Bitcoin Forum
May 14, 2024, 03:48:39 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: What should i do ?  (Read 985 times)
bjbear123 (OP)
Full Member
***
Offline Offline

Activity: 181
Merit: 100


View Profile
January 03, 2016, 11:18:44 AM
 #1


I was just sent a message from a user under the name of Hotsfet, the message contained a link to an IP address followed buy a file named freebitcoin.zip.

Here is the message he sent me :



I was foolish enough to accentently click the URL before even reading the message and as soon as i clicked on it a white page appeared with no content, I immediately knew i did wrong.

After i closed the page i thought it was finished and no harm was done however around 5 minutes later the file downloaded itself and popped into my downloads tab on Safari, i thought this was impossible since the page was closed. I closed the download before it finished and moved it to Trash and emptied the trash.

I am now running a full Virus scan with Bitfender.

To let you know I'm using a Macbook on El Capitan.

Does anyone have any advice for me, is this software on my mac or am i alright.

Thanks

BTC: 1Q3B9pr84adJJxBNmo3w3FaEWgcCjCSPTv | ETH: 0x1A053Df90E06f59fc7Aeb12F7a7Ea1f47FA53748 | LTC: LYUQYCy7S68Yry2qv3XRC7xx62GbHZEWhH | BCH: lol Wink
1715658519
Hero Member
*
Offline Offline

Posts: 1715658519

View Profile Personal Message (Offline)

Ignore
1715658519
Reply with quote  #2

1715658519
Report to moderator
1715658519
Hero Member
*
Offline Offline

Posts: 1715658519

View Profile Personal Message (Offline)

Ignore
1715658519
Reply with quote  #2

1715658519
Report to moderator
The Bitcoin network protocol was designed to be extremely flexible. It can be used to create timed transactions, escrow transactions, multi-signature transactions, etc. The current features of the client only hint at what will be possible in the future.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715658519
Hero Member
*
Offline Offline

Posts: 1715658519

View Profile Personal Message (Offline)

Ignore
1715658519
Reply with quote  #2

1715658519
Report to moderator
LiteCoinGuy
Legendary
*
Offline Offline

Activity: 1148
Merit: 1010


In Satoshi I Trust


View Profile WWW
January 03, 2016, 11:25:25 AM
 #2

delete the file and run an antivirus scan.

if you own a large amount of coins, use a hardware wallet like Trezor. even maleware cant break that.

https://bitcointalk.org/index.php?topic=899253.0

smith coins
Hero Member
*****
Offline Offline

Activity: 504
Merit: 500



View Profile
January 03, 2016, 11:27:54 AM
 #3


I was just sent a message from a user under the name of Hotsfet, the message contained a link to an IP address followed buy a file named freebitcoin.zip.

Here is the message he sent me :



I was foolish enough to accentently click the URL before even reading the message and as soon as i clicked on it a white page appeared with no content, I immediately knew i did wrong.

After i closed the page i thought it was finished and no harm was done however around 5 minutes later the file downloaded itself and popped into my downloads tab on Safari, i thought this was impossible since the page was closed. I closed the download before it finished and moved it to Trash and emptied the trash.

I am now running a full Virus scan with Bitfender.

To let you know I'm using a Macbook on El Capitan.

Does anyone have any advice for me, is this software on my mac or am i alright.

Thanks

As far as i know it's hard to get infected in OS X ?
Since you didn't opened the zip file then you should not be worried.
And please report it to the moderators they will take action for that user.
ZeroGee
Member
**
Offline Offline

Activity: 92
Merit: 10


View Profile
January 03, 2016, 11:29:07 AM
 #4

I'd say do a full virus scan, malware scan, possibly in safe mode, and it might be a good idea to make a hard wallet in the mean time if you have too much BTC to lose, so to speak. You're not likely to be infected with what you described, but better safe than sorry.

I'd also report the user.
smith coins
Hero Member
*****
Offline Offline

Activity: 504
Merit: 500



View Profile
January 03, 2016, 11:30:50 AM
 #5

I'd say do a full virus scan, malware scan, possibly in safe mode, and it might be a good idea to make a hard wallet in the mean time if you have too much BTC to lose, so to speak. You're not likely to be infected with what you described, but better safe than sorry.

I'd also report the user.

I just made an online virus scan (without downloading the file on my computer)
Here is the link https://www.virustotal.com/en/url/f02262e2726978c94fc5efe430b9ae801d47ab4c9dbd054693acf558c6816a90/analysis/1451820523/
Detection ratio:   4 / 66, so from 4 Antiviruses it is marked as Malicious site.
FruitsBasket
Legendary
*
Offline Offline

Activity: 1232
Merit: 1017


View Profile
January 03, 2016, 11:34:44 AM
 #6

I know this kind of viruses, it steals your money in a way, or it steals your wallet login or it locks up all your files and you need to pay to get your files back through torbrowser and pay them with bitcoin. That is called ransomware, never download an excutable file that can change things on your pc from an unreliable source. Just report this user, I bet the user will make money through affiliate virus spreading.

fck@dt-alwayzz_newbz
NorrisK
Legendary
*
Offline Offline

Activity: 1946
Merit: 1007



View Profile
January 03, 2016, 11:40:50 AM
 #7

The file cannot run itself after downloading right? As long as you make sure not to run the file you should be fine, or can executables run itself nowadays?

Best is indeed to run a couple of independant virus scans and move any coins you have on your pc.

You could also try hitman pro, a second opinion scanner that may find something suspicious.
~Bitcoin~
Legendary
*
Offline Offline

Activity: 994
Merit: 1000



View Profile
January 03, 2016, 11:44:11 AM
 #8

If you haven't clicked any file inside that downloaded zip file then there shouldn't be any problem to worry about. Better you do full scan with whatever antivirus you have, i have also used bitdefender on past and i think it can catch if any malware is there.

I have done same and get infected but i have got the direct software link via email.

dan91
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile WWW
January 03, 2016, 11:53:19 AM
 #9

malwarebytes is good to scan with too. You can use the free version Smiley
tyz
Legendary
*
Offline Offline

Activity: 3360
Merit: 1531



View Profile
January 03, 2016, 12:03:21 PM
 #10

Well, if you use a Macbook you are very likely safe of it. I guess it was a virus for Windows. Have you unzipped the archive and opened the containing files?
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
January 03, 2016, 12:37:50 PM
 #11

Well, if you use a Macbook you are very likely safe of it. I guess it was a virus for Windows. Have you unzipped the archive and opened the containing files?

Yes, its windows based malware[1], but dont think Macs are safe.

[1] https://www.virustotal.com/en/file/2011dc64139e21aa6b40d660bdd808641f2e862508ba3cef99f97ca8be61f139/analysis/1451820527/

Im not really here, its just your imagination.
Denker
Legendary
*
Offline Offline

Activity: 1442
Merit: 1014


View Profile
January 03, 2016, 01:00:46 PM
 #12

malwarebytes is good to scan with too. You can use the free version Smiley

Yes Malwarebytes should be good to go.
Also a full AV scan I recommend. And as a few other already have suggested, the usage of a hardware wallet if he has a bigger amount of coins.
These types of pms I got also  few times.I delete them all. And never ever click any links!!!!
Or you run a virtual machine when surfing the web is also a possibility if can't avoid being curious what's behind some suspicious websites or links.
unamis76
Legendary
*
Offline Offline

Activity: 1512
Merit: 1009


View Profile
January 03, 2016, 01:08:11 PM
 #13

Gave him negative trust and reported his only post. Possibly impersonating HostFat too? Either way, I think he should just be nuked.
helloeverybody
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000


★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile WWW
January 03, 2016, 01:09:52 PM
 #14

Id say you are probably good, If you never actually opened the file then i doubt the site had any scripts good enough that you will be infected with anything but like others have said worth doing a virus scan anyway. id recommend malawarebytes as above poster mentioned and also try running hijackthis to check everything thats running. I wouldnt worry though.

maku
Legendary
*
Offline Offline

Activity: 1288
Merit: 1000



View Profile
January 03, 2016, 01:27:02 PM
 #15

And I thought that Huge Sign above private message :!!! Warning! This user is a newbie etc. will be enough of a notice for people to not click links from unknown newbie accounts.
Maybe forum staff/admins should block ability for newbie users to send links in PM?
NorrisK
Legendary
*
Offline Offline

Activity: 1946
Merit: 1007



View Profile
January 03, 2016, 02:04:40 PM
 #16

Also it is probably best to make a habit of never ever clicking links without verifying them first.

Do you also open links in all emails you get? If so, stop doing that, you are asking to be hacked somewhere along the lines.
Epicnicity
Member
**
Offline Offline

Activity: 110
Merit: 10


View Profile
January 03, 2016, 02:47:18 PM
 #17

Nice to see nothing on your mac got affected. Thanks for posting this as well to aware others on the forum.

▲▼▲▼▲▼▲▼  No.1 Bitcoin Binary Options and Double Dice  ▲▼▲▼▲▼▲▼
████████████████████████████████  sec◔nds trade  ████████████████████████████████
↑↓ Instant Bets ↑↓ Flexible 1~720 minutes Expiry time ↑↓ Highest Reward 190% ↑↓ 16 Assets [btc, forex, gold, 1% edge double dice] ↑↓
davinchi
Legendary
*
Offline Offline

Activity: 2100
Merit: 1058


View Profile
January 03, 2016, 03:02:23 PM
 #18

I know this kind of viruses, it steals your money in a way, or it steals your wallet login or it locks up all your files and you need to pay to get your files back through torbrowser and pay them with bitcoin. That is called ransomware, never download an excutable file that can change things on your pc from an unreliable source. Just report this user, I bet the user will make money through affiliate virus spreading.

This has happened several times on this forum and users have lost their accounts and bitcoins due to the malware. I too was a victim once and before damage was done, I changed all my passwords and it took my hours to do so. I thought of asking the mods or admin to restrict newbies/Jr. members from posting links but I don't think this will happen. Also, this forum has no way to detect malware or suspicious links (only few are detected).
Amph
Legendary
*
Offline Offline

Activity: 3206
Merit: 1069



View Profile
January 03, 2016, 03:37:53 PM
 #19

Thank you all for helping, I finished the Bitdefender virus scan and it all showed as clear thankfully.

I have learnt a lot from this, especially not to open links from unknown sources.

i would not trust bitdefender only as a unique antivirus, you need more source

try with hitman pro plus malwarebyte and maybe avira antivirus, just to be more secure
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
January 03, 2016, 04:10:12 PM
 #20

Thank you all for helping, I finished the Bitdefender virus scan and it all showed as clear thankfully.

I have learnt a lot from this, especially not to open links from unknown sources.

i would not trust bitdefender only as a unique antivirus, you need more source

try with hitman pro plus malwarebyte and maybe avira antivirus, just to be more secure

Downloading a file itself is not problematic, executing it is. As OP said they just deleted it once it was on the machine, so I doubt they are infected.

Im not really here, its just your imagination.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!