Bitcoin Forum
May 13, 2024, 09:38:28 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: YACoin - Bitcoin Stealing Claim List (Facts only)  (Read 6306 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic.
mr_random (OP)
Legendary
*
Offline Offline

Activity: 1288
Merit: 1001


View Profile
May 11, 2013, 01:57:22 PM
 #21

I am deleting all messages in ALL CAPS bright red font. Nothing personal. Looking at you hdclover.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715636308
Hero Member
*
Offline Offline

Posts: 1715636308

View Profile Personal Message (Offline)

Ignore
1715636308
Reply with quote  #2

1715636308
Report to moderator
1715636308
Hero Member
*
Offline Offline

Posts: 1715636308

View Profile Personal Message (Offline)

Ignore
1715636308
Reply with quote  #2

1715636308
Report to moderator
GröBkAz
Hero Member
*****
Offline Offline

Activity: 854
Merit: 500



View Profile
May 11, 2013, 01:58:52 PM
 #22

Just Jr. Members lost ther BTC and they registed in this Forum just to post, that they lost some BTC. A bad  joke
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
*
Offline Offline

Activity: 1316
Merit: 1043

👻


View Profile
May 11, 2013, 01:59:06 PM
 #23

Looks like there's another report here: https://bitcointalk.org/index.php?topic=202122.msg2110421#msg2110421

I haven't being able to reproduce this (but my wallet is encrypted, hmm)
TheSwede75
Full Member
***
Offline Offline

Activity: 224
Merit: 100



View Profile
May 11, 2013, 02:00:38 PM
 #24

Just Jr. Members lost ther BTC and they registed in this Forum just to post, that they lost some BTC. A bad  joke

Says the JR member? I'm not saying it's true or false, but I will say that its amazing so many people are willing to download a random 'wallet' and run whatever commands some random member tells them to with NO idea what it is they are doing.
Mike Christ
aka snapsunny
Legendary
*
Offline Offline

Activity: 1078
Merit: 1003



View Profile
May 11, 2013, 02:01:44 PM
 #25

Just Jr. Members lost ther BTC and they registed in this Forum just to post, that they lost some BTC. A bad  joke

Says the JR member? I'm not saying it's true or false, but I will say that its amazing so many people are willing to download a random 'wallet' and run whatever commands some random member tells them to with NO idea what it is they are doing.

Ehh, not really amazing.  The herd mentality is really popular nowadays; why think, when you can be led?

fenican
Hero Member
*****
Offline Offline

Activity: 1394
Merit: 505


View Profile
May 11, 2013, 02:02:49 PM
 #26

I think all posts with ALL RED or special fonts are very suspicious and seem to be either FUD or hacked accounts.

Hopefully administrators can clean this up, delete all those posts, suspend any accounts that look hacked, and get any substantive posts into an official thread
rbdrbd
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250



View Profile
May 11, 2013, 02:08:10 PM
 #27

Just Jr. Members lost ther BTC and they registed in this Forum just to post, that they lost some BTC. A bad  joke

Says the JR member? I'm not saying it's true or false, but I will say that its amazing so many people are willing to download a random 'wallet' and run whatever commands some random member tells them to with NO idea what it is they are doing.

Ehh, not really amazing.  The herd mentality is really popular nowadays; why think, when you can be led?

I think it's more the profit motivator at play. Throw in the opportunity to make money, and much reason/caution goes out the window for most folks. It's all about getting there before the other guy. Not saying I don't suffer from this too, but I realize it. Can only mitigate it when you realize it.
Goldmember
Newbie
*
Offline Offline

Activity: 26
Merit: 0



View Profile
May 11, 2013, 02:08:56 PM
 #28

I am deleting all messages in ALL CAPS bright red font. Nothing personal. Looking at you hdclover.
Thank you!

