Bitcoin Forum
December 13, 2024, 10:26:26 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Electrum wallet virus  (Read 907 times)
digaran
Copper Member
Hero Member
*****
Offline Offline

Activity: 1330
Merit: 900

🖤😏


View Profile
January 07, 2018, 03:52:17 AM
 #21

Warning, read the news header in here, do not use Electrum 3.0.3 because it is compromised, update your Electrum clients immediately.

🖤😏
pooya87
Legendary
*
Offline Offline

Activity: 3668
Merit: 11107


Crypto Swap Exchange


View Profile
January 07, 2018, 05:08:46 AM
 #22

Warning, read the news header in here, do not use Electrum 3.0.3 because it is compromised, update your Electrum clients immediately.[/color][/size]

stop being dramatic, Electrum is not compromised and it certainly has NOTHING to do with this topic.

what happened is that any version below 3.0.3 has a vulnerability that may be compromised if
- you have Electrum open
- you haven't set a password
- at the same time you visit a website that is looking for this exploit and runs a script using the RPC commands to steal your private keys

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
TeePee
Member
**
Offline Offline

Activity: 183
Merit: 13


View Profile
January 07, 2018, 06:01:31 AM
Last edit: January 07, 2018, 06:12:25 AM by TeePee
 #23

Quick question guys:

I'm not very good with computers and I therefore have troubles understanding how to verify a signature. I read everywhere that you need to do this when downloading Electrum 3.0.4
Would it be incredibly dangerous to therefore skip that step, as long as I make sure I only download Electrum from the official website https://electrum.org/#download ?
After all, the version on there has to be the original, real one for sure? Any yes, some people will now probably answer that you can never be sure, but as long as I can be 99,9999999% sure then it's fine for me.
ranochigo
Legendary
*
Offline Offline

Activity: 3052
Merit: 4443


Crypto Swap Exchange


View Profile
January 07, 2018, 06:48:58 AM
 #24

Would it be incredibly dangerous to therefore skip that step, as long as I make sure I only download Electrum from the official website https://electrum.org/#download ?
Generally speaking, no. Its relatively hard to replace the information on that site. However, it is by no means, impossible if you have a zero day exploit or is a huge organisation with vast resources (ie. Governments).
After all, the version on there has to be the original, real one for sure? Any yes, some people will now probably answer that you can never be sure, but as long as I can be 99,9999999% sure then it's fine for me.
No. There's no such thing as real or fake. If you were to download from there and verify the signature, it would be just like saying you trust ThomasV and he is correct.

If you need to verify: https://bitcointalk.org/index.php?topic=2489301.msg25624488#msg25624488.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
AlexBeast
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
January 07, 2018, 11:53:41 AM
 #25

Hey guys, I know It's an old thread, but my antivirus
finds new infected files every 5 minutes

always in the same directory.. I can't do a system restore because it's windows 8.1 recovery error 0x80070005

And every single infected file ends with .pyc
e.g.: bitcoin.pyc

.pyc are compiled python files (modules loaded in scripts).
Did you already try to do a full scan of your pc with your AV?

How is this problem related to electrum? Did this problem start occuring after you installed electrum?
If so, did you check the signature or at least the checksum?

You can find the signature for the current windows installer [1] and the standalone executable [2] on their official site, just like the ThomasV's PGP key [3].
You can verify your files (if you have gpg installed) with gpg --verify electrum-3.0.3.exe.asc electrum-3.0.3.exe in your command line.

[1] .asc
[2] .asc
[3] https://pgp.mit.edu/pks/lookup?op=vindex&search=0x2BD5824B7F9470E6

Yeah, It happend immediately after installing Electrum and GPG thing, I don't know which one is the culprit. I managed to restore my system..
But I'm still using Electrum 2.xx.
I'm afraid of using the gpg verifier because It might happen again. So I'll backup my system and try Electrum 3.0.3.
thenarog
Member
**
Offline Offline

Activity: 113
Merit: 10


View Profile
January 07, 2018, 01:21:33 PM
 #26

Very strange Electrum 3.04 seems a phising link for me...They say to update but i can't read nothing on electrum official website.
keyboard warrior
Sr. Member
****
Offline Offline

Activity: 266
Merit: 251


View Profile
January 08, 2018, 12:58:10 AM
 #27

Very strange Electrum 3.04 seems a phising link for me...They say to update but i can't read nothing on electrum official website.

This warning is written at the top of the electrum website home page. I don't know how you missed it.

https://electrum.org/#home

Quote
Security Notice: A vulnerability has been found in Electrum, and patched in version 3.0.5. Please update your software if you are running an earlier version


The release notes on the electrum github explain that version 3.0.4 didn't completely fix the vulnerability, so version 3.0.5 was quickly released a day later.

https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES

Quote
# Release 3.0.5 : (Security update)

This is a follow-up to the 3.0.4 release, which did not completely fix
issue #3374. Users should upgrade to 3.0.5.

 * The JSONRPC interface is password protected
 * JSONRPC commands are disabled if the GUI is running, except 'ping',
   which is used to determine if a GUI is already running
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4363

<insert witty quote here>


View Profile
January 08, 2018, 11:25:00 AM
Last edit: January 08, 2018, 11:43:52 AM by HCP
 #28

Somewhat confusingly... the links on the "download" page still link to version v3.0.3 downloads!!?! Shocked Shocked

For the record, the v3.0.5 downloads are here: https://download.electrum.org/3.0.5/

Seems, like my chrome is "broken", or my ISP is caching stuff again to be "helpful"... *sigh*... Undecided

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
ranochigo
Legendary
*
Offline Offline

Activity: 3052
Merit: 4443


Crypto Swap Exchange


View Profile
January 08, 2018, 11:37:38 AM
 #29

Somewhat confusingly... the links on the "download" page still link to version v3.0.3 downloads!!?! Shocked Shocked

For the record, the v3.0.5 downloads are here: https://download.electrum.org/3.0.5/
Huh? It has been showing 3.0.5 for me for a long time. Try clearing your cache.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2504



View Profile WWW
January 08, 2018, 12:39:49 PM
 #30

Very strange Electrum 3.04 seems a phising link for me...They say to update but i can't read nothing on electrum official website.

For the record, the v3.0.5 downloads are here: https://download.electrum.org/3.0.5/
Huh? It has been showing 3.0.5 for me for a long time. Try clearing your cache.


Version 3.0.5 got released about 13 hours ago, as a follow up to 3.0.4 (which mostly shut down the vulnerability) [1].
No way you got 3.0.5 for a long time now. You might verify the signature of your current version to exclude the possibility of a malicious application.

[1] Release notes: https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES

Darooghe
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 255



View Profile
January 08, 2018, 05:42:20 PM
 #31

Very strange Electrum 3.04 seems a phising link for me...They say to update but i can't read nothing on electrum official website.

This warning is written at the top of the electrum website home page. I don't know how you missed it.

https://electrum.org/#home


I don't see it either. could you give us a screenshot?
Maybe electrum.org is hacked.
Darooghe
Sr. Member
****
Offline Offline

Activity: 1120
Merit: 255



View Profile
January 08, 2018, 06:49:23 PM
 #32

I did verifying signature's process with GPG Kleopatra. electrum 3.0.5 verified but says the data could not be verified. Is there any problem with Electrum 3.0.5?

keyboard warrior
Sr. Member
****
Offline Offline

Activity: 266
Merit: 251


View Profile
January 08, 2018, 07:31:47 PM
 #33

Very strange Electrum 3.04 seems a phising link for me...They say to update but i can't read nothing on electrum official website.

This warning is written at the top of the electrum website home page. I don't know how you missed it.

https://electrum.org/#home


I don't see it either. could you give us a screenshot?
Maybe electrum.org is hacked.

HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4363

<insert witty quote here>


View Profile
January 09, 2018, 01:11:46 AM
Last edit: November 15, 2023, 08:21:25 AM by HCP
 #34

I did verifying signature's process with GPG Kleopatra. electrum 3.0.5 verified but says the data could not be verified. Is there any problem with Electrum 3.0.5?
No... it is just the way that GPG works... you can import keys, but not TRUST them... until you explicitiy trust the key you will see something like:



NOTE: THIS IS A GOOD SIGNATURE! The signature checks out, and the file is signed with the signature... YOU just haven't trusted it yet.


If you "trust" ThomasV... then you can sign the key, saying that you vouch for Thomas and he is legit and all things signed with his key are legit... then you will see something like this:




The important thing is that you DON'T see a red warning like this:


If you see "Invalid Signature" then that is BAD!

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
thenarog
Member
**
Offline Offline

Activity: 113
Merit: 10


View Profile
January 21, 2018, 02:54:11 AM
 #35

I gat the new version of Electrum... Now impossible to open my wallet with the right password...
And when i try to recover it wth the seed words, it doesn't works...

Great job, what i have to do now ?
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4363

<insert witty quote here>


View Profile
January 21, 2018, 04:42:35 AM
 #36

I gat the new version of Electrum... Now impossible to open my wallet with the right password...
Then the password you are typing in is incorrect. When was the last time you used the password you are trying to open the wallet? Was it months ago? or was it yesterday?


Quote
And when i try to recover it wth the seed words, it doesn't works...
How exactly are the seed words "doesn't works"? Is it giving an error? Is the "next" button not available... is it just showing a 0 balance? do you see any transaction history?

What sort of wallet was it? Standard? MultiSig? 2FA?

What wallet version did you upgrade from? What version have you just installed?

Can you confirm you downloaded the file from: https://electrum.org/#download and did you check the digital signature?

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
thenarog
Member
**
Offline Offline

Activity: 113
Merit: 10


View Profile
January 21, 2018, 12:53:28 PM
 #37

I gat the new version of Electrum... Now impossible to open my wallet with the right password...
Then the password you are typing in is incorrect. When was the last time you used the password you are trying to open the wallet? Was it months ago? or was it yesterday?


Quote
And when i try to recover it wth the seed words, it doesn't works...
How exactly are the seed words "doesn't works"? Is it giving an error? Is the "next" button not available... is it just showing a 0 balance? do you see any transaction history?

What sort of wallet was it? Standard? MultiSig? 2FA?

What wallet version did you upgrade from? What version have you just installed?

Can you confirm you downloaded the file from: https://electrum.org/#download and did you check the digital signature?

1 / Last time was the 8 th january.
2 / I have the seed words. When i put them, i have my wallet back, but no money on it, no transactions, no history, nothing...
3 / Standard Wallet
4 / 2.8 to 3.04 first and 24 hours later 3.05 all from the Electrum official Website. I did all the verification, i was very suspicious about the new version...

Something wrong with Electrum and this story...Be very careful and thanks for any help.
baundul
Full Member
***
Offline Offline

Activity: 307
Merit: 100



View Profile
January 21, 2018, 06:05:57 PM
 #38

There are no viruses in Electrum that remove the installed applications of antivirus. I used the official update of Electrum for but I have no problem. I think your downloaded software is infected or you download unknown wallet. So download the official wallet and used Electrum , do not worry.
thenarog
Member
**
Offline Offline

Activity: 113
Merit: 10


View Profile
January 21, 2018, 07:00:26 PM
 #39

There are no viruses in Electrum that remove the installed applications of antivirus. I used the official update of Electrum for but I have no problem. I think your downloaded software is infected or you download unknown wallet. So download the official wallet and used Electrum , do not worry.

I used the same official electrum, i check it. I have a big problem with it.
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4363

<insert witty quote here>


View Profile
January 21, 2018, 11:26:14 PM
 #40

1 / Last time was the 8 th january.
2 / I have the seed words. When i put them, i have my wallet back, but no money on it, no transactions, no history, nothing...
3 / Standard Wallet
4 / 2.8 to 3.04 first and 24 hours later 3.05 all from the Electrum official Website. I did all the verification, i was very suspicious about the new version...
If you look in the wallets folder (http://docs.electrum.org/en/latest/faq.html#where-is-my-wallet-file-located), are there other wallet files there? It's possible that you were not using the "default_wallet" with the earlier version of Electrum, and when you updated to the newer version, on first start, it defaulted back to "default_wallet", hence why your password is not working.

As for the seed restoring an empty wallet, have you ever used your seed words to restore your wallet before? It would seem you have a "valid" seed, but not the seed for your wallet Undecided I've seen several users over the last few months who have written down a valid seed but have some how ended up using a different wallet... So, when they try and restore from seed, they get an empty wallet.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!