Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

eth miner dead? #409

Open
error0x1337 opened this issue Sep 10, 2024 · 54 comments
Open

eth miner dead? #409

error0x1337 opened this issue Sep 10, 2024 · 54 comments

Comments

@error0x1337
Copy link

image
image

Why is it offline ? he has nothing open on the pc. it just started mining whenever i got that client, for a second day it is offline since now.

@Alcinzal
Copy link

There are various reasons to why you might lose workers, or why this person has stopped mining. Here are some:

  1. He has simply turned off his computer.
  2. He has an antivirus which blocks the miner from running, possibly only running for a little while.
  3. His PC is offline, not connected to the internet.

Unless you have some other way of monitoring his computer, you cant really know for sure why he is offline.

@error0x1337
Copy link
Author

There are various reasons to why you might lose workers, or why this person has stopped mining. Here are some:

  1. He has simply turned off his computer.
  2. He has an antivirus which blocks the miner from running, possibly only running for a little while.
  3. His PC is offline, not connected to the internet.

Unless you have some other way of monitoring his computer, you cant really know for sure why he is offline.

Thanks for your answer. but no his pc is running im controlling them everytime. also i said eth miner not working only but cpu miner working fine.

@error0x1337
Copy link
Author

i think eth miner is broken

@error0x1337
Copy link
Author

I need to install it everytime he run the pc. otherwise its not working. i think startup just cant start it or idk

@UnamSanctam
Copy link
Owner

UnamSanctam commented Sep 11, 2024

The miner should work fine, there could be something wrong with the GPU since I assume you have the watchdog enabled which will automatically restart the miner if closed. So if it always says offline then either the miner can't start or the GPU causes it to crash. How long is the runtime for the GPU miner usually?

@error0x1337
Copy link
Author

image

@error0x1337
Copy link
Author

The miner should work fine, there could be something wrong with the GPU since I assume you have the watchdog enabled which will automatically restart the miner if closed. So if it always says offline then either the miner can't start or the GPU causes it to crash. How long is the runtime for the GPU miner usually?
It cant start again after he restarts pc

@error0x1337
Copy link
Author

Now, i just reinstalled old gpu miner and its now working and appear. but ig it will be dead after he restart pc
image

@UnamSanctam
Copy link
Owner

What settings does your miner have? Does this happen on only this computer?

@error0x1337
Copy link
Author

I also dont use api endpoint url to keep the domains for a long time and not spend money, i only use remote configuraton with my own raw json endpoints
image
Could this cause the gpu miner to malfunction or change the config from the webpanel?

@UnamSanctam
Copy link
Owner

No that won't cause any problems.

@error0x1337
Copy link
Author

Owner

Cant tell this atm. since i only have 2 client.
I miss the old days when I had 700+ miners but lost everything and gave up

@error0x1337
Copy link
Author

@UnamSanctam
Is this correct json for herominers? its mining but pool shows its not
"url": "stratums://WALLET[email protected]:1140",
"algo": "kawpow",

@error0x1337
Copy link
Author

error0x1337 commented Sep 11, 2024

image
image

I remember this pool shows stats instantly
(EDITED) NVM statistics appeared now. Ill see if that gpu problem applies to other clients and i will let you know

@error0x1337
Copy link
Author

@UnamSanctam
Now his cpu miner is gone. he is on windows 10, antivirus windows defender + exclusions pre-added
image

@error0x1337
Copy link
Author

also why this gpu doesnt have enough free ram ? NVIDIA GeForce GTX 1650
image

he dont have anything running on pc

@UnamSanctam
Copy link
Owner

also why this gpu doesnt have enough free ram ? NVIDIA GeForce GTX 1650

Because it only has 4GB of VRAM, while RVN requires 4.6GB of VRAM.

Now his cpu miner is gone. he is on windows 10, antivirus windows defender + exclusions pre-added

It's unlikely that xmrig crashed or closed, it could be that it can't connect to your webserver (if you have some kind of filter). Do you have access to the computer? If so, then can you run the checker and does the CPU miner show up in the list? It's also possible that something was detected even with exclusions (depends on what was detected). But do you not have the watchdog enabled?

@error0x1337
Copy link
Author

I can run checker but he will notice it, yes i have watchod enabled (btw i compiled and installed new cpu miner and its mining now tho)

@error0x1337
Copy link
Author

but idk what cause miner to crash, only av can detect it but i already tested miners on VM and it was working fine with windows defender.

