Tips For Deleting Shadowsocks Miner Trojan From Windows PC


This post contains all necessary information about Shadowsocks Miner Trojan and it's removal tip. If somehow your Windows System has been infected with such a Miner Trojan and want to delete it from your compromised machine easily and completely then follow the provided removal instruction as in the exact order.

Delete Shadowsocks Miner Trojan

Detailed Information & Removal Guide of Shadowsocks Miner Trojan

Shadowsocks Miner Trojan is a recently identified Trojan variant that uses the power of CPU processing to mine the digital CryptoCurrency. First of all, it's sample has been discovered by security analysts on October 10th, 2017. Once Shadowsocks Miner Trojan has infected your PC successfully, it creates several schedules task that executes Websock.exe miner. After that, miner connects to a server and then attempts to mine coins by using all resources of System's processor. It has the capability to use almost all available CPU power of PC for coins.

You can notice it's presence on your PC easily because it throws an executable file named Websock.exe with a description which informs System user that CPU utility executing in the Task Manager. You can also notice Service.exe file process which is executing in the task manager. Since, it uses the large amount of the CPU power, so it can run on CPU at very hot temperature for carry on the large periods of time. It is responsible for shorten the life of CPU and make your PC crash and too much slow than before.

Propagation Channels of Shadowsocks Miner Trojan

Similar to the other variant of Trojan infection, Shadowsocks Miner Trojan often lurks inside the Windows PC in the secret mode without user awareness. It is known to install bundled with adware and other unwanted program, malware, spyware and other notorious System viruses. The installation of this Trojan is usually performed by the Trojan downloader or third-party download manager that already infected the PC. Besides, it also offered into the PC as an advanced or custom installation by the shareware and freeware packages. Therefore, it is very necessary to avoid the installation of any freeware packages online. Apart from this, there are several other distribution channels through which it infected Windows PC including torrent hackers, spam campaigns, online games, infected devices, file sharing sources and much more.

Common Symptoms of Shadowsocks Miner Trojan

  • Highly usages graphics cards and CPU resources through Websock.exe and Service.exe processes.
  • Drastically slows down System and Internet performance speed.
  • Slows the execution speed of programs and software.
  • Throws tons of fake alerts, scary messages and notifications on Windows PC.
  • Modifies your all crucial settings without asking for your approval.

>>Free Download Shadowsocks Miner Trojan Scanner<<



Manual Shadowsocks Miner Trojan Removal Guide

Step 1: How to Start your PC in Safe Mode with Networking to Get Rid of Shadowsocks Miner Trojan

(For Win 7 | XP | Vista Users)

  • first of all PC is to be rebooted in Safe Mode with Networking
  • Select on Start Button and Click on Shutdown | Restart option and select OK
  • when the PC restarts, keep tapping on F8 until you don’t get Advanced Boot Options.
  • Safe Mode with Networking Option is to be selected from the list.



(For Win 8 | 8.1 | Win 10 Users)

  • Click on Power Button near Windows Login Screen
  • Keep Shift Button on the keyboard pressed and select Restart Option
  • Now Select on Enable Safe Mode with Networking Option



In case Shadowsocks Miner Trojan, is not letting your PC to Start in Safe Mode, then following Step is to followed

Step 2: Remove Shadowsocks Miner Trojan Using System Restore Process

  • PC need to be rebooted to Safe Mode with Command Prompt
  • As soon as Command Prompt Window appear on the screen, select on cd restore and press on Enter option


Type rstrui.exe and Click on Enter again.


Now users need to Click on Next option and Choose restore point that was the last time Windows was working fine prior to Shadowsocks Miner Trojan infection. Once done, Click on Next button.



Select Yes to Restore your System and get rid of Shadowsocks Miner Trojan infection.


