This is why most of AV detects miners as threat: http://img851.imageshack.us/img851/9199/combofixm.jpg http://img233.imageshack.us/img233/7248/malwaremal.jpg It is all because creators of viruses are so lazy that they don't take source code of miner and use it in virus but they copy binary files from creator of miner and write only starter (something like GUIMiner). So viruses use original files of miners so AV threat them also as virus!