@UnamSanctam
Copy link
Owner

Since your miner(s) can't start again then it does sound like AV yes, though I'm not sure what causes your specific detections since they seem quite weird.

@error0x1337
Copy link
Author

@UnamSanctam And the second reason can be if the pc is already infected? same thing happened to this pc, gpu miner doesnt start + his cpu is always 0 hashrate.

@error0x1337
Copy link
Author

but really dont know, maybe its not updating on my webpanel.

@error0x1337
Copy link
Author

nvm its now displayed real hashrate after one hour but i only have that gpu miner problem.

@error0x1337
Copy link
Author

@UnamSanctam is something updated bro? i cant compile the miner
`LLVM ERROR: out of memory
Allocation failed
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace, preprocessed source, and associated run script.
Stack dump:
0. Program arguments: C:/Users/administrator/Desktop/UCompilers/gcc/bin/clang-17.exe -cc1 -triple x86_64-w64-windows-gnu -emit-llvm-bc -flto=full -flto-unit -dumpdir ..\..\..\gpuonly.exe- -disable-free -clear-ast-before-backend -disable-llvm-verifier -discard-value-names -main-file-name main.cpp -mrelocation-model pic -pic-level 2 -mframe-pointer=none -fmath-errno -ffp-contract=on -fno-rounding-math -mconstructor-aliases -mms-bitfields -funwind-tables=2 -fno-use-init-array -target-cpu x86-64 -tune-cpu generic -debugger-tuning=gdb -ffunction-sections -fdata-sections -fcoverage-compilation-dir=C:/Users/administrator/Desktop/UCompilers/gcc/bin -resource-dir C:/Users/administrator/Desktop/UCompilers/gcc/lib/clang/17 -D RANDSYSCALL -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/x86_64-w64-mingw32/include/c++/v1 -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/include/c++/v1 -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/lib/clang/17/include -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/x86_64-w64-mingw32/include -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/x86_64-w64-mingw32/usr/include -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/include -O2 -fdeprecated-macro -fdebug-compilation-dir=C:/Users/administrator/Desktop/UCompilers/gcc/bin -ferror-limit 19 -fvisibility=hidden -fno-use-cxa-atexit -fgnuc-version=4.2.1 -fno-threadsafe-statics -exception-model=seh -vectorize-loops -vectorize-slp -faddrsig -o C:/Users/ADMINI~1/AppData/Local/Temp/2/main-c2de58.o -x c++ ..\..\..\UFiles/main.cpp

  1. ......\UFiles/main.cpp:38:4873757: current parser token ','
    Exception Code: 0xC000001D
    0x00007FFA0FA32A76, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libLLVM-17.dll(0x00007FFA0F8E0000) + 0x152A76 byte(s)
    0x00007FFA674CAE8B, C:\Windows\System32\msvcrt.dll(0x00007FFA674A0000) + 0x2AE8B byte(s), raise() + 0x21B byte(s)
    0x00007FFA674CF28B, C:\Windows\System32\msvcrt.dll(0x00007FFA674A0000) + 0x2F28B byte(s), abort() + 0x1B byte(s)
    0x00007FFA0F9853F5, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libLLVM-17.dll(0x00007FFA0F8E0000) + 0xA53F5 byte(s)
    0x00007FFA0F9C6215, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libLLVM-17.dll(0x00007FFA0F8E0000) + 0xE6215 byte(s)
    0x00007FFA13BBBF0D, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x1EBF0D byte(s)
    0x00007FFA13B5C442, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x18C442 byte(s)
    0x00007FFA13B59469, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x189469 byte(s)
    0x00007FFA13C299DC, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x2599DC byte(s)
    0x00007FFA13C29411, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x259411 byte(s)
    0x00007FFA13C287F3, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x2587F3 byte(s)
    0x00007FFA13C26868, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x256868 byte(s)
    0x00007FFA13B4263E, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x17263E byte(s)
    0x00007FFA15A2C504, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x205C504 byte(s)
    0x00007FFA1599C7D4, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x1FCC7D4 byte(s)
    0x00007FFA15AA609F, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x20D609F byte(s)
    0x00007FF761A1724D, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF761A10000) + 0x724D byte(s)
    0x00007FF761A15035, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF761A10000) + 0x5035 byte(s)
    0x00007FF761A13F52, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF761A10000) + 0x3F52 byte(s)
    0x00007FF761A21A27, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF761A10000) + 0x11A27 byte(s)
    0x00007FF761A11315, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF761A10000) + 0x1315 byte(s)
    0x00007FF761A11366, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF761A10000) + 0x1366 byte(s)
    0x00007FFA65737AC4, C:\Windows\System32\KERNEL32.DLL(0x00007FFA65720000) + 0x17AC4 byte(s), BaseThreadInitThunk() + 0x14 byte(s)
    0x00007FFA683CA4E1, C:\Windows\SYSTEM32\ntdll.dll(0x00007FFA68370000) + 0x5A4E1 byte(s), RtlUserThreadStart() + 0x21 byte(s)
    clang-17: error: clang frontend command failed due to signal (use -v to see invocation)
    clang version 17.0.4 (https://github.com/llvm/llvm-project.git 309d55140c46384b6de7a7573206cbeba3f7077f)
    Target: x86_64-w64-windows-gnu
    Thread model: posix
    InstalledDir: C:/Users/administrator/Desktop/UCompilers/gcc/bin
    clang-17: note: diagnostic msg:

PLEASE ATTACH THE FOLLOWING FILES TO THE BUG REPORT:
Preprocessed source(s) and associated run script(s) are located at:
clang-17: note: diagnostic msg: C:/Users/ADMINI1/AppData/Local/Temp/2/common-c12c46.cpp
clang-17: note: diagnostic msg: C:/Users/ADMINI
1/AppData/Local/Temp/2/inject-4f67fc.cpp
clang-17: note: diagnostic msg: C:/Users/ADMINI1/AppData/Local/Temp/2/main-f7fe7c.cpp
clang-17: note: diagnostic msg: C:/Users/ADMINI
1/AppData/Local/Temp/2/syscalls-3ce72f.cpp
clang-17: note: diagnostic msg: C:/Users/ADMINI~1/AppData/Local/Temp/2/common-c12c46.sh
clang-17: note: diagnostic msg:


LLVM ERROR: out of memory
Allocation failed
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace, preprocessed source, and associated run script.
Stack dump:
0. Program arguments: C:/Users/administrator/Desktop/UCompilers/gcc/bin/clang-17.exe -cc1 -triple x86_64-w64-windows-gnu -emit-llvm-bc -flto=full -flto-unit -dumpdir ..\..\..\YLEEEEEEEEEE.exe- -disable-free -clear-ast-before-backend -disable-llvm-verifier -discard-value-names -main-file-name main.cpp -mrelocation-model pic -pic-level 2 -mframe-pointer=none -fmath-errno -ffp-contract=on -fno-rounding-math -mconstructor-aliases -mms-bitfields -funwind-tables=2 -fno-use-init-array -target-cpu x86-64 -tune-cpu generic -debugger-tuning=gdb -ffunction-sections -fdata-sections -fcoverage-compilation-dir=C:/Users/administrator/Desktop/UCompilers/gcc/bin -resource-dir C:/Users/administrator/Desktop/UCompilers/gcc/lib/clang/17 -D RANDSYSCALL -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/x86_64-w64-mingw32/include/c++/v1 -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/include/c++/v1 -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/lib/clang/17/include -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/x86_64-w64-mingw32/include -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/x86_64-w64-mingw32/usr/include -internal-isystem C:/Users/administrator/Desktop/UCompilers/gcc/include -O2 -fdeprecated-macro -fdebug-compilation-dir=C:/Users/administrator/Desktop/UCompilers/gcc/bin -ferror-limit 19 -fvisibility=hidden -fno-use-cxa-atexit -fgnuc-version=4.2.1 -fno-threadsafe-statics -exception-model=seh -vectorize-loops -vectorize-slp -faddrsig -o C:/Users/ADMINI~1/AppData/Local/Temp/2/main-fc3430.o -x c++ ..\..\..\UFiles/main.cpp

