Originally posted over on /r/piracy (https://www.reddit.com/r/Piracy/comments/15itrip/1337x_admins_allowing_bg3_torrent_with_bitcoin/)

It looks like a bitcoin miner was included in the installer, and the admins on 1337x may or may not give a shit apparently. Scanned my pc and my wifes and found the same stuff the others mentioned.

According to the other comments, don't feel the need to uninstall as the miner was installed separate to the game, just give a Malwarebytes scan to get rid of the junk.

top 50 comments

sorted by: hot top controversial new old
[–] 114 points 3 years ago (3 children)

It's even worse apparently. Apparently someone looked at where the coins are going, and the coins are going to the 1337x admins, and the uploader is just getting a cut of those coins. Which explains why the admins are unlikely to really care because they're profiting off their users.

I have severe trust issues with any kind of pirated software so I basically never download it as a result, and shit like this is why. Even private trackers and "trusted" groups aren't enough for me to download most software.

  • source
  • hideshow 6 child comments
  • [–] 14 points 3 years ago (1 child)

    How did they figure that out?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 45 points 3 years ago (2 children)

    Crytpo isn't inherently anonymous. you can easily follow coins.

  • source
  • parent
  • hideshow 4 child comments
  • [+] 18 points 3 years ago* (last edited 2 years ago) (1 child)
  • [–] 101 points 3 years ago

    For gog games you can check the digital signature on the installer to make sure it's legit. It should be signed by GOG.

  • source
  • [–] 83 points 3 years ago (6 children)

    If you aren't scanning every software you download, whether a pirate torrent or normal direct download, that's kinda your own fault

  • source
  • hideshow 9 child comments
  • [–] 73 points 3 years ago (3 children)

    To be fair, I cannot remember a software where no anti virus program turned red. Those cracks always look suspicous to the heuristics.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 24 points 3 years ago (1 child)

    Of course but it's usually pretty easy to filter out the false positives that always appear as a Trojan (because of the file modification payload) vs a crypto miner

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (1 reply)
  • [–] [S] 18 points 3 years ago (1 child)

    Oh 100%. Was a dumb moment where I didn't expect it and didn't bother, and neither did a lot of other people from the looks of it. Good thing is it was something fixable in less than 5 mins and not a bigger problem.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (3 replies)
    [–] 64 points 3 years ago (1 child)

    You shouldn't trust anything uploaded there by IGGGames. They've been caught before adding miners to their files. I downloaded the rune release somewhere else seeing as they were the uploader on 1337x. I only really use 1337x for fitgirl repacks.

  • source
  • hideshow 2 child comments
  • [–] 61 points 3 years ago (1 child)

    Just popping in to say that if you enjoy the game and if you are financially able to, buy the game properly to support the developers, especially Larian Studios.

  • source
  • hideshow 2 child comments
  • [–] 49 points 3 years ago (1 child)

    LOL idiots BG3 is DRM Free just get the GOG installer, surely people mirror that shit, I've seent it before.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [+] 38 points 3 years ago* (last edited 2 years ago) (2 children)
  • [–] 20 points 3 years ago (2 children)

    Yeah the thing is it installs programs that then give themselves access. You can block install.exe all you like, they're way more advanced than that.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (1 reply)
  • [–] 35 points 3 years ago (1 child)

    Dont be mad at me but I bought the game from GOG :)

  • source
  • hideshow 2 child comments
  • [–] 24 points 3 years ago

    I reported it on 1337x earlier today, but they aren't very responsive. Fitgirl has it listed as an upcoming repack, so hopefully not long to wait for a clean copy.

  • source
  • [–] 21 points 3 years ago (1 child)

    I opened this post all scared that I might've accidentally downloaded malware and my fuckin' AV alerted

    yeah yeah I know piracy and AVs don't generally mix

  • source
  • hideshow 2 child comments
  • [+] 11 points 3 years ago* (last edited 2 years ago) (1 child)
  • [–] 7 points 3 years ago (5 children)

    Has anyone seen anything on the DODI release or is it clean?

  • source
  • hideshow 7 child comments
  • [–] 13 points 3 years ago* (last edited 3 years ago) (6 children)

    The DODI repack is based on the RUNE release which I believe is clean. Another commenter claims a found Trojan but there are others who found nothing, and imo it's probably just the usual crack shenanigans.

    Edit: See replies! It seems there are tainted versions of the repack out there, but there are clean ones too. Remember to keep a critical eye on your sites and uploaders in addition to your release groups. There's a useful link in a reply to me below showing what you might see if you've downloaded a bad one.

  • source
  • parent
  • hideshow 7 child comments
  • load more comments (5 replies)
  • load more comments (3 replies)
    load more comments
    view more: next ›