Bitcoin Forum

Other => Off-topic => Topic started by: adamstgBit on November 07, 2011, 02:22:42 AM



Title: I just got Hacked!
Post by: adamstgBit on November 07, 2011, 02:22:42 AM
i come back home today, and find my computer in sore shape.

its tell me some files where accesed remotely and asks me to block this attact

it would seem i have a w32.Blaster worm. and was unable to start any programs.

after running the virus scan everything seems back to normal... ish

it would seem the attacker did NOT steal my bitcoin wallet!



 


Title: Re: I just got Hacked!
Post by: worldinacoin on November 07, 2011, 02:24:16 AM
better get a secure computer, setup bitcoin and transfer your coins away.


Title: Re: I just got Hacked!
Post by: bitplane on November 07, 2011, 02:47:25 AM
Blaster is an old memory resident worm from 2006 and doesn't spread anymore, you've probably got a scareware infection.


Title: Re: I just got Hacked!
Post by: adamstgBit on November 07, 2011, 03:05:08 AM
Blaster is an old memory resident worm from 2006 and doesn't spread anymore, you've probably got a scareware infection.

i think your right the thing running the scan right now is porbly the bug.

"Privcay Protection"

yup
http://www.2-viruses.com/remove-privacy-protection

Quote
What is Privacy Protection?
Privacy Protection is fake anti-malware program that simulates activity of legitimate programs capable to solve your computer’s protection issues. ....


Title: Re: I just got Hacked!
Post by: deslok on November 07, 2011, 03:12:57 AM
I would advise trying to load a legitimate antivirus such as avast as well as an antispyware software such as spybot, if you can't get to their sites to even install these you've definitly got something going on


Title: Re: I just got Hacked!
Post by: Yankee (BitInstant) on November 07, 2011, 03:22:39 AM
phew, I got scared there for a second  :'(

Glad your bitcoins are safe  :D

Go for Kaspersky or AVN anti-virus, both amazing.
(Maybe change the title of this thread, its a tad scary)

Cheers


Title: Re: I just got Hacked!
Post by: Snapman on November 07, 2011, 03:26:23 AM
Might want to also run "malwarebytes" through there once, might help in picking up whatever files or entries are left.


Title: Re: I just got Hacked!
Post by: Raoul Duke on November 07, 2011, 03:40:53 AM
Run Hitman Pro 3.5. It will kill the bastard.


Title: Re: I just got Hacked!
Post by: naypalm on November 07, 2011, 04:51:57 AM
If you run a legit version of Windows, give MSE a try. Before I was running a combo of Symantec and Spybot S&D. Now I do not.

in b4 M$uck, Linux! and "It's unpossible for my iMac to get virus."


Title: Re: I just got Hacked!
Post by: adamstgBit on November 07, 2011, 05:06:28 AM
Might want to also run "malwarebytes" through there once, might help in picking up whatever files or entries are left.

ya i'm running it right now in "windows safe mode"

f-in shit is taking 1 hour to scann everthing, i hope everything is back to normal after


Title: Re: I just got Hacked!
Post by: BadBear on November 07, 2011, 01:58:24 PM
Seconding MSE, it's most totally excellent.  No loud noises, no annoying popups, no loud voices saying VIRUS DATABASE HAS BEEN UPDATED.  It just works and works quietly. 


Title: Re: I just got Hacked!
Post by: Tuxavant on November 07, 2011, 02:34:52 PM
If there's any indication your machine has been compromised or unauthorized/malicious software has been able to run on your system, your only recourse to be absolutely sure is to reflash your bios, wipe your drive, and reinstall.

Anything less than that, and you can't really be sure you're in a trustable, safe state.


Title: Re: I just got Hacked!
Post by: RodeoX on November 07, 2011, 02:40:49 PM
I would not assume your wallet has not been copied. Especially if you are using an encrypted wallet. Your thief could be trying to brute force the password as we speak. It might be worth it to put that wallet on another computer and do some kind of transaction. Then the wallet he/she has will no longer be valid.


