EVGA

System hacked cards used to take over and mine crypto

Author
RoyTyrell
New Member
  • Total Posts : 40
  • Reward points : 0
  • Joined: 2018/01/10 08:56:00
  • Status: offline
  • Ribbons : 0
2018/01/18 14:25:12 (permalink)
Was unable to modify numerous errors regarding directx. Finally deleted xprecision profile files along with uninstall and all cards were operating at max base clock. Completely hidden in profile folder. Was unable to update GeForce Experience.

3 1080 ti’s were cranking it out and running hot with just simple visual studio running.

Working with AV to hunt down. Too many screenshots for here.

Just fyi
#1

24 Replies Related Threads

    RoyTyrell
    New Member
    • Total Posts : 40
    • Reward points : 0
    • Joined: 2018/01/10 08:56:00
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/18 14:27:04 (permalink)
    Reinstalling entire system
    #2
    AHowes
    CLASSIFIED ULTRA Member
    • Total Posts : 6681
    • Reward points : 0
    • Joined: 2005/09/20 15:38:10
    • Location: Macomb MI
    • Status: offline
    • Ribbons : 27
    Re: System hacked cards used to take over and mine crypto 2018/01/18 14:31:23 (permalink)
    ?? How do you know it was hacked for mining?

    Intel i9 9900K @ 5.2Ghz Single HUGE Custom Water Loop.
    Asus Z390 ROG Extreme XI MB
    G.Skill Trident Z 32GB (4x8GB) 4266MHz DDR4 
    EVGA 2080ti K|NGP|N w/ Hydro Copper block.  
    34" Dell Alienware AW3418DW 1440 Ultra Wide GSync Monitor
    Thermaltake Core P7 Modded w/ 2x EK Dual D5 pump top,2 x EK XE 480 2X 360 rads.1 Corsair 520 Rad.
    #3
    RoyTyrell
    New Member
    • Total Posts : 40
    • Reward points : 0
    • Joined: 2018/01/10 08:56:00
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/18 14:44:07 (permalink)
    That is admittedly a guess. The rest of the system aside from gpu processes were minimally effected.

    Were they being used for atomic research by North Korea? (I’m being facetious of course).

    They weren’t being used by me. I had nothing running, nothing debugging after a clean shut down and restart.

    This is just an fyi. I’m pretty sure it was infected from a nonstandard benchmark. It was not ransomware. But it was persistently hiding gpu usage.

    I would not download anything other than 3dmark. I made the mistake of downloading from a third party download site.

    Read into it what you will.
    post edited by RoyTyrell - 2018/01/18 14:47:05
    #4
    HeavyHemi
    Insert Custom Title Here
    • Total Posts : 15665
    • Reward points : 0
    • Joined: 2008/11/28 20:31:42
    • Location: Western Washington
    • Status: offline
    • Ribbons : 135
    Re: System hacked cards used to take over and mine crypto 2018/01/18 15:11:52 (permalink)
    RoyTyrell
    That is admittedly a guess. The rest of the system aside from gpu processes were minimally effected.

    Were they being used for atomic research by North Korea? (I’m being facetious of course).

    They weren’t being used by me. I had nothing running, nothing debugging after a clean shut down and restart.

    This is just an fyi. I’m pretty sure it was infected from a nonstandard benchmark. It was not ransomware. But it was persistently hiding gpu usage.

    I would not download anything other than 3dmark. I made the mistake of downloading from a third party download site.

    Read into it what you will.

    There are a lot of mining virii out there.  A wipe and clean install is your safest (which apparently you're doing) solution.

    EVGA X99 FTWK / i7 6850K @ 4.5ghz / RTX 3080Ti FTW Ultra / 32GB Corsair LPX 3600mhz / Samsung 850Pro 256GB / Be Quiet BN516 Straight Power 12-1000w 80 Plus Platinum / Window 10 Pro
     
    #5
    FBHERO
    New Member
    • Total Posts : 64
    • Reward points : 0
    • Joined: 2018/01/18 17:18:07
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/18 17:19:41 (permalink)
    Wipe and Clean install is the ONLY way to fix the issue. 
    #6
    squall-leonhart
    CLASSIFIED Member
    • Total Posts : 2904
    • Reward points : 0
    • Joined: 2009/07/27 19:57:03
    • Location: Australia
    • Status: offline
    • Ribbons : 24
    Re: System hacked cards used to take over and mine crypto 2018/01/19 05:15:34 (permalink)
    garbage, any user can track down this kind of infection with a few simple tools and manually remove them using ACL's.

