Bitcoin Forum

Economy => Scam Accusations => Topic started by: fixxi.net on March 31, 2013, 02:06:31 PM



Title: 50 btc miner virus detected
Post by: fixxi.net on March 31, 2013, 02:06:31 PM
Both Avira and Avast detect viruses in the 50Btc miner, are they really viruses ? Do they run mining on your pc without u knowing it ?

The 50 download from https://50btc.com includes this file

scrypt121016.cl

which is A BANK INFORMATION STEALER according to this:

http://www.averscanner.com/scan/a2/scrypt121016-cl.shtml

Other files in download also are reported viruses by those two AV programs.


Title: Re: 50 btc miner virus detected
Post by: Jocky on March 31, 2013, 02:29:33 PM
Thanks for reporting! I don't know anything about 50BTC miner, but I know it is important we share this info asap.


Title: Re: 50 btc miner virus detected
Post by: kinlo on March 31, 2013, 04:38:08 PM
Guys, it's just an antivirus vendor who just identified a scrypt decoder... I don't think it is a virus, I just think it is a bad virsuscanner...


Title: Re: 50 btc miner virus detected
Post by: crazyates on March 31, 2013, 08:32:46 PM
We have 2 problems here.

1) A lot of BTC mining softwares have been falsely identified as viruses in the past. For example, CGMiner used to have issues with a number of antivirus softwares, and was a false positive. Luckily, CGMiner is open source, so people can build from source and verify that there is nothing malicious going on in the background.

Related to this note: I previously ran my BTC client (on a separate computer that I mine on) with the default 8 connections. I forwarded port 8332, and went up to about 30 connections. Within a week, I got a letter from my ISP warning me that one of my computers had been infected with a botnet. Seems Comcast doesn't like the increase in network activity.

2) Unlike CGMiner, 50BTC miner is NOT open source. There is no way to prove that there really isn't anything malicious going on. For all we know, it really could be a bank information stealer or a keylogger or something. The source code for 50BTC miner has been requested, but those requests have been denied.

Safest option: switch to CGMiner, which can still be used with the 50BTC pool and website. If CGMiner is too complicated for you (like the thought of a command line or terminal scares you), then switch to BitMinter pool and mining software. They have a nice, easy to use program that also works with most GPUs and FPGAs. They have said they will also work with ASICs, too.


Title: Re: 50 btc miner virus detected
Post by: j980 on March 31, 2013, 08:50:32 PM
The scryptXXX.cl file contains only OpenCL code for the scrypt hasher, and it does not seem to include anything that steals bank information.   Other files in the package might still contain a virus.  Compiling from source provides better protection against virus infections.