Anyone who downloaded the GOG Baldur's Gate 3 release from 1337x, scan with Malwarebytes asap!

GeekFTW@kbin.social to Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ@lemmy.dbzer0.com – 411 points –

Originally posted over on /r/piracy (https://www.reddit.com/r/Piracy/comments/15itrip/1337x\_admins\_allowing\_bg3\_torrent\_with\_bitcoin/)

It looks like a bitcoin miner was included in the installer, and the admins on 1337x may or may not give a shit apparently. Scanned my pc and my wifes and found the same stuff the others mentioned.

According to the other comments, don't feel the need to uninstall as the miner was installed separate to the game, just give a Malwarebytes scan to get rid of the junk.

80

You are viewing a single comment

I downloaded the RUNE release from TorrentLeech and Windows Defender found a trojan so yeah I'll believe it. I guess I'll wait for a FitGirls repack.

Torrent galaxy rune release. However not seeing any issues? Malwarebytes scans coming up clean. No integritycheck folder in app data. No hidden process running when game running. 🤷‍♂️?

I've had false positives from cracks on TL before, several times. I respect your carefulness with a known problem with another release, though.

From TL? Really? That's a surprise I didn't wanna hear! :/

Sadly even with private sites a lot of things are taken from a public source and you occasionally run into this problem. Like some people up their ratios on these sites by using their VPN to get the public torrent and then seeding it back to the private one.

As long as the first uploader didn't do it, then that won't cause other downloaders any issues. Torrents always verify the hash is correct and will discard bad data. And TorrentLeech has uploading torrents limited.

More than likely a false positive- they often show up as Trojans due to the payload. I saw a similar issue from the rune release off of my private tracker.

Now that's not something I'd have expected. I've never encountered anything like that in the nearly 15-20 years I've been using TL.

20? Interesting.

Just took a look at my profile, registered on 27 June 2006. So it's in my 15-20 year window that I mentioned