Bitcoin Forum
May 13, 2024, 12:59:09 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Fake Google Sheets Extension - Scammed | Last Update!  (Read 610 times)
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 744



View Profile
August 11, 2022, 01:47:57 PM
Last edit: August 11, 2022, 02:32:14 PM by Ultegra134
Merited by Stalker22 (1)
 #21

New update!

The extension auto reinstalled itself, honestly, I don't understand what's causing its installation, but certainly it's not me. I haven't deleted its files yet, because they could possibly come in handy for other users and its declaration as a malicious extension. Could it be possible that one of them includes a script to install it without your permission?





The scammer's BTC address (https://www.blockchain.com/btc/address/16Adp6PaLTDqejGo4W4Yy8kzixgQVwFoEx)


Real BTC deposit address



Edit: Went to the extension's folder and started opening up each file, all folders feature the same files and are exact copies of each other. I honestly don't understand what's going on.



Edit 2: Okay, here's what I also found, there are two folders named "Extension" and "Extensions", the first one consists of several other folders containing the same fake Google Sheets extension, while the latter, has all the legit ones along with a fake one as well.


R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
1715561949
Hero Member
*
Offline Offline

Posts: 1715561949

View Profile Personal Message (Offline)

Ignore
1715561949
Reply with quote  #2

1715561949
Report to moderator
Bitcoin mining is now a specialized and very risky industry, just like gold mining. Amateur miners are unlikely to make much money, and may even lose money. Bitcoin is much more than just mining, though!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Stalker22
Legendary
*
Offline Offline

Activity: 1498
Merit: 1358



View Profile
August 11, 2022, 09:06:54 PM
 #22

New update!

The extension auto reinstalled itself, honestly, I don't understand what's causing its installation, but certainly it's not me. I haven't deleted its files yet, because they could possibly come in handy for other users and its declaration as a malicious extension. Could it be possible that one of them includes a script to install it without your permission?

In the past, I have come across similar extensions, but they were never as malicious. They usually hijacked control of the internal search engine and opened some suspicious websites and pop-up windows. Even after removing and resetting all Chrome settings, they persistently returned to the browser.

I am not sure that such extensions can be reinstalled by themselves. It seems to me that there must be some kind of executable that instructs these annoying extensions to re-load themselves. There must be a process running quietly in the background on your system which is responsible. I recommend that you back up your data (such as passwords and bookmarks), completely remove the Google Chrome profile and user data folder, and perform a thorough adware and malware check of your system with Malwarebytes and an antivirus program. You can also manually check all programs and processes that start automatically after system startup to see if you notice anything suspicious.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
Potato Chips
Hero Member
*****
Offline Offline

Activity: 2758
Merit: 896


yesssir! 🫡


View Profile
August 12, 2022, 12:42:14 AM
 #23

Hmmm. If I were you, I'd opt for a fresh OS installation since we don't know what slips thru AVs and our own eyes. Probably opt out on extensions in the sync settings as well, just to be extra sure.

You can try to compartmentalize if you're dabbling with potentially dangerous stuff like pirated softwares, keeping the data of malicious extensions, etc.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Maus0728
Legendary
*
Offline Offline

Activity: 1904
Merit: 1577


Bitcoin Casino Est. 2013


View Profile
August 12, 2022, 12:58:18 AM
 #24

Wouldn't you like to wipe out your machine and start with a clean slate? Because a quick search suggests that you're not the only one having this kind of problem. There's even a redditor with a similar issue in the past1 and an article2 about this kind of adware.

The only problem in the article is that they suggest you use 3rd party applications to remove the malicious files which could be usually removed from wiping out your entire machine and install your OS. Plus, make a habit of minimizing your browser extensions and uninstall those that aren't needed including software programs.

[1] https://www.reddit.com/r/techsupport/comments/qp9fc7/removing_fake_sheets_extension_from_chrome_and/
[2] https://www.myantispyware.com/2020/10/21/how-to-remove-fake-google-docs-extension-virus-removal-guide/

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 744



View Profile
August 12, 2022, 08:26:27 PM
 #25

Unfortunately, I don't have the necessary time available to back everything up and reinstall my OS, it's certainly the best option here, but I don't have the time for it. I've proceeded and deleted any extension files I've found, and will also remove any pirated software I've downloaded in the past few months.

The fake extension folder was created in 01/07/2022, so it's been in my computer for a while, there's a chance that I had downloaded something and is now deleted, but I'll be on the lookout in case it appears again.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
swegmen1
Newbie
*
Offline Offline

Activity: 1
Merit: 2


View Profile
October 16, 2022, 02:02:27 AM
Last edit: October 16, 2022, 02:37:11 AM by swegmen1
Merited by Lucius (1), Ultegra134 (1)
 #26

Hello

I just got scammed for 200 bucks by trying to withdraw from exchange 1 (binance) and deposit to exchange 2 (MEXC). This is NOT your regular clipboard hijacker, the JS script did the following for me:

  • When you copy deposit address from exchange 2 to withdrawal field in exchange 1, the address doesn't immediately change visibly, it gets swapped with scam address DURING confirmation, there's NO way to see it coming since it happens backend via script
  • If you try to deposit (instead of withdraw) on Binance, the address is VISIBLY changed to the scammer address. The deposit address on MEXC didn't change, it was legit
  • When pasting the deposit address of exchange 2 into the corresponding blockchain explorer, the result will be the scammers address. This can make you confused EVEN if you know what you are doing
  • When you search for the scammer address on blockchain explorer, it will crash the site


Now, I didn't figure out where this Google sheets thing came from because I pirate a lot but I did figure out how it got loaded.
I found this because I deleted the "Extension" folder which had all the malicious stuff in it and I kept getting a message saying "failed to load extension" whenever I would start Brave.
I searched on YT how to fix this, most videos recommended deleteing/renaming the BraveSoftware folder under "%Appdata%\Local\BraveSoftware".
After I did this, I still kept getting the error message so it didn't make sense anymore. This is when I found this:


If you right click on the Chrome (Brave in my case) shortcut, click properties, you will find this:

Code:
"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe"  --load-extension="C:\Users\x\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extension\jeelboaldqeqfqemlljamankmbnoefre\4.3.6._0"

Considering the malicious extensions stem from my Brave shortcut, I knew it was impossible that I downloaded any extensions and I am almost certain it stems from a torrent.
My download history of my browser etc couldn't be it because it was never an executable or a script. So all that's left is my torrent history:

https://ibb.co/z6YJzNX

Considering most of my downloads on this list are movies or series, we can safely assume they aren't the culprit. The torrent from Vegas Pro, C4D and V-Ray ALL share the same crack with same icons but different file sizes:

https://ibb.co/S7DV2jm

That's all I have for now, I am kinda done with this, I won't look into it any further. It hurts to think about this even thought the money isn't really a big loss, I'm just disappointed and guilty with myself and I want to forget this ASAP.
If anyone has downloaded anything from this list during july, be kind and reply so that others can avoid getting scammed like this as well.


EDIT: I forgot to add, I ran the crack exe's from those 3 torrents in sandboxie and it didn't show anything but I mean whats the point of that, if someone can engineer shit like this then he will have absolutely no problem to implement anti-sandbox features into his cracks.
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 744



View Profile
October 16, 2022, 11:13:09 AM
 #27

~snipped~
I'm really sorry for your loss. Your case sounds way more tricky and way harder to predict since, from what I understood, you were shown the correct address at first but the script switched it at the final stages. $200 is not a huge amount, but not a petty one either. As much as torrenting is useful for obtaining software you need, I've come to terms with the fact that it's a huge risk when having cryptocurrencies stored on your computer, and that it's not worth it. One idea is to keep cryptocurrencies and transactions away from your main computer.

I see that you're a newbie and put some decent effort into your post. I hope you stick around in the forum. There's a lot to learn. Thank you for spending your time to inform others regarding such a serious malicious script.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Lucius
Legendary
*
Offline Offline

Activity: 3234
Merit: 5676


Blackjack.fun🎲


View Profile WWW
October 16, 2022, 01:52:58 PM
 #28

@swegmen1, thank you for the warning and the detailed description, and I hope that the $200 is not something that meant too much to you in your life, so that it can be just one life lesson for you. If you can somehow (in the future) separate everything that belongs to entertainment (and it is risky) from anything related to cryptocurrencies, that would protect you from something like this happening to you again. Pirated content whether it's movies/music or software is very risky and you should find an alternative in a legal way to access such things.

I advise formatting the disk and a fresh installation of the OS to make sure that you have removed the infection.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
thusharaabc
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
November 23, 2022, 01:34:40 AM
 #29

I was a victim of this two days ago.
It changed my Binance bitcoin address to this address:
1bmL3m2Wrb4qzSyNnLU3ExEhWX8C7QeWK
I lost 0.00810000 BTC.
BTC is still unspent.
https[Suspicious link removed]hWX8C7QeWK

Is it possible to get the real ID/team of this extension maker?
Potato Chips
Hero Member
*****
Offline Offline

Activity: 2758
Merit: 896


yesssir! 🫡


View Profile
November 23, 2022, 11:33:57 AM
 #30

Is it possible to get the real ID/team of this extension maker?

You can spend thousands of dollars to hire investigators for a chance they might be able to piece something out. Emphasis on "for a chance"... as you can guess, it's not advisable in most cases.

The most attainable thing you could do right now is to take precautions so this never happens again and maybe monitor the transaction in the blockchain to see if your scammer is dumb enough to send your coins directly to an exchange [unlikely chance so keep your expectations low]. You could use block explorers like oxt.me which labels known exchange addresses.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 744



View Profile
November 23, 2022, 04:41:07 PM
 #31

I was a victim of this two days ago.
It changed my Binance bitcoin address to this address:
1bmL3m2Wrb4qzSyNnLU3ExEhWX8C7QeWK
I lost 0.00810000 BTC.
BTC is still unspent.
https[Suspicious link removed]hWX8C7QeWK

Is it possible to get the real ID/team of this extension maker?
I'm sorry for your loss. Do you have any idea how the extension got installed in the first place? In my case, I found that it had been running for quite a while and couldn't possibly trace back to who was responsible for its installation. I had a few guesses regarding some torrented software, but the creation date of the extension's folder doesn't line up with the download date; thus, I can't be sure that the torrents were to blame. Although I will refrain from downloading pirated software from now on.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 744



View Profile
August 21, 2023, 11:46:03 PM
 #32

Excuse me for grave digging such an old thread, but I figured it would be best to revive it rather than come up with a new thread since the update is referring to the exact incident.

I haven't had access to my computer for the past few months due to personal reasons that aren't the main subject; thus, I had my laptop completely abandoned and left in a state of despair. I strongly remember that if I uninstalled the extension through Chrome's extension manager, it would simply reappear the next time Chrome was launched. Thus, I resorted to finding the corresponding files in the data folder and deleting them myself. This worked, although Chrome appeared to still attempt to launch the now-missing extension, as seen in the following photo. However, that didn't bother me too much since the extension was practically gone. Keep in mind that no kind of antivirus software was able to spot anything unusual, even if I selected Chrome's folder directly.

Today I decided to do a long-needed cleanup on the computer after more than half a year of being inactive. I started with a malware scan from Malwarebytes, and to my surprise, it still detected the fake extension! However, the extension was found on Microsoft Edge, something that completely slipped undetected because I generally use Chrome and never spotted it on Edge.


It also certainly found malware in Chrome's folders because, after the scan was complete and the threat was wiped, the message on the first screenshot stopped appearing, meaning that it wasn't trying to launch it anymore.

So, this is hopefully the last update on this thread, and the reason for me to update it is due to it no longer being undetected by antiviruses, as I was pleasantly surprised by Malwarebytes, which caught all threats. Up to this day, I still haven't found any clues on how this extension got installed, nor can I suspect any torrents that I have used in the past. Thus, keep your software and Windows updated at all times, as security breaches are becoming more and more dangerous.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Nwada001
Hero Member
*****
Offline Offline

Activity: 574
Merit: 627



View Profile
August 23, 2023, 12:00:11 AM
Merited by The Sceptical Chymist (3)
 #33

So, this is hopefully the last update on this thread, and the reason for me to update it is due to it no longer being undetected by antiviruses, as I was pleasantly surprised by Malwarebytes, which caught all threats. Up to this day, I still haven't found any clues on how this extension got installed, nor can I suspect any torrents that I have used in the past. Thus, keep your software and Windows updated at all times, as security breaches are becoming more and more dangerous.

This part is what scares me the most, as the level that this virus programmers have gone up to not being detected by any anti virus either paid or free one is what scares me the most, as one will not be able to detect when they are actually free from virus and when they are not, when we need to worry about something or not, especially when you are making use of a same PC which you use for crypto related transaction, the risk is very high as most of the virus is designed to target crypto related transaction just as the case of swegmen1 which I never even still don't know if such was ever going to be possible as what I know of is clipboard virus and I have learned to reconfirm my address every time i want to execute a transaction in other to avoid falling into the hackers hands.

It's good you bumped this thread, as I have been able to grab a few, if not up to two, types of viruses and how they attack, which ordinarily I was not aware of.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
albon
Legendary
*
Offline Offline

Activity: 1694
Merit: 1387



View Profile
August 23, 2023, 12:06:24 AM
 #34

Today I decided to do a long-needed cleanup on the computer after more than half a year of being inactive. I started with a malware scan from Malwarebytes, and to my surprise, it still detected the fake extension! However, the extension was found on Microsoft Edge, something that completely slipped undetected because I generally use Chrome and never spotted it on Edge.
Thank you all for updating the topic, and the fake extension of browsers is dangerous, and the hacker can access the important data saved in the browser and steal it; frankly, I found a safe solution for you is to make a new copy of Windows or Linux and remove your current version of Windows completely, because your computer may also be infected. Although antivirus software may be effective, it may not be able to detect all encrypted malwares.

Really, 111 malwares are very scary. Shocked

I still haven't found any clues on how this extension got installed, nor can I suspect any torrents that I have used in the past. Thus, keep your software and Windows updated at all times, as security breaches are becoming more and more dangerous.
Torrent files are risky, illegal, and contain malwares. I do not advise you, after making a new Windows for your computer, to use the torrent files that you downloaded before and stored on your computer. I think it is the main reason for installing this fake extension on your computer without your knowledge.

Yes, updating the system continuously is important, also downloading programs from their official websites only.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
noorman0
Hero Member
*****
Offline Offline

Activity: 1764
Merit: 694


[Nope]No hype delivers more than hope


View Profile WWW
August 23, 2023, 01:21:18 AM
 #35

-snip-
However, that didn't bother me too much since the extension was practically gone. Keep in mind that no kind of antivirus software was able to spot anything unusual, even if I selected Chrome's folder directly.
I suggest that you don't do some large crypto transactions before making sure that your computer is really clean. You can do light activities, and try to connect to the internet, will the extension contact the server to try to reinstall without permission.

As a tip, in the past I was also used to handling the laptops of some of my office employees who were infected with viruses. Besides relying on antivirus, I do manual cleaning especially on registry configuration.

This space for rent.
Available in mid January 2024 - PM me
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 744



View Profile
August 23, 2023, 10:08:20 PM
 #36

So, this is hopefully the last update on this thread, and the reason for me to update it is due to it no longer being undetected by antiviruses, as I was pleasantly surprised by Malwarebytes, which caught all threats. Up to this day, I still haven't found any clues on how this extension got installed, nor can I suspect any torrents that I have used in the past. Thus, keep your software and Windows updated at all times, as security breaches are becoming more and more dangerous.

This part is what scares me the most, as the level that this virus programmers have gone up to not being detected by any anti virus either paid or free one is what scares me the most, as one will not be able to detect when they are actually free from virus and when they are not, when we need to worry about something or not, especially when you are making use of a same PC which you use for crypto related transaction, the risk is very high as most of the virus is designed to target crypto related transaction just as the case of swegmen1 which I never even still don't know if such was ever going to be possible as what I know of is clipboard virus and I have learned to reconfirm my address every time i want to execute a transaction in other to avoid falling into the hackers hands.

It's good you bumped this thread, as I have been able to grab a few, if not up to two, types of viruses and how they attack, which ordinarily I was not aware of.
This was the worst part; no antivirus software or VirusTotal was able to detect the malware when I fell victim to the extension. I couldn't believe my eyes when I saw it, and I probably wouldn't have suspected it myself if Binance's customer support agent hadn't mentioned checking for possible malware. It didn't make any sense, and nothing was able to detect it on my computer if I hadn't seen it myself and realized it. It's delightful that at least now, a year later, it's fully recognized by even free software such as Malwarebytes. I also had the Brave browser installed, which swegmen1 was using when he was scammed, but I didn't think to check if it had the extension installed on it.
Thank you all for updating the topic, and the fake extension of browsers is dangerous, and the hacker can access the important data saved in the browser and steal it; frankly, I found a safe solution for you is to make a new copy of Windows or Linux and remove your current version of Windows completely, because your computer may also be infected. Although antivirus software may be effective, it may not be able to detect all encrypted malwares.

Really, 111 malwares are very scary. Shocked

Torrent files are risky, illegal, and contain malwares. I do not advise you, after making a new Windows for your computer, to use the torrent files that you downloaded before and stored on your computer. I think it is the main reason for installing this fake extension on your computer without your knowledge.

Yes, updating the system continuously is important, also downloading programs from their official websites only.
I just rechecked the quarantine history, and the majority of the malware found was involved with the fake extension that was left on Microsoft Edge. Fortunately, it seems to be gone for good. I'll do a clean installation of Windows soon. The most frustrating matter I'm facing is that I could never track what caused the extension to install—was it a torrent or another kind of software? I guess we'll never learn.
-snip-
However, that didn't bother me too much since the extension was practically gone. Keep in mind that no kind of antivirus software was able to spot anything unusual, even if I selected Chrome's folder directly.
I suggest that you don't do some large crypto transactions before making sure that your computer is really clean. You can do light activities, and try to connect to the internet, will the extension contact the server to try to reinstall without permission.

As a tip, in the past I was also used to handling the laptops of some of my office employees who were infected with viruses. Besides relying on antivirus, I do manual cleaning especially on registry configuration.
Malwarebytes caught some stuff on the registry too, but I've got no clue what it is about. My wallet has no transactions on it, and I intend to keep it that way. I'm generally a little paranoid after this incident and will be extra careful if I make any transactions. So far, after I manually deleted the extension files a year ago, I've faced no issues, nor have I suspected that something was off.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
PX-Z
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 850


Top Crypto Casino


View Profile WWW
August 23, 2023, 10:47:19 PM
 #37

I just saw this thread but damn. I could only bet that this extension came from your browser activity, it could be from ads, and was accepted without you remembering, or you are busy downloading other things then this one pops up, since installing an extension will have a browser pop up notification, thats the standard for security purposes in browsers, it could not be installed from without it.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Ultegra134 (OP)
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 744



View Profile
August 23, 2023, 11:57:32 PM
 #38

I just saw this thread but damn. I could only bet that this extension came from your browser activity, it could be from ads, and was accepted without you remembering, or you are busy downloading other things then this one pops up, since installing an extension will have a browser pop up notification, thats the standard for security purposes in browsers, it could not be installed from without it.
That also crossed my mind, but back then, I couldn't bring myself to rewind if I possibly did such a thing. However, it would make sense, as I probably wouldn't suspect a Google Sheets extension. I would like to know in order to prevent something similar in the future. As far as I know, no torrents were downloaded anywhere close to the date the extension appeared. I have no evidence that they are to blame, and to be honest, I do doubt to this day that it was the cause, as it was two torrents for Adobe software that were supposedly by a so-called reputable torrent source.

However, I never use Microsoft Edge. I get that I could possibly accept a pop-up without realizing it, but what about Edge? I've never used it in the past, and up to this day, I hadn't realized that it was also installed there, which means that the infected files were still on my computer but were affecting a different application.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
NotATether
Legendary
*
Offline Offline

Activity: 1596
Merit: 6739


bitcoincleanup.com / bitmixlist.org


View Profile WWW
August 24, 2023, 08:38:09 AM
 #39

That also crossed my mind, but back then, I couldn't bring myself to rewind if I possibly did such a thing. However, it would make sense, as I probably wouldn't suspect a Google Sheets extension. I would like to know in order to prevent something similar in the future. As far as I know, no torrents were downloaded anywhere close to the date the extension appeared. I have no evidence that they are to blame, and to be honest, I do doubt to this day that it was the cause, as it was two torrents for Adobe software that were supposedly by a so-called reputable torrent source.

There is supposed to be a pop-up warning in Google Chrome that tells you when an extension was installed (or prompts you whether you want to install an extension in the case of Chrome Web Store). Unless Developer Mode is enabled in chrome://extensions, in which case there will be no prompt at all when you use the "load unpacked" button, so you should probably disable that unless you absolutely need that feature.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
logfiles
Copper Member
Legendary
*
Offline Offline

Activity: 1974
Merit: 1656


Top Crypto Casino


View Profile WWW
August 24, 2023, 12:32:15 PM
 #40

Today I decided to do a long-needed cleanup on the computer after more than half a year of being inactive. I started with a malware scan from Malwarebytes, and to my surprise, it still detected the fake extension! However, the extension was found on Microsoft Edge, something that completely slipped undetected because I generally use Chrome and never spotted it on Edge.
There is something weird about Microsoft Edge that I noticed. It seems to automatically install extensions that are already installed on Chrome. I saw this on my Windows PC

Up to this day, I still haven't found any clues on how this extension got installed, nor can I suspect any torrents that I have used in the past. Thus, keep your software and Windows updated at all times, as security breaches are becoming more and more dangerous.
By the way, there are some software apps that maliciously install browser extensions and even change the default search engine settings of your browser. So it's a possibility that at one point you installed an app and without properly reviewing the additional add-ons it would install, you just kept clicking OK or Next on the software installer dialogue box.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!