Bitcoin Forum
November 15, 2024, 05:01:41 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [HELP!] What should I do after being phished?  (Read 3425 times)
kira4light (OP)
Newbie
*
Offline Offline

Activity: 37
Merit: 0


View Profile
July 04, 2013, 07:30:46 PM
Last edit: July 04, 2013, 11:25:38 PM by kira4light
 #1

Follow up on the "5 coins Raffle scam".

I actually clicked on this link:

[Be cautious! This link is dangerous! Unless you are absolutely sure what you are doing please do NOT click on it]
http://rghost.net/47200539?r=1096  


and clicked the Trojan script.....

Now I'm thinking about re-install my whole operational system and change every single password I have...

Could anybody look into the script and see what it does? Or any general suggestions or help would be appreciated!!!

Big lesson from this  Angry
threeip
Full Member
***
Offline Offline

Activity: 154
Merit: 100



View Profile WWW
July 04, 2013, 08:00:12 PM
 #2

The first thing you should do is remove the link to the phishing page?

ส็็็็็็็็็็็็็็็็็็็็็็็็็ GPG:2AFD99BB ಠ_ಠ mon
kira4light (OP)
Newbie
*
Offline Offline

Activity: 37
Merit: 0


View Profile
July 04, 2013, 08:12:10 PM
 #3

The first thing you should do is remove the link to the phishing page?

I think the link is ok as long as you don't download the actual script... Or I may be wrong...
chadtn
Sr. Member
****
Offline Offline

Activity: 672
Merit: 250



View Profile
July 04, 2013, 08:22:27 PM
 #4

I'm ashamed to say I fell for it.  I thought it was a wallet file and accidentally clicked on it while I was trying to import the keys.  I deleted the file and scanned my computer for problems.  I thought I removed the problem and went to bed.  I woke up about twenty minutes ago and saw my mouse moving by itself.  Someone had messed with my firewall settings, opened up bitcoin-qt, and had just downloaded a file called _DVSoy.exe from plasmon.ghost.ru.

Chad



     ▄██    ▐███████▄▄▄       ▄▄█████▄▄      ▄██▄      ▐██▄    ▒▓▓▄      ▄▓▓▒
     ███    ▐██▌▀▀▀▀▀███▄    ███▀▀▀▀▀███▄    ████▄     ▐██▌  ▐▓▄ ▀▓▓▄  ▄▓▓▀ ▄▓▌
     ███    ▐██▌      ███   ███▌      ███▌   ██████    ▐██▌   ▀▓▓▄ ▀▓▓▓▓▀ ▄▓▓▀
     ███    ▐██▌    ▄████  ▐███▌      ▐██▌   ███ ███▄  ▐██▌     ▀▓▓▄ ▀▀ ▄▓▓▀
     ███    ▐█████████▀▀   ▐███▌      ▐██▌   ███  ▀███ ▐██▌      ▓▓▓    ▓▓▓
     ███    ▐██▌   ▀███     ███▌      ███▌   ███    ██████▌   ▄▓▓▀ ▄▓▓▓▓▄ ▓▓▓▄
     ███    ▐██▌     ███    ▀███▄▄▄▄▄████    ███     ▀████▌  ▐▓▀ ▄▓▓▀  ▀▓▓▄ ▀▓▌
     ███    ▐██▌      ███     ▀▀██████▀▀     ███       ███▌    ▄▓▓▀      ▀▓▓▄
                  ▄▄▄█████▄▄▄▄
             ▄▄█▓▓▓▓▓█▀▀▀▀█▓▓▓▓▓█▄
           ▄▓▓▓█▀▀            ▀▀█▓▓█▄
         ▓▓▓█▀                    ▀▓▓█▄
       ▄▓▓▓▀                        ▀▓▓█
      ▄▓▓█                            █▓▓
      ▓▓▓                    ▄██▄     ▐▓▓█
     ▓▓▓                   ▄█▓▓▀       ▐▓▓▌
     ▓▓▓                 ▄█▓▓▀          ▓▓▓
     ▓▓▓       ▓▓▓▄    ▓▓▓▓▀            ▓▓▓
     ▓▓▓        ▀▓▓▓▄█▓▓▓▀             ▐▓▓▌
     ▀▓▓▓         ▀█▓▓█▀               █▓▓
      ▓▓▓▄                            ▓▓▓▌
       ▓▓▓█                         ▄█▓▓▀
        ▀▓▓█▄                     ▄▓▓▓█▀
          ▀▓▓▓█▄               ▄▄█▓▓█▀
            ▀▀█▓▓▓█▄▄▄▄▄▄▄▄▄▄█▓▓▓█▀
                ▀▀██▓▓▓▓▓▓▓███▀▀
CurbsideProphet
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500


View Profile
July 04, 2013, 09:06:53 PM
 #5

The first thing you should do is remove the link to the phishing page?

I think the link is ok as long as you don't download the actual script... Or I may be wrong...

To be safe, I would just remove it so others don't run the script on accident.

1ProphetnvP8ju2SxxRvVvyzCtTXDgLPJV
cp1
Hero Member
*****
Offline Offline

Activity: 616
Merit: 500


Stop using branwallets


View Profile
July 04, 2013, 09:17:16 PM
 #6

You could go through a long process and remove it or just format, which is what I'd do.

Guide to armory offline install on USB key:  https://bitcointalk.org/index.php?topic=241730.0
Mylon
Full Member
***
Offline Offline

Activity: 140
Merit: 100

Mining FTW


View Profile
July 04, 2013, 10:42:04 PM
 #7

The first thing you should do is remove the link to the phishing page?

I think the link is ok as long as you don't download the actual script... Or I may be wrong...

To be safe, I would just remove it so others don't run the script on accident.
Put it between spoiler tags, and put alerts notifications around it, people wanting to help still like the link Smiley

You could go through a long process and remove it or just format, which is what I'd do.
the long process... is so long that I could spend months on it... and still see the mouse move on its own after I hook it back up to the internet... reinstalling is the only safe option...

"All Your Base Are Belong To Us" by CATS
nottm28
Hero Member
*****
Offline Offline

Activity: 574
Merit: 500



View Profile
July 04, 2013, 10:44:32 PM
 #8

MOD's- can someone please remove the link from the OP's post - he seems incapable of editing his own post

[EDIT] wouldn't be surprised if this is a sock puppet post

[EDIT2] reported to moderator

donations not accepted
chadtn
Sr. Member
****
Offline Offline

Activity: 672
Merit: 250



View Profile
July 04, 2013, 11:00:35 PM
 #9

On my system the downloaded file opened up access to DarkComet RAT.  They used that to remote onto my system to try installing other software.  In the details of the file it downloaded Dell Datasafe was mentioned.  It looks like a service similar to Dropbox.

Chad



     ▄██    ▐███████▄▄▄       ▄▄█████▄▄      ▄██▄      ▐██▄    ▒▓▓▄      ▄▓▓▒
     ███    ▐██▌▀▀▀▀▀███▄    ███▀▀▀▀▀███▄    ████▄     ▐██▌  ▐▓▄ ▀▓▓▄  ▄▓▓▀ ▄▓▌
     ███    ▐██▌      ███   ███▌      ███▌   ██████    ▐██▌   ▀▓▓▄ ▀▓▓▓▓▀ ▄▓▓▀
     ███    ▐██▌    ▄████  ▐███▌      ▐██▌   ███ ███▄  ▐██▌     ▀▓▓▄ ▀▀ ▄▓▓▀
     ███    ▐█████████▀▀   ▐███▌      ▐██▌   ███  ▀███ ▐██▌      ▓▓▓    ▓▓▓
     ███    ▐██▌   ▀███     ███▌      ███▌   ███    ██████▌   ▄▓▓▀ ▄▓▓▓▓▄ ▓▓▓▄
     ███    ▐██▌     ███    ▀███▄▄▄▄▄████    ███     ▀████▌  ▐▓▀ ▄▓▓▀  ▀▓▓▄ ▀▓▌
     ███    ▐██▌      ███     ▀▀██████▀▀     ███       ███▌    ▄▓▓▀      ▀▓▓▄
                  ▄▄▄█████▄▄▄▄
             ▄▄█▓▓▓▓▓█▀▀▀▀█▓▓▓▓▓█▄
           ▄▓▓▓█▀▀            ▀▀█▓▓█▄
         ▓▓▓█▀                    ▀▓▓█▄
       ▄▓▓▓▀                        ▀▓▓█
      ▄▓▓█                            █▓▓
      ▓▓▓                    ▄██▄     ▐▓▓█
     ▓▓▓                   ▄█▓▓▀       ▐▓▓▌
     ▓▓▓                 ▄█▓▓▀          ▓▓▓
     ▓▓▓       ▓▓▓▄    ▓▓▓▓▀            ▓▓▓
     ▓▓▓        ▀▓▓▓▄█▓▓▓▀             ▐▓▓▌
     ▀▓▓▓         ▀█▓▓█▀               █▓▓
      ▓▓▓▄                            ▓▓▓▌
       ▓▓▓█                         ▄█▓▓▀
        ▀▓▓█▄                     ▄▓▓▓█▀
          ▀▓▓▓█▄               ▄▄█▓▓█▀
            ▀▀█▓▓▓█▄▄▄▄▄▄▄▄▄▄█▓▓▓█▀
                ▀▀██▓▓▓▓▓▓▓███▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!