GB/512GB with all Windows 10 Pro updates completed.

    Office 365 environment with most all files stored in OneDrive or SharePoint.

    Thank you for any further thoughts on this issue.

    -bs


    How to delete Trojan:HTML/CoinMiner? d96afd83-e398-49da-836d-8aa82a4861ec?upload=true.jpg
     
    Moirty, May 15, 2020
    #3
  4. How to delete Trojan:HTML/CoinMiner?

    Trojan: HTML/Brocoiner!rfn

    Thank you for your advice. Since restarting my computer, after running a full scan, I haven't had any "reminders" that I have a Trojan on my computer. I will keep your suggestions in mind in case it does show up again.
     
    MSBuchanan, May 15, 2020
    #4
Thema:

How to delete Trojan:HTML/CoinMiner?

Loading...
  1. How to delete Trojan:HTML/CoinMiner? - Similar Threads - delete Trojan HTML

  2. how to delete trojan virus

    in Windows 10 Installation and Upgrade
    how to delete trojan virus: Whenever I attach files in an email or other website, Chrome will be dead. There is an USB with trojan virus plugged into my computer. I do know whether it is the reason. If it is, how could I delete it.Thanks,...
  3. how to delete trojan virus

    in Windows 10 Gaming
    how to delete trojan virus: Whenever I attach files in an email or other website, Chrome will be dead. There is an USB with trojan virus plugged into my computer. I do know whether it is the reason. If it is, how could I delete it.Thanks,...
  4. how to delete trojan virus

    in Windows 10 Software and Apps
    how to delete trojan virus: Whenever I attach files in an email or other website, Chrome will be dead. There is an USB with trojan virus plugged into my computer. I do know whether it is the reason. If it is, how could I delete it.Thanks,...
  5. how to remove trojan HTML/Phish!pz

    in AntiVirus, Firewalls and System Security
    how to remove trojan HTML/Phish!pz: How can I remove the Trojan HTML/Phish!pz? https://answers.microsoft.com/en-us/windows/forum/all/how-to-remove-trojan-htmlphishpz/fce31a02-416e-41fa-aaf5-364b808ad30a
  6. how to remove trojan HTML/Phish!pz

    in Windows 10 Gaming
    how to remove trojan HTML/Phish!pz: How can I remove the Trojan HTML/Phish!pz? https://answers.microsoft.com/en-us/windows/forum/all/how-to-remove-trojan-htmlphishpz/fce31a02-416e-41fa-aaf5-364b808ad30a
  7. how to remove trojan HTML/Phish!pz

    in Windows 10 Software and Apps
    how to remove trojan HTML/Phish!pz: How can I remove the Trojan HTML/Phish!pz? https://answers.microsoft.com/en-us/windows/forum/all/how-to-remove-trojan-htmlphishpz/fce31a02-416e-41fa-aaf5-364b808ad30a
  8. Trojan/coinminer

    in Windows 10 Network and Sharing
    Trojan/coinminer: My pc is about 3 years old now and this is the first time something like this has happend to me my antivirus the one that u have on your pc from the get go with windows 10 starter saying mu pc had trojan coinminer i tried to use the remove option and og course that disnt work...
  9. Trojan Found and Deleted....but it Returns Trojan: HTML/Phish.AB!MSR

    in AntiVirus, Firewalls and System Security
    Trojan Found and Deleted....but it Returns Trojan: HTML/Phish.AB!MSR: Windows defender periodically finds a Trojan in a .htm file in my Windows Communications appdata area see attachment. You will notice that the file is in the Attachments folder. Windows defender seems to delete this threat but after a few days or a couple weeks, the threat...
  10. Trojan HTML/fakealert.AA

    in AntiVirus, Firewalls and System Security
    Trojan HTML/fakealert.AA: I have ran a full scan both online and offline and the results are no actions needed but it says allowed threats for this fake alert and then Remidation incomplete. What does this mean?...