Bitcoin Forum
April 25, 2024, 09:38:20 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 »  All
  Print  
Author Topic: Bitcoin Malware  (Read 3997 times)
Hailedllama (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
August 31, 2015, 02:25:54 PM
 #1

i recently found a malware that changes bitcoin addresses when copied to the hackers address so just watch out and check to make sure that the bitcoin address you copy comes out the same when you paste it  Smiley
1714037900
Hero Member
*
Offline Offline

Posts: 1714037900

View Profile Personal Message (Offline)

Ignore
1714037900
Reply with quote  #2

1714037900
Report to moderator
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714037900
Hero Member
*
Offline Offline

Posts: 1714037900

View Profile Personal Message (Offline)

Ignore
1714037900
Reply with quote  #2

1714037900
Report to moderator
1714037900
Hero Member
*
Offline Offline

Posts: 1714037900

View Profile Personal Message (Offline)

Ignore
1714037900
Reply with quote  #2

1714037900
Report to moderator
Hailedllama (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
August 31, 2015, 02:42:57 PM
 #2

it happened to me about a hour ago but heres a guide on how to get rid of it if it is on your pc
10
Remove the malware
Finally remove it from your computer:
1.
Start Windows Task Manager and terminate the Chrome32.exe or
AcroRd32.exe process!
2.
Go to %appdata% in your file browser.
3.
Delete AppData/Roaming/Adobe (x86) folder.
4.
Delete AppData/Local/Google (x86) folder.
If you don't terminate the malware manually, as it is described
in the first point you can't delete one of the folder.
If you've deleted the Adobe folder it won't start again on your
computer, so you're good, but to completly remove it you have to
do one more thing:

Start the Registry Editor (regedit) and delete our software from
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru
n"
If you don't find it, check HKEY_LOCAL_MACHINE instead of
HKEY_CURRENT_USER


hope it helps this malware is being sold for $1.10 in bitcoin
Snorek
Legendary
*
Offline Offline

Activity: 1400
Merit: 1001



View Profile
August 31, 2015, 03:25:11 PM
 #3

it happened to me about a hour ago but heres a guide on how to get rid of it if it is on your pc
10
Remove the malware
Finally remove it from your computer:
1.
Start Windows Task Manager and terminate the Chrome32.exe or
AcroRd32.exe process!
2.
Go to %appdata% in your file browser.
3.
Delete AppData/Roaming/Adobe (x86) folder.
4.
Delete AppData/Local/Google (x86) folder.
If you don't terminate the malware manually, as it is described
in the first point you can't delete one of the folder.
If you've deleted the Adobe folder it won't start again on your
computer, so you're good, but to completly remove it you have to
do one more thing:

Start the Registry Editor (regedit) and delete our software from
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru
n"
If you don't find it, check HKEY_LOCAL_MACHINE instead of
HKEY_CURRENT_USER


hope it helps this malware is being sold for $1.10 in bitcoin
You mean that you can have your own version of this Malware with your own address for $1. That's sick. I was worried about new kind of malwares and viruses associated with bitcoin and here they are.
So far I know about this Malware changing address and another that encodes data on your disks and then want bitcoin to decypher it. New technologies, new threats.
Aggressor66
Hero Member
*****
Offline Offline

Activity: 728
Merit: 501



View Profile
August 31, 2015, 03:37:18 PM
 #4

Malwarebytes’ Anti-Malware is currently one of the most successful tools at identifying and removing the types of malware that we’re talking about here.
It’s not really a replacement for anti-virus software but in cases of infection, it has a pretty darn good track record.
Download the free version, install and run it, and then see what it turns up.
LiteCoinGuy
Legendary
*
Offline Offline

Activity: 1148
Merit: 1010


In Satoshi I Trust


View Profile WWW
August 31, 2015, 03:47:50 PM
 #5

i recently found a malware that changes bitcoin addresses when copied to the hackers address so just watch out and check to make sure that the bitcoin address you copy comes out the same when you paste it  Smiley

it is safer to store your coins on a hardware wallet:

https://bitcointalk.org/index.php?topic=899253.0

tadakaluri
Hero Member
*****
Offline Offline

Activity: 616
Merit: 500



View Profile WWW
August 31, 2015, 04:17:57 PM
 #6

it happened to me about a hour ago but heres a guide on how to get rid of it if it is on your pc
10
Remove the malware
Finally remove it from your computer:
1.
Start Windows Task Manager and terminate the Chrome32.exe or
AcroRd32.exe process!
2.
Go to %appdata% in your file browser.
3.
Delete AppData/Roaming/Adobe (x86) folder.
4.
Delete AppData/Local/Google (x86) folder.
If you don't terminate the malware manually, as it is described
in the first point you can't delete one of the folder.
If you've deleted the Adobe folder it won't start again on your
computer, so you're good, but to completly remove it you have to
do one more thing:

Start the Registry Editor (regedit) and delete our software from
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru
n"
If you don't find it, check HKEY_LOCAL_MACHINE instead of
HKEY_CURRENT_USER


hope it helps this malware is being sold for $1.10 in bitcoin

Thank you very much for the valuable information.  I need to check my PC and gadgets, is they already infected with this Malware or not? Once again thank you very much for this information.
nero987
Sr. Member
****
Offline Offline

Activity: 259
Merit: 250


View Profile
August 31, 2015, 04:23:44 PM
 #7

This is arround for some time already...
It first came up on Evo market arround 1 month before the exit scam.
I have the source code of v1.3 here.
Before you compile the malware you set some parameters, which include the process name.
In Snorek's "examples" its Chrome32.exe or AcroRd32.exe, but it can be literally everything.

