Originally posted over on /r/piracy (https://www.reddit.com/r/Piracy/comments/15itrip/1337x_admins_allowing_bg3_torrent_with_bitcoin/)

It looks like a bitcoin miner was included in the installer, and the admins on 1337x may or may not give a shit apparently. Scanned my pc and my wifes and found the same stuff the others mentioned.

According to the other comments, don’t feel the need to uninstall as the miner was installed separate to the game, just give a Malwarebytes scan to get rid of the junk.

  • @[email protected]
    link
    fedilink
    English
    311 months ago

    I downloaded the RUNE release from TorrentLeech and Windows Defender found a trojan so yeah I’ll believe it. I guess I’ll wait for a FitGirls repack.

    • @[email protected]
      link
      fedilink
      English
      611 months ago

      I’ve had false positives from cracks on TL before, several times. I respect your carefulness with a known problem with another release, though.

    • Elegast
      link
      fedilink
      English
      611 months ago

      Torrent galaxy rune release. However not seeing any issues? Malwarebytes scans coming up clean. No integritycheck folder in app data. No hidden process running when game running. 🤷‍♂️?

      • JelloBrains
        link
        fedilink
        211 months ago

        Sadly even with private sites a lot of things are taken from a public source and you occasionally run into this problem. Like some people up their ratios on these sites by using their VPN to get the public torrent and then seeding it back to the private one.

        • @[email protected]
          link
          fedilink
          English
          111 months ago

          As long as the first uploader didn’t do it, then that won’t cause other downloaders any issues. Torrents always verify the hash is correct and will discard bad data. And TorrentLeech has uploading torrents limited.

    • @5redie8
      link
      English
      111 months ago

      More than likely a false positive- they often show up as Trojans due to the payload. I saw a similar issue from the rune release off of my private tracker.

    • Nimmo
      link
      fedilink
      English
      -211 months ago

      Now that’s not something I’d have expected. I’ve never encountered anything like that in the nearly 15-20 years I’ve been using TL.

        • Nimmo
          link
          fedilink
          English
          111 months ago

          Just took a look at my profile, registered on 27 June 2006. So it’s in my 15-20 year window that I mentioned