Author

Topic: BITCON MINER VIRUS (Read 9065 times)

member
Activity: 84
Merit: 10
November 29, 2013, 01:36:23 PM
#51
If you go to the : hackforums.net and go to the marketplace there are several of these and trust me it is something you do not want to have on your computer

Stay safe scan links and files
full member
Activity: 154
Merit: 100
November 29, 2013, 04:55:30 AM
#50
Well after I installed Bit miner program my anti-virus went crazy. Started deleting files and so on.. I uninstalled it and everything was alright.
full member
Activity: 210
Merit: 100
Crypto News & Tutorials - Coinramble.com
November 29, 2013, 02:51:22 AM
#49
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
Generate bitcoins for free and get rich.  Cheesy

and i assume it steals everythig what u have?!?! am I right?

OP did you really dl a 'get free bitcoin generator' from yt?!

Yes I did  Lips sealed



did it steal anything from you ?!
Not yet, let's see, maybe its waiting for an oppurtunity
newbie
Activity: 52
Merit: 0
November 23, 2013, 01:07:11 PM
#48
of course
sr. member
Activity: 294
Merit: 250
November 23, 2013, 04:31:30 AM
#47


If you just realized that there are bitcoin trojans, ehhhh.. Do a system scan then.
 They've been out since bitcoin caught traction, sadly enough..
 
 Between getting hundreds of bot's to mine for you.
 Injecting code into your client to steal from you.
 Setting up on-demand keylogger to capture your keys for your wallet.
 etc.



The trojans stealing wallet is far worst then stealing CPU usage....
newbie
Activity: 52
Merit: 0
November 23, 2013, 03:01:51 AM
#46


If you just realized that there are bitcoin trojans, ehhhh.. Do a system scan then.
 They've been out since bitcoin caught traction, sadly enough..
 
 Between getting hundreds of bot's to mine for you.
 Injecting code into your client to steal from you.
 Setting up on-demand keylogger to capture your keys for your wallet.
 etc.

hero member
Activity: 490
Merit: 501
November 18, 2013, 01:09:54 PM
#45
newbie
Activity: 4
Merit: 0
November 17, 2013, 09:17:42 PM
#44
noisy CPU fan should arouse the suspicion of of most users
full member
Activity: 214
Merit: 100
November 17, 2013, 05:39:10 AM
#43
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.

Really? why can't botnet use memory?
Its probably more detectable. Making the computer slower.

Im not too good with CPU coins but why would PTS use more memory?
full member
Activity: 140
Merit: 100
November 17, 2013, 02:34:49 AM
#42
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.

Really? why can't botnet use memory?
Its probably more detectable. Making the computer slower.
hero member
Activity: 502
Merit: 500
November 16, 2013, 11:31:47 PM
#41
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.

Really? why can't botnet use memory?
hero member
Activity: 868
Merit: 1000
November 16, 2013, 10:02:01 PM
#40
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.


i agree i tryed and it stucks all the time

You mean you are one who makes those bot too!!!  Cry
full member
Activity: 154
Merit: 100
November 16, 2013, 06:01:12 PM
#39
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.


i agree i tryed and it stucks all the time
legendary
Activity: 2674
Merit: 2965
Terminated.
November 16, 2013, 02:58:38 PM
#38
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
PTS is a bit botnet resistant due to high memory requirements.
full member
Activity: 188
Merit: 100
November 16, 2013, 10:15:53 AM
#37
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.

Like PTS and primecoin? Looks like people need to stop investing on CPU coins cause of this...
legendary
Activity: 2674
Merit: 2965
Terminated.
November 16, 2013, 09:08:15 AM
#36
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
They can mine CPU coins for huge profits though.
full member
Activity: 140
Merit: 100
November 16, 2013, 08:21:14 AM
#35
I know about this virus it is usually created on a botnet were many people get infected/given a virus and then a hole bunch of people mine for this 1 person it is crazy but has recently became low profit so you should not find this virus to much anymore

Wrong, if the one that created the botnet is smart enough, he should mine the most profitable CPU coins instead of BTC....
No one creates those CPU botnets for SHA256 coins anymore. They either do it with GPU or make an scrypt coin botnet.
sr. member
Activity: 286
Merit: 250
November 16, 2013, 08:18:10 AM
#34
I know about this virus it is usually created on a botnet were many people get infected/given a virus and then a hole bunch of people mine for this 1 person it is crazy but has recently became low profit so you should not find this virus to much anymore

