Bitcoin Forum
April 27, 2024, 12:54:26 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Beware trojan  (Read 1444 times)
zazarb (OP)
Legendary
*
Offline Offline

Activity: 3360
Merit: 1548


Get loan in just five minutes goo.gl/8WMW6n


View Profile WWW
December 20, 2015, 09:19:42 AM
 #1

Self-moderated Topic:
https://bitcointalk.org/index.php?topic=1259902.0
I downloaded candlecoin wallet via link provided in OP, my antivirus software found virus.
C:\Users\******\Downloads\Candle-qt.rar » RAR » Candle-qt.exe » DEEPSEA » deobfuscated.exe - a variant of MSIL/Injector.NGC trojan


I PM's OP , but no reaction, then post in topic, today got message that my post deleted:

Quote
Deleted Post
« Sent to: zazarb on: Today at 08:08:29 AM »
   Reply with quoteReply with quote Remove this messageDelete
A reply of yours, quoted below, was deleted by the starter of a self-moderated topic. There are no rules of self-moderation, so this deletion cannot be appealed. Do not continue posting in this topic if the topic-starter has requested that you leave.

You can create a new topic if you are unsatisfied with this one. If the topic-starter is scamming, post about it in Scam Accusations.

Quote
hello
since you did not reply me via PM, I ask you here:
18 december I download candlecoin wallet from link in your OP and try install in my pc , my antivirus found trojan

C:\Users\******\Downloads\Candle-qt.rar » RAR » Candle-qt.exe » DEEPSEA » deobfuscated.exe - a variant of MSIL/Injector.NGC trojan

today I try download again and now file clear

you are aware of this fact?

Admin Dave4You behavior very shady, amateurish.

edit: got reply:
Quote
Ok,ok you use infected wallet and other 250+ people use clean wallet??
and that's it?

,

       ███████████████▄▄
    ██████████████████████▄
  ██████████████████████████▄
 ███████   ▀████████▀   ████▄
██████████    █▀  ▀    ██████▄
███████████▄▄▀  ██  ▀▄▄████████
███████████          █████████
███████████▀▀▄  ██  ▄▀▀████████
██████████▀   ▀▄  ▄▀   ▀██████▀
 ███████  ▄██▄████▄█▄  █████▀
  ██████████████████████████▀
    ██████████████████████▀
       ███████████████▀▀
.
.Duelbits.
.
..THE MOST REWARDING CASINO......
   ▄▄▄▄████▀███▄▄▄▄▄
▄███▄▀▄██▄   ▄██▄▀▄███▄
████▄█▄███▄█▄███▄█▄████
███████████████████████   ▄██▄
██     ██     ██     ██   ▀██▀
██ ▀▀█ ██ ▀▀█ ██ ▀▀█ ██    ██
██  █  ██  █  ██  █  ██
█▌  ██
██     ██     ██     ████  ██
█████████████████████████  ██
████████████████████████████▀
█████████████████████████
█████████████████████████
████████████████████████▌
       +4,000      
PROVABLY FAIR
GAMES
   $500,000  
MONTHLY
PRIZE POOL
      $10,000     
BLACKJACK
GIVEAWAY
1714179266
Hero Member
*
Offline Offline

Posts: 1714179266

View Profile Personal Message (Offline)

Ignore
1714179266
Reply with quote  #2

1714179266
Report to moderator
Whoever mines the block which ends up containing your transaction will get its fee.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714179266
Hero Member
*
Offline Offline

Posts: 1714179266

View Profile Personal Message (Offline)

Ignore
1714179266
Reply with quote  #2

1714179266
Report to moderator
1714179266
Hero Member
*
Offline Offline

Posts: 1714179266

View Profile Personal Message (Offline)

Ignore
1714179266
Reply with quote  #2

1714179266
Report to moderator
1714179266
Hero Member
*
Offline Offline

Posts: 1714179266

View Profile Personal Message (Offline)

Ignore
1714179266
Reply with quote  #2

1714179266
Report to moderator
mexxer-2
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1003


4 Mana 7/7


View Profile
December 20, 2015, 10:31:18 AM
 #2

Please show a virustotal link along with the file link,preferably mediafire,and the link from which you downloaded the file to prove your claims
InvoKing
Legendary
*
Offline Offline

Activity: 2142
Merit: 1065


✋(▀Ĺ̯ ▀-͠ )


View Profile WWW
December 20, 2015, 10:39:44 AM
 #3

Hey zarzarb, which anti-virus do you use? The candlecoin admin posted a virus total link to his ''Candle-qt.exe'' here https://www.virustotal.com/en/file/543e3874be615567bb08b509685b4d527175de09501c6d6de329b34e9c4daeb4/analysis/1448484116/
Can you re-analyse the file with virustotal as mexxer said? If the results isn't the same then...

PSPD:law and order enforcement!
Press Section Police Department!
zazarb (OP)
Legendary
*
Offline Offline

Activity: 3360
Merit: 1548


Get loan in just five minutes goo.gl/8WMW6n


View Profile WWW
December 20, 2015, 10:58:14 AM
 #4

I do not seek something slander, I have plan to participate in candlecoin avatar campaign, so to get CD address downloaded wallet from link in OP, I did not think that possible found other place to download this wallet.

https://www.virustotal.com/en/file/8a257675c9b7584bd14cc5680ffbbb654938ad7ae554ccbb7e80b16417c66f91/analysis/1450608977/

       ███████████████▄▄
    ██████████████████████▄
  ██████████████████████████▄
 ███████   ▀████████▀   ████▄
██████████    █▀  ▀    ██████▄
███████████▄▄▀  ██  ▀▄▄████████
███████████          █████████
███████████▀▀▄  ██  ▄▀▀████████
██████████▀   ▀▄  ▄▀   ▀██████▀
 ███████  ▄██▄████▄█▄  █████▀
  ██████████████████████████▀
    ██████████████████████▀
       ███████████████▀▀
.
.Duelbits.
.
..THE MOST REWARDING CASINO......
   ▄▄▄▄████▀███▄▄▄▄▄
▄███▄▀▄██▄   ▄██▄▀▄███▄
████▄█▄███▄█▄███▄█▄████
███████████████████████   ▄██▄
██     ██     ██     ██   ▀██▀
██ ▀▀█ ██ ▀▀█ ██ ▀▀█ ██    ██
██  █  ██  █  ██  █  ██
█▌  ██
██     ██     ██     ████  ██
█████████████████████████  ██
████████████████████████████▀
█████████████████████████
█████████████████████████
████████████████████████▌
       +4,000      
PROVABLY FAIR
GAMES
   $500,000  
MONTHLY
PRIZE POOL
      $10,000     
BLACKJACK
GIVEAWAY
mexxer-2
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1003


4 Mana 7/7


View Profile
December 20, 2015, 01:54:11 PM
 #5

-snip-

Sorry if I caused any confusion due to my laziness for using a list . Now could you point to the file source you downloaded it from? And do you have any proof that it was indeed in the OP(of the ANN thread), archive link or something similar?
zazarb (OP)
Legendary
*
Offline Offline

Activity: 3360
Merit: 1548


Get loan in just five minutes goo.gl/8WMW6n


View Profile WWW
December 22, 2015, 01:52:10 PM
 #6

-snip-

Sorry if I caused any confusion due to my laziness for using a list . Now could you point to the file source you downloaded it from? And do you have any proof that it was indeed in the OP(of the ANN thread), archive link or something similar?
I not have proof, so this my submission at no in scam section. I don know how track, from where came files.

       ███████████████▄▄
    ██████████████████████▄
  ██████████████████████████▄
 ███████   ▀████████▀   ████▄
██████████    █▀  ▀    ██████▄
███████████▄▄▀  ██  ▀▄▄████████
███████████          █████████
███████████▀▀▄  ██  ▄▀▀████████
██████████▀   ▀▄  ▄▀   ▀██████▀
 ███████  ▄██▄████▄█▄  █████▀
  ██████████████████████████▀
    ██████████████████████▀
       ███████████████▀▀
.
.Duelbits.
.
..THE MOST REWARDING CASINO......
   ▄▄▄▄████▀███▄▄▄▄▄
▄███▄▀▄██▄   ▄██▄▀▄███▄
████▄█▄███▄█▄███▄█▄████
███████████████████████   ▄██▄
██     ██     ██     ██   ▀██▀
██ ▀▀█ ██ ▀▀█ ██ ▀▀█ ██    ██
██  █  ██  █  ██  █  ██
█▌  ██
██     ██     ██     ████  ██
█████████████████████████  ██
████████████████████████████▀
█████████████████████████
█████████████████████████
████████████████████████▌
       +4,000      
PROVABLY FAIR
GAMES
   $500,000  
MONTHLY
PRIZE POOL
      $10,000     
BLACKJACK
GIVEAWAY
MissCrypto
Hero Member
*****
Offline Offline

Activity: 945
Merit: 1000



View Profile
December 22, 2015, 04:11:58 PM
 #7

Many users reported the same in the thread and the posts got deleted.

The download link may have been switched from clean wallet to infected one and back.

Here is something https://bitcointalk.org/index.php?topic=1257893.0

|̲̲̲͡͡͡ ̲▫̲͡ ̲̲̲͡͡π̲̲͡͡ ̲̲͡▫̲̲͡͡ ̲|̡̡̡ ̡ ̴̡ı̴̡̡ ̡͌l̡ ̴̡ı̴̴̡ ̡l̡*̡̡ ̴̡ı̴̴̡ ̡̡͡|̲̲̲͡͡͡ ̲▫̲͡ ̲̲̲͡͡π̲̲͡͡ ̲̲͡▫̲̲͡͡ |
zazarb (OP)
Legendary
*
Offline Offline

Activity: 3360
Merit: 1548


Get loan in just five minutes goo.gl/8WMW6n


View Profile WWW
January 13, 2016, 03:58:07 PM
 #8

hm...nevertheless I was right Sad
https://bitcointalk.org/index.php?topic=1325261.0

       ███████████████▄▄
    ██████████████████████▄
  ██████████████████████████▄
 ███████   ▀████████▀   ████▄
██████████    █▀  ▀    ██████▄
███████████▄▄▀  ██  ▀▄▄████████
███████████          █████████
███████████▀▀▄  ██  ▄▀▀████████
██████████▀   ▀▄  ▄▀   ▀██████▀
 ███████  ▄██▄████▄█▄  █████▀
  ██████████████████████████▀
    ██████████████████████▀
       ███████████████▀▀
.
.Duelbits.
.
..THE MOST REWARDING CASINO......
   ▄▄▄▄████▀███▄▄▄▄▄
▄███▄▀▄██▄   ▄██▄▀▄███▄
████▄█▄███▄█▄███▄█▄████
███████████████████████   ▄██▄
██     ██     ██     ██   ▀██▀
██ ▀▀█ ██ ▀▀█ ██ ▀▀█ ██    ██
██  █  ██  █  ██  █  ██
█▌  ██
██     ██     ██     ████  ██
█████████████████████████  ██
████████████████████████████▀
█████████████████████████
█████████████████████████
████████████████████████▌
       +4,000      
PROVABLY FAIR
GAMES
   $500,000  
MONTHLY
PRIZE POOL
      $10,000     
BLACKJACK
GIVEAWAY
arbitrage
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500



View Profile
January 28, 2016, 03:20:34 PM
 #9

And what will happen to lucky user who accidentally install this wallet?
And what they must do in that situation? Wiping HD?
Any help of antivirus? Undecided
teddy5145
Hero Member
*****
Offline Offline

Activity: 714
Merit: 528


View Profile
January 29, 2016, 08:39:41 PM
 #10

And what will happen to lucky user who accidentally install this wallet?
And what they must do in that situation? Wiping HD?
Any help of antivirus? Undecided
Antivirus should detect this virus and remove it
Considering that you have an updated antivirus and turned on the shield Wink
Are you asking this question because you downloaded the infected wallet ?
You should scan your PC if you do so Sad
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!