Bitcoin Forum
April 30, 2024, 01:38:45 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Trojan in Electrum wallet?  (Read 154 times)
Xal0lex (OP)
Staff
Legendary
*
Offline Offline

Activity: 2436
Merit: 2370



View Profile WWW
January 20, 2024, 06:15:49 PM
 #1

I downloaded a portable version of Electrum wallet from the official website. Checked it with VirusTotal service and one engine showed me that there is a trojan in the wallet. What do you think, is it true that the file from the official site may contain a trojan or is it a false positive of the Ikarus engine?



P.S. The Windows Installer version is clean, but the Standalone Executable version also has the same trojan.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Bitcoin mining is now a specialized and very risky industry, just like gold mining. Amateur miners are unlikely to make much money, and may even lose money. Bitcoin is much more than just mining, though!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714484325
Hero Member
*
Offline Offline

Posts: 1714484325

View Profile Personal Message (Offline)

Ignore
1714484325
Reply with quote  #2

1714484325
Report to moderator
1714484325
Hero Member
*
Offline Offline

Posts: 1714484325

View Profile Personal Message (Offline)

Ignore
1714484325
Reply with quote  #2

1714484325
Report to moderator
jrrsparkles
Sr. Member
****
Online Online

Activity: 2380
Merit: 253


Eloncoin.org - Mars, here we come!


View Profile
January 20, 2024, 06:19:36 PM
Merited by pooya87 (2), nc50lc (1), hosseinimr93 (1)
 #2

Just one report, then it seems a false positive.

If you still worried about it then verifying it on your own is recommended : [GUIDE] How to Safely Download and Verify Electrum

How to verify your Electrum download









▄▄████████▄▄
▄▄████████████████▄▄
▄██
████████████████████▄
▄███
██████████████████████▄
▄████
███████████████████████▄
███████████████████████▄
█████████████████▄███████
████████████████▄███████▀
██████████▄▄███▄██████▀
████████▄████▄█████▀▀
██████▄██████████▀
███▄▄█████
███████▄
██▄██████████████
░▄██████████████▀
▄█████████████▀
████████████
███████████▀
███████▀▀
Mars,           
here we come!
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██████████
███████████
▄███████████████████████▄
█████████████████████████
█████████████████████████
█████████████████████████
▀█
██████████████████████▀
▀██
███████████████████▀
▀███████████████████▀
▀█████████
██████▀
▀▀███████▀▀
ElonCoin.org.
████████▄▄███████▄▄
███████▄████████████▌
██████▐██▀███████▀▀██
███████████████████▐█▌
████▄▄▄▄▄▄▄▄▄▄██▄▄▄▄▄
███▐███▀▄█▄█▀▀█▄█▄▀
███████████████████
█████████████▄████
█████████▀░▄▄▄▄▄
███████▄█▄░▀█▄▄░▀
███▄██▄▀███▄█████▄▀
▄██████▄▀███████▀
████████▄▀████▀
█████▄▄
.
"I could either watch it
happen or be a part of it"

▬▬▬▬▬
Bitcoin_Arena
Copper Member
Legendary
*
Online Online

Activity: 2016
Merit: 1786


฿itcoin for all, All for ฿itcoin.


View Profile
January 20, 2024, 11:04:47 PM
Merited by nc50lc (1)
 #3

Definitely a false positive. I have never even heard of Ikarus Antivirus before.  Grin

So false positives have been popping up in the past too if you explore the closed issues in Github. At one point, there were 9 AV engines that would flag electrum as a malware, but a fix was done to reduce on those false positive detections.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
TheUltraElite
Legendary
*
Offline Offline

Activity: 2856
Merit: 1220


Call your grandparents and tell them you love them


View Profile WWW
January 21, 2024, 06:02:12 AM
 #4

If it is from their official website, then highly unlikely to be a true positive AV flag.

A remote possibility of their site having been hacked and posted a malware bound software there.

Just one report, then it seems a false positive.

If you still worried about it then verifying it on your own is recommended : [GUIDE] How to Safely Download and Verify Electrum

How to verify your Electrum download
Verifying the signature does not completely rule out that possibility.

Hence that tingling spider sense of mine tells me that you should wait it out before operating that software. Mostly likely its false positive, but ..

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
tranthidung
Legendary
*
Online Online

Activity: 2254
Merit: 3983


Farewell o_e_l_e_o


View Profile WWW
January 21, 2024, 07:25:08 AM
 #5

I believe it is a false positive from Virustotal but to make sure, we must get official answer from Electrum team.

Can send a PM in bitcointalk to ThomasV or create an issue on Electrum Github or Electrum Twitter and wait for their team reply.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
khaled0111
Legendary
*
Offline Offline

Activity: 2506
Merit: 2840


Top Crypto Casino


View Profile WWW
January 21, 2024, 08:50:56 PM
Merited by Xal0lex (2)
 #6

If you have downloaded Electrum for the official website (electrum.org) then you should have read this note on the bottom of the download page:
Electrum binaries are often flagged by various anti-virus software. There is nothing we can do about it, so please stop reporting that to us. Anti-virus software uses heuristics in order to determine if a program is malware, and that often results in false positives.
There is no need to report this issue to devs team. They will most likely ignore it.

Verifying the signature does not completely rule out that possibility.
If you trust the signers (Electrum devs) and you have properly imported their public keys from trusted sources then verifying the gpg signature should be enough.


█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Abdussamad
Legendary
*
Offline Offline

Activity: 3598
Merit: 1560



View Profile
January 21, 2024, 09:15:43 PM
 #7

See "notes for windows users" at the bottom of the download page:

https://electrum.org/#download
Yamane_Keto
Sr. Member
****
Offline Offline

Activity: 462
Merit: 486



View Profile WWW
January 22, 2024, 03:02:24 AM
 #8

make sure to verify the signature with the wallet file that you downloaded. If the file is signed by the developer, do not pay attention to these warnings because they are false positive, else there is a virus that will redirect you outside electrum.org.

.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
keychainX
Member
**
Offline Offline

Activity: 374
Merit: 53

Telegram @keychainX


View Profile WWW
January 26, 2024, 08:30:44 AM
 #9

I downloaded a portable version of Electrum wallet from the official website. Checked it with VirusTotal service and one engine showed me that there is a trojan in the wallet. What do you think, is it true that the file from the official site may contain a trojan or is it a false positive of the Ikarus engine?



P.S. The Windows Installer version is clean, but the Standalone Executable version also has the same trojan.
¨

Windows flags several Bitcoin wallets as trojans.

NotATether
Legendary
*
Offline Offline

Activity: 1582
Merit: 6715


bitcoincleanup.com / bitmixlist.org


View Profile WWW
January 28, 2024, 04:09:58 AM
 #10

Also in addition to what keychainX said, if you got an app that is making lots of connections to random servers, as Electrum does for its network of SPV nodes, then any antivirus is going to think that is malicious activity, because that's what malware does too. Although I have no idea what kind of virus "Win32.Patched" is refering to in this context, and it doesn't help that different vendors give viruses completely illogical and meaningless names for them.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!