Bitcoin Forum
May 14, 2024, 08:33:54 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Most likely - Possible malware in latest Bitcoin Core 64 bits bitcoin-qt.exe  (Read 2863 times)
Shady
Full Member
***
Offline Offline

Activity: 294
Merit: 100


Life is a game, you either play it or get played.


View Profile
November 27, 2016, 09:12:53 PM
 #21

As long as no vulnerabilities are present this may display as a false positive... It's extremely unlikely that somebody would tap into your device in that way so either ignore until another sign comes up or scan the computer to, prevent further complications.

I recommend using encrypted web wallets or run exclusive with a personal design.

1715675634
Hero Member
*
Offline Offline

Posts: 1715675634

View Profile Personal Message (Offline)

Ignore
1715675634
Reply with quote  #2

1715675634
Report to moderator
1715675634
Hero Member
*
Offline Offline

Posts: 1715675634

View Profile Personal Message (Offline)

Ignore
1715675634
Reply with quote  #2

1715675634
Report to moderator
1715675634
Hero Member
*
Offline Offline

Posts: 1715675634

View Profile Personal Message (Offline)

Ignore
1715675634
Reply with quote  #2

1715675634
Report to moderator
Every time a block is mined, a certain amount of BTC (called the subsidy) is created out of thin air and given to the miner. The subsidy halves every four years and will reach 0 in about 130 years.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
November 27, 2016, 10:03:09 PM
 #22

As long as no vulnerabilities are present this may display as a false positive... It's extremely unlikely that somebody would tap into your device in that way so either ignore until another sign comes up or scan the computer to, prevent further complications.

I recommend using encrypted web wallets or run exclusive with a personal design.

Can you elaborate? It sounds like you suggest OP to write their own wallet software.

Im not really here, its just your imagination.
IH-Antonio (OP)
Member
**
Offline Offline

Activity: 79
Merit: 10


View Profile
November 27, 2016, 10:13:03 PM
 #23

Where did you download your bitcoin core.. honestly i tried to scan and here the 2 result from their exeinstall and zip file
Exe result https://www.virustotal.com/en/url/8fea1cc9947c2a98ca0877240732c7dbcb3d1f01d6ee35d313b7b0ad6089ea5b/analysis/1480269102/
Zip file result: https://www.virustotal.com/en/url/ac4e447006b7fc4085d760427d40fcf66b5b4090ed2c51144ab9bbafab27ccdb/analysis/

This one is exe and i download it from bitcoin.org but upon scanning it in virus total there is one detected
here https://www.virustotal.com/en/file/a7d1d25bbc46b4f0fe333f7d3742c22defdba8db9ffd6056770e104085d24709/analysis/

I think it is just false scan from some anti virus just like other said.. i tried to scan it in my kaspersky but there is no virus detected..

I'm scanning the bitcoin-qt.exe client. Try with the one you have installed.

Donations for keeping x2 Bitcoin Full Node online 24/7 are welcome: 14GPNioy3mi3D9iMge67j5UAoEy5hT4btn
IH-Antonio (OP)
Member
**
Offline Offline

Activity: 79
Merit: 10


View Profile
November 27, 2016, 10:13:57 PM
 #24

May I ask why you are running a full bitcoin node on your home computer? Doesn't it take forever to sync or are you running your computer 24/7? Thanks for supporting the network btw  Grin Grin Grin

Dedicated server, anyway, if you run a computer 24/7 it does work without problems.

Donations for keeping x2 Bitcoin Full Node online 24/7 are welcome: 14GPNioy3mi3D9iMge67j5UAoEy5hT4btn
0xfff
Full Member
***
Offline Offline

Activity: 224
Merit: 100


View Profile
November 27, 2016, 11:32:29 PM
 #25

May I ask why you are running a full bitcoin node on your home computer? Doesn't it take forever to sync or are you running your computer 24/7? Thanks for supporting the network btw  Grin Grin Grin

I also run a full node at home  Wink  It's fine for me cause i run my computer 24/7 anyway and i dont have any limits from my broadband provider,  everyone who can, should run a full node.  Wink

You're lucky that you can run your computer all the time and dont have any internet limits!

May I ask why you are running a full bitcoin node on your home computer? Doesn't it take forever to sync or are you running your computer 24/7? Thanks for supporting the network btw  Grin Grin Grin

Dedicated server, anyway, if you run a computer 24/7 it does work without problems.

How much does it cost for a dedicated server per month? I looked awhile back and they were fairly expensive.
Shiroslullaby
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250



View Profile
November 28, 2016, 12:21:40 AM
 #26

Some antivirus flag anything that has to do with Bitcoin, or alt-coins as a virus.
For example, some of the Monero mining programs are flagged by Malwarebytes and Google as a virus,
probably because there were some botnets mining coins, and the programs trigger on the same heuristics.

Still, OP or anyone else who has information on this should follow up in this thread,
since there have been instances of github and similar websites being hacked and binaries or compiled programs being replaced with backdoored versions.

pooya87
Legendary
*
Offline Offline

Activity: 3444
Merit: 10561



View Profile
November 28, 2016, 04:20:26 AM
 #27

Where did you download your bitcoin core.. honestly i tried to scan and here the 2 result from their exeinstall and zip file
Exe result https://www.virustotal.com/en/url/8fea1cc9947c2a98ca0877240732c7dbcb3d1f01d6ee35d313b7b0ad6089ea5b/analysis/1480269102/
Zip file result: https://www.virustotal.com/en/url/ac4e447006b7fc4085d760427d40fcf66b5b4090ed2c51144ab9bbafab27ccdb/analysis/

This one is exe and i download it from bitcoin.org but upon scanning it in virus total there is one detected
here https://www.virustotal.com/en/file/a7d1d25bbc46b4f0fe333f7d3742c22defdba8db9ffd6056770e104085d24709/analysis/

I think it is just false scan from some anti virus just like other said.. i tried to scan it in my kaspersky but there is no virus detected..

