Bitcoin Forum
July 15, 2024, 02:05:58 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Security Issue - BV:Miner-T [Trojan] - coinhive.com  (Read 135 times)
sebastian787 (OP)
Jr. Member
*
Offline Offline

Activity: 182
Merit: 8


View Profile
May 07, 2018, 11:05:52 AM
 #1

Im writing to inform you about the BV:Miner-T trojan.
I searched on the forum but i found nothing about it.
If im writing on the wrong section please move it to the right one.

So, surfing around i received this popup message from my antivirus that the connection on coinhive.com is aborted because it was infected with BV:Miner-T trojan.
I have never visited this site before nor i received this message while visiting the specific site.
Searching about this trojan i found few websites explaining how to remove it but i trust none of them yet so here i am.
So from what i found  this trojan can mess up your computer.

Troubles Made by BV:Miner-T [Trj]
It alters your browser settings and avoids you changing them back
It modifies DNS configuration and blocks you accessing most of legitimate websites
It may communicates with remote server to install more malware in your computer silently
It messes up your Registry and degrades your computer performance strikingly
It installs malicious browser extension to generate annoying pop-ups
It redirects you to other phishing sites which may steal your privacy
It facilitates remote hacker to invade your system without permission

The primary symptoms of BV:Miner-A infections are:

Computer behaving unpredictably
Unexpected operating system error messages
Blue screen errors in Windows
Sluggish computer performance
Programs stop responding and show “Not Responding” error messages
New files getting created at the root-level of a hard drive
Spam messages unknowingly being sent from your email account
Mysterious files and folder deletions

I have already made a scan with an anti-malware or antivirus and found nothing.
Some sites recommend installing some specific anti-malwares to get rid of this trojan but they look somehow shady.
When trying to find similar files on registry the result is that registry freezes and exits.

Does anybody have a similar issue or found any solution?

Here is a screenshot.


sebastian787 (OP)
Jr. Member
*
Offline Offline

Activity: 182
Merit: 8


View Profile
May 09, 2018, 11:47:43 AM
 #2

From a research i made hackers have been targeting websites with inadequate security to implement cryptojacking. The websites have been affected with a malicious code due to a vulnerability in an outdated version of Drupal.
Coinhive injected via the same Javascript library (jquery.once.js?v=1.2).

Every website that is affected should upgrade their Drupal version asap.
xpdeus
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
May 10, 2018, 06:50:34 AM
 #3

I also just got the Avast popup of Tri-version. So it's not gone yet ?
Damn :s
sebastian787 (OP)
Jr. Member
*
Offline Offline

Activity: 182
Merit: 8


View Profile
May 10, 2018, 06:57:22 AM
 #4

I also just got the Avast popup of Tri-version. So it's not gone yet ?
Damn :s
Check the source code of the page you visited when the popup appeared. Ctrl+ F and search for jquery.once.js?v=1.2. If you see this then avoid visiting this site until they update their Drupal version.
xpdeus
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
May 10, 2018, 07:06:55 AM
 #5

I think this one : http://www.btcsatoshi.com/

But I don't see that part (I used to be better at this).
I'm not sure if it's that site but I was on it at the time when the popup appeared, and don't have any others in my history. 
sebastian787 (OP)
Jr. Member
*
Offline Offline

Activity: 182
Merit: 8


View Profile
May 14, 2018, 07:59:34 PM
 #6

I think this one : http://www.btcsatoshi.com/

But I don't see that part (I used to be better at this).
I'm not sure if it's that site but I was on it at the time when the popup appeared, and don't have any others in my history. 


Did it popup the message i attached on my first post or it was different?
I tested the site you visited at siteguarding and it appeared that is affected. So, avoid it.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!