Do we have a Boinc virus? |
![]() |
| log in |
Message boards : Number crunching : Do we have a Boinc virus?
Previous · 1 . . . 3 · 4 · 5 · 6 · 7 · 8 · 9 . . . 27 · Next
| Author | Message |
|---|---|
|
For the record, it *does* look like there is the distinct possibility that a worm/virus is spreading around running BOINC under this guy's name (there are many hosts with his userid, all running windows, and with IP addresses all over the world). That's all the evidence we have, and there's really not much we can do. | |
| ID: 240694 · | |
For the record, it *does* look like there is the distinct possibility that a worm/virus is spreading around running BOINC under this guy's name Thanks for the update Matt. I knew it had to be some type of a worm, virus or botnet. Things never added up no matter how many different explanations were theorized. You can hide the program but in the end a specific user has to get the credit! Thanks again! >Fred ____________ http://www.teamstarfire.org/ | |
| ID: 240706 · | |
|
I thought that I read yesterday that the guy who reported this originally from England said that it looked like a normal Microsoft Windows update when this happened. Maybe Microsoft would be interested? | |
| ID: 240713 · | |
I thought that I read yesterday that the guy who reported this originally from England said that it looked like a normal Microsoft Windows update when this happened. Maybe Microsoft would be interested?He is from Canada. Someone here theorized that it may have been a bogus MS update email because of the exe file name that was used, "wupdmgr1.exe". The user never verified whether he updated from an email or website. I'll try to clarify this with him. >Fred ____________ http://www.teamstarfire.org/ | |
| ID: 240717 · | |
For the record, it *does* look like there is the distinct possibility that a worm/virus is spreading around running BOINC under this guy's name (there are many hosts with his userid, all running windows, and with IP addresses all over the world). That's all the evidence we have, and there's really not much we can do. For what it's worth, are these units at least legit? Virus or no virus, if these units are legit, the results probably should not be discarded. ____________ | |
| ID: 240725 · | |
|
By the way, it should be noted that if any of y'all do manage to get a copy of the infected wupdmgr1.exe, please send a copy to me or tell me how to get it. Don't worry, I don't work on any windows machines (just solaris, linux, and macs of course). | |
| ID: 240735 · | |
|
Matt- | |
| ID: 240741 · | |
By the way, it should be noted that if any of y'all do manage to get a copy of the infected wupdmgr1.exe, please send a copy to me or tell me how to get it. I'll get a copy from him. As soon as I get it I'll let you know. >Fred ____________ http://www.teamstarfire.org/ | |
| ID: 240742 · | |
Matt- I agree. The stats in Seti Classic became meaningless because of all the cheating. Is the same thing happening here? I hope not! ____________ Boinc....Boinc....Boinc....Boinc.... | |
| ID: 240744 · | |
I agree. The stats in Seti Classic became meaningless because of all the cheating. Is the same thing happening here? I hope not! I agree as well. Whatever happens I'll try to get a list of his "real" hosts versus his "hacked" hosts and adjust credit accordingly. - Matt ____________ -- BOINC/SETI@home network/web/science/development person -- "Any idiot can have a good idea. What is hard is to do it." - Jeanne-Claude | |
| ID: 240749 · | |
I'll try to get a list of his "real" hosts versus his "hacked" hosts and adjust credit accordingly. I was going to ask if you could do that, but I thought it might be too difficult. Thanks for your work, Matt. ____________ SETI.USA | |
| ID: 240757 · | |
I agree as well. Whatever happens I'll try to get a list of his "real" hosts versus his "hacked" hosts and adjust credit accordingly. Thanks Matt...it's nice to have you around to keep us in line! ____________ Boinc....Boinc....Boinc....Boinc.... | |
| ID: 240764 · | |
|
As was already told by others, the damage of this incident caused to BOINC and to its projects may be huge, and what is even worse, we can be almost certain that this case will not stay isolate. When people see it is possible, there maybe be soon crowds of others trying to do the same. Some followers may use more primitive methods, like simple Trojans, or instalation scripts, other may invent even more sophisticated viruses. | |
| ID: 240782 · | |
I agree. The stats in Seti Classic became meaningless because of all the cheating. Is the same thing happening here? I hope not! Thanks for the update - I belive that if he is found quilty that his TOTAL credits be removed - including all credits he crunched while with any team he may have been with. Just a personal feeling is all. | |
| ID: 240786 · | |
|
I feel that, if he is found guilty, he should have all credit removed. Keep the signals, but remove all credit. I don't think anyone should waste time trying to be 'fair' with someone who would do this. If guilty, he should be made an example to others who would try the same thing. | |
| ID: 240788 · | |
As was already told by others, the damage of this incident caused to BOINC and to its projects may be huge, and what is even worse, we can be almost certain that this case will not stay isolate. Or maybe it can be. I have read the whole Starfire thread and have seen the pictures the person provided. There is NO BOINC. Whoever cleverly made this, has gotten setiathome_4.18.exe to run almost stand alone, probably with the wupdmgr1.exe only doing the up&downloads. It won't hurt other projects as much, as no other project has the science application in Open Source. The threat of this thing may also be over soon if we can release Seti-Enhanced quickly enough. If SE takes over from 4.18, then all those "worms" will starve to death... until the person who made it updates it to SE, of course. At least it's a wake up call for the BOINC/Seti developers. ____________ Jord - BOINC FAQ Service - BOINC User Wiki Real is just a matter of perception. | |
| ID: 240789 · | |
...There is NO BOINC. Whoever cleverly made this, has gotten setiathome_4.18.exe to run almost stand alone, probably with the wupdmgr1.exe only doing the up&downloads.I hate to disapoint you, but you can rename boinc.exe to whatever you want. All it takes are as many keystrokes as the new name has. No rocket science, no Open Source programming. It won't hurt other projects as much, as no other project has the science application in Open Source.It has nothing to do with the openess of the project. You can simply take an available virus kit (there are plenty of them around) and change the payload or the download to whatever you want. It makes no difference if it is Open Source S@H or closed source Einstein@Home or whatever else. ____________ trux BOINC software Freediving Team Czech Republic | |
| ID: 240790 · | |
I hate to disapoint you, but you can rename boinc.exe to whatever you want. All it takes are as many keystrokes as the new name has. No rocket science, no Open Source programming. Okay, I take your word for that. That is, if wupdmgr1.exe is running from the system32 directory. The OP was never clear on that. Can Boinc.exe run (under whatever assumed name) from for instance Program Files, while the rest is under system32? ____________ Jord - BOINC FAQ Service - BOINC User Wiki Real is just a matter of perception. | |
| ID: 240795 · | |
Okay, I take your word for that. That is, if wupdmgr1.exe is running from the system32 directory. The OP was never clear on that. Can Boinc.exe run (under whatever assumed name) from for instance Program Files, while the rest is under system32?You can run any executable in any location you wish. Boinc core searches the needed files in the subdirectory structure based on its location (just like many other programs). In this case the renamed boinc.exe and all BOINC subdirs were within system32 ____________ trux BOINC software Freediving Team Czech Republic | |
| ID: 240808 · | |
Okay, I take your word for that. That is, if wupdmgr1.exe is running from the system32 directory. The OP was never clear on that. Can Boinc.exe run (under whatever assumed name) from for instance Program Files, while the rest is under system32?You can run any executable in any location you wish. Boinc core searches the needed files in the subdirectory structure based on its location (just like many other programs). In this case the renamed boinc.exe and all BOINC subdirs were within system32 For some reason I think this topic needs to be limited. No idea who is reading this - could be some people out there that could take this information and make a lot of trouble for all of us. It is just that some information should not be displayed in a public forum. Careful here. ____________ | |
| ID: 240812 · | |
Message boards : Number crunching : Do we have a Boinc virus?
| Copyright © 2013 University of California |