FYI:
This is a common mistake people make when using virustotal.
the two first links you posted are not scanning any files (.zip, ...) they are instead scanning the URL you can see it from the link itself which is marked by ../url/... and reporting if the website has any malware on if when you visit.

the last link however is scanning the file because you have uploaded it. the link has ../file/... in it.
i could not find a way to not download then upload so far so if anyone has any solution i would be glad to know it. but with virustotal if you want to scan a file you have to upload it just putting the link and scanning will not scan the file.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
IH-Antonio (OP)
Member
**
Offline Offline

Activity: 79
Merit: 10


View Profile
November 28, 2016, 02:02:25 PM
 #28

Where did you download your bitcoin core.. honestly i tried to scan and here the 2 result from their exeinstall and zip file
Exe result https://www.virustotal.com/en/url/8fea1cc9947c2a98ca0877240732c7dbcb3d1f01d6ee35d313b7b0ad6089ea5b/analysis/1480269102/
Zip file result: https://www.virustotal.com/en/url/ac4e447006b7fc4085d760427d40fcf66b5b4090ed2c51144ab9bbafab27ccdb/analysis/

This one is exe and i download it from bitcoin.org but upon scanning it in virus total there is one detected
here https://www.virustotal.com/en/file/a7d1d25bbc46b4f0fe333f7d3742c22defdba8db9ffd6056770e104085d24709/analysis/

I think it is just false scan from some anti virus just like other said.. i tried to scan it in my kaspersky but there is no virus detected..

FYI:
This is a common mistake people make when using virustotal.
the two first links you posted are not scanning any files (.zip, ...) they are instead scanning the URL you can see it from the link itself which is marked by ../url/... and reporting if the website has any malware on if when you visit.

the last link however is scanning the file because you have uploaded it. the link has ../file/... in it.
i could not find a way to not download then upload so far so if anyone has any solution i would be glad to know it. but with virustotal if you want to scan a file you have to upload it just putting the link and scanning will not scan the file.

You can click, in the upper part: File scan:   Go to downloaded file analysis

Donations for keeping x2 Bitcoin Full Node online 24/7 are welcome: 14GPNioy3mi3D9iMge67j5UAoEy5hT4btn
pooya87
Legendary
*
Offline Offline

Activity: 3444
Merit: 10561



View Profile
November 29, 2016, 06:06:21 AM
 #29

Where did you download your bitcoin core.. honestly i tried to scan and here the 2 result from their exeinstall and zip file
Exe result https://www.virustotal.com/en/url/8fea1cc9947c2a98ca0877240732c7dbcb3d1f01d6ee35d313b7b0ad6089ea5b/analysis/1480269102/
Zip file result: https://www.virustotal.com/en/url/ac4e447006b7fc4085d760427d40fcf66b5b4090ed2c51144ab9bbafab27ccdb/analysis/

This one is exe and i download it from bitcoin.org but upon scanning it in virus total there is one detected
here https://www.virustotal.com/en/file/a7d1d25bbc46b4f0fe333f7d3742c22defdba8db9ffd6056770e104085d24709/analysis/

I think it is just false scan from some anti virus just like other said.. i tried to scan it in my kaspersky but there is no virus detected..

FYI:
This is a common mistake people make when using virustotal.
the two first links you posted are not scanning any files (.zip, ...) they are instead scanning the URL you can see it from the link itself which is marked by ../url/... and reporting if the website has any malware on if when you visit.

the last link however is scanning the file because you have uploaded it. the link has ../file/... in it.
i could not find a way to not download then upload so far so if anyone has any solution i would be glad to know it. but with virustotal if you want to scan a file you have to upload it just putting the link and scanning will not scan the file.

You can click, in the upper part: File scan:   Go to downloaded file analysis

VirusTotal does not check the file itself when you give only the download link.
what you see is the file which socks435 uploaded from his computer to virustotal and since the files are the same virustotal links that analysis in the /url/... link too.

here is an example:
results for scanning: https://download.electrum.org/2.7.12/electrum-2.7.12-setup.exe
https://www.virustotal.com/en/url/64b402b0bcdc6e59521f143305987a83afacc3986548efec1cd47c797cfeccd0/analysis/1480399277/

and since virustotal could not find any file uploaded before it did not include any link to "file analysis"


however if you check the other link to https://download.electrum.org/2.7.12/electrum-2.7.12.exe you can see there is a link to "file analysis" since someone had uploaded the .exe before manually from his computer.
https://www.virustotal.com/en/url/f64b0cba4ed0afc2b5ed9fedfc8189a3ebf4e6893fd7825057cfb5a928900d4c/analysis/

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
IH-Antonio (OP)
Member
**
Offline Offline

Activity: 79
Merit: 10


View Profile
December 02, 2016, 11:12:32 PM
 #30

Updated original post.

Donations for keeping x2 Bitcoin Full Node online 24/7 are welcome: 14GPNioy3mi3D9iMge67j5UAoEy5hT4btn
Teccr
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
December 07, 2016, 07:27:25 AM
 #31

As of today, the 64 bit binary bitcoin-qt.exe shouldn't be detected by Kaspersky IS anymore.
The other anti-malware vendors haven't replied to my requests yet.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!