Author

Topic: Boost interprocess folder - Malicious? (Read 5233 times)

full member
Activity: 212
Merit: 100
February 25, 2014, 09:07:51 PM
#11
Same just happened with me when I was doing some system cleaning and I found this path C:\ProgramData\boost_interprocess\20140225072043.xxxxxxx\BitcoinURI and seems that this file contains machine code (correct me if im wrong) getting words such as "STX" "NUL" "BS" "SOH"

  This was with Ultracoin by the way.
legendary
Activity: 1946
Merit: 1007
February 25, 2014, 11:18:07 AM
#10
Have this folder as well but no idea what it's for.

My only guess is that it's to do with the boost c++ library, which doesn't automatically make it suspicious, but it does concern me that only some wallets seem to use it.

I did a full sweep and nothing came up. Various google searches haven't been too clear either.

I did find that some wallets use a boost::interprocess code or something, I'll check some of the older coins as well to see if it shows up there as well.

Looks to be something that is used for syncing the wallet, but better safe than sorry.
hero member
Activity: 532
Merit: 500
February 25, 2014, 11:08:05 AM
#9
Have this folder as well but no idea what it's for.

My only guess is that it's to do with the boost c++ library, which doesn't automatically make it suspicious, but it does concern me that only some wallets seem to use it.

I did a full sweep and nothing came up. Various google searches haven't been too clear either.
legendary
Activity: 1946
Merit: 1007
February 25, 2014, 11:04:11 AM
#8
Is there really nobody else that has this folder or knows more about it?
legendary
Activity: 1946
Merit: 1007
February 24, 2014, 06:43:44 PM
#7
thanks for the I.fo amph. anybody else has this folder/file?
legendary
Activity: 3248
Merit: 1070
February 24, 2014, 04:15:17 PM
#6
with malwarebyte, but now when i open ebt client, it will pop up again but without any files inside

When I open a wallet and scan the file using virustotal it comes out clean.. Still not sure what to think Shocked

yeah, problaby a virus residual or other shit
legendary
Activity: 1946
Merit: 1007
February 24, 2014, 03:57:19 PM
#5
with malwarebyte, but now when i open ebt client, it will pop up again but without any files inside

When I open a wallet and scan the file using virustotal it comes out clean.. Still not sure what to think Shocked
legendary
Activity: 3248
Merit: 1070
February 24, 2014, 03:45:06 PM
#4
with malwarebyte, but now when i open ebt client, it will pop up again but without any files inside
legendary
Activity: 1946
Merit: 1007
February 24, 2014, 03:39:44 PM
#3
How did you get rid of it?
legendary
Activity: 3248
Merit: 1070
February 24, 2014, 03:35:03 PM
#2
malwarebyte report it as a malicious, not the folder, i mean the file inside it when it is created

first time i found that was after installing rabbitcoin client
legendary
Activity: 1946
Merit: 1007
February 24, 2014, 03:28:05 PM
#1
Hi all,

I recently noticed that whenever I open a wallet on my pc, a file called bitcoinurl in the folder boost interprocess is created. Is this supposed to happen or could this be virus/trojan related?

I've always scanned doubtful wallets using virustotal, so I have a hard time believing this is malicious.

Could anyone please check there C:\ProgramData for a folder called boost interprocess? The file bitcoinurl is created whenever I open any wallet and is removed as soon as I close it.

Thanks!
Jump to: