Post
Topic
Board Bitcoin Discussion
Re: Beware! MultiPlatform Malware Try To Steal Your Wallet
by
Aditya
on 16/06/2014, 03:12:20 UTC
Tried on Windows 8.1

On Windows 8.1 The JAR file Run on single double-click without any warnings. No need to mark it as executable first. Anti Virus also doesn't show any warnings. I use Panda Internet Security 2014, latest update and no warning at all.

The malware installed itself on this Directory



Using Super Hidden Attribute, you can't see the file. Even you will not find FolrderName folder if you don't reveal it using attrib -s -h /s /d command. Turning on show hidden items doesn't reveal the malware.





The malware start itself up when infected user log in. You can view it on Task Manager under Start-up Tab, there is Java there.

Also the malware create a directory in C:\Users\<username>\.RsPJzZlzez

To manually remove, disable the start-up process and Delete that hidden folder (you have to use attrib -s -h /s /d command to reveal it)