Bitcoin Forum
November 06, 2024, 08:25:29 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: [ NEW VIRUS ] THIS ADDY GETS PASTED : 19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u  (Read 5989 times)
txbtc (OP)
Hero Member
*****
Offline Offline

Activity: 499
Merit: 500



View Profile
January 17, 2016, 12:20:55 PM
 #1

I am really horrified now!

when I withdrew money from somewhere i see i copied and pasted addy ,but when i not got for a long time i searched whats the issue and i see funds sent to : 19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u

and now I see this is a virus address , its a virus where u copy anything but this : 19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u will be pasted, no matter , what !

I have searched internet more and saw someone else had same issue

please help me !
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
January 17, 2016, 12:24:01 PM
 #2

Backup wallet.dat and the blockchain (depending on what wallet you are using) and reinstall OS.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
lite
Legendary
*
Offline Offline

Activity: 1400
Merit: 1009


View Profile
January 17, 2016, 12:43:18 PM
 #3

Run a live linux OS from a usb drive and recover your wallet.dat/ withdraw your money then reinstall your OS. (i prefer using a linux OS instead of windows)
digit
Legendary
*
Offline Offline

Activity: 1672
Merit: 1014



View Profile WWW
January 17, 2016, 12:46:33 PM
 #4

I am really horrified now!

when I withdrew money from somewhere i see i copied and pasted addy ,but when i not got for a long time i searched whats the issue and i see funds sent to : 19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u

and now I see this is a virus address , its a virus where u copy anything but this : 19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u will be pasted, no matter , what !

I have searched internet more and saw someone else had same issue

please help me !

what extensions you installed in browser? there have some nasty ones in the past that would change the btc address.  eg one originally started as an innocent price ticker, then gets updated with malicious code a few months later when adoption has increased  Sad


try running a clean profile or a different browser and see if it happens again to isolate the cause

Stay Safe and use NO KYC exchanges ■ Craig Wright is NOT Satoshi  ■
BTC:1DigitwteXwFcRAaWpVDRp6eKqzC6y9tgm ■ ŁTC:LKMcEHoFWHAUoRscqW1cwjhLgFrk7MgCWU ■ Coinkit:digit ■ §digit
darkstarzz69
Member
**
Offline Offline

Activity: 112
Merit: 10

★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
January 17, 2016, 02:21:04 PM
 #5

Disconnect from the internet and run an antivirus off a linux live os. That's the first time I heard of such a virus. Do be careful.

██████████    YoBit.net - Cryptocurrency Exchange - Over 350 coins
█████████    <<  ● $$$ - $$$ - $$$ - $$$ - $$$ - $$$ - $$$   >>
██████████    <<  ● Play DICE! Win 1-5 btc just for 5 mins!  >>
DaMut
Sr. Member
****
Offline Offline

Activity: 1274
Merit: 263


View Profile
January 17, 2016, 02:56:12 PM
 #6

I am really horrified now!

when I withdrew money from somewhere i see i copied and pasted addy ,but when i not got for a long time i searched whats the issue and i see funds sent to : 19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u

and now I see this is a virus address , its a virus where u copy anything but this : 19ZM2pjq6U4jVb283GZkCPNukjeyb2YZ2u will be pasted, no matter , what !

I have searched internet more and saw someone else had same issue

please help me !

everything you need is sent ALL OF YOUR COIN TO ANOTHER using DRAG(click on your address and press it to another web wallet) then REINSTALL YOUR OS .

because i ever experience that
franky1
Legendary
*
Offline Offline

Activity: 4396
Merit: 4760



View Profile
January 17, 2016, 02:58:46 PM
 #7

OP name the browser extension..

that way people know what to stay away from

im guessing if its not abrowser extension that 'suppose to' aid copying addresses instead of manually writing them..
then the other option is probably the OP downloaded one of them crappy "bitcoin generator" programs(no positive function and just a trojan) after watching a get rich with bitcoin hacks video.. as that is another big scam that people have been crying about

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
Amph
Legendary
*
Offline Offline

Activity: 3248
Merit: 1070



View Profile
January 17, 2016, 03:29:27 PM
 #8

virus does not enter into your computer of its own will, so you must have installed somethign suspicious and forget about it

try to run malwarebyte + hitmanpro, then you have combofix, or a secure erase if nathing will solve it
mtnsaa
Legendary
*
Offline Offline

Activity: 1568
Merit: 1000


View Profile
January 17, 2016, 03:36:48 PM
 #9

So nobody asks about his technical specs? I'm no IT support but that's the first thing we should be doing I think. It's most likely like others have said that you've installed spyware/malware. This is usually downloaded from pirate download sites, porn sites, etc. Please keep us posted.
elyas772
Hero Member
*****
Offline Offline

Activity: 756
Merit: 502



View Profile
January 17, 2016, 03:43:53 PM
 #10

look at this post
https://bitcointalk.org/index.php?topic=1317718.msg13575511#msg13575511

someone use that address

▄▄▄██████▄▄▄
▄███▀▀▀▀▀████▄▄ █▄▄
▄▄          ▀▀████▄  ██▄
█████▄            ▀█████  ██▄
▄█████████           ▀█████ ███▄
▄█████████▀▀           ▀█████ ███▄
▄███  █████             ▀█████ ████
███  █████                █████ ████
███ █████                  ████  ████
███ █████                ▄████  ████
███ █████                ███████████
▀██ █████▄                █████████
▀██ ██████▄                ▀█████
▀██ ███████                  ▀▀▀
▀██ ██████▄▄                 
▀██ ██████▄▄▄▄▄▄▄▄▄▄▄▄███▀
▀▀ █████████████████▀
▀▀▀██████▀▀▀▀

Fast, Secure, and Fully

DecentralizeTrading
BACKED BY:
─────────────────────────
BINANCE
─────── LAB
&█████████████████████████████████ █  ███
█▀    ▀█  ███▀▀▀▀▀████████  ████▀▀███▀ █
█  █████    ▄▄▄▄▄  █  ▀  █    ███  █  ██
█▄    ▀█  ██       █  ▄███  ██████   ███
█████  █  ██  ███  █  ████  ████  ▄  ███
█▄    ▄█▄  ▄█▄     ▀  ████▄  ▄█   ██  ██
████████████████████████████████████████


  Whitepaper
 Medium
Reddit
ShrykeZ
Hero Member
*****
Offline Offline

Activity: 630
Merit: 500


View Profile
January 17, 2016, 03:46:01 PM
 #11

So is this replacing your pasted data, aka if you were to actually recheck the address after pasting would it be the incorrect address?
pjsonowal
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250



View Profile
January 17, 2016, 03:48:57 PM
 #12

This is because of some file or a script that work in background .It must have come with something . I think it is with some software . I think you have installed a new software which runs the command in cmd to do it.

Can you please give me a view of a task manager- process section & startup section , i think i can crack which file it is working in background. If you want to keep up the softwares and files and dont lose them up . You have to end that process which is working in background everytime you run up your PC or you can remove that up from program startup like this:-


1)Press Win-r . In the "Open:" field, type msconfig and press Enter .
2)Click the Startup tab.
3)Uncheck the items you do not want to launch on startup. Note: ...
4)When you have finished making your selections, click OK.
5)n the box that appears, click Restart to restart your computer.

There is a solution : Reset your PC

Reset is an option which allows you to reinstall OS with the option to KEEP THE FILES OR NOT.

What things affects:-

a) all the software you had installed are gone,but you can keep up with the files.




So does that mean bx2.club behind it ? Huh

Blawpaw
Legendary
*
Offline Offline

Activity: 1596
Merit: 1027



View Profile
January 17, 2016, 03:51:37 PM
 #13

This is very worrying. Do you know where did you could have gotten that virus? It would be great to know where is this menace coming from.
ShrykeZ
Hero Member
*****
Offline Offline

Activity: 630
Merit: 500


View Profile
January 17, 2016, 03:52:11 PM
 #14


Nice find, also further research led me to find someone who uses Bitcoin on facebook who has the name of that user account that may own that address, not sure if there's a naming and shaming policy at all here so will refrain from posting it although it's an easy find.
redsn0w
Legendary
*
Offline Offline

Activity: 1778
Merit: 1043


#Free market


View Profile
January 17, 2016, 04:01:22 PM
 #15

Backup wallet.dat and the blockchain (depending on what wallet you are using) and reinstall OS.

@txbtc, this is the best option that you can do... Next step, improve your security and change your habits.
franky1
Legendary
*
Offline Offline

Activity: 4396
Merit: 4760



View Profile
January 17, 2016, 04:11:34 PM
 #16

seems like its not a virus..
but people naively using blockchain.info to view transactions after its sent..

seems there is a bug on blockchain.info involving how they display transactions on the website

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
calkob
Hero Member
*****
Offline Offline

Activity: 1106
Merit: 521


View Profile
January 17, 2016, 04:27:30 PM
 #17

seems like its not a virus..
but people naively using blockchain.info to view transactions after its sent..

seems there is a bug on blockchain.info involving how they display transactions on the website

Could you explain abit more about this franky, i use blockchain.info all the time  Shocked

although most of my wallets are watch only.
franky1
Legendary
*
Offline Offline

Activity: 4396
Merit: 4760



View Profile
January 17, 2016, 04:52:54 PM
 #18

seems like its not a virus..
but people naively using blockchain.info to view transactions after its sent..

seems there is a bug on blockchain.info involving how they display transactions on the website

Could you explain abit more about this franky, i use blockchain.info all the time  Shocked

although most of my wallets are watch only.

someone else in this thread posted
https://bitcointalk.org/index.php?topic=1317718.msg13575511#msg13575511

it showed people complaining that when they looked at blockchain.info they seen tx's going to that magical address..

later posts mentioned that the transactions appeared where they should have gone and that it was a bug in the blockchain.info service displaying wrong details..

i advise you to not rely on just blockchain.info..

instead use the API of atleast 3 different explorers and a couple lines of code to compare the results from the 3 explorers.. and if one is wrong, ignore it. that way you have more chance of relying on data spoonfed to you if it comes from different sources and compared against each other

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
txbtc (OP)
Hero Member
*****
Offline Offline

Activity: 499
Merit: 500



View Profile
January 17, 2016, 05:55:01 PM
 #19

This is because of some file or a script that work in background .It must have come with something . I think it is with some software . I think you have installed a new software which runs the command in cmd to do it.

Can you please give me a view of a task manager- process section & startup section , i think i can crack which file it is working in background. If you want to keep up the softwares and files and dont lose them up . You have to end that process which is working in background everytime you run up your PC or you can remove that up from program startup like this:-


1)Press Win-r . In the "Open:" field, type msconfig and press Enter .
2)Click the Startup tab.
3)Uncheck the items you do not want to launch on startup. Note: ...
4)When you have finished making your selections, click OK.
5)n the box that appears, click Restart to restart your computer.

There is a solution : Reset your PC

Reset is an option which allows you to reinstall OS with the option to KEEP THE FILES OR NOT.

What things affects:-

a) all the software you had installed are gone,but you can keep up with the files.




So does that mean bx2.club behind it ? Huh


Hey, thanks really you seem to help me.

Please can u help me, give me ur skype i will tell u all process running on my pc
Hugroll
Hero Member
*****
Offline Offline

Activity: 756
Merit: 500


View Profile
January 17, 2016, 05:56:41 PM
 #20

I am really horrified now!
I have searched internet more and saw someone else had same issue

please help me !
ive heard about it before, but im not really sure what kind of malware this is. i suggest you download malwarebytes to scan your computer. its free and its pretty good imo.
Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!