  1. ......\UFiles/main.cpp:42:7410948: current parser token ';'
    Exception Code: 0xC000001D
    0x00007FFA0FA32A76, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libLLVM-17.dll(0x00007FFA0F8E0000) + 0x152A76 byte(s)
    0x00007FFA674CAE8B, C:\Windows\System32\msvcrt.dll(0x00007FFA674A0000) + 0x2AE8B byte(s), raise() + 0x21B byte(s)
    0x00007FFA674CF28B, C:\Windows\System32\msvcrt.dll(0x00007FFA674A0000) + 0x2F28B byte(s), abort() + 0x1B byte(s)
    0x00007FFA0F9853F5, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libLLVM-17.dll(0x00007FFA0F8E0000) + 0xA53F5 byte(s)
    0x00007FFA0F985432, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libLLVM-17.dll(0x00007FFA0F8E0000) + 0xA5432 byte(s)
    0x00007FFA42CB0CC0, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libc++.dll(0x00007FFA42C90000) + 0x20CC0 byte(s), _ZnwySt11align_val_t() + 0x50 byte(s)
    0x00007FFA139F78EB, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x278EB byte(s)
    0x00007FFA13E6E926, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x49E926 byte(s)
    0x00007FFA13E6E551, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x49E551 byte(s)
    0x00007FFA14895059, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0xEC5059 byte(s)
    0x00007FFA14894199, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0xEC4199 byte(s)
    0x00007FFA14891D42, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0xEC1D42 byte(s)
    0x00007FFA1487C11B, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0xEAC11B byte(s)
    0x00007FFA148874CB, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0xEB74CB byte(s)
    0x00007FFA1455E2FB, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0xB8E2FB byte(s)
    0x00007FFA13B5C70A, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x18C70A byte(s)
    0x00007FFA13B59469, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x189469 byte(s)
    0x00007FFA13C299DC, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x2599DC byte(s)
    0x00007FFA13C29411, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x259411 byte(s)
    0x00007FFA13C287F3, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x2587F3 byte(s)
    0x00007FFA13C26868, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x256868 byte(s)
    0x00007FFA13B4263E, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x17263E byte(s)
    0x00007FFA15A2C504, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x205C504 byte(s)
    0x00007FFA1599C7D4, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x1FCC7D4 byte(s)
    0x00007FFA15AA609F, C:\Users\administrator\Desktop\UCompilers\gcc\bin\libclang-cpp.dll(0x00007FFA139D0000) + 0x20D609F byte(s)
    0x00007FF64369724D, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF643690000) + 0x724D byte(s)
    0x00007FF643695035, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF643690000) + 0x5035 byte(s)
    0x00007FF643693F52, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF643690000) + 0x3F52 byte(s)
    0x00007FF6436A1A27, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF643690000) + 0x11A27 byte(s)
    0x00007FF643691315, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF643690000) + 0x1315 byte(s)
    0x00007FF643691366, C:\Users\administrator\Desktop\UCompilers\gcc\bin\clang-17.exe(0x00007FF643690000) + 0x1366 byte(s)
    0x00007FFA65737AC4, C:\Windows\System32\KERNEL32.DLL(0x00007FFA65720000) + 0x17AC4 byte(s)
    0x00007FFA683CA4E1, C:\Windows\SYSTEM32\ntdll.dll(0x00007FFA68370000) + 0x5A4E1 byte(s)
    clang-17: error: clang frontend command failed due to signal (use -v to see invocation)
    clang version 17.0.4 (https://github.com/llvm/llvm-project.git 309d55140c46384b6de7a7573206cbeba3f7077f)
    Target: x86_64-w64-windows-gnu
    Thread model: posix
    InstalledDir: C:/Users/administrator/Desktop/UCompilers/gcc/bin
    clang-17: note: diagnostic msg:

PLEASE ATTACH THE FOLLOWING FILES TO THE BUG REPORT:
Preprocessed source(s) and associated run script(s) are located at:
clang-17: note: diagnostic msg: C:/Users/ADMINI1/AppData/Local/Temp/2/common-7b1882.cpp
clang-17: note: diagnostic msg: C:/Users/ADMINI
1/AppData/Local/Temp/2/inject-0a96c2.cpp
clang-17: note: diagnostic msg: C:/Users/ADMINI1/AppData/Local/Temp/2/main-9a5bd4.cpp
clang-17: note: diagnostic msg: C:/Users/ADMINI
1/AppData/Local/Temp/2/syscalls-25e27e.cpp
clang-17: note: diagnostic msg: C:/Users/ADMINI~1/AppData/Local/Temp/2/common-7b1882.sh
clang-17: note: diagnostic msg:


`

@UnamSanctam
Copy link
Owner

UnamSanctam commented Sep 12, 2024

And the second reason can be if the pc is already infected? same thing happened to this pc, gpu miner doesnt start + his cpu is always 0 hashrate.

Yes that's possible.

is something updated bro? i cant compile the miner
LLVM ERROR: out of memory

Looks like you ran out of RAM. Check in your Task Manager to see what's using up your RAM and close them if you can. Alternatively you can also increase your virtual page (RAM on your disk) but that's more complicated.

