Author

Topic: Trojan in Electrum wallet? (Read 154 times)

legendary
Activity: 1568
Merit: 6660
bitcoincleanup.com / bitmixlist.org
January 28, 2024, 12:09:58 AM
#10
Also in addition to what keychainX said, if you got an app that is making lots of connections to random servers, as Electrum does for its network of SPV nodes, then any antivirus is going to think that is malicious activity, because that's what malware does too. Although I have no idea what kind of virus "Win32.Patched" is refering to in this context, and it doesn't help that different vendors give viruses completely illogical and meaningless names for them.
member
Activity: 372
Merit: 53
Telegram @keychainX
January 26, 2024, 04:30:44 AM
#9
I downloaded a portable version of Electrum wallet from the official website. Checked it with VirusTotal service and one engine showed me that there is a trojan in the wallet. What do you think, is it true that the file from the official site may contain a trojan or is it a false positive of the Ikarus engine?



P.S. The Windows Installer version is clean, but the Standalone Executable version also has the same trojan.
¨

Windows flags several Bitcoin wallets as trojans.
sr. member
Activity: 406
Merit: 443
January 21, 2024, 11:02:24 PM
#8
make sure to verify the signature with the wallet file that you downloaded. If the file is signed by the developer, do not pay attention to these warnings because they are false positive, else there is a virus that will redirect you outside electrum.org.
legendary
Activity: 3584
Merit: 1560
January 21, 2024, 05:15:43 PM
#7
See "notes for windows users" at the bottom of the download page:

https://electrum.org/#download
legendary
Activity: 2506
Merit: 2832
Top Crypto Casino
January 21, 2024, 04:50:56 PM
#6
If you have downloaded Electrum for the official website (electrum.org) then you should have read this note on the bottom of the download page:
Verifying the signature does not completely rule out that possibility.
If you trust the signers (Electrum devs) and you have properly imported their public keys from trusted sources then verifying the gpg signature should be enough.

legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
January 21, 2024, 03:25:08 AM
#5
I believe it is a false positive from Virustotal but to make sure, we must get official answer from Electrum team.

Can send a PM in bitcointalk to ThomasV or create an issue on Electrum Github or Electrum Twitter and wait for their team reply.
legendary
Activity: 2828
Merit: 1213
Call your grandparents and tell them you love them
January 21, 2024, 02:02:12 AM
#4
If it is from their official website, then highly unlikely to be a true positive AV flag.

A remote possibility of their site having been hacked and posted a malware bound software there.

Just one report, then it seems a false positive.

If you still worried about it then verifying it on your own is recommended : [GUIDE] How to Safely Download and Verify Electrum

How to verify your Electrum download
Verifying the signature does not completely rule out that possibility.

Hence that tingling spider sense of mine tells me that you should wait it out before operating that software. Mostly likely its false positive, but ..
copper member
Activity: 2016
Merit: 1783
฿itcoin for all, All for ฿itcoin.
January 20, 2024, 07:04:47 PM
#3
Definitely a false positive. I have never even heard of Ikarus Antivirus before.  Grin

So false positives have been popping up in the past too if you explore the closed issues in Github. At one point, there were 9 AV engines that would flag electrum as a malware, but a fix was done to reduce on those false positive detections.
sr. member
Activity: 2380
Merit: 251
Eloncoin.org - Mars, here we come!
January 20, 2024, 02:19:36 PM
#2
Just one report, then it seems a false positive.

If you still worried about it then verifying it on your own is recommended : [GUIDE] How to Safely Download and Verify Electrum

How to verify your Electrum download
staff
Activity: 2436
Merit: 2347
January 20, 2024, 02:15:49 PM
#1
I downloaded a portable version of Electrum wallet from the official website. Checked it with VirusTotal service and one engine showed me that there is a trojan in the wallet. What do you think, is it true that the file from the official site may contain a trojan or is it a false positive of the Ikarus engine?



P.S. The Windows Installer version is clean, but the Standalone Executable version also has the same trojan.
Jump to: