Bitcoin Forum
May 05, 2024, 07:08:31 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Electrum Phishing  (Read 436 times)
BugBasher82 (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
February 27, 2019, 12:11:16 AM
 #1

Hi All,

So I fell foul to the Electrum phishing scam (it had been awhile since i used it and I'm not on form atm,, don't say it  Cry ) and downloaded and installed "version 4.0.0", and to no surprise within a jiffy lost about £100 in btc (all that was in the wallet) when trying to send it.
I've come to terms with my stupidity now and have consigned that wallet to the grave. I have removed Electrum from my laptop (Add/Removed programs) and deleted all files with electrum in the name I can find to try and be sure. I've run a Bitdefender scan of the whole computer which has turned up nothing, but I still feel a little worried I might have left something nasty on my machine.
I'm also a bit nervous about installing and setting up a new Electrum wallet (from the correct .org site!) just because like anyone I don't want to chuck my money away.

Any advise would be welcome.

Thanks
1714892911
Hero Member
*
Offline Offline

Posts: 1714892911

View Profile Personal Message (Offline)

Ignore
1714892911
Reply with quote  #2

1714892911
Report to moderator
Unlike traditional banking where clients have only a few account numbers, with Bitcoin people can create an unlimited number of accounts (addresses). This can be used to easily track payments, and it improves anonymity.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714892911
Hero Member
*
Offline Offline

Posts: 1714892911

View Profile Personal Message (Offline)

Ignore
1714892911
Reply with quote  #2

1714892911
Report to moderator
1714892911
Hero Member
*
Offline Offline

Posts: 1714892911

View Profile Personal Message (Offline)

Ignore
1714892911
Reply with quote  #2

1714892911
Report to moderator
FinneysTrueVision
Sr. Member
****
Offline Offline

Activity: 1652
Merit: 365


Top Crypto Casino


View Profile
February 27, 2019, 01:13:34 AM
 #2

I would buy a hardware wallet. They're not that expensive.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
CASINO
.
SPORTS
.
RACING
OFFICIAL PARTNER OF
Argentina NT
CLOUD9
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
wiik
Member
**
Offline Offline

Activity: 293
Merit: 12


View Profile
February 27, 2019, 03:20:49 AM
 #3

Simply deleting/uninstalling is not an assurance. I would recommend a fresh install of OS ? And wipe everything on that drive , or just use another PC for crypto purposes . I mean buying a new pc for a specific purpose like in your this case , Cryptocurrency. Scammers/hackers has a lot of ways to deceive users. Make sure to install antivirus/anti-malware softwares. Feels bad for your loss , thats a quite big money. Well, that would be a charge to experience. Sometimes we learn the hard way. Take extra care next time folks.

dothebeats
Legendary
*
Offline Offline

Activity: 3640
Merit: 1352


Cashback 15%


View Profile
February 27, 2019, 03:30:22 AM
Merited by Questat (1)
 #4

Always check the domain and just make sure you are getting it from the correct repository (electrum.org). The phishing incident has been going on for a couple while now and the Electrum team had already done things to negate the said issue so you'll be golden for a reinstall. However, if you are still afraid of any unwanted malware that the phishing software has left on your machine, a fresh install would be nice, though not really necessary as most antivirus software will see if something's wrong with your machine. Just run a deep scan of your PC if you're really that paranoid and you'll be fine.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
jseverson
Hero Member
*****
Offline Offline

Activity: 1834
Merit: 759


View Profile
February 27, 2019, 03:30:37 AM
 #5

There shouldn't be any risks at all in installing a fresh one from the correct site:

https://electrum.org/#home

If it makes you feel better, transfer a small amount and let it sit for a while. AFAIK though, there's still a vulnerability where attackers can send you erroneous notices asking you to update, linking to phishing websites. I don't know if that issue has been fixed, but it shouldn't be too dangerous if you know about it.

Also, here's a way to check if your Electrum copy is legit.

samcrypto
Sr. Member
****
Offline Offline

Activity: 2044
Merit: 314


Vave.com - Crypto Casino


View Profile
February 27, 2019, 03:37:19 AM
 #6

I would buy a hardware wallet. They're not that expensive.
Always a good choice to store our coins. But I think you have nothing to worry about if you downloaded it from the legit site, so you must double check the link or what before you click the download sign. Its always better to be safe so do your best for this one, don't trust any link aside from the real one.

pooya87
Legendary
*
Offline Offline

Activity: 3444
Merit: 10546



View Profile
February 27, 2019, 04:19:47 AM
Merited by Botnake (2)
 #7

I've run a Bitdefender scan of the whole computer which has turned up nothing, but I still feel a little worried I might have left something nasty on my machine.
as far as i can tell about the malicious versions that i have seen, they don't install any malware (like viruses or keylogger,...) on your computer. it is a simple modification of the code so that it spends your funds automatically as soon as you open the wallet and sends them to the hardcoded hacker's address.
so your Bitdefender or any other AV is never going to detect it.

Quote
I'm also a bit nervous about installing and setting up a new Electrum wallet (from the correct .org site!) just because like anyone I don't want to chuck my money away.

Any advise would be welcome.
familiarize yourself with digital signatures (PGP) and Web of trust concepts and learn how to use them to verify the authenticity of everything you download to install.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
BlackPanda
Legendary
*
Offline Offline

Activity: 1414
Merit: 1001



View Profile
February 27, 2019, 05:05:45 AM
 #8

I would buy a hardware wallet. They're not that expensive.
Always a good choice to store our coins. But I think you have nothing to worry about if you downloaded it from the legit site, so you must double check the link or what before you click the download sign. Its always better to be safe so do your best for this one, don't trust any link aside from the real one.
Downloading from the official website is a must because then security will be guaranteed, there are currently many services that provide this.
So please note that there are a lot of phishing sites and that our assets are not guaranteed.
livingfree
Hero Member
*****
Offline Offline

Activity: 2786
Merit: 578



View Profile
February 27, 2019, 05:12:59 AM
 #9

This is electrum related topic so it must be on Development & Technical Discussion > Wallet software > Electrum .

As they suggested, just download to the main site and don't go with any other websites which isn't owned by electrum and you're going to be fine with what you are downloading especially with desktop wallets like electrum.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Botnake
Hero Member
*****
Offline Offline

Activity: 2856
Merit: 667



View Profile
February 27, 2019, 05:19:34 AM
 #10

~snip~
I feel you man, I was a victim of this today and I loss my money as well, luckily that was only BTC0.0075.

This is what happen to me which I posted in this thread https://bitcointalk.org/index.php?topic=5113056.msg49936408#msg49936408


Quote
Just today I was a victim of this one. the same address above where my BTC goes.
You can check my address - https://www.blockchain.com/btc/address/158BpFWP32CU1wv54Rm2NqKGosFLvZbacd


I was transacting today using my electrum desktop wallet (electrum-3.3.2) but I count not proceed because  it prompt that I should update and go to this site -https://www.myelectrum.org, so since the message was shown in the app that I was using without a problem so I trusted it.

Next, I downloaded the " Windows Installer (signature) " it showed a file name ( electrum-4.0.0-setup.exe) and them installed it.

Afterwards I open the electrum app, then proceed to transact, actually I entered the right address but when I send it, it does not prompt to ask password like the old ones, so I was thinking, it could be because of the new update... then check the blockchain and to my dismay I have not seen my transaction which suppose to be instant.

So, I checked the history in my electrum app and saw that I sent it to the address " bc1qhsrl6ywvwx44zycz2tylpexza4xvtqkv6d903q " as you can see in the blockchain explorer link.



This is real, I hope everyone would read this so they will see this as a warning, they have to be careful, luckily I did not transact a higher amount.

So guys, what I should do now? Do I have to uninstall the new one I installed and then just install the old one? What if it will prompt again that I cannot transact?


Thanks, I just read your comment and I guess I would not reformat my PC anymore, I had already run my antivirus and no detection of any malware.
though not really necessary as most antivirus software will see if something's wrong with your machine

█████▄▄██
███▄█████
██▄███████▄
████████████████
███▀██████████▀
██▄████████████▄
░█████▀▀▀▀▀▀█████
████▀████████▀████
▀▀▀▀▄▄▄▄▄█████████
█████▀███████▄████
███████▀▀▄▄▄█████
███████████████▀
████████████▀▀
OMBARD.com|.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀
██████░██░████░██
▄▄░▄▄░▄▄░▄▄░▄▄░▄▄▄▄
▀▀░▀▀░▀▀░▀▀░▀▀░▀▀▀▀
██████████████
▄▄░▄▄▄▄░▄▄░▄▄▄▄▄▄
▀▀░▀▀▀▀░▀▀░▀▀▀▀▀▀
██░██░██████████
▄▄▄▄▄▄▄▄░▄▄░▄▄▄▄
▀▀▀▀▀▀▀▀░▀▀░▀▀▀▀
.
PICK,
PLAY,
PROSPER!
|.

