So, let's debunk this one LAST time.(I could almost make a f'n dayjob out off this...
)
According to a well known online AV scan gatherer
54, of 56, online AV scanners returned that
the Windows 32bit executable of Slothcoin 1.3.1 build 3 is CLEAN! They have a sign for that a:
V. And here is the list, according to that online AV scanner gatherer:
ALYac
AVG
AVware
Ad-Aware
AegisLab
Agnitum
Alibaba
Antiy-AVL
Arcabit
Avast
Avira (This one I used for local scan)
Baidu-International
BitDefender
Bkav
ByteHero
CAT-QuickHeal
CMC
ClamAV (This one I used for local scan)
Comodo
Cyren
DrWeb
Emsisoft
F-Prot
F-Secure
Fortinet
GData
Ikarus
Jiangmin
K7AntiVirus
K7GW
Kaspersky
Kingsoft
Malwarebytes (This one I used for local scan)
McAfee
McAfee-GW-Edition
MicroWorld-eScan
Microsoft YES they gave CLEAR too!!!
NANO-Antivirus
Panda
Qihoo-360
Rising
SUPERAntiSpyware
Sophos
Symantec
Tencent
TheHacker
TrendMicro
TrendMicro-HouseCall
VBA32
VIPRE
ViRobot
Zillya
Zoner
nProtectThere were two, though that gave 'red', now let's have a look at those, shall we?First, the one that got my attention right away and convinced me that I would have to dig in deep to prove it to be shaite.
Or to say it in other words: to proof that this is a false alert! Simply stating that the other 54 proved it to be wrong, like MICROSOFT themselves, SYMANTEC, to name but a few small names...
No, that would not be enough, as was proven in this ANN thread. Even a panic reply came by, but understandable when you come to think of the real bad image that some real malifide coins have given to the community. But that could also be stated to be a view of a pessimist, which can be as bad as the one of a blind optimist, really.
So, let's keep it real and f'n debunk this further!
Ahnlab, Korean AV, way back in 2013...! How about an up-to-date database perhaps? (Thanks to VirScan.org for the info!)
Scanner Country Engine Ver Sig Ver Sig Date Last update(CST)
ahnlab Korea-South 9.9.9 9.9.9 2013-05-28 2013-05-28 01:13:46
Might I now call this a false 'outdated' alert then...?
And people from VirusTotal.com, why do you keep those out of date scanners in your list???
Because you actually are doing a good job normaly!
And then when I try to find the actual thing that should lurge inside, according to the way-back-engine of Ahnlab, there's almost no data. Or it leads to some software that has many reviews stating how great it is at removing crap... YEAH RIGHT!
Then there should be some files being created, at least that's the best I've found, in the Windows TEMP folder. Well, as a former IT idiot I know that shit all to well. First time you remove it, the next second to see it return. Just a few days ago I helped a family member remove some Chinese Malware that behaved like that from a Windows7 computer. Oh, happy day, but I cleared that thing up nicely, so it can be used safely again.
And while running Slothcoin 1.3.1 build 3, tested on the cleaned Win7 PC, none of that crap happened. Through my years of experience I know how that kind of horror works. And this is not the case. But on with the debunking!
NOD32, whoops sorry, I mean EsetIn the VirusTotal results is states only 'potentially unsafe' and that is based on outdated data. Where code inside the BiTCoin code, of all Wallets, mind you, contacted IRC to get Peers to connect to. Not a bad idea actually, but could be considered a danger. As is opening ports and advertising them in sourcecode or here in this forum as Addnode = ... That is a potential danger.
And that is why there is Firewall, AV, Anti-malware and that kind of software, to keep you safe, as good as possible.
Now, in my opinion NOD32/Eset, should adjust this, but it is their companies choice to do otherwise. Then VirusTotal.Com might be more critical, maybe painting it orange, instead of red? But still it is the same as that what went on with minderD, remember that?
Also VirusScan.jotti.org at least might add 'potentially unsafe' to the NOD32/Eset outdated data... Because all Wallets will give one result or the other in that manner, if the IRC code is still inside. (Which is a note to self: REMOVE IRC code in next release.)
Alerts:
DEBUNKED!
And the local test?Well, WINE, WindowsXP in VirtualBox and Windows7 just cleaned from malware, all had Slothcoin 1.3.1 build 3 running. Virus and malware scanners ready to respond, firewall supervising and me checking the places where malware puts their crap most of the time.
And you know what?
CLEAN CONFIRMED!
Final word, well I do hope so, on this matter.Caution is good, being prepared to threats that really excist? You should do that, by all means. But when 54 of the 56 AV products give a clear, if a team themselves have tested it over and over, scanned and whatever was needed, then what does that say?
Specially when one of the alerts states as 'potentially unsafe', what seems to be outdated and is known as to what causes the heuristics to 'think' of it as a thread. BiTCoin wallets posted and read IRC channels for peers to connect to, that is what triggered it.
And the second, even worse alert, is one of an outdated (2013!
) unknown AV product called Ahnlab, that leads to almost no information at the world wide web, except for some software that has many satisfied users and it is very cheap and find things that others don't find. Yeah, right...
This, for me, is enough to debunk it and state here, one last time, that Slothcoin 1.3.1 build 3 is clean!
Now... Let's get back to get the Sloth goin'!