Bitcoin Forum
May 21, 2024, 11:14:36 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Windows Malware and Trojan in Windows Wallets  (Read 2868 times)
TimFChavez (OP)
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
December 27, 2013, 02:20:31 PM
Last edit: December 27, 2013, 03:50:46 PM by TimFChavez
 #1

So I checked some of the windows wallets at http://www.virustotal.com and I see quite a few of them have either Malware or Trojan or both. Here is the list that I found and the Malware or Trojan they have.

Malware and Trojan

Diamond Coin (diamond-qt.exe): Malware.XPACK/RDM!5.1
Dime Coin (Dimecoin-qt.exe): Malware.XPACK/RDM!5.1
Feather Coin (feathercoin-qt.exe): TROJ_GEN.F47V1122
Fedora Coin (fedoracoin-qt.exe): Trojan-Spy.Win32.Zbot
Hot Coin (hotcoin-qt.exe): WS.Reputation.1
Min Coin (mincoin-qt.exe): HW32.Laneul.iywu
Philosopherstone (philosopherstone-qt.exe): Malware.XPACK/RDM!5.1
Prime Coin (primecoin-qt.exe): Primecoin Miner; TROJ_GEN.F47V1123
Protoshares (protoshares-qt.exe): HW32.Laneul.asqy
Seconds Coin (secondscoin-qt.exe): Malware.XPACK/RDM!5.1; WS.Reputation.1
Star Coin: (starcoin-qt.exe): WS.Reputation.1
Terra Coin: (terracoin-qt.exe): TROJ_GEN.F47V1101; Trojan.Win32.Generic!BT
World Coin: (worldcoin-qt.exe): HW32.Laneul.teuy

Tim


So I guess they are false positives....


>>Hey knucklehead, ever hear of false positives?

>>noobs gonna noob

I was just checking since it is better to be safe then sorry.

Tim
yabit
Hero Member
*****
Offline Offline

Activity: 658
Merit: 500



View Profile
December 27, 2013, 02:24:06 PM
 #2

good work, please add the number of alerts xxx/50, thx!
pikuchato
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500


Activity: yes


View Profile
December 27, 2013, 02:32:26 PM
 #3

So.... what should I do if I have few of those installed? (windows 7)

And what about mac os?
atta2k15
Sr. Member
****
Offline Offline

Activity: 315
Merit: 250


View Profile
December 27, 2013, 02:37:43 PM
 #4

So.... what should I do if I have few of those installed? (windows 7)

And what about mac os?

...window open, pc out...
atta2k15
Sr. Member
****
Offline Offline

Activity: 315
Merit: 250


View Profile
December 27, 2013, 02:38:53 PM
 #5

And what about mac os?

...close window, mac out...
Ribhu
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
December 27, 2013, 02:40:43 PM
 #6

Less alert! false positives are 1 in detection of 49 rising antivirus.
Source code can be checked and is clean.
Antivirus good, do not detect malware.
Executable to mine are always detected as a virus, and everyone this mining.
So... no problem !



This is true https://cryptocointalk.com/topic/1760-warning-coins/

 Grin

✪ Accepted by, more merchants! - Franko
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
December 27, 2013, 02:42:43 PM
 #7

This is a bit alarmist. I just did a single scan against Dimecoin-qt.exe;

Detection ratio:    1 / 48

That's pretty low. Could easily be a false positive.

Handy site link though. Danke.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
Hazard
Legendary
*
Offline Offline

Activity: 980
Merit: 1000



View Profile WWW
December 27, 2013, 02:46:58 PM
 #8

Hey knucklehead, ever hear of false positives?

pikuchato
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500


Activity: yes


View Profile
December 27, 2013, 02:48:54 PM
 #9

Ok I put my computer on fire and run over it with my truck 12 times with 2 elephants in the cabin, is it enough? I may launch it to space just to make sure.
abstractednerve
Hero Member
*****
Offline Offline

Activity: 752
Merit: 500


Bcnex - The Ultimate Blockchain Trading Platform


View Profile
December 27, 2013, 02:49:26 PM
 #10

Hey knucklehead, ever hear of false positives?


▄▄██████████▄▄
▄██████████████████▄
▄██████████▌ ██████████▄
▄████████▀       ▀███████▄
▄████████  ▄██████▄████████▄
█████████  ▀██▀  ▄██████████
▐██████████▄     ▀███████████▌
▐█████████████  ▄  ▀█████████▌
█████████████ ▐██  █████████
▀████████▀██████▀  ████████▀
▀███████▄       ▄████████▀
▀██████████▌ ██████████▀
▀██████████████████▀
▀▀██████████▀▀
.$martFund.

  ▄▄▀▀▀▄▄
▀       ▀
▀▄▄   ▄▄▀█      ▄▄▀▀▀▄▄
   ▀█▀   █    ▄▀       ▀
▄   █   ▄█▄   █▀▄▄   ▄▄▀
  ▀▀▄█▄▀▀   ▀▀▄█   ▀█▀   
     █▄       ▄▄   █   ▄█▄
     █ ▀▀▄▄▄▀▀ █ ▀▀▄█▄▀▀   ▀▀
     █    █    █    █▄       ▄█
  ▄▄▀▀▀▄▄ █ ▄▄▀▀▀▄▄ █ ▀▀▄▄▄▀▀
▀       ▀▀       ▀    █   
▀▄▄   ▄▄▀▀▄▄   ▄▄▀█▀▄▄ █ ▄▄
   ▀█▀      ▀█▀   █   ▀▀▀
▄   █   ▄▄   █   ▄
  ▀▀▄█▄▀▀   ▀▀▄█▄▀▀
..One-stop Blockchain..
..Investment Solution..
▄▄████████▄▄
▄████████████████▄
▄████████████████████▄
███████████▀    ▐███████
███████████    ▄▄█████████
▐██████████▀    ▀▀█████████▌
▐█████████▌       █████████▌
▐███████████    ███████████▌
███████████    ███████████
██████████    ██████████
▀████████▄  ▄████████▀
▀████████████████▀
▀▀████████▀▀



nocoin
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
December 27, 2013, 02:49:37 PM
 #11

Hey knucklehead, ever hear of false positives?
Came here to wrote the same thing.
BlackShadowX1
Member
**
Offline Offline

Activity: 70
Merit: 10


View Profile
December 27, 2013, 02:55:03 PM
 #12

I would not DL any of that crap to my computer, if not already, sooner or later someone going to get burnt.
miffman
Legendary
*
Offline Offline

Activity: 1904
Merit: 1005


PGP ID: 78B7B84D


View Profile
December 27, 2013, 02:57:23 PM
 #13

they're probably all false positives. scanned with eset, all is good














 

 

█ 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
BitBlender 

 













 















 












 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
█ 
TimFChavez (OP)
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
December 27, 2013, 02:58:43 PM
 #14

they're probably all false positives. scanned with eset, all is good

OK. Just checking. Thanks

Tim
Tripmode
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile WWW
December 27, 2013, 03:43:25 PM
 #15

A lot of things these programs are installed without people's knowledge on their PCs to mine, that is why they are sometimes considered "malware". You can view the source and compile yourself if you want to be sure it is clean.

I am in IT and I have seen many of that flagged by antivirus software. Even coin based websites can be blocked by corporate content filters.

No need to be alarmed.

Trade PXL and other coins at Atomic Trade!
LiteMine
Sr. Member
****
Offline Offline

Activity: 380
Merit: 250



View Profile
December 27, 2013, 03:45:55 PM
 #16

noobs gonna noob
TimFChavez (OP)
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
December 27, 2013, 03:52:53 PM
 #17

noobs gonna noob

Hey, it is always better to be safe then to be sorry. Also I bet that I've been using a computer longer then you have. I started using them back in 1984 and been online since 1986 and got my first internet account in 1994.

Tim
hastalavista
Full Member
***
Offline Offline

Activity: 197
Merit: 100


View Profile
December 27, 2013, 04:01:28 PM
 #18

Ok I put my computer on fire and run over it with my truck 12 times with 2 elephants in the cabin, is it enough? I may launch it to space just to make sure.

launch the truck with the elephants to space yay...

sell pc as hardly used on ebay Wink
Hippie Tech
aka Amenstop
Legendary
*
Offline Offline

Activity: 1624
Merit: 1001


All cryptos are FIAT digital currency. Do not use.


View Profile WWW
June 13, 2014, 12:11:36 AM
 #19

noobs gonna noob

Hey, it is always better to be safe then to be sorry. Also I bet that I've been using a computer longer then you have. I started using them back in 1984 and been online since 1986 and got my first internet account in 1994.

Tim


Where are the links to the results ?

My FTC QT is showing the normal botnet/ false ID and not what you are claiming.

https://www.virustotal.com/en/file/125a8497012bd3a90b1bcfa2b51ff8b5ac85e19c5d68e377046390e4ff4008e0/analysis/

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!