Do yourself a favor and check you pc of BitCoin minners

Discussion in 'Lounge' started by virusg, Jan 30, 2016.

  1. virusg

    virusg Rock Star

    Joined:
    Jan 4, 2012
    Messages:
    988
    Likes Received:
    401
    Location:
    near you
    ...as you read, just about yesterday cleaned my freshly installed system of a miner ...there must be a program ive installed with it ...dont know winch but from now on ill check more often ...it was using my cpu and Gpu to almost 80% ...the name of this was cfthost.exe and was located in a very strange place on my ssd ...installed hwmonitor to see whats going on with the whole hardware and infact the gpu was picking 80% with high temps 60 degrees C ...the cpu was indicating 53 C ...just what the hell!!! ...after cleanning it with Malwarebytes and rescanned, restarted the system like 3 times all was back to normal ...please even if you are not connected to the net it can be there using you hw almost to the max ...just check it !
     
    Last edited: Jan 30, 2016
    • Interesting Interesting x 4
    • Like Like x 3
    • Useful Useful x 1
    • List
  2.  
  3. SineWave

    SineWave Audiosexual

    Joined:
    Sep 4, 2011
    Messages:
    4,612
    Likes Received:
    3,776
    Location:
    Where the sun doesn't shine.
    No need to check anything as I use Debian Linux for Internet. :wink:

    I would rely on Malwarebytes and nothing else on Windows. Just scan occasionally with it.

    Good luck :mates: !
     
    • Like Like x 1
    • Funny Funny x 1
    • List
  4. RMorgan

    RMorgan Audiosexual

    Joined:
    May 17, 2014
    Messages:
    649
    Likes Received:
    516
    Utorrent was installing one of these bastards a while ago. Thankfully, the unusual GPU fan noise tipped me that something was wrong. That's why I've changed to Tixati and never looked back.

    Anyway, if you really want to be on the safe side, do yourself a favor and buy Hitman Pro. It does a very quick scan on startup and has the best detection rates around. It's better than Malwarebytes, in my opinion.

    Also, please, use a firewall. I've been using Glasswire, which is very simple and intuitive, along with Windows native firewall. It's a great combo.
     
    Last edited: Jan 30, 2016
    • Like Like x 3
    • Interesting Interesting x 1
    • List
  5. dreaded

    dreaded Newbie

    Joined:
    Nov 19, 2011
    Messages:
    11
    Likes Received:
    1
    Location:
    Lower Alabama
    Great find. I've been looking for a small-footprint firewall. You uncovered a gem here.
     
    • Like Like x 1
    • Agree Agree x 1
    • List
  6. wuzzle

    wuzzle Rock Star

    Joined:
    Nov 28, 2014
    Messages:
    518
    Likes Received:
    322
    Location:
    Lesser Galactic Co-ordinates: Earth (0.0.0)
    Yeah I too had questionable stuff appear after using utorrent. Sad really because I liked that app. Another free safe app to check out is http://www.qbittorrent.org/if you need a win-based torrent client.
     
  7. HPF

    HPF Kapellmeister

    Joined:
    Jun 23, 2012
    Messages:
    201
    Likes Received:
    56
    Location:
    Block 4
    there are even jscripts in webpages doing mining so watch out for suspicious cpu peaks on sites.
     
  8. yomav

    yomav Ultrasonic

    Joined:
    May 31, 2023
    Messages:
    139
    Likes Received:
    22
    It sounds like you encountered some malicious software using a significant portion of your CPU and GPU resources. The cfthost.exe process was likely part of a miner or unwanted program installed without your knowledge. It's good that you used Malwarebytes to clean it up. Moving forward, make sure to regularly scan your system with trusted security software, avoid downloading questionable programs, and monitor your hardware for any unusual activity.
     
  9. Djord Emer

    Djord Emer Audiosexual

    Joined:
    Sep 12, 2021
    Messages:
    1,097
    Likes Received:
    925
    Just be glad it was a bitcoin miner and not an infostealer. :mates:
     
  10. shinyzen

    shinyzen Audiosexual

    Joined:
    Sep 28, 2023
    Messages:
    1,110
    Likes Received:
    688
    A miner needs to be connected to the internet, how would it confirm blocks if it wasnt connected to the network?

    Either way, glad you found it, and that it wasnt something more malicious.

    Fun fact, i was mining btc in 2013 for fun but sold in the 2017 bull.

