Hey,
Everyone that downloaded the windows wallet early needs to check that AppData\Local\Spoon directory. That is where the backdoor was installed, it doesn't come up on a lot of virus scans, and was packaged with the windows wallet. Seems that the dev has now removed the malicious wallet.
You need to delete that directory asap. The program installed after you ran the zipcoin wallet for the first time and ztor.exe remains running even after you close the zipcoin wallet.
Obviously the exchanges and people who complied from source weren't affected, as this was zipped with the original windows wallet that was posted in the announcement.
Digiguy seems like the attacker shilling to extend time cleaning people out, posting screenshots to direct attention from where the problem is.
So if you downloaded that original windows wallet you need to check that C:\USERS\youraccount\APPDATA\LOCAL\SPOON, delete that directory asap, and then look for all your wallet.dat files in the APPDATA roaming folder, if you were infected the "wallet.dat" files were renamed to whatever coin it was such as "Dogecoin.dat" and then sent to the attacker.
Gonna repeat, Zipcoin-qt.exe itself is not malicious it was the ztor.exe bullshit that was packaged with the windows wallet, maybe thats why the dev called it zipcoin heh.
Again this shit doesnt come up on a lot of antivirus scanners and you need to remove this manually if you were infected, and then there is no telling what else could have been installed so its best to reformat your harddrive.
I fear a good amount of people got cleaned out already if they had all their wallets on the infected PC, I guess we'll find out with time.
Hey all, I can confirm that this is a virus. I downloaded yesterday, woke up this morning and my Bitcoin Wallet and my Minerals Coins had been cleaned out. Not a great deal about 2.5 BTC worth, but still lost revenue from mining.
I ran the Malware bytes scan and Avast and it did indeed confirm that the file named netsh.exe was located in the directory C:\users\MyUsername\Appdata\Local\Spoon\Sandbox\Zipcoin-Qt\2.0.0.0\local\stubexe\0x94D16BC4A71627A1
Running through the blockchain it appears that a few others have been taken so check your balances and it is not only limited to BTC wallets, it is ALL wallets. So I endeavour all who has the wallet installed to do a
complete re-install of the system. Just deleting those files is not enough, you dont want to risk it
This fucking scumbag sure has some bad karma coming their way