Bitcoin Forum
June 28, 2024, 11:41:40 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 [4]  All
  Print  
Author Topic: EasyLTC--The Easiest Litecoin GUIMiner!  (Read 45340 times)
pgbit
Sr. Member
****
Offline Offline

Activity: 771
Merit: 258


Trident Protocol | Simple «buy-hold-earn» system!


View Profile
July 19, 2013, 05:43:18 PM
 #61

I get a trojan alert when running this software, any idea why?


The virus alerts that appear here involve:
(1) MULDROP.Trojan, for more details see here:
http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Trojan%3AWin32%2FClort.A.dr#tab=2

but the essence is this:
Launches MS08-067 Attack
When Trojan:Win32/Clort.A is executed, it creates a mutex named ‘2008-MS08-067_TEST’ and exits if it already exists. This trojan connects to a remote site to retrieve target information, or IP address range data for the trojan to attack. The data is retrieved from the domain address 'gsinvest.gov.cn/*******/VoteModiy.asp'.
 
Next, Win32/Clort.A executes %TEMP%\svchost.exe, attacking IP addresses provided by text from the page 'VoteModify.asp'. It tries to connect to port 139, and if successful, launches
 
%TEMP%\svchost.exe <IP address>
 
The attack attempts to locate vulnerable computers that have not applied Security Bulletin MS08-067.
 
Downloads Other Malware
If a target computer is exploited, Win32/Clort.A!exploit executes shell code that instructs the target to download TrojanDownloader:Win32/VB.CJ from the domain 'dabao8.net' as a file named 'cc.exe'. The downloaded trojan is then run.
 
Win32/VB.CJ is a trojan that downloads other malware. When run, it attempts to download TrojanDownloader:Win32/VB.CQ from the domain 'nowbt.net' as a file named 'cpa.exe'.
 
Downloads Adware
After TrojanDownloader:Win32/VB.CQ is downloaded it is run. It attempts to connect to the Web address 'cpa123.cn' and downloads adware.

(2) WS.Reputation.1
for symantec, the alert they have is for any new program, apparently:
http://community.norton.com/t5/Norton-Internet-Security-Norton/WS-Reputation-1-is-this-the-best-they-can-come-with/td-p/616601

Just to add, all LTC software I have ever downloaded gets auto deleted by my antivirus (Bitdefender). Other LTC miners tend to have more virus warnings. I would say that this is kinda off-putting. Someone PM me or post if they know a recognised LTC miner that, as a downloaded zip or whatever, is clean on virustotal.com. Other alt coins manage it.

██▄     ▄▄░
▀██▄ ▄██▀
▄▄███████████████████▄▄
▄█████▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
████▀                   ▀████
████       ▄▄█████▄▄  ▀▄   ████
████      ▄██████████▄▀    ████
████      ████████▀▀       ████
████  ▄▀ ▄██▀▀▀   ▄██      ████
████   ▀▀     ▄▄███▀       ████
████▄                   ▄████
▀█████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀▀███████████████████▀▀
.
SECONDLIVE
.
CHOOSE LIFE      CHOOSE SPACE      CHOOSE FRIENDS
.
|    Twitter    |  Telegram  |   Medium   |  YouTube  |   Discord   |    TikTok    |    GitHub    |
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
   S T A K E   L I T T L E   W I N   B I G   
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
        ▄▄███████▄▄▄
    ▄▄████████████████▄▄
   ████████████████████▄
  ███████▀▀▀█████████████
 ██████▌     ▀████████████
███████▀ ▀▀▄▄██▀▀▀█████████
██████             ▀███████
██████▄             ███████
 ███████▄▄        ▄███████
  ███████████▄▄▄▄█████████
   ▀███████████████████▀
     ▀████████████████▀▀
   ██████████████████████
Vorksholk (OP)
Legendary
*
Offline Offline

Activity: 1713
Merit: 1029



View Profile WWW
July 20, 2013, 03:59:57 AM
 #62

I get a trojan alert when running this software, any idea why?


The virus alerts that appear here involve:
(1) MULDROP.Trojan, for more details see here:
http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Trojan%3AWin32%2FClort.A.dr#tab=2

but the essence is this:
Launches MS08-067 Attack
When Trojan:Win32/Clort.A is executed, it creates a mutex named ‘2008-MS08-067_TEST’ and exits if it already exists. This trojan connects to a remote site to retrieve target information, or IP address range data for the trojan to attack. The data is retrieved from the domain address 'gsinvest.gov.cn/*******/VoteModiy.asp'.
 
Next, Win32/Clort.A executes %TEMP%\svchost.exe, attacking IP addresses provided by text from the page 'VoteModify.asp'. It tries to connect to port 139, and if successful, launches
 
%TEMP%\svchost.exe <IP address>
 
The attack attempts to locate vulnerable computers that have not applied Security Bulletin MS08-067.
 
Downloads Other Malware
If a target computer is exploited, Win32/Clort.A!exploit executes shell code that instructs the target to download TrojanDownloader:Win32/VB.CJ from the domain 'dabao8.net' as a file named 'cc.exe'. The downloaded trojan is then run.
 
Win32/VB.CJ is a trojan that downloads other malware. When run, it attempts to download TrojanDownloader:Win32/VB.CQ from the domain 'nowbt.net' as a file named 'cpa.exe'.
 
Downloads Adware
After TrojanDownloader:Win32/VB.CQ is downloaded it is run. It attempts to connect to the Web address 'cpa123.cn' and downloads adware.

(2) WS.Reputation.1
for symantec, the alert they have is for any new program, apparently:
http://community.norton.com/t5/Norton-Internet-Security-Norton/WS-Reputation-1-is-this-the-best-they-can-come-with/td-p/616601

Just to add, all LTC software I have ever downloaded gets auto deleted by my antivirus (Bitdefender). Other LTC miners tend to have more virus warnings. I would say that this is kinda off-putting. Someone PM me or post if they know a recognised LTC miner that, as a downloaded zip or whatever, is clean on virustotal.com. Other alt coins manage it.

Probably doesn't sound legit coming from me, but it's fine. I've seen reaper and cgminer get hung up by virus scanners. It's kinda dumb, but I think they were used in some botnets or something... Sad

VeriBlock: Securing The World's Blockchains Using Bitcoin
https://veriblock.org
freethebitcoin
Member
**
Offline Offline

Activity: 65
Merit: 10



View Profile
July 30, 2013, 06:52:43 PM
 #63

Probably doesn't sound legit coming from me, but it's fine. I've seen reaper and cgminer get hung up by virus scanners. It's kinda dumb, but I think they were used in some botnets or something... Sad

Well i was hoping the developer of the software would have a better explanation than:
Quote
It's kinda dumb, but I think they were used in some botnets or something... Sad

/ Don't waste time on another ASIC scam - Work, sell or build for Bitcoin and benefit all.
ScoMo
Newbie
*
Offline Offline

Activity: 49
Merit: 0


View Profile
November 10, 2013, 05:29:01 PM
Last edit: November 10, 2013, 05:53:38 PM by ScoMo
 #64

Hi, I'm new to LTC, what exactly is a 'pool worker'? When it asks me to enter pool worker, how do I know what to write in?
Edit: Also, I tried using the miner, but it's giving me 0 kH/s. How do I fix this?
Pages: « 1 2 3 [4]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!