Title: Re: I just got Hacked!
Post by: Tuxavant on November 07, 2011, 03:00:23 PM
What rodeoX said...

If you have a significant sum of Bitcoins, you should take a large portion offline immediately into multiple addresses (so you dont have to bring your entire offline sum online if you need to spend a small amount). Move the rest to a new wallet to spend as needed like allowance or discretionary spending.


Title: Re: I just got Hacked!
Post by: DeathAndTaxes on November 07, 2011, 03:06:44 PM
If there's any indication your machine has been compromised or unauthorized/malicious software has been able to run on your system, your only recourse to be absolutely sure is to reflash your bios, wipe your drive, and reinstall.

Anything less than that, and you can't really be sure you're in a trustable, safe state.

This.  It doesn't take that long.  Looking for signs of an attack is often futile.  Many malware are very good at hiding even from anti-malware software.  Since XP has no admin restrictins you could already been rootkitted and any detection software is simply seeing what the malicous software wants it to see.

I would not assume your wallet has not been copied. Especially if you are using an encrypted wallet. Your thief could be trying to brute force the password as we speak. It might be worth it to put that wallet on another computer and do some kind of transaction. Then the wallet he/she has will no longer be valid.

This to.  To easy to simply take the precaution of creating new wallet and transferring all balances from old wallet to the new one.  While your encryption may not be breakable today if the attacker got it you are taking the chance it will never be breakable ever in the future. 


Title: Re: I just got Hacked!
Post by: Matthew N. Wright on November 07, 2011, 03:10:34 PM
If there's any indication your machine has been compromised or unauthorized/malicious software has been able to run on your system, your only recourse to be absolutely sure is to reflash your bios, wipe your drive, and reinstall.

Anything less than that, and you can't really be sure you're in a trustable, safe state.
Of course you're right, but I'd say flashing the bios is a bit unnecessary in most cases as viruses aren't really allowed to access the bios so easily in modern operating systems, especially considering flashing your BIOS is a gamble (most people don't have extra CMOS chips laying around).


Title: Re: I just got Hacked!
Post by: DeathAndTaxes on November 07, 2011, 03:14:20 PM
If there's any indication your machine has been compromised or unauthorized/malicious software has been able to run on your system, your only recourse to be absolutely sure is to reflash your bios, wipe your drive, and reinstall.

Anything less than that, and you can't really be sure you're in a trustable, safe state.
Of course you're right, but I'd say flashing the bios is a bit unnecessary in most cases as viruses aren't really allowed to access the bios so easily in modern operating systems, especially considering flashing your BIOS is a gamble (most people don't have extra CMOS chips laying around).

It is very easy to flash a modern bios with a virus.  Most motherboards have a windows based tool to flash bios without rebooting.  While this is convenient it also makes it easy to infect the bios.  If it can be done for a "good bios" it can be done for a malicious one.  

http://www.tomshardware.com/news/bios-virus-rootkit-security-backdoor,7400.html


Still it all depends on how paranoid you are.  An alternative, some (but not all) motherboards offer an option to make a backup of the bios.  Some do this from same windows utility to flash a bios, some from a option in the bios to write to a thumb drive.  If you can get a copy of the bios currently loaded you can take a hash of it and compare it to the official bios.  If they match then no need to flash.  If they don't match then I would definitely flash.


Title: Re: I just got Hacked!
Post by: Matthew N. Wright on November 07, 2011, 04:34:26 PM
If there's any indication your machine has been compromised or unauthorized/malicious software has been able to run on your system, your only recourse to be absolutely sure is to reflash your bios, wipe your drive, and reinstall.

Anything less than that, and you can't really be sure you're in a trustable, safe state.
Of course you're right, but I'd say flashing the bios is a bit unnecessary in most cases as viruses aren't really allowed to access the bios so easily in modern operating systems, especially considering flashing your BIOS is a gamble (most people don't have extra CMOS chips laying around).

It is very easy to flash a modern bios with a virus.  Most motherboards have a windows based tool to flash bios without rebooting.  While this is convenient it also makes it easy to infect the bios.  If it can be done for a "good bios" it can be done for a malicious one.  

http://www.tomshardware.com/news/bios-virus-rootkit-security-backdoor,7400.html


Still it all depends on how paranoid you are.  An alternative, some (but not all) motherboards offer an option to make a backup of the bios.  Some do this from same windows utility to flash a bios, some from a option in the bios to write to a thumb drive.  If you can get a copy of the bios currently loaded you can take a hash of it and compare it to the official bios.  If they match then no need to flash.  If they don't match then I would definitely flash.

Quote
The reason that Microsoft Windows has more viruses that any other operating system isn't so much about its vulnerabilities as it is about it's success. People will argue which is more of a contributing factor, but there's no denying that the fact that Windows runs on a gazillion machines is a huge factor.

"Now, while Windows is relatively standard across PCs, BIOS's are not."
By writing a single virus that targets Microsoft Windows, a virus writer can potentially infect more computers on the planet than by writing it to target any other system. It's no secret that virus and malware writers regularly target the greatest potential audience so as to get the greatest number of infections for their malicious intent.

Now, while Windows is relatively standard across PCs, BIOS's are not.

The BIOS used in a PC built by one manufacturer may be radically different than that from another company. A virus that attempts to target a BIOS vulnerability or to somehow "hide" within a BIOS has to, essentially, be rewritten for or at least be customized and aware of every different BIOS that it might want target.

It's easier to simply rely on user apathy and target unpatched vulnerabilities in Windows. One virus per vulnerability, and all unpatched machines become malware's playground.

That's potentially a lot. A gazillion, even.

So just like Mac or Linux malware, there may be a few BIOS targeting viruses out there, but they're not even close to being as common as the more standard Windows-based malware.

Now, that's not to say that there's zero risk.

As you point out, a virus that manages to embed itself into the BIOS or BIOS's flash memory has one extremely unique characteristic: it'll survive even if you completely reformat and erase everything on your hard disk.

However, even that is easily remedied, either by resetting your BIOS to it's factory image - which most modern motherboards support - or often simply by updating or re-flashing your BIOS.

My take: it's not something I'd worry about at all just yet. In a rare case where malware appears to have survived a reformatting ... well, I'd first look at all the other ways that a machine can get immediately reinfected as you rebuild it from scratch (lack of firewall, infected external hard drives and the like). Only after eliminating those might I think about checking or resetting the BIOS.

It's just not that common a problem right now.


Title: Re: I just got Hacked!
Post by: dooglus on November 08, 2011, 12:47:28 AM
It might be worth it to put that wallet on another computer and do some kind of transaction. Then the wallet he/she has will no longer be valid.

Are you sure?

If you send the entire balance to a new address, the thief's copy of the wallet will be empty, but still valid.

If you send less than the entire balance, you stand a chance of leaving some coins untouched and still available to the thief, and any change from the coins you do send will be sent to an address from the keypool, which the thief will also have access to.

I don't think there's any "kind of transaction" you can make that will invalidate the thief's copy of your wallet.


Title: Re: I just got Hacked!
Post by: Tuxavant on November 08, 2011, 12:57:59 AM

I don't think there's any "kind of transaction" you can make that will invalidate the thief's copy of your wallet.

He just means that you're "invalidating" it by taking the money out of it and not using it anymore. The thief would still have access to the private keys to send money, but there would be none there. And you may have to watch for future transactions sent to that wallet and "spend" them before the thief did.


Title: Re: I just got Hacked!
Post by: P4man on November 08, 2011, 08:27:19 AM
Yes, someone predicted it, but it has to be said; you should give ubuntu a try.