However, if the above steps does not work to remove Shadowsocks Miner Trojan, follow the below mentioned steps

Step:3  Unhide All Hidden Files and Folders to Delete Shadowsocks Miner Trojan

How to View Shadowsocks Miner Trojan Hidden Folders on Windows XP

  1. In order to show the hidden files and folders, you need to follow the given instructions:-
  2. Close all the Windows or minimize the opened application to go to desktop.
  3. Open “My Computer” by double-clicking on its icon.
  4. Click on Tools menu and select Folder options.
  5. Click on the View tab from the new Window.
  6. Check the Display contents of the system folders options.
  7. In the Hidden files and folders section, you need to put a check mark on Show hidden files and folders option.
  8. Click on Apply and then OK button. Now, close the Window.
  9. Now, you can see all the Shadowsocks Miner Trojan related hidden files and folders on the system.

win xpView-tab-1

How to Access Shadowsocks Miner Trojan Hidden folders on Windows Vista

  1. Minimize or close all opened tabs and go to Desktop.
  2. Go to the lower left of your screen, you will see Windows logo there, click on Start button.
  3. Go to Control Panel menu and click on it.
  4. After Control Panel got opened, there will two options, either “Classic View” or “Control Panel Home View”.
  5. Do the following when you are in “Classic View”.
  6. Double click on the icon and open Folder Options.
  7. Choose View tab.
  8. Again move to step 5.
  9. Do the following if you are “Control Panel Home View”.
  10. Hit button on Appearance and Personalization link.
  11. Chose Show Hidden Files or Folders.
  12. Under the Hidden File or Folder section, click on the button which is right next to the Show Hidden Files or Folders.
  13. Click on Apply button and then hit OK. Now, close the window.
  14. Now, to show you all hidden files or folders created by Shadowsocks Miner Trojan, you have successfully considered Windows Vista.




How to Unhide Shadowsocks Miner Trojan Created Folders on Windows 7

1. Go to the desktop and tap on the small rectangle which is located in the lower-right part of the system screen.

2. Now, just open the “Start” menu by clicking on the Windows start button which is located in the lower-left side of the PC screen that carries the windows logo.

3. Then after, look for the “Control Panel” menu option in the right-most row and open it.

4. When the Control Panel menu opens, then look for the “Folder Options” link.

5. Tap over the “View tab”.

6. Under the “Advanced Settings” category, double click on the “Hidden Files or Folders” associated with Shadowsocks Miner Trojan.

7. Next, just select the check-box in order to Show hidden files, folders, or drives.

8. After this, click on “Apply” >> “OK” and then close the menu.

9. Now, the Windows 7 should be configured to show you all hidden files, folders or drives.


Steps to Unhide Shadowsocks Miner Trojan related Files and Folders on Windows 8

  1. First of all, power on your Windows PC and click on start logo button that is found in left side of the system screen.
  2. Now, move to program lists and select control panel app.
  3. When Control panel is open completely, click on more settings option.
  4. After, you will see a Control panel Window and then you choose “Appearance and Personalization” tab.
  5. In Advance settings dialogue box, you need to tick mark on Show hidden files and folders and clear the check box for Hide protected system files.
  6. Click on Apply and Ok button. This apply option helps you to detect and eradicate all types of Shadowsocks Miner Trojan related suspicious files.
  7. Finally, navigate your mouse cursor on close option to exit this panel.

win 8 unhide folders


How to View Shadowsocks Miner Trojan associated folders on Windows 10

1. Open the folder if you wish to unhide files.

2. Search and Click on View in Menu bar

3. In Menu click on to view folder options.

4. Again click on View and Enable Radio Button associated with Show hidden files created by Shadowsocks Miner Trojan, folder and drive.

5. Press apply and OK.

win 10 Options

Step 4: Press Start Key along with R- copy + paste the below stated command and Click on OK

notepad %windir%/system32/Drivers/etc/hosts

  • This will open up a new file, in case if your system has been hacked, some IP’s will be shown at the bottom of the screen


Click on the Start Menu, Input “Control Panel” in the search box —> Select. Network and Internet —> Network and Sharing Center —> Next Change Adapter Settings. Right-click your Internet connection —> Select on Properties.

  • In case if you find Suspicious IP in the local host –or if you are finding it difficult and have any problem then submit question to us and we will be happy to help you.