Bitcoin Forum
May 07, 2024, 08:42:40 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: BITCON MINER VIRUS  (Read 9025 times)
ajax3592 (OP)
Full Member
***
Offline Offline

Activity: 210
Merit: 100

Crypto News & Tutorials - Coinramble.com


View Profile
November 12, 2013, 05:08:32 PM
Last edit: November 12, 2013, 06:43:19 PM by ajax3592
 #1

I just ran a full system scan using Malwarebytes Antimalware and two sneaky "Bitcoin Mining" viruses showed up in temp directory  Shocked
Lol, Einsteins of today's world.
Have you guys hear about this virus ?

Crypto news/tutorials >>CoinRamble<<                            >>Netcodepool<<                >>My graphics<<
The Bitcoin network protocol was designed to be extremely flexible. It can be used to create timed transactions, escrow transactions, multi-signature transactions, etc. The current features of the client only hint at what will be possible in the future.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
sushi
Full Member
***
Offline Offline

Activity: 238
Merit: 100

ASIC Myth Buster


View Profile
November 12, 2013, 11:29:31 PM
 #2

No....

What's the description?  What is it going to do if you get infected?

Keylog?  steal your private keys?  or scam off portion of your mining powers?

>>> PM me for New ASIC Miner's Info.  We will go check it out <<<
FEEL GENEROUS TODAY?  ==> 1AHNusc3BQA2QJCokySAQ1Qtymr1ZyAG6P
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
November 13, 2013, 12:02:44 AM
 #3

What the?
Please copy the log here.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
Sythyn
Hero Member
*****
Offline Offline

Activity: 1082
Merit: 505


A Digital Universe with Endless Possibilities.


View Profile WWW
November 13, 2013, 01:29:12 AM
 #4

I found minerd.exe in my office computer and my CPU usage were 100%. Installed free AVG to get ride of it Smiley
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
November 13, 2013, 05:01:33 AM
 #5

I found minerd.exe in my office computer and my CPU usage were 100%. Installed free AVG to get ride of it Smiley
Can you provide the log?

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
sushi
Full Member
***
Offline Offline

Activity: 238
Merit: 100

ASIC Myth Buster


View Profile
November 13, 2013, 06:15:00 AM
 #6

Someone was making side money at your office  Angry

You should have looked into the process and the memory and see who the miner user ID at the pool was

>>> PM me for New ASIC Miner's Info.  We will go check it out <<<
FEEL GENEROUS TODAY?  ==> 1AHNusc3BQA2QJCokySAQ1Qtymr1ZyAG6P
FarSky7
Member
**
Offline Offline

Activity: 100
Merit: 10



View Profile
November 13, 2013, 08:05:05 AM
 #7

Could be that trojan mining bot. Huh http://forum.avast.com/index.php?topic=129680.0
JessicaSe
Legendary
*
Offline Offline

Activity: 840
Merit: 1000



View Profile
November 13, 2013, 08:09:39 AM
 #8

I am mining in my office please don't tell anyone Tongue But my boss know it and she is ok Smiley
AuroraHF
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500


View Profile
November 13, 2013, 08:14:07 AM
 #9

I am mining in my office please don't tell anyone Tongue But my boss know it and she is ok Smiley

We don't know who to tell considering we don't know where you work.

These are silent miners used by hackers. You were infected.

lmao
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
November 13, 2013, 02:46:58 PM
 #10

Could be that trojan mining bot. Huh http://forum.avast.com/index.php?topic=129680.0
So we have that too now. Damn.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
AuroraHF
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500


View Profile
November 13, 2013, 02:53:42 PM
 #11


This form of malware has been here since the start of Bitcoins. It used to just drop CGMiner without the GUI.

lmao
wpgdeez
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500


View Profile
November 13, 2013, 06:04:48 PM
 #12

Zero Access rootkit had some Mining code in it but they removed it since cpu mining is now useless.
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
November 13, 2013, 07:29:18 PM
 #13

Zero Access rootkit had some Mining code in it but they removed it since cpu mining is now useless.
Could still be used for CPU coins.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
wpgdeez
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500


View Profile
November 13, 2013, 08:00:01 PM
 #14

Sure but the profit isnt there for the blackhats. They make more money off of click fraud than mining without drwaing unwanted attention to themselves.
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
November 13, 2013, 08:06:25 PM
 #15

Sure but the profit isnt there for the blackhats. They make more money off of click fraud than mining without drwaing unwanted attention to themselves.
Wrong. Buy cheap botnet -> mine CPU coin -> dump all.
Profit.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
ajax3592 (OP)
Full Member
***
Offline Offline

Activity: 210
Merit: 100

Crypto News & Tutorials - Coinramble.com


View Profile
November 13, 2013, 08:18:44 PM
Last edit: November 13, 2013, 10:08:24 PM by ajax3592
 #16

What the?
Please copy the log here.

Here you go guys, check this out:

Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.08.16.07
06-11-2013 14:11:06
mbam-log-2013-11-06 (14-11-06).txt

Scan type: Full scan (C:\|E:\|F:\|G:\|H:\|I:\|K:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 146706
Time elapsed: 30 minute(s), 11 second(s) [aborted]

Memory Processes Detected: 1
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> 7280 -> Delete on reboot.

Files Detected: 7
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\coinutil.dll (PUP.BitcoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\miner.dll (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\service.exe (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\usft_ext.dll (PUP.BitCoinMiner) -> No action taken.
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.
C:\Users\***\AppData\Roaming\XHvQH\taskengine.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.

(end)

Crypto news/tutorials >>CoinRamble<<                            >>Netcodepool<<                >>My graphics<<
rampalija
Full Member
***
Offline Offline

Activity: 154
Merit: 100



View Profile
November 13, 2013, 10:19:22 PM
 #17

What the?
Please copy the log here.

Here you go guys, check this out:

Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.08.16.07
06-11-2013 14:11:06
mbam-log-2013-11-06 (14-11-06).txt

Scan type: Full scan (C:\|E:\|F:\|G:\|H:\|I:\|K:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 146706
Time elapsed: 30 minute(s), 11 second(s) [aborted]

Memory Processes Detected: 1
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> 7280 -> Delete on reboot.

Files Detected: 7
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\coinutil.dll (PUP.BitcoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\miner.dll (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\service.exe (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\usft_ext.dll (PUP.BitCoinMiner) -> No action taken.
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.
C:\Users\***\AppData\Roaming\XHvQH\taskengine.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.

(end)



I think it is only fake detection

AuroraHF
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500


View Profile
November 14, 2013, 05:10:51 AM
 #18

"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy

lmao
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
November 14, 2013, 05:12:13 AM
 #19

"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
Generate bitcoins for free and get rich.  Cheesy

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
rampalija
Full Member
***
Offline Offline

Activity: 154
Merit: 100



View Profile
November 14, 2013, 06:47:59 AM
 #20

"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
Generate bitcoins for free and get rich.  Cheesy

and i assume it steals everythig what u have?!?! am I right?

Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!