Bitcoin Forum
November 15, 2024, 11:24:13 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Trojan in Electrum wallet?  (Read 180 times)
Xal0lex (OP)
Staff
Legendary
*
Offline Offline

Activity: 2646
Merit: 2619



View Profile WWW
January 20, 2024, 06:15:49 PM
 #1

I downloaded a portable version of Electrum wallet from the official website. Checked it with VirusTotal service and one engine showed me that there is a trojan in the wallet. What do you think, is it true that the file from the official site may contain a trojan or is it a false positive of the Ikarus engine?



P.S. The Windows Installer version is clean, but the Standalone Executable version also has the same trojan.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
jrrsparkles
Sr. Member
****
Offline Offline

Activity: 2520
Merit: 280


Hire Bitcointalk Camp. Manager @ r7promotions.com


View Profile
January 20, 2024, 06:19:36 PM
Merited by pooya87 (2), nc50lc (1), hosseinimr93 (1)
 #2

Just one report, then it seems a false positive.

If you still worried about it then verifying it on your own is recommended : [GUIDE] How to Safely Download and Verify Electrum

How to verify your Electrum download

█████████████████████████████████
████████▀▀█▀▀█▀▀█▀▀▀▀▀▀▀▀████████
████████▄▄█▄▄█▄▄██████████▀██████
█████░░█░░█░░█░░████████████▀████
██▀▀█▀▀█▀▀█▀▀█▀▀██████████████▀██
██▄▄█▄▄█▄▄█▄▄█▄▄█▄▄▄▄▄▄██████████
██░░█░░█░░███████████████████████
██▀▀█▀▀█▀▀███████████████████████
██▄▄█▄▄█▄▄███████████████████████
██░░█░░█░░███████████████████████
██▀▀█▀▀█▀▀██████████▄▄▄██████████
██▄▄█▄▄█▄▄███████████████████████
██░░█░░█░░███████████████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
R7 PROMOTIONS Crypto Marketing Agency
By AB de Royse Campaign Management

███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████████████████████████████████████████████████████████████████████████████████████████
WIN $50 FREE RAFFLE
Community Giveaway

██████████████████████████████████████████████████████████████████████████████████████████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████████████████
██
██████████████████████
██████████████████▀▀████
██████████████▀▀░░░░████
██████████▀▀░░░▄▀░░▐████
██████▀▀░░░░▄█▀░░░░█████
████▄▄░░░▄██▀░░░░░▐█████
████████░█▀░░░░░░░██████
████████▌▐░░▄░░░░▐██████
█████████░▄███▄░░███████
████████████████████████
████████████████████████
████████████████████████
Bitcoin_Arena
Copper Member
Legendary
*
Offline Offline

Activity: 2128
Merit: 1814


฿itcoin for all, All for ฿itcoin.


View Profile
January 20, 2024, 11:04:47 PM
Merited by nc50lc (1)
 #3

Definitely a false positive. I have never even heard of Ikarus Antivirus before.  Grin

So false positives have been popping up in the past too if you explore the closed issues in Github. At one point, there were 9 AV engines that would flag electrum as a malware, but a fix was done to reduce on those false positive detections.

TheUltraElite
Legendary
*
Offline Offline

Activity: 3066
Merit: 1330


Going to reach LEET merits soon!


View Profile WWW
January 21, 2024, 06:02:12 AM
 #4

If it is from their official website, then highly unlikely to be a true positive AV flag.

A remote possibility of their site having been hacked and posted a malware bound software there.

Just one report, then it seems a false positive.

If you still worried about it then verifying it on your own is recommended : [GUIDE] How to Safely Download and Verify Electrum

How to verify your Electrum download
Verifying the signature does not completely rule out that possibility.

Hence that tingling spider sense of mine tells me that you should wait it out before operating that software. Mostly likely its false positive, but ..

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
tranthidung
Legendary
*
Offline Offline

Activity: 2464
Merit: 4279


Farewell o_e_l_e_o


View Profile WWW
January 21, 2024, 07:25:08 AM
 #5

I believe it is a false positive from Virustotal but to make sure, we must get official answer from Electrum team.

Can send a PM in bitcointalk to ThomasV or create an issue on Electrum Github or Electrum Twitter and wait for their team reply.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
khaled0111
Legendary
*
Offline Offline

Activity: 2716
Merit: 3060


Top Crypto Casino


View Profile WWW
January 21, 2024, 08:50:56 PM
Merited by Xal0lex (2)
 #6

If you have downloaded Electrum for the official website (electrum.org) then you should have read this note on the bottom of the download page:
Electrum binaries are often flagged by various anti-virus software. There is nothing we can do about it, so please stop reporting that to us. Anti-virus software uses heuristics in order to determine if a program is malware, and that often results in false positives.
There is no need to report this issue to devs team. They will most likely ignore it.

Verifying the signature does not completely rule out that possibility.
If you trust the signers (Electrum devs) and you have properly imported their public keys from trusted sources then verifying the gpg signature should be enough.


Abdussamad
Legendary
*
Offline Offline

Activity: 3682
Merit: 1580



View Profile
January 21, 2024, 09:15:43 PM
 #7

See "notes for windows users" at the bottom of the download page:

https://electrum.org/#download
Yamane_Keto
Hero Member
*****
Offline Offline

Activity: 630
Merit: 510



View Profile WWW
January 22, 2024, 03:02:24 AM
 #8

make sure to verify the signature with the wallet file that you downloaded. If the file is signed by the developer, do not pay attention to these warnings because they are false positive, else there is a virus that will redirect you outside electrum.org.

えいごをはなせますか。
keychainX
Member
**
Offline Offline

Activity: 378
Merit: 53

Telegram @keychainX


View Profile WWW
January 26, 2024, 08:30:44 AM
 #9

I downloaded a portable version of Electrum wallet from the official website. Checked it with VirusTotal service and one engine showed me that there is a trojan in the wallet. What do you think, is it true that the file from the official site may contain a trojan or is it a false positive of the Ikarus engine?



P.S. The Windows Installer version is clean, but the Standalone Executable version also has the same trojan.
¨

Windows flags several Bitcoin wallets as trojans.

NotATether
Legendary
*
Offline Offline

Activity: 1792
Merit: 7382


Top Crypto Casino


View Profile WWW
January 28, 2024, 04:09:58 AM
 #10

Also in addition to what keychainX said, if you got an app that is making lots of connections to random servers, as Electrum does for its network of SPV nodes, then any antivirus is going to think that is malicious activity, because that's what malware does too. Although I have no idea what kind of virus "Win32.Patched" is refering to in this context, and it doesn't help that different vendors give viruses completely illogical and meaningless names for them.

███████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████

███████████████████████
.
BC.GAME
▄▄▀▀▀▀▀▀▀▄▄
▄▀▀░▄██▀░▀██▄░▀▀▄
▄▀░▐▀▄░▀░░▀░░▀░▄▀▌░▀▄
▄▀▄█▐░▀▄▀▀▀▀▀▄▀░▌█▄▀▄
▄▀░▀░░█░▄███████▄░█░░▀░▀▄
█░█░▀░█████████████░▀░█░█
█░██░▀█▀▀█▄▄█▀▀█▀░██░█
█░█▀██░█▀▀██▀▀█░██▀█░█
▀▄▀██░░░▀▀▄▌▐▄▀▀░░░██▀▄▀
▀▄▀██░░▄░▀▄█▄▀░▄░░██▀▄▀
▀▄░▀█░▄▄▄░▀░▄▄▄░█▀░▄▀
▀▄▄▀▀███▄███▀▀▄▄▀
██████▄▄▄▄▄▄▄██████
.
..CASINO....SPORTS....RACING..


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!