    I had a substantial amount leftover, but lost it like an idiot. i didnt take it as seriously back then, and did not backup my keys. if i didnt sell, and didnt lose the rest, id have 10 or 20 million worth at todays rate. fun stuff. :(
     
    • Interesting Interesting x 1
    • List
  11. Usr4321

    Usr4321 Kapellmeister

    Joined:
    Mar 27, 2025
    Messages:
    87
    Likes Received:
    40
    Most regret stories are like... I spent 45 btc on pizza hut when they were .25 to .50 cents.

    From 13 to 17 it nearly did 2000x. Been a measly 5x since. You didn't miss anything. :)
     
  12. virusg

    virusg Rock Star

    Joined:
    Jan 4, 2012
    Messages:
    988
    Likes Received:
    401
    Location:
    near you
    well I remember I found keys for Ethereum ...deleted them:suicide: I dont even know what to do with that stuff... we just woke a thread from 7 yrs ago :crazy:

    PS: I believe Ethereum could be mined offline and compare the results when connecting, at least I read that somewhere sometimes
     
  13. saccamano

    saccamano Audiosexual

    Joined:
    Mar 26, 2023
    Messages:
    1,718
    Likes Received:
    716
    Location:
    CBGB omfug
    :rofl:
    You think linux is going to protect you from virus/malware?? :no: That's about as naive as the apple folks saying the apple OS is invulnerable to the same. It isn't and neither is any *NIX system... You might wanna Chek yourself before you Wrek yourself on that one... Maybe do a web search on *NIX vulnerabilities - just FYI, there's a lot to discover.
     
    • Winner Winner x 2
    • Like Like x 1
    • Agree Agree x 1
    • Interesting Interesting x 1
    • List
  14. ArticStorm

    ArticStorm Moderator Staff Member

    Joined:
    Jun 7, 2011
    Messages:
    8,295
    Likes Received:
    4,324
    Location:
    AudioSexPro
    i dont need to, i check taskmgr daily and i also monitor fan speed, CPU temp and SSD Temps and investigate, when the computer produces lots of heat.

    just yesterday i had a local host service in windows using one core in my CPU, turn out windows store installer service was doing shit again, so i deactivated it permantely. It was not possible to find out, what was going on.

    Right now my computer here is idle and 15C over room temperature.
     
  15. paul_audioz

    paul_audioz Kapellmeister

    Joined:
    Feb 21, 2023
    Messages:
    155
    Likes Received:
    63
    Would you like to elaborate on this? I googled it but apparently I am not smart enough to even remotely understand what this is and how I can detect (or better: prevent!) it on my Linux MX21 system?
     
  16. Somnambulist

    Somnambulist Audiosexual

    Joined:
    Aug 27, 2024
    Messages:
    663
    Likes Received:
    548
    A.I.DDS

    It's sneaky.
     
  17. aleksalt

    aleksalt Producer

    Joined:
    Jul 1, 2013
    Messages:
    474
    Likes Received:
    135
    Task manager doesn't show all processes running on PC, I use Process explorer, it shows near 3 times more processes than TM,
    but still some suspectful processes appear on my PC just for a moment (less than 1 second) they are marked with red in PE,
    Mawarebytes? I scanned with it my PC few days ago, but still those red lines appear in PE
     
    • Interesting Interesting x 1
    • List
  18. ArticStorm

    ArticStorm Moderator Staff Member

    Joined:
    Jun 7, 2011
    Messages:
    8,295
    Likes Received:
    4,324
    Location:
    AudioSexPro
    i do additional things as i wrote above, which show if something is using extensive resources and produces a lot of heat.
     
  19. xorome

    xorome Audiosexual

    Joined:
    Sep 28, 2021
    Messages:
    1,416
    Likes Received:
    1,060
    If you install the program in my signature, I'll check your PC for you, for free - perpetually.
     
Loading...
Similar Threads - yourself favor check Forum Date
Why Torture Yourself with Updates Lounge Feb 14, 2025
Love Yourself Music Aug 9, 2023
Which Three Synths Can You Limit Yourself To? Samplers, Synthesizers May 3, 2022
[Poll] Do you consider yourself Talented ? Lounge May 6, 2020
Teaching Yourself to Make Music Software: Steve Duda in Conversation | Loop Lounge Nov 25, 2019
Loading...