    CPU:Intel Xeon x5690 @ 4.2Ghz, Mainboard:Asus Rampage III Extreme, Memory:48GB Corsair Vengeance LP 1600
    Video:EVGA Geforce GTX 1080 Founders Edition, NVidia Geforce GTX 1060 Founders Edition
    Monitor:BenQ G2400WD, BenQ BL2211, Sound:Creative XFI Titanium Fatal1ty Pro
    SDD:Crucial MX300 275, Crucial MX300 525, Crucial MX300 1000
    HDD:500GB Spinpoint F3, 1TB WD Black, 2TB WD Red, 1TB WD Black
    Case:NZXT Phantom 820, PSU:Seasonic X-850, OS:Windows 7 SP1
    Cooler: ThermalRight Silver Arrow IB-E Extreme
    #7
    RoyTyrell
    New Member
    • Total Posts : 40
    • Reward points : 0
    • Joined: 2018/01/10 08:56:00
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/19 05:59:57 (permalink)
    squall-leonhart
    garbage, any user can track down this kind of infection with a few simple tools and manually remove them using ACL's.


    I’ll play nice and simply say it does not work that way.

    Tools are designed to remove specific virus. I promise you I could design a virus you would not be able to remove with any existing tool. But then, that would be a felony ;-)
    post edited by RoyTyrell - 2018/01/19 06:27:20
    #8
    squall-leonhart
    CLASSIFIED Member
    • Total Posts : 2904
    • Reward points : 0
    • Joined: 2009/07/27 19:57:03
    • Location: Australia
    • Status: offline
    • Ribbons : 24
    Re: System hacked cards used to take over and mine crypto 2018/01/19 07:23:15 (permalink)
    I'll be nice and call you ignorant.

    I remove mining malware as part of my work, none of them can get so deep in the system that they are untrackable with file and process monitors and stopped in their tracks with the removal of execution priviledges.

    CPU:Intel Xeon x5690 @ 4.2Ghz, Mainboard:Asus Rampage III Extreme, Memory:48GB Corsair Vengeance LP 1600
    Video:EVGA Geforce GTX 1080 Founders Edition, NVidia Geforce GTX 1060 Founders Edition
    Monitor:BenQ G2400WD, BenQ BL2211, Sound:Creative XFI Titanium Fatal1ty Pro
    SDD:Crucial MX300 275, Crucial MX300 525, Crucial MX300 1000
    HDD:500GB Spinpoint F3, 1TB WD Black, 2TB WD Red, 1TB WD Black
    Case:NZXT Phantom 820, PSU:Seasonic X-850, OS:Windows 7 SP1
    Cooler: ThermalRight Silver Arrow IB-E Extreme
    #9
    Athena
    iCX Member
    • Total Posts : 328
    • Reward points : 0
    • Joined: 2016/11/04 12:05:53
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/19 11:47:35 (permalink)
    squall-leonhart
    I'll be nice and call you ignorant.

    I remove mining malware as part of my work, none of them can get so deep in the system that they are untrackable with file and process monitors and stopped in their tracks with the removal of execution priviledges.


    That would not be "any user" then would it.  lol
     
    As an IT manager I am often asked "would it be easy for you to blah blah blah?"
    "Yes"
    "Then why can't I do this?"
    "Are you a post graduate trained Computer Science major with over 20 years experience or a bank teller that deep down could care less about computers and technology?"
    #10
    squall-leonhart
    CLASSIFIED Member
    • Total Posts : 2904
    • Reward points : 0
    • Joined: 2009/07/27 19:57:03
    • Location: Australia
    • Status: offline
    • Ribbons : 24
    Re: System hacked cards used to take over and mine crypto 2018/01/19 20:32:21 (permalink)
    Any user could do it, it's not something that requires binary understanding.
     
    All of the crypto malwares once installed use a trojan registered as either
     
    shell loaded dll
    windows service
    system service
     
    Which downloads an executable to a random location on the system.  This executable is often run as a scheduled task with termination events. It usually has a self defense mechanism which automatically repairs a removal attempt of the trojan loader so in order to get it you have to edit the ownership and permissions of the files to revoke execution status after identifying all of the files.

    most of the time you only need autoruns and gpu-shark to spot a crypto malware as it uses service names that try to look like real windows services while operating in a user directory.

    CPU:Intel Xeon x5690 @ 4.2Ghz, Mainboard:Asus Rampage III Extreme, Memory:48GB Corsair Vengeance LP 1600
    Video:EVGA Geforce GTX 1080 Founders Edition, NVidia Geforce GTX 1060 Founders Edition
    Monitor:BenQ G2400WD, BenQ BL2211, Sound:Creative XFI Titanium Fatal1ty Pro
    SDD:Crucial MX300 275, Crucial MX300 525, Crucial MX300 1000
    HDD:500GB Spinpoint F3, 1TB WD Black, 2TB WD Red, 1TB WD Black
    Case:NZXT Phantom 820, PSU:Seasonic X-850, OS:Windows 7 SP1
    Cooler: ThermalRight Silver Arrow IB-E Extreme
    #11
    Blitqz
    New Member
    • Total Posts : 23
    • Reward points : 0
    • Joined: 2018/01/20 10:39:57
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/20 10:58:46 (permalink)
    So wait, let me get this straight.
     
    You're saying that some malware hacked into your computer and is using your gpus for mining cryptocurrency?
    #12
    soimusan
    New Member
    • Total Posts : 16
    • Reward points : 0
    • Joined: 2013/07/21 19:11:15
    • Location: Here
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/20 11:14:12 (permalink)
    Blitqz
    So wait, let me get this straight.
     
    You're saying that some malware hacked into your computer and is using your gpus for mining cryptocurrency?




     No, he said the miner was hidden in an installer he downloaded from some random website. He downloaded the benchmark and during the installation of the benchmark the miner was installed too.
     
    post edited by soimusan - 2018/01/20 11:17:01
    #13
    RoyTyrell
    New Member
    • Total Posts : 40
    • Reward points : 0
    • Joined: 2018/01/10 08:56:00
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/21 20:06:21 (permalink)
    Downloaded and installed what appeared to be furmark from a spoofing site.

    I suppose leonard must be a billionaire since he is so much smarter than kaspersky. A COM service can piggy back off of any process - even legitimate ones and even hidden from task manager.

    And yes, I could pound your system with one and you would never know it. If you download the wrong activex control - I could own you.

    But then that’s where folks like kaspersky come in.
    post edited by RoyTyrell - 2018/01/21 20:15:51
    #14
    XrayMan
    Insert Custom Title Here
    • Total Posts : 73000
    • Reward points : 0
    • Joined: 2006/12/14 22:10:06
    • Location: Santa Clarita, Ca.
    • Status: offline
    • Ribbons : 115
    Re: System hacked cards used to take over and mine crypto 2018/01/21 20:22:08 (permalink)
     
    Moved to Crypto.

                My Affiliate Code: 8WEQVXMCJL
     
            Associate Code: VHKH33QN4W77V6A
     
                 
     
     
                      
     
     
     
              
     
       
     
               
     
     
     
     
     
     
     
     
     
     
     
     
     
     
     



     
     
     
     
     
     &nbsp
    #15
    QuintLeo
    SSC Member
    • Total Posts : 946
    • Reward points : 0
    • Joined: 2016/04/16 23:05:09
    • Status: offline
    • Ribbons : 3
    Re: System hacked cards used to take over and mine crypto 2018/01/22 21:19:32 (permalink)
    And that's WHY you don't trust software that is downloaded from sites that aren't trustworthy.
     

    Now that vorsholk has stopped his abuse, I'm returning to folding.
     I no longer MOO due to abuses by certain "whales" in the Gridcoin community - so I now work the Distributed.net project directly again.
     
    #16
    badFerret
    Superclocked Member
    • Total Posts : 101
    • Reward points : 0
    • Joined: 2018/01/24 22:27:36
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/25 07:47:07 (permalink)
    I create a base install with imaging software and just do a clean wipe one a year or so or when it seems to be slower than normal.  Always makes me feel safer and seems to make it run faster for a while....but i am using windows.  It is a pain to redo all the updates, but it makes up for it cause it see small increase in hashing (at least for a while).  Macrium reflect is a free one that seems to work ok, but i've been using an old norton ghost image for a long time.
     
    And of course all paper wallets i make are done using an old clunker i have around USB booting into ubuntu trial version while offline...that computer never gets online and it doesn't even have a non-USB OS on it.

     



     
    #17
    FBHERO
    New Member
    • Total Posts : 64
    • Reward points : 0
    • Joined: 2018/01/18 17:18:07
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/28 14:03:30 (permalink)
    check you address, then worry.
    #18
    SierraWolf117
    Superclocked Member
    • Total Posts : 114
    • Reward points : 0
    • Joined: 2018/01/27 13:09:15
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/28 22:20:23 (permalink)
    badFerret
    I create a base install with imaging software and just do a clean wipe one a year or so or when it seems to be slower than normal.  Always makes me feel safer and seems to make it run faster for a while....but i am using windows.  It is a pain to redo all the updates, but it makes up for it cause it see small increase in hashing (at least for a while).  Macrium reflect is a free one that seems to work ok, but i've been using an old norton ghost image for a long time.
     
    And of course all paper wallets i make are done using an old clunker i have around USB booting into ubuntu trial version while offline...that computer never gets online and it doesn't even have a non-USB OS on it.


    Do you have links to the software, I think I'd like to do this at some point soon but I hate having to do fresh installs. At least a base image with some programs where I want them would be better the next time I get around to doing a clean wipe.
    #19
    Noxnoctis1976
    Superclocked Member
    • Total Posts : 117
    • Reward points : 0
    • Joined: 2018/01/25 11:22:56
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/29 08:46:20 (permalink)
    Only going to get worse as mining mania grips the world.
    #20
    EchofoxtrotFTW
    New Member
    • Total Posts : 99
    • Reward points : 0
    • Joined: 2017/12/25 09:51:10
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/29 11:30:39 (permalink)
    ohh my god my computer is not even built yet and im wooried
    #21
    SuperSchnitzel
    New Member
    • Total Posts : 60
    • Reward points : 0
    • Joined: 2018/01/28 11:05:44
    • Location: South Florida
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/29 13:01:58 (permalink)
    squall-leonhart
    Any user could do it, it's not something that requires binary understanding.
     
    All of the crypto malwares once installed use a trojan registered as either
     
    shell loaded dll
    windows service
    system service
     
    Which downloads an executable to a random location on the system.  This executable is often run as a scheduled task with termination events. It usually has a self defense mechanism which automatically repairs a removal attempt of the trojan loader so in order to get it you have to edit the ownership and permissions of the files to revoke execution status after identifying all of the files.

    most of the time you only need autoruns and gpu-shark to spot a crypto malware as it uses service names that try to look like real windows services while operating in a user directory.


    what if its in a blocked off folder? i.e. refusing admin access
    #22
    bcavnaugh
    The Crunchinator
    • Total Posts : 38977
    • Reward points : 0
    • Joined: 2012/09/18 17:31:18
    • Location: USA Affiliate E5L3CTGE12 Associate 9E88QK5L7811G3H
    • Status: offline
    • Ribbons : 282
    Re: System hacked cards used to take over and mine crypto 2018/01/29 13:10:42 (permalink)
    I do love Jagerschnitzel

    Associate Code: 9E88QK5L7811G3H


     
    #23
    SuperSchnitzel
    New Member
    • Total Posts : 60
    • Reward points : 0
    • Joined: 2018/01/28 11:05:44
    • Location: South Florida
    • Status: offline
    • Ribbons : 0
    Re: System hacked cards used to take over and mine crypto 2018/01/29 13:24:00 (permalink)
    German cuisine is awesome
    #24
    bcavnaugh
    The Crunchinator
    • Total Posts : 38977
    • Reward points : 0
    • Joined: 2012/09/18 17:31:18
    • Location: USA Affiliate E5L3CTGE12 Associate 9E88QK5L7811G3H
    • Status: offline
    • Ribbons : 282
    Re: System hacked cards used to take over and mine crypto 2018/01/29 13:29:29 (permalink)
    SuperSchnitzel
    German cuisine is awesome


    But the Bread is the Best next to the Beer.
    Stuttgarter Hofbräu Pilsner Best Beer in the World, at least back in the Day of the West and East.

    Associate Code: 9E88QK5L7811G3H


     
    #25
    Jump to:
  • Back to Mobile