██████
██████████
██████████
██████████████
████████████████
████████████████
████████████████
████████████████
████████████████
█████████████████   ██
PROVABLY
FAIR
1%█████████████████   ██
HOUSE
EDGE
100%█████████████████   ██
DEPOSIT
BONUS
.
  Play now  
NeuroticFish
Legendary
*
Offline Offline

Activity: 3668
Merit: 6376


Looking for campaign manager? Contact icopress!


View Profile
February 27, 2019, 10:03:35 AM
 #11

Any advise would be welcome.

The idea to put a few bucks onto the wallet and wait for a couple of days is not bad at all.

The only thing I'd do would be a thorough scan. I don't know if you ran the AV scan from an installed Bitdefender or from a bootable DVD/USB. I would download 1-2 reputed "recovery" antivirus images (at least one different from Bitdefender), burn them, boot and scan from them. May be a bit of overkill, but if you want to be 100% sure, this is a possible direction.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5637


Blackjack.fun-Free Raffle-Join&Win $50🎲


View Profile WWW
February 27, 2019, 11:24:35 AM
 #12

Any advise would be welcome.
Thanks

Some say that it's just enough to remove fake version, and then install original from official site, but I would not feel safe to do only that. A safer option would be to format the disc and install fresh OS, and if you do not want to do it be sure to delete all traces of fake Electrum, and to do that go just paste %appdata%\Electrum in your C:/ and delete Electrum folder.

Good AV would probably stop you to even download such fake file, so consider some better option than you have now, or even better invest in hardware wallet.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
BugBasher82 (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
February 27, 2019, 12:00:33 PM
 #13

Thank you for all the info good people.

I think I am going to go with a format C: and reinstall just to be on the safe side.

Goodness knows what could have been done by me running a malicious .exe on my machine.

Serious stupidity on my part but very cleverly implemented by the hackers, they really tricked me good but have to say, I'm astounded Electrum left themselves open to this type of vulnerability. I mean the hackers actually manage to block initial outgoing transactions in order to fool you into thinking you need an update.

Bastards.
whotookmycrypto
Full Member
***
Offline Offline

Activity: 168
Merit: 214


WhoTookMyCrypto.com


View Profile WWW
March 07, 2019, 12:31:07 PM
Last edit: March 08, 2019, 06:29:18 AM by whotookmycrypto
 #14

familiarize yourself with digital signatures (PGP) and Web of trust concepts and learn how to use them to verify the authenticity of everything you download to install.

hey OP, pooya87 made a very good point about verifying your downloads. It could have helped prevent what happened to you. This is a good site that covers it. Link. Sorry for what happened to you.

bathrobehero
Legendary
*
Offline Offline

Activity: 2002
Merit: 1051


ICO? Not even once.


View Profile
March 07, 2019, 09:14:51 PM
 #15

I'm late but I just got tricked into the fake, 4.0.0 version in a hurry and the moment I knew it was fake when it asked for my 2FA when I launched it. So I didn't give it to them.

Removed it, did a malware scan and did a search for all the files that were created/last accessed in the last 20 minutes and I didn't find any new or suspicious files or any extra running processes or msconfig service/startup entries so now I'm wondering if it had any persistent elements to it as I don't think so but I'm curious about others. Did it also target other wallets?

Not your keys, not your coins!
BitMaxz
Legendary
*
Offline Offline

Activity: 3248
Merit: 2965


Block halving is coming.


View Profile WWW
March 07, 2019, 09:42:08 PM
 #16

Removed it, did a malware scan and did a search for all the files that were created/last accessed in the last 20 minutes and I didn't find any new or suspicious files or any extra running processes or msconfig service/startup entries so now I'm wondering if it had any persistent elements to it as I don't think so but I'm curious about others. Did it also target other wallets?

Never heard yet that they are also targeted other wallets. If you want to make sure that your PC is safe, scan the whole PC with Malwarebytes and deep scan on kaspersky might find some suspicious activity in your PC. Also, I recommend you to use IObit advance uninstaller to fully remove all traces from your PC including Regedit before you install the legit Electrum wallet.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
DireWolfM14
Copper Member
Legendary
*
Offline Offline

Activity: 2170
Merit: 4238


Join the world-leading crypto sportsbook NOW!


View Profile WWW
March 07, 2019, 09:49:27 PM
 #17

I have a hard time trusting third party virus and malware removers when it comes to crypto wallets.  A scammer can take measures to mitigate the chances of their malware being found, or you could get false positives.

To be on the safe side, I would reinstall the OS.  That's likely overkill, but my financial security deserves overkill.

@OP and bathrobehero, learn to use PGP and verify the signature when you download Electrum.  It's a great desktop wallet, and is worth the extra security steps to make sure you're using it safely.  Otherwise, hardware wallets are a great alternative.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
bathrobehero
Legendary
*
Offline Offline

Activity: 2002
Merit: 1051


ICO? Not even once.


View Profile
March 07, 2019, 10:04:58 PM
Merited by vapourminer (1)
 #18

@DireWolfM14 Yep, the payload could be encrypted or otherwise hidden so scanners are never a 100% reliable, we know that. I got used to verifying my download sources but I've never seen an Electrum broadcast message so it took my guard down. And after seeing how many people got fooled by it, in many waves and since how long ago since the first, I'm feeling pretty annoyed with how the Electrum devteam is handling it.

I moved my funds to an offline computer and will be formating this PC.

It's just people tend to become lazy with security until they get caught. Didn't lose anything but easily could have. Anyway, thank your for your help.

Not your keys, not your coins!
Botnake
Hero Member
*****
Offline Offline

Activity: 2856
Merit: 667



View Profile
March 08, 2019, 02:26:10 AM
 #19

Removed it, did a malware scan and did a search for all the files that were created/last accessed in the last 20 minutes and I didn't find any new or suspicious files or any extra running processes or msconfig service/startup entries so now I'm wondering if it had any persistent elements to it as I don't think so but I'm curious about others. Did it also target other wallets?

Never heard yet that they are also targeted other wallets. If you want to make sure that your PC is safe, scan the whole PC with Malwarebytes and deep scan on kaspersky might find some suspicious activity in your PC. Also, I recommend you to use IObit advance uninstaller to fully remove all traces from your PC including Regedit before you install the legit Electrum wallet.
So far my other wallet are safe, I was able to do a successful transaction after I got phish with a small amount.
I don't need to reinstall my OS as I believe my antivirus would detect if there's some traces left, hopefully I'm be safe and I would regret if my funds will be stolen again since I don't follow other's suggestion to have my PC fresh.

█████▄▄██
███▄█████
██▄███████▄
████████████████
███▀██████████▀
██▄████████████▄
░█████▀▀▀▀▀▀█████
████▀████████▀████
▀▀▀▀▄▄▄▄▄█████████
█████▀███████▄████
███████▀▀▄▄▄█████
███████████████▀
████████████▀▀
OMBARD.com|.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀
██████░██░████░██
▄▄░▄▄░▄▄░▄▄░▄▄░▄▄▄▄
▀▀░▀▀░▀▀░▀▀░▀▀░▀▀▀▀
██████████████
▄▄░▄▄▄▄░▄▄░▄▄▄▄▄▄
▀▀░▀▀▀▀░▀▀░▀▀▀▀▀▀
██░██░██████████
▄▄▄▄▄▄▄▄░▄▄░▄▄▄▄
▀▀▀▀▀▀▀▀░▀▀░▀▀▀▀
.
PICK,
PLAY,
PROSPER!
|.

██████
██████████
██████████
██████████████
████████████████
████████████████
████████████████
████████████████
████████████████
█████████████████   ██
PROVABLY
FAIR
1%█████████████████   ██
HOUSE
EDGE
100%█████████████████   ██
DEPOSIT
BONUS
.
  Play now  
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7132



View Profile
March 08, 2019, 09:17:55 AM
 #20

I don't need to reinstall my OS as I believe my antivirus would detect if there's some traces left, hopefully I'm be safe and I would regret if my funds will be stolen again since I don't follow other's suggestion to have my PC fresh.
I wouldn't risk it if I were you. If you have a lot of assets worth protecting on that PC just reinstall it to be perfectly safe. If you had a fake software installed who knows what else it could have done to your system that your AV hasn't yet picked up! 

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!