Bitcoin Forum

Bitcoin => Mining => Topic started by: ajax3592 on November 12, 2013, 05:08:32 PM



Title: BITCON MINER VIRUS
Post by: ajax3592 on November 12, 2013, 05:08:32 PM
I just ran a full system scan using Malwarebytes Antimalware and two sneaky "Bitcoin Mining" viruses showed up in temp directory  :o
Lol, Einsteins of today's world.
Have you guys hear about this virus ?


Title: Re: BITCON MINER VIRUS
Post by: sushi on November 12, 2013, 11:29:31 PM
No....

What's the description?  What is it going to do if you get infected?

Keylog?  steal your private keys?  or scam off portion of your mining powers?


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 13, 2013, 12:02:44 AM
What the?
Please copy the log here.


Title: Re: BITCON MINER VIRUS
Post by: Sythyn on November 13, 2013, 01:29:12 AM
I found minerd.exe in my office computer and my CPU usage were 100%. Installed free AVG to get ride of it :)


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 13, 2013, 05:01:33 AM
I found minerd.exe in my office computer and my CPU usage were 100%. Installed free AVG to get ride of it :)
Can you provide the log?


Title: Re: BITCON MINER VIRUS
Post by: sushi on November 13, 2013, 06:15:00 AM
Someone was making side money at your office  >:(

You should have looked into the process and the memory and see who the miner user ID at the pool was


Title: Re: BITCON MINER VIRUS
Post by: FarSky7 on November 13, 2013, 08:05:05 AM
Could be that trojan mining bot. ??? http://forum.avast.com/index.php?topic=129680.0


Title: Re: BITCON MINER VIRUS
Post by: JessicaSe on November 13, 2013, 08:09:39 AM
I am mining in my office please don't tell anyone :P But my boss know it and she is ok :)


Title: Re: BITCON MINER VIRUS
Post by: AuroraHF on November 13, 2013, 08:14:07 AM
I am mining in my office please don't tell anyone :P But my boss know it and she is ok :)

We don't know who to tell considering we don't know where you work.

These are silent miners used by hackers. You were infected.


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 13, 2013, 02:46:58 PM
Could be that trojan mining bot. ??? http://forum.avast.com/index.php?topic=129680.0
So we have that too now. Damn.


Title: Re: BITCON MINER VIRUS
Post by: AuroraHF on November 13, 2013, 02:53:42 PM
Could be that trojan mining bot. ??? http://forum.avast.com/index.php?topic=129680.0
So we have that too now. Damn.

This form of malware has been here since the start of Bitcoins. It used to just drop CGMiner without the GUI.


Title: Re: BITCON MINER VIRUS
Post by: wpgdeez on November 13, 2013, 06:04:48 PM
Zero Access rootkit had some Mining code in it but they removed it since cpu mining is now useless.


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 13, 2013, 07:29:18 PM
Zero Access rootkit had some Mining code in it but they removed it since cpu mining is now useless.
Could still be used for CPU coins.


Title: Re: BITCON MINER VIRUS
Post by: wpgdeez on November 13, 2013, 08:00:01 PM
Sure but the profit isnt there for the blackhats. They make more money off of click fraud than mining without drwaing unwanted attention to themselves.


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 13, 2013, 08:06:25 PM
Sure but the profit isnt there for the blackhats. They make more money off of click fraud than mining without drwaing unwanted attention to themselves.
Wrong. Buy cheap botnet -> mine CPU coin -> dump all.
Profit.


Title: Re: BITCON MINER VIRUS
Post by: ajax3592 on November 13, 2013, 08:18:44 PM
What the?
Please copy the log here.

Here you go guys, check this out:

Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.08.16.07
06-11-2013 14:11:06
mbam-log-2013-11-06 (14-11-06).txt

Scan type: Full scan (C:\|E:\|F:\|G:\|H:\|I:\|K:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 146706
Time elapsed: 30 minute(s), 11 second(s) [aborted]

Memory Processes Detected: 1
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> 7280 -> Delete on reboot.

Files Detected: 7
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\coinutil.dll (PUP.BitcoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\miner.dll (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\service.exe (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\usft_ext.dll (PUP.BitCoinMiner) -> No action taken.
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.
C:\Users\***\AppData\Roaming\XHvQH\taskengine.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.

(end)


Title: Re: BITCON MINER VIRUS
Post by: rampalija on November 13, 2013, 10:19:22 PM
What the?
Please copy the log here.

Here you go guys, check this out:

Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.08.16.07
06-11-2013 14:11:06
mbam-log-2013-11-06 (14-11-06).txt

Scan type: Full scan (C:\|E:\|F:\|G:\|H:\|I:\|K:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 146706
Time elapsed: 30 minute(s), 11 second(s) [aborted]

Memory Processes Detected: 1
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> 7280 -> Delete on reboot.

Files Detected: 7
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\coinutil.dll (PUP.BitcoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\miner.dll (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\service.exe (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\usft_ext.dll (PUP.BitCoinMiner) -> No action taken.
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.
C:\Users\***\AppData\Roaming\XHvQH\taskengine.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.

(end)



I think it is only fake detection


Title: Re: BITCON MINER VIRUS
Post by: AuroraHF on November 14, 2013, 05:10:51 AM
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  :D


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 14, 2013, 05:12:13 AM
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  :D
Generate bitcoins for free and get rich.  :D


Title: Re: BITCON MINER VIRUS
Post by: rampalija on November 14, 2013, 06:47:59 AM
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  :D
Generate bitcoins for free and get rich.  :D

and i assume it steals everythig what u have?!?! am I right?


Title: Re: BITCON MINER VIRUS
Post by: ajax3592 on November 14, 2013, 07:22:29 AM
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  :D
Generate bitcoins for free and get rich.  :D

and i assume it steals everythig what u have?!?! am I right?
Lol yes I used desperate measures to get some of my first Bitcoins.
No it is not a fake detection, even Kaspersky have reported few days back about a "BitCoin Miner" Virus


Title: Re: BITCON MINER VIRUS
Post by: tel on November 14, 2013, 01:19:32 PM
Hi man,

To be sure that this is false positive detection you can try to upload the file to www.virustotal.com


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 14, 2013, 03:20:08 PM
I doubt that it's a false positive as my secure system hasn't encountered it and yet it has a few wallets, among them is the bitcoin one.


Title: Re: BITCON MINER VIRUS
Post by: rampalija on November 15, 2013, 12:01:53 AM
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  :D
Generate bitcoins for free and get rich.  :D

and i assume it steals everythig what u have?!?! am I right?
Lol yes I used desperate measures to get some of my first Bitcoins.
No it is not a fake detection, even Kaspersky have reported few days back about a "BitCoin Miner" Virus


did it steal anything from you ?!


Title: Re: BITCON MINER VIRUS
Post by: MaxBTC1 on November 15, 2013, 12:04:04 AM
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  :D
Generate bitcoins for free and get rich.  :D

and i assume it steals everythig what u have?!?! am I right?

OP did you really dl a 'get free bitcoin generator' from yt?!


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 15, 2013, 02:38:03 PM
Don't download any generators.  :D


Title: Re: BITCON MINER VIRUS
Post by: chaosknight on November 15, 2013, 03:09:32 PM
Actually, don't download any app or plugin also..


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 15, 2013, 03:55:05 PM
Actually, don't download any app or plugin also..
Why is that?


Title: Re: BITCON MINER VIRUS
Post by: BitcoinAddicts on November 16, 2013, 01:25:02 AM
Actually, don't download any app or plugin also..
Why is that?

Some plugin are trojan maybe?


Title: Re: BITCON MINER VIRUS
Post by: Johanna on November 16, 2013, 03:48:09 AM
Its easy to check, if your CPU is at 100% without much program running, you know something is wrong..


Title: Re: BITCON MINER VIRUS
Post by: MilesJohan on November 16, 2013, 05:08:10 AM
Don't plug in any USB too, easiest way to transfer virus...


Title: Re: BITCON MINER VIRUS
Post by: JTrain_51 on November 16, 2013, 05:21:22 AM
I know about this virus it is usually created on a botnet were many people get infected/given a virus and then a hole bunch of people mine for this 1 person it is crazy but has recently became low profit so you should not find this virus to much anymore


Title: Re: BITCON MINER VIRUS
Post by: Thenen on November 16, 2013, 11:12:08 AM
I know about this virus it is usually created on a botnet were many people get infected/given a virus and then a hole bunch of people mine for this 1 person it is crazy but has recently became low profit so you should not find this virus to much anymore

Yeah agree, but they can still use the CPU to mine CPU only coin...


Title: Re: BITCON MINER VIRUS
Post by: Undefeatable on November 16, 2013, 01:18:10 PM
I know about this virus it is usually created on a botnet were many people get infected/given a virus and then a hole bunch of people mine for this 1 person it is crazy but has recently became low profit so you should not find this virus to much anymore

Wrong, if the one that created the botnet is smart enough, he should mine the most profitable CPU coins instead of BTC....


Title: Re: BITCON MINER VIRUS
Post by: Leehoya on November 16, 2013, 01:21:14 PM
I know about this virus it is usually created on a botnet were many people get infected/given a virus and then a hole bunch of people mine for this 1 person it is crazy but has recently became low profit so you should not find this virus to much anymore

Wrong, if the one that created the botnet is smart enough, he should mine the most profitable CPU coins instead of BTC....
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 16, 2013, 02:08:15 PM
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.


Title: Re: BITCON MINER VIRUS
Post by: MarketTime on November 16, 2013, 03:15:53 PM
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...


Title: Re: BITCON MINER VIRUS
Post by: Lauda on November 16, 2013, 07:58:38 PM
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.


Title: Re: BITCON MINER VIRUS
Post by: rampalija on November 16, 2013, 11:01:12 PM
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.


i agree i tryed and it stucks all the time


Title: Re: BITCON MINER VIRUS
Post by: chaosknight on November 17, 2013, 03:02:01 AM
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.


i agree i tryed and it stucks all the time

You mean you are one who makes those bot too!!!  :'(


Title: Re: BITCON MINER VIRUS
Post by: BitcoinAddicts on November 17, 2013, 04:31:47 AM
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.

Really? why can't botnet use memory?


Title: Re: BITCON MINER VIRUS
Post by: Leehoya on November 17, 2013, 07:34:49 AM
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.

Really? why can't botnet use memory?
Its probably more detectable. Making the computer slower.


Title: Re: BITCON MINER VIRUS
Post by: whitemage on November 17, 2013, 10:39:10 AM
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.

Really? why can't botnet use memory?
Its probably more detectable. Making the computer slower.

Im not too good with CPU coins but why would PTS use more memory?


Title: Re: BITCON MINER VIRUS
Post by: davidbow on November 18, 2013, 02:17:42 AM
noisy CPU fan should arouse the suspicion of of most users


Title: Re: BITCON MINER VIRUS
Post by: braytz on November 18, 2013, 06:09:54 PM
"BTCGenv1.0"

pfffff , noob.  ;D


Title: Re: BITCON MINER VIRUS
Post by: Ally_Rob on November 23, 2013, 08:01:51 AM
Could be that trojan mining bot. ??? http://forum.avast.com/index.php?topic=129680.0
So we have that too now. Damn.


If you just realized that there are bitcoin trojans, ehhhh.. Do a system scan then.
 They've been out since bitcoin caught traction, sadly enough..
 
 Between getting hundreds of bot's to mine for you.
 Injecting code into your client to steal from you.
 Setting up on-demand keylogger to capture your keys for your wallet.
 etc.



Title: Re: BITCON MINER VIRUS
Post by: CounterStrike on November 23, 2013, 09:31:30 AM
Could be that trojan mining bot. ??? http://forum.avast.com/index.php?topic=129680.0
So we have that too now. Damn.


If you just realized that there are bitcoin trojans, ehhhh.. Do a system scan then.
 They've been out since bitcoin caught traction, sadly enough..
 
 Between getting hundreds of bot's to mine for you.
 Injecting code into your client to steal from you.
 Setting up on-demand keylogger to capture your keys for your wallet.
 etc.



The trojans stealing wallet is far worst then stealing CPU usage....


Title: Re: BITCON MINER VIRUS
Post by: Ally_Rob on November 23, 2013, 06:07:11 PM
of course


Title: Re: BITCON MINER VIRUS
Post by: ajax3592 on November 29, 2013, 07:51:22 AM
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  :D
Generate bitcoins for free and get rich.  :D

and i assume it steals everythig what u have?!?! am I right?

OP did you really dl a 'get free bitcoin generator' from yt?!

Yes I did  :-X



did it steal anything from you ?!
Not yet, let's see, maybe its waiting for an oppurtunity


Title: Re: BITCON MINER VIRUS
Post by: yntro on November 29, 2013, 09:55:30 AM
Well after I installed Bit miner program my anti-virus went crazy. Started deleting files and so on.. I uninstalled it and everything was alright.


Title: Re: BITCON MINER VIRUS
Post by: JTrain_51 on November 29, 2013, 06:36:23 PM
If you go to the : hackforums.net and go to the marketplace there are several of these and trust me it is something you do not want to have on your computer

Stay safe scan links and files