this post was submitted on 05 Aug 2023
424 points (96.9% liked)
Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ
54788 readers
677 users here now
⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.
Rules • Full Version
1. Posts must be related to the discussion of digital piracy
2. Don't request invites, trade, sell, or self-promote
3. Don't request or link to specific pirated titles, including DMs
4. Don't submit low-quality posts, be entitled, or harass others
Loot, Pillage, & Plunder
📜 c/Piracy Wiki (Community Edition):
💰 Please help cover server costs.
Ko-fi | Liberapay |
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
it's not a false positive people are finding. it's a bitcoin miner called integritycheck.exe
https://www.reddit.com/r/Piracy/comments/15itrip/1337x_admins_allowing_bg3_torrent_with_bitcoin/juxiobs/
Hey, thanks for that link! I'm really glad to have the details so I can verify for myself.
However, with that, I can REALLY confirm this is not an issue inherent to the DODI repack. DODI's is what I'm using and I have none of that on my system -- I checked with that powershell command, then also followed along with the comments to check other files and scheduled tasks that were mentioned.
That said, I got my download from torrentleech. I suspect a tainted version of the repack got onto certain other sites. It wouldn't be the first time (which is why I specify trusted sites and uploaders in addition to release groups).
good to hear. dodi just officially denied the accusations as well:
https://www.reddit.com/r/Piracy/comments/15ivtzk/dodi_verified_release_on_tg_has_crypto_miner/juy98il/
although he claims integritycheck.exe is a windows process, when clearly it is also the name of that miner I linked above
my guess is the dodi account on torrent galaxy, although verified, could be a fake and is putting in these viruses, or maybe the people commenting saying they got the virus from dodi actually got it from that hogwarts legacy crack which originally had this miner.
either way, I always hope the community will take these sorts of claims seriously and investigate to ensure everyone's safety