Does anyone know how this "virus" works? I cant really imagine how it is possible to automatically transfer funds without specific compromised wallets/browsersites etc?
There are multiple ways.
But i'd think the most commons are:
- Scan harddrive for private keys (e.g. in text files). If found -> create transaction
- Scan harddrive for wallets. If not password protected or encrypted -> create transaction
- If the wallet is password protected / encrypted -> wait for user to decrypt/open the wallet -> create transaction
These options apply to desktop (software-) wallets.
Online wallets (or wallets accessed via any browser interface, e.g. MEW) are way easier to steal funds from.
A virus would simply create an entry into the DNS cache. If a user tries to visit MEW, the virus is redirecting him to either (1) the attackers server or (2) a local hosted server on the targets machine. Once he enters his private key / seed --> Funds being stolen.
Those are (probably) the most easiest ways to steal user funds. I am sure that there are more tricky (but also more promising) way to steal funds.
How it EXACTLY happened in OP's case can't be said for sure without inspecting his computer.
@OP:
Did you scan your computer for malware ? I'd heavily suggest doing this.