Title: Re: I just got Hacked!
Post by: BadBear on November 08, 2011, 12:53:52 PM
Why the shit would he want to use Ubuntu? 


Title: Re: I just got Hacked!
Post by: DeathAndTaxes on November 08, 2011, 01:22:59 PM
Well if for no other reason the w32.blaster would have done nothing on a Linux box.  I am a Windows developer by trade and I won't use my wallet on my windows workstation.  Windows is good for a lot of things (if you want to play games it is your only real choice) but I wouldn't exactly call it a secure financial platform.


Title: Re: I just got Hacked!
Post by: BadBear on November 08, 2011, 01:57:07 PM
Yeah one of the downsides of bitcoin, having to use linux.  I kid, but in all seriousness, look at his OP again. 

Quote
i come back home today, and find my computer in sore shape.

its tell me some files where accesed remotely and asks me to block this attact

it would seem i have a w32.Blaster worm. and was unable to start any programs.

after running the virus scan everything seems back to normal... ish

it would seem the attacker did NOT steal my bitcoin wallet!

He got hit with a 8 year old worm, and is probably still using XP (a decade old at this point).  Nothing will help people like this. 


Title: Re: I just got Hacked!
Post by: DeathAndTaxes on November 08, 2011, 02:01:47 PM
Yeah one of the downsides of bitcoin, having to use linux.  I kid, but in all seriousness, look at his OP again. 

Quote
i come back home today, and find my computer in sore shape.

its tell me some files where accesed remotely and asks me to block this attact

it would seem i have a w32.Blaster worm. and was unable to start any programs.

after running the virus scan everything seems back to normal... ish

it would seem the attacker did NOT steal my bitcoin wallet!

He got hit with a 8 year old worm, and is probably still using XP (a decade old at this point).  Nothing will help people like this. 


Yeah good point.  Sadly w/ Blaster it was developed by reverse engineering a critical security fix that Microsoft had already pushed out.  So even on day 0 the only system vulnerable were ones that hadn't upgraded.   To still be vulnerable 7+ years later is just bad.  It is systems like this that make botnets such a problem.  I think Microsoft will eventually have to take away all choice, your system auto upgrades to latest version and it can't be stopped.


Title: Re: I just got Hacked!
Post by: Tuxavant on November 08, 2011, 02:18:58 PM
I think Microsoft will eventually have to take away all choice, your system auto upgrades to latest version and it can't be stopped.

Makes me giggle to think of all the apps this could break.


Title: Re: I just got Hacked!
Post by: P4man on November 08, 2011, 02:25:46 PM
He got hit with a 8 year old worm, and is probably still using XP (a decade old at this point).  Nothing will help people like this. 

On the contrary, the fact he is probably using ancient software (and probably hardware too) suggests he's not a hardcore gamer. Ubuntu will help people like that, it does it all the time. I just upgraded a malware infected windows 2000 machine to ubuntu for someone. You wouldnt believe how pleased she was with the "new pc".


Title: Re: I just got Hacked!
Post by: RodeoX on November 08, 2011, 02:27:11 PM
Why the shit would he want to use Ubuntu? 
Ubuntu is miles ahead of windows. With the exception of gaming, I don't understand why anyone uses windows.


Title: Re: I just got Hacked!
Post by: Tuxavant on November 08, 2011, 02:43:52 PM
I don't understand why anyone uses windows.

I think mappers vs packers theory applies. Honestly, I don't want Linux to be a mainstream desktop OS. I'd much prefer it keep it's "high hanging fruit" status.


Title: Re: I just got Hacked!
Post by: ineededausername on November 10, 2011, 02:36:00 AM
Why the shit would he want to use Ubuntu? 
Ubuntu is miles ahead of windows. With the exception of gaming, I don't understand why anyone uses windows.
For games you can use Wine most of the time...