Page 1 of 4

An unwanted guest?

Posted: 28 Aug 2013, 21:01
by DaveB
Hi Chaps :)

I took a saunter from Brunters this morning in FSX using a Ju52. Nothing much happening.. poodling along at around 135kts/5000ft. The intention was to make my way down to GCI but SWMBO got up (off nights) so I landed at the nearest airfield.. Exeter. Around 10mins before this, I noticed the FR's starting to fluctuate culminating in a 3-4fps stutter :-O I was goofing outside the aircraft at the time so quickly nipped inside and the stutter disappeared. A few mins later, off it went again.. lots of HD thrashing around and the FR's dropped to 4fps once more. I changed the zoom and was able to land.
I dunno what made me look but I opened Task Manager to see WTF was going on. My usual 40-odd processes were present but 1 caught my eye that appeared to be hogging the CPU (50) called btc-miner.exe. I sat for what seemed ages waiting for the CPU load to drop (a-n-other process was hogging 47 or so CPU useage) but it remained at almost 100%. A quick check online to see what btc-miner.exe might be has me confused no end. Google referenced BitCoin-Miner as a program and a virus/Trojan but I actually didn't find anything for btc-miner.exe. A search using 'FIND' found 2 references on my HD living in C:\WINDOWS\.. one in prefetch dated 28.8.13 - BTC-MINER.EXE-055E955C.PF and btc-miner.exe in dfrg dated 25.8.13. Despite dire warnings, I stopped btc-miner.exe in task manager and my CPU use dropped immediately.

I then ran a full virus scan of C:\WINDOWS and watched MSE gladly accept btc-miner.exe (though it did pause). Does anyone know what the hell it is? If it's a Trojan, MSE isn't phased by it :dunno:

I restarted Windows some time later and flashed up FSX with Task Manager running and flew around until btc-miner appeared or the FR's started dropping and all worked normally :wall: Now.. some while later, I've returned to the pc and flicked Task Manger on and there was btc-miner running again. I immediately stopped it and my cpu is wafting along at 0-1% while I'm here online. Should I panic or is this a bonafide program? If it is.. why the hell does it seem to hog so much CPU time :dunno:

ATB
DaveB B)smk

Re: An unwanted guest?

Posted: 28 Aug 2013, 21:39
by emfrat
Dave - you might find this worth a read, especially the summaries at the bottom of the main page. Personally I don't like the look of it. I don't welcome things which have been loaded into my 'poota without my knowledge or informed consent.
ATB
MikeW
http://www.tomshardware.com/reviews/bit ... ,3514.html

Re: An unwanted guest?

Posted: 28 Aug 2013, 23:14
by DaveB
Hi Mike :hello:

Thanks for that. I'm still not sure exactly what it is and have no idea where the hell it came from but I don't like it either. I found reference to another program in that article which I've seen running (tor.exe?). Hen's teeth.. if these things are malicious, why aren't they being flagged by MSE :dunno:

ATB
DaveB B)smk

Re: An unwanted guest?

Posted: 28 Aug 2013, 23:29
by TSR2
They're not malicious per say as they don't do any harm other than use your CPU cycles (which would be harm enough for me.) Is this on your XP machine Dave?

Re: An unwanted guest?

Posted: 28 Aug 2013, 23:30
by DaveB
Hello Mate :hello:

Yes.. it's on the XP pc.

ATB
Dave B)smk

Re: An unwanted guest?

Posted: 28 Aug 2013, 23:35
by TSR2
I'll need to check mate, but there's a wee niggling thought about MSE on XP... give me 5

Re: An unwanted guest?

Posted: 28 Aug 2013, 23:36
by DaveB
Okey doh :)

ATB
Dave B)smk

Re: An unwanted guest?

Posted: 28 Aug 2013, 23:42
by dfarrow
Dave , hope they've not brought XP retirement forward , without telling anyone !

Dave f .

Re: An unwanted guest?

Posted: 28 Aug 2013, 23:44
by DaveB
That same thought has gone through my mind Dave :worried:

ATB
Dave B)smk

Re: An unwanted guest?

Posted: 28 Aug 2013, 23:44
by TSR2
Check that your running the latest version of MSE, depending on the Windows update settings you may find that signatures are updating, but your not running the latest version of the product, so just go to the Microsoft site and download it again. I think the last version (of the main program) is version 4 on XP.