For what it is worth, I had no coins stolen. I used the original executable from the OP announcement, plus compile from source on linux. If (if!) this is true, I suspect it is one of the later binaries that came out.
xibeijan
Legendary
*
Offline Offline

Activity: 1232
Merit: 1001


View Profile
May 11, 2013, 02:12:13 PM
 #29

FACT: YAC fear mongering is a testament to YAC's success.  They want it.

Notable projects 2019: Semux, Dero, Wagerr, BEAM
skull88
Hero Member
*****
Offline Offline

Activity: 683
Merit: 500



View Profile
May 11, 2013, 02:13:15 PM
 #30

I installed the client and miner for YACoin on a windowscomputer to test it yesterday, the computer has several altcoin clients on it, there was still an old bitcoinwallet on that computer (unencrypted!) that had a very small amount of btc's in it. Not really enough to get worried about so I actually didn't bother much and didn't transfer them. Also a wallet with an even smaller amount of Litecoins in it is on that computer (also unencrypted), just checked and everything is still there and no suspicious activity is going on. I downloaded them from the mega link.

BTC: 1MifMqtqqwMMAbb6zr8u6qEzWqq3CQeGUr
LTC: LhvMYEngkKS2B8FAcbnzHb2dvW8n9eHkdp
LOG123
Full Member
***
Offline Offline

Activity: 153
Merit: 100


...


View Profile
May 11, 2013, 02:14:25 PM
 #31

I think all posts with ALL RED or special fonts are very suspicious and seem to be either FUD or hacked accounts.

Hopefully administrators can clean this up, delete all those posts, suspend any accounts that look hacked, and get any substantive posts into an official thread

There's nothing suspicious about this, jeez fenican.
shaal
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
May 11, 2013, 02:17:01 PM
 #32

I know i keep posting this but, can we get ONE screenshot of peoples bitcoin wallet with transactions going out?
Mushoz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


Bitbuy


View Profile WWW
May 11, 2013, 02:17:27 PM
 #33

One of the minerd.exe programs is infected, see here:




That's probably how some people's coin got stolen. This was the minerd.exe that was downloaded from the "virusscanner friendly" Minerd topic.

www.bitbuy.nl - Koop eenvoudig, snel en goedkoop bitcoins bij Bitbuy!
mr_random (OP)
Legendary
*
Offline Offline

Activity: 1288
Merit: 1001


View Profile
May 11, 2013, 02:19:21 PM
 #34

Nice find Mushoz. Updating the OP.
theking
Full Member
***
Offline Offline

Activity: 154
Merit: 100



View Profile
May 11, 2013, 02:20:17 PM
 #35

The only way to find out is to reverse the exe, forget about virus scans etc, these are 100% proof, also the fact that some people claim to be affected is also not much proof, its possible its either made up, or caused by another exe or attack too, plus if its caused by this exe, it may not be attacking everyone for various reasons.
Luckily the exe does not seem to be protected with a strong packer. Running a packet sniffer alone also may not show much. So if anyone has had a look through the source to start off with that can be helpful but we need someone experienced with reversing exes to check em out to be sure.

WIN: WQvqPASu4ffjfupfwkZCX2zECLAedBfSxT /// TheSmurfsCoin. TgKhTqtEe2NRQXKzUNL6TXs9NNSXTvxg26 /// [ANN] PixxCoin | PoS | Wallet with built in Exchange Dice Game And Fa | Free IPO. PLncxuyTOpsdASEAIweeoweKSJASJDNZETR /// CoolCoin - Free+IPO POS. CJG2g8CDkTrj5TMHHzi9ynkAvHamuUiKhC /// Get GiveawayCoin(GC)? (Free 100%NO IPO NO POW,PURE POS. G********* /// Let's flower the moon. Shjtq1XLnjgpbzSK3SvqMhQpK9CeAYLCPZ /// FootballCoin(FBC):FiaYuHEWhoS8v5dPbGLRDh7FBtcDV7TdnA /// Freebiescoin- 100% FREE Distribution FKDJUQ4Ybzdno2hoAP2NuYh1VAaTwMq1y2 /// ShareCoin Free and Fair Distribution. SR8eG4bhC2CzKnN2PfBz7vtj3zrcyXAuWr /// Energycoin - Save Energy, Pure POS (Free IPO). eCvsqEW2oFaSRq4XozfrHP8XuZ9kvrfQ5W /// Tagbond Rewards - My TAG ID is 5834 - Tag someone today with a reward, get your own TAG ID # (www.tagbond.com/5834)
theking
Full Member
***
Offline Offline

Activity: 154
Merit: 100



View Profile
May 11, 2013, 02:21:57 PM
 #36

Yea its seemed suspect to use themida in order to stop the original minerd.exe from showing up in virus scanners as themedia causes even more propblems for virus scanners and can be very hard to reverse too.

WIN: WQvqPASu4ffjfupfwkZCX2zECLAedBfSxT /// TheSmurfsCoin. TgKhTqtEe2NRQXKzUNL6TXs9NNSXTvxg26 /// [ANN] PixxCoin | PoS | Wallet with built in Exchange Dice Game And Fa | Free IPO. PLncxuyTOpsdASEAIweeoweKSJASJDNZETR /// CoolCoin - Free+IPO POS. CJG2g8CDkTrj5TMHHzi9ynkAvHamuUiKhC /// Get GiveawayCoin(GC)? (Free 100%NO IPO NO POW,PURE POS. G********* /// Let's flower the moon. Shjtq1XLnjgpbzSK3SvqMhQpK9CeAYLCPZ /// FootballCoin(FBC):FiaYuHEWhoS8v5dPbGLRDh7FBtcDV7TdnA /// Freebiescoin- 100% FREE Distribution FKDJUQ4Ybzdno2hoAP2NuYh1VAaTwMq1y2 /// ShareCoin Free and Fair Distribution. SR8eG4bhC2CzKnN2PfBz7vtj3zrcyXAuWr /// Energycoin - Save Energy, Pure POS (Free IPO). eCvsqEW2oFaSRq4XozfrHP8XuZ9kvrfQ5W /// Tagbond Rewards - My TAG ID is 5834 - Tag someone today with a reward, get your own TAG ID # (www.tagbond.com/5834)
cheapbit
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
May 11, 2013, 02:22:30 PM
 #37

(the win32 binary downloaded soon after release)

tested under a VM for ~30minutes.
no read operation toward bitcoin wallet yet.
and no dns request to the suffix yet.

although the motivation to release yacoin is still highly suspicious.
eule
Hero Member
*****
Offline Offline

Activity: 756
Merit: 501


View Profile
May 11, 2013, 02:22:56 PM
 #38

Even the normal minerd (for scrypt and sha256) gives an anti virus warning, have to whitelist the dir to start it...
So the windows compiled "new minerd for scrypt-jane" posted later could indeed have a trojan and most wouldn't notice as the program is already known to cause false positives.

Mushoz
Hero Member
*****
Offline Offline

Activity: 686
Merit: 500


Bitbuy


View Profile WWW
May 11, 2013, 02:28:24 PM
 #39

Cannot show the whole list, as it won't fit my screen, but I've checked all entries, and the ONLY wallet.dat Yacoin accesses, is the one it's supposed to access (Yacoin's wallet.dat). I have NOT seen it access Bitcoin's wallet.dat


www.bitbuy.nl - Koop eenvoudig, snel en goedkoop bitcoins bij Bitbuy!
cheapbit
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
May 11, 2013, 02:30:19 PM
 #40

Cannot show the whole list, as it won't fit my screen, but I've checked all entries, and the ONLY wallet.dat Yacoin accesses, is the one it's supposed to access (Yacoin's wallet.dat). I have NOT seen it access Bitcoin's wallet.dat

http://i39.tinypic.com/4j9f7q.png

+1

although so all altcoin clients should first go to a vm
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!