Wrong, if the one that created the botnet is smart enough, he should mine the most profitable CPU coins instead of BTC....
full member
Activity: 226
Merit: 100
November 16, 2013, 06:12:08 AM
#33
I know about this virus it is usually created on a botnet were many people get infected/given a virus and then a hole bunch of people mine for this 1 person it is crazy but has recently became low profit so you should not find this virus to much anymore

Yeah agree, but they can still use the CPU to mine CPU only coin...
member
Activity: 84
Merit: 10
November 16, 2013, 12:21:22 AM
#32
I know about this virus it is usually created on a botnet were many people get infected/given a virus and then a hole bunch of people mine for this 1 person it is crazy but has recently became low profit so you should not find this virus to much anymore
sr. member
Activity: 378
Merit: 250
November 16, 2013, 12:08:10 AM
#31
Don't plug in any USB too, easiest way to transfer virus...
sr. member
Activity: 255
Merit: 250
November 15, 2013, 10:48:09 PM
#30
Its easy to check, if your CPU is at 100% without much program running, you know something is wrong..
hero member
Activity: 502
Merit: 500
November 15, 2013, 08:25:02 PM
#29
Actually, don't download any app or plugin also..
Why is that?

Some plugin are trojan maybe?
legendary
Activity: 2674
Merit: 2965
Terminated.
November 15, 2013, 10:55:05 AM
#28
Actually, don't download any app or plugin also..
Why is that?
hero member
Activity: 868
Merit: 1000
November 15, 2013, 10:09:32 AM
#27
Actually, don't download any app or plugin also..
legendary
Activity: 2674
Merit: 2965
Terminated.
November 15, 2013, 09:38:03 AM
#26
Don't download any generators.  Cheesy
newbie
Activity: 56
Merit: 0
November 14, 2013, 07:04:04 PM
#25
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
Generate bitcoins for free and get rich.  Cheesy

and i assume it steals everythig what u have?!?! am I right?

OP did you really dl a 'get free bitcoin generator' from yt?!
full member
Activity: 154
Merit: 100
November 14, 2013, 07:01:53 PM
#24
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
Generate bitcoins for free and get rich.  Cheesy

and i assume it steals everythig what u have?!?! am I right?
Lol yes I used desperate measures to get some of my first Bitcoins.
No it is not a fake detection, even Kaspersky have reported few days back about a "BitCoin Miner" Virus


did it steal anything from you ?!
legendary
Activity: 2674
Merit: 2965
Terminated.
November 14, 2013, 10:20:08 AM
#23
I doubt that it's a false positive as my secure system hasn't encountered it and yet it has a few wallets, among them is the bitcoin one.
tel
member
Activity: 77
Merit: 10
November 14, 2013, 08:19:32 AM
#22
Hi man,

To be sure that this is false positive detection you can try to upload the file to www.virustotal.com
full member
Activity: 210
Merit: 100
Crypto News & Tutorials - Coinramble.com
November 14, 2013, 02:22:29 AM
#21
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
Generate bitcoins for free and get rich.  Cheesy

and i assume it steals everythig what u have?!?! am I right?
Lol yes I used desperate measures to get some of my first Bitcoins.
No it is not a fake detection, even Kaspersky have reported few days back about a "BitCoin Miner" Virus
full member
Activity: 154
Merit: 100
November 14, 2013, 01:47:59 AM
#20
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
Generate bitcoins for free and get rich.  Cheesy

and i assume it steals everythig what u have?!?! am I right?
legendary
Activity: 2674
Merit: 2965
Terminated.
November 14, 2013, 12:12:13 AM
#19
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
Generate bitcoins for free and get rich.  Cheesy
hero member
Activity: 784
Merit: 500
November 14, 2013, 12:10:51 AM
#18
"BTCGenv1.0"

Did you download a "Bitcoin Generator" from YouTube or something?  Cheesy
full member
Activity: 154
Merit: 100
November 13, 2013, 05:19:22 PM
#17
What the?
Please copy the log here.

Here you go guys, check this out:

Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.08.16.07
06-11-2013 14:11:06
mbam-log-2013-11-06 (14-11-06).txt

Scan type: Full scan (C:\|E:\|F:\|G:\|H:\|I:\|K:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 146706
Time elapsed: 30 minute(s), 11 second(s) [aborted]

Memory Processes Detected: 1
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> 7280 -> Delete on reboot.

Files Detected: 7
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\coinutil.dll (PUP.BitcoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\miner.dll (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\service.exe (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\usft_ext.dll (PUP.BitCoinMiner) -> No action taken.
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.
C:\Users\***\AppData\Roaming\XHvQH\taskengine.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.

(end)



I think it is only fake detection
full member
Activity: 210
Merit: 100
Crypto News & Tutorials - Coinramble.com
November 13, 2013, 03:18:44 PM
#16
What the?
Please copy the log here.

Here you go guys, check this out:

Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.08.16.07
06-11-2013 14:11:06
mbam-log-2013-11-06 (14-11-06).txt

Scan type: Full scan (C:\|E:\|F:\|G:\|H:\|I:\|K:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 146706
Time elapsed: 30 minute(s), 11 second(s) [aborted]

Memory Processes Detected: 1
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> 7280 -> Delete on reboot.

Files Detected: 7
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\coinutil.dll (PUP.BitcoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\miner.dll (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\service.exe (PUP.BitCoinMiner) -> No action taken.
C:\Users\***\AppData\Roaming\XHvQH\usft_ext.dll (PUP.BitCoinMiner) -> No action taken.
I:\Softwares\Top Setup's\Bitcoin\Generator\BTCGenV1.0.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.
C:\Users\***\AppData\Roaming\XHvQH\taskengine.exe (Backdoor.MSIL.P) -> Quarantined and deleted successfully.

(end)
legendary
Activity: 2674
Merit: 2965
Terminated.
November 13, 2013, 03:06:25 PM
#15
Sure but the profit isnt there for the blackhats. They make more money off of click fraud than mining without drwaing unwanted attention to themselves.
Wrong. Buy cheap botnet -> mine CPU coin -> dump all.
Profit.
hero member
Activity: 728
Merit: 500
November 13, 2013, 03:00:01 PM
#14
Sure but the profit isnt there for the blackhats. They make more money off of click fraud than mining without drwaing unwanted attention to themselves.
legendary
Activity: 2674
Merit: 2965
Terminated.
November 13, 2013, 02:29:18 PM
#13
Zero Access rootkit had some Mining code in it but they removed it since cpu mining is now useless.
Could still be used for CPU coins.
hero member
Activity: 728
Merit: 500
November 13, 2013, 01:04:48 PM
#12
Zero Access rootkit had some Mining code in it but they removed it since cpu mining is now useless.
hero member
Activity: 784
Merit: 500
November 13, 2013, 09:53:42 AM
#11

This form of malware has been here since the start of Bitcoins. It used to just drop CGMiner without the GUI.
legendary
Activity: 2674
Merit: 2965
Terminated.
November 13, 2013, 09:46:58 AM
#10
hero member
Activity: 784
Merit: 500
November 13, 2013, 03:14:07 AM
#9
I am mining in my office please don't tell anyone Tongue But my boss know it and she is ok Smiley

We don't know who to tell considering we don't know where you work.

These are silent miners used by hackers. You were infected.
legendary
Activity: 840
Merit: 1000
November 13, 2013, 03:09:39 AM
#8
I am mining in my office please don't tell anyone Tongue But my boss know it and she is ok Smiley
member
Activity: 100
Merit: 10
November 13, 2013, 03:05:05 AM
#7
Could be that trojan mining bot. Huh http://forum.avast.com/index.php?topic=129680.0
full member
Activity: 238
Merit: 100
ASIC Myth Buster
November 13, 2013, 01:15:00 AM
#6
Someone was making side money at your office  Angry

You should have looked into the process and the memory and see who the miner user ID at the pool was
legendary
Activity: 2674
Merit: 2965
Terminated.
November 13, 2013, 12:01:33 AM
#5
I found minerd.exe in my office computer and my CPU usage were 100%. Installed free AVG to get ride of it Smiley
Can you provide the log?
hero member
Activity: 1082
Merit: 505
A Digital Universe with Endless Possibilities.
November 12, 2013, 08:29:12 PM
#4
I found minerd.exe in my office computer and my CPU usage were 100%. Installed free AVG to get ride of it Smiley
legendary
Activity: 2674
Merit: 2965
Terminated.
November 12, 2013, 07:02:44 PM
#3
What the?
Please copy the log here.
full member
Activity: 238
Merit: 100
ASIC Myth Buster
November 12, 2013, 06:29:31 PM
#2
No....

What's the description?  What is it going to do if you get infected?

Keylog?  steal your private keys?  or scam off portion of your mining powers?
full member
Activity: 210
Merit: 100
Crypto News & Tutorials - Coinramble.com
November 12, 2013, 12:08:32 PM
#1
I just ran a full system scan using Malwarebytes Antimalware and two sneaky "Bitcoin Mining" viruses showed up in temp directory  Shocked
Lol, Einsteins of today's world.
Have you guys hear about this virus ?
Jump to: