Thanks Frank. I'm using BAMT from a usb stick and nothing else has ever been installed on this. Furthermore, because we were on vacation, other computers in the local network were shut down, and my home router is tiered with a second home router, so to get access to this machine someone would have had to have hacked through two routers/firewalls.... My miner is currently resolving us.clevermining.com fine, but its possible that dns was poisoned temporarily at the ISP level to trick my miner into resolving to a different IP. I found
using netstat that the only connection to an external IP was to 46.28.205.80:3333 from Zurich (
http://www.iplookup.ca/46.28.205.80 ). Clearly they somehow tricked the miner into connecting to that IP address. I have tons to catch up on after being out for almost 2 weeks so I haven't read up all the thread on this, but the speculation that it was some malicious software we downloaded is simply not possible. It had to be either a DNS hijacking, or the BAMT software has a backdoor, or possibly clevermining purposely resolved us to this new IP. No other possibility in my mind. Very suspicious of BAMT as well as clevermining... Since the dns is hosted by cloudflare, it could have been someone at cloudflare too. I may start specifying the IP in my cgminer.conf rather than the us.clevermining.com address. That should eliminate the DNS hijacking possibility.
Anyways, thanks for pointing me to the beginning of that thread.
Rob
Not affiliated with Clevermining... just a user but this sounds like your miner was redirected. Read this thread starting around the bottom of page 153 for what likely happened to your miner.
Basically, a bunch of miners from a bunch of different pools got redirected to a different IP address. There were a bunch of correlations people found, but no one ever found -THE- cause as far as I can tell. Anyone who got redirected were essentially mining for free at a pool stealing hashrate.
Restarting the miner at a minimum will fix it at least temporarily. I have not seen anyone complain about being redirected in at least a few days so maybe the root cause has been solved.