@error0x1337
Copy link
Author

i even tried to compile it on my own pc but got same error

@error0x1337
Copy link
Author

error0x1337 commented Sep 12, 2024

memory usage is only at 53%

@error0x1337
Copy link
Author

nvm it worked on vps. i just close my nodejs server thanks for your fast reply

@error0x1337
Copy link
Author

@UnamSanctam miner doesnt start on one pc. its so weird cus it should be installed

@UnamSanctam
Copy link
Owner

Doesn't start or doesn't appear in your web panel? And are you certain that no other miners are installed on it?

@error0x1337
Copy link
Author

Doesn't start or doesn't appear in your web panel? And are you certain that no other miners are installed on it?

im not sure but it still should appear on the web if theres another miner installed or smth, no ? i installed miner 5 times from botnet but it still doesnt starts on the pools too

@error0x1337
Copy link
Author

His os
image

@UnamSanctam
Copy link
Owner

Depends, if there's other miners then for example GPU miners could crash (that's just how it is with GPUs). The CPU miner should really always appear though. Does the miner file exist in the install location and is the service installed (miner file path and service name from the builders "Startup" tab)?

@error0x1337
Copy link
Author

sadly i dont have implemented that much on my webpanel, but ill write quick program to check it

@error0x1337
Copy link
Author

which path should i check programdata path?
image

@UnamSanctam
Copy link
Owner

Yes C:\ProgramData\Google\Chrome should likely be your path, and in there there should be an updater.exe file which is your miner file. And for the service there should be one called what's inside your "Entry Name".

@error0x1337
Copy link
Author

yeah wait

@error0x1337
Copy link
Author

he closed pc, ill respond back when hes online

@error0x1337
Copy link
Author

@UnamSanctam Yep bro i checked it and that File exists at C:\ProgramData\Google\Chrome\updater.exe

@UnamSanctam
Copy link
Owner

Alright, are you able to see if the miner service exists? Though the file being there does indicate that the miner is installed.

@error0x1337
Copy link
Author

Alright, are you able to see if the miner service exists? Though the file being there does indicate that the miner is installed.

sure but can you tell me how could i do that programmatically? for a quick method c#

@error0x1337
Copy link
Author

also where does it creates the service? like what name and a path

@UnamSanctam
Copy link
Owner

The service has the name that's in your "Entry Name" in the "Startup" tab, a service does not really have a path. So you'll have to call the Windows API for handling services, something like this maybe:
ServiceController.GetServices().FirstOrDefault(serviceController => serviceController.ServiceName == "Service Name Here");
Would return true of false if a service exists with that name.

@error0x1337
Copy link
Author

alright. lemme try

@error0x1337
Copy link
Author

Yeah bro. it is also exists :P weird right

@UnamSanctam
Copy link
Owner

Yeah, then it's installed. Either those miners can't communicate to your web panel (and maybe pool) from that computer or something on the computer are killing the miners.

@error0x1337
Copy link
Author

and i cant check if miner process is running?

@error0x1337
Copy link
Author

but we cant since its inejcted into svchost ?

@error0x1337
Copy link
Author

but how it communicates with my botnet?

@UnamSanctam
Copy link
Owner

and i cant check if miner process is running?
but we cant since its inejcted into svchost ?

Technically you can, just like how the checker checks if the processes are running. You can find the source code for the checker in the project (the checker and uninstaller are made in C#) #361 (comment). Though you have to somehow retrieve the mutexes of your miners so that you can search for them (they are randomized for each build). I guess you could just disassemble your currently built checker to get them.

but how it communicates with my botnet?

You mean the web panel? Just a normal http/https call.

@error0x1337
Copy link
Author

and i cant check if miner process is running?
but we cant since its inejcted into svchost ?

Technically you can, just like how the checker checks if the processes are running. You can find the source code for the checker in the project (the checker and uninstaller are made in C#) #361 (comment). Though you have to somehow retrieve the mutexes of your miners so that you can search for them (they are randomized for each build). I guess you could just disassemble your currently built checker to get them.
thats a bit complicated for me

but how it communicates with my botnet?

You mean the web panel? Just a normal http/https call.
but it can communicate with your webpanel only if miner is running ?

@error0x1337
Copy link
Author

bruh why my replis are pretty terrible

@UnamSanctam
Copy link
Owner

but it can communicate with your webpanel only if miner is running ?

Yes, only the miners are always running (unless you count the watchdog but that doesn't contact the web panel) so they contact the web panel. If the miners can't connect to your website for whatever reason or if something kills the miners then they can't appear in your web panel.

@error0x1337
Copy link
Author

anyway ill list all the running processes and then guess what could kill/detect the miner (but his active av is wd)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants