Bitcoin Forum
April 26, 2024, 03:33:39 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: 50 btc miner virus detected  (Read 9914 times)
fixxi.net (OP)
Member
**
Offline Offline

Activity: 89
Merit: 10


View Profile
March 31, 2013, 02:06:31 PM
Last edit: March 31, 2013, 03:23:30 PM by fixxi.net
 #1

Both Avira and Avast detect viruses in the 50Btc miner, are they really viruses ? Do they run mining on your pc without u knowing it ?

The 50 download from https://50btc.com includes this file

scrypt121016.cl

which is A BANK INFORMATION STEALER according to this:

http://www.averscanner.com/scan/a2/scrypt121016-cl.shtml

Other files in download also are reported viruses by those two AV programs.
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714102419
Hero Member
*
Offline Offline

Posts: 1714102419

View Profile Personal Message (Offline)

Ignore
1714102419
Reply with quote  #2

1714102419
Report to moderator
Jocky
Member
**
Offline Offline

Activity: 85
Merit: 10


View Profile WWW
March 31, 2013, 02:29:33 PM
 #2

Thanks for reporting! I don't know anything about 50BTC miner, but I know it is important we share this info asap.

.
kinlo
Sr. Member
****
Offline Offline

Activity: 263
Merit: 250


Pool operator of Triplemining.com


View Profile
March 31, 2013, 04:38:08 PM
 #3

Guys, it's just an antivirus vendor who just identified a scrypt decoder... I don't think it is a virus, I just think it is a bad virsuscanner...
crazyates
Legendary
*
Offline Offline

Activity: 952
Merit: 1000



View Profile
March 31, 2013, 08:32:46 PM
 #4

We have 2 problems here.

1) A lot of BTC mining softwares have been falsely identified as viruses in the past. For example, CGMiner used to have issues with a number of antivirus softwares, and was a false positive. Luckily, CGMiner is open source, so people can build from source and verify that there is nothing malicious going on in the background.

Related to this note: I previously ran my BTC client (on a separate computer that I mine on) with the default 8 connections. I forwarded port 8332, and went up to about 30 connections. Within a week, I got a letter from my ISP warning me that one of my computers had been infected with a botnet. Seems Comcast doesn't like the increase in network activity.

2) Unlike CGMiner, 50BTC miner is NOT open source. There is no way to prove that there really isn't anything malicious going on. For all we know, it really could be a bank information stealer or a keylogger or something. The source code for 50BTC miner has been requested, but those requests have been denied.

Safest option: switch to CGMiner, which can still be used with the 50BTC pool and website. If CGMiner is too complicated for you (like the thought of a command line or terminal scares you), then switch to BitMinter pool and mining software. They have a nice, easy to use program that also works with most GPUs and FPGAs. They have said they will also work with ASICs, too.

Tips? 1crazy8pMqgwJ7tX7ZPZmyPwFbc6xZKM9
Previous Trade History - Sale Thread
j980
Newbie
*
Offline Offline

Activity: 42
Merit: 0



View Profile
March 31, 2013, 08:50:32 PM
 #5

The scryptXXX.cl file contains only OpenCL code for the scrypt hasher, and it does not seem to include anything that steals bank information.   Other files in the package might still contain a virus.  Compiling from source provides better protection against virus infections.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!