About anti malware:
The program does not make any connection to the internet, for this reason it is almost never picked up by anti-virus/malware software.
When a particular compilation of the malware (with particular process name) is reported to an antivirus database, only that version will be picked up by av's...
There are some av's that notice that part of the code is comparable to know malware, but thats only a minority of the av's....


damn, practice your english nero!

edit: I'm not selling/sharing the source code, neither sharing any detailled information how it actually works!
ikydesu
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500

fb.com/Bitky.shop | Bitcoin Merch!Premium Quality!


View Profile WWW
August 31, 2015, 07:32:07 PM
 #8

i recently found a malware that changes bitcoin addresses when copied to the hackers address so just watch out and check to make sure that the bitcoin address you copy comes out the same when you paste it  Smiley

There are a lot malware out there come from related bitcoin service. I personally always check and scanned the site first when i want to visit, especially with a site which strange or fishy for me. This some tips for make your PC secure and avoid any virus/malware: https://bitcointalk.org/index.php?topic=203876.0
Mickeyb
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000

Move On !!!!!!


View Profile
August 31, 2015, 08:33:38 PM
 #9

i recently found a malware that changes bitcoin addresses when copied to the hackers address so just watch out and check to make sure that the bitcoin address you copy comes out the same when you paste it  Smiley

it is safer to store your coins on a hardware wallet:

https://bitcointalk.org/index.php?topic=899253.0

Doesn't this malware work even if you use a Trezor for example? I guess that people should be always careful and double check. MyTrezor Web wallet works in the browser as well.

The truth of the matter is that everybody should be double checking are addresses changed. If anybody  can have a copy of this malware for a $1, this means that this malware can become very widespread.
Meuh6879
Legendary
*
Offline Offline

Activity: 1512
Merit: 1011



View Profile
August 31, 2015, 08:38:48 PM
 #10

Chrome is the malware.


it seems logical ...  Grin
Gyfts
Legendary
*
Offline Offline

Activity: 2758
Merit: 1512


View Profile
August 31, 2015, 08:45:38 PM
 #11

Important to note that there are countless types of malware that can infect your PC and steal your wallet.  A virus that copies and pastes the wrong address seems like something that would be easy to catch, at least for me as I double check addresses before sending. Keyloggers are probably the most notable or taking people's bitcoin, or RATs. Both are very easy to steal Bitcoin while the owner of the wallet is away from their computer and unaware of their PC being infected.
Hailedllama (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
August 31, 2015, 09:49:24 PM
 #12

im glad i could help everyone but just because your internet security says its ok still be cautious because there are ways around internet security. There is alot of software like this being sold for like $2-$5 some even give it out for free so be careful
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
August 31, 2015, 09:58:17 PM
 #13

Linux.

No anti-this and anti-that software. Ditch Windows and use Linux, you'll avoid most of these types of attacks.

Vires in numeris
Hailedllama (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
August 31, 2015, 10:01:33 PM
 #14

i would love to use linux but my wifi stick doesnt have the drivers for linux
Hailedllama (OP)
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
August 31, 2015, 10:08:03 PM
 #15

Damn that looks good i would buy it but i just lost my money to this stupid malware  Angry
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
August 31, 2015, 10:19:37 PM
 #16

Linux.

No anti-this and anti-that software. Ditch Windows and use Linux, you'll avoid most of these types of attacks.
If you are looking for a linux version that has a windows feel I suggest Linux Mint, you can use wine for most windows programs but games have a lot of compatibility issues.

Don't forget linux is free :http://www.linuxmint.com/

Yes, Mint is excellent for new Linux users, it's really easy to install and is very forgiving when it comes to using peripherals with it. At least compared to other Linux distros anyway.



Be careful everybody with Linux if you have a brand new, latest Intel chip computer. Sometimes the newest hardware isn't supported properly yet, so either wait till the hardware is 6 months or so old, or wait that long till you try Linux on it. Or you could be brave  Cheesy It is a brave move, though.

Vires in numeris
Jeremycoin
Legendary
*
Offline Offline

Activity: 1022
Merit: 1003


𝓗𝓞𝓓𝓛


View Profile
August 31, 2015, 10:41:32 PM
 #17

Wow that could be a serious problem, but I always checked twice when I want to send a Bitcoin.

faucet used to be profitable
zero01
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
August 31, 2015, 10:49:13 PM
 #18

thank you for the information you provided
I would be more careful
rinhunter
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000



View Profile
August 31, 2015, 10:53:06 PM
 #19

Wow that could be a serious problem, but I always checked twice when I want to send a Bitcoin.

Great, so we as users have to remain cautious.
very serious, for those who frequently send BTC in large amount.
Coinshot
Hero Member
*****
Offline Offline

Activity: 521
Merit: 500


View Profile
August 31, 2015, 11:42:25 PM
 #20

Just wanted to add this; Sometimes mallwares makes additional registry entry to both CurrentVersion\Run" and CurrentVersion\RunOnce"
So it's best to check both, because one can copy the instance back to every registry entry, forcing you back to square one.


██████████████████████████████████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████▄▄▄███████████████████████
███████████████████████████████████████████████████████████████████████▀▀▀████████████████████████
██████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████



...INTRODUCING WAVES........
...ULTIMATE ASSET/CUSTOM TOKEN BLOCKCHAIN PLATFORM...






Pages: [1] 2 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!