Bitcoin Forum
May 02, 2024, 09:59:22 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Electrum.lnk is infected with Trojan.GenericKD.41303315  (Read 150 times)
Keelcz (OP)
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
June 02, 2019, 08:38:25 PM
 #1

Hi,when i install electrum wallet from official page " https://electrum.org/#download " and install it, my Bitdefender goes crazy


Electrum.lnk is infected with Trojan.GenericKD.41303315 and was moved to quarantine.


its downloaded from official page and i dont see any way it not being legitimate version of the electrum wallet.Is bitdefender crazy and should i just restore the file ?

pls give me your thoughts



1714687162
Hero Member
*
Offline Offline

Posts: 1714687162

View Profile Personal Message (Offline)

Ignore
1714687162
Reply with quote  #2

1714687162
Report to moderator
1714687162
Hero Member
*
Offline Offline

Posts: 1714687162

View Profile Personal Message (Offline)

Ignore
1714687162
Reply with quote  #2

1714687162
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714687162
Hero Member
*
Offline Offline

Posts: 1714687162

View Profile Personal Message (Offline)

Ignore
1714687162
Reply with quote  #2

1714687162
Report to moderator
1714687162
Hero Member
*
Offline Offline

Posts: 1714687162

View Profile Personal Message (Offline)

Ignore
1714687162
Reply with quote  #2

1714687162
Report to moderator
BristolRovers
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
June 02, 2019, 08:45:42 PM
 #2

Hi,when i install electrum wallet from official page " https://electrum.org/#download " and install it, my Bitdefender goes crazy


Electrum.lnk is infected with Trojan.GenericKD.41303315 and was moved to quarantine.


its downloaded from official page and i dont see any way it not being legitimate version of the electrum wallet.Is bitdefender crazy and should i just restore the file ?

pls give me your thoughts





I just downloaded the latest version by clicking your link which points to the official website.I used a virtual machine just to be sure and it all worked normally.I don't think it has any problems or any trojans there and most probably your Bitdefender is not as good as an antivirus as you might think.
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18509


View Profile
June 02, 2019, 09:02:43 PM
 #3

Have a read of this thread: Electrum-3.3.6 Trojan.GenericKD.41303315

Electrum commonly has false positives. Make sure you are downloading it from the correct link (you are), and make sure you verify your download by following these instructions: https://bitcoinelectrum.com/how-to-verify-your-electrum-download/.

If you've done both of those things, then it comes down to whether or not you trust the developers (almost everybody here does). If you don't then the only solution is to examine the source code yourself (if you have the knowledge/ability to do so) and then compile it yourself if you trust it.
BitMaxz
Legendary
*
Offline Offline

Activity: 3248
Merit: 2955


Block halving is coming.


View Profile WWW
June 02, 2019, 10:07:37 PM
 #4

Electrum.lnk is infected with Trojan.GenericKD.41303315 and was moved to quarantine.


Where did you get this "Electrum.lnk" I can't find this file on my Electrum wallet files in program files folder or in %appdata%

Can you clarify which wallet you installed is it standalone, Executable or the portable one? Because I can't find this file "Electrum.lnk" in my laptop it seems that your PC is already infected not the Electrum wallet.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
June 02, 2019, 10:15:08 PM
 #5

Where did you get this "Electrum.lnk" I can't find this file on my Electrum wallet files in program files folder or in %appdata%
If you use the Windows installer, it creates .lnk files in the "Start Menu". For instance, on Windows 10, I have "Electrum.lnk", "Electrum Testnet.lnk" and "uninstall.lnk" in the following directory: C:\Users\YOURUSERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Electrum

If you use Standalone or Portable version, these shortcuts are not created.


As for the OP's original question:
Is bitdefender crazy and should i just restore the file ?
Bitdefender is "crazy" Tongue

It's most likely just a false positive... It's a known issue due to the Electrum devs using PyInstaller... If you have a look on the electrum.org download page... and read the "Notes for Windows users":
Electrum binaries are often flagged by various anti-virus software. There is nothing we can do about it, so please stop reporting that to us. Anti-virus software uses heuristics in order to determine if a program is malware, and that often results in false positives. If you trust the developers of the project, you can verify the GPG signature of Electrum binaries, and safely ignore any anti-virus warnings. If you do not trust the developers of the project, you should build the binaries yourself, or run the software from source. Finally, if you are really concerned about malware, you should not use an operating system that relies on anti-virus software.

If you are 100% sure you downloaded from electrum.org and you have verified the digital signature, then it should be fine to add an exception to your antivirus to allow it to run.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
nc50lc
Legendary
*
Offline Offline

Activity: 2408
Merit: 5581


Self-proclaimed Genius


View Profile
June 03, 2019, 04:06:04 AM
 #6

What's crazy here is Bitdefender detected the "shortcut" (.lnk) file as the one with the virus, not the executable  Undecided
There are known viruses that infects shortcuts to spread to the system, your system might be already infected prior to the installation.

Take note that Electrum does have a lot of false positives from multiple Antivirus Software but the latest version of Bitdefender shouldn't have any detection to Electrum v3.3.6:

BitDefender Undetected

It may also be caused by your Antivirus' "aggressiveness" settings.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!