VIRUS ALERT! ???

Message boards : Number crunching : VIRUS ALERT! ???
Message board moderation

To post messages, you must log in.

AuthorMessage
Profile Dave Barstow

Send message
Joined: 14 May 99
Posts: 76
Credit: 15,064,044
RAC: 0
Philippines
Message 1081974 - Posted: 27 Feb 2011, 9:31:24 UTC

Renocide.gen!G

Category: Worm

Description: This program is dangerous and self-propagates over a network connection.

Recommended action: Remove this software immediately.

Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.

Items:
file:C:\ProgramData\BOINC\projects\setiathome.berkeley.edu\06no10ad.29815.22153.7.10.73


Got this message today and removed the file manually since even though the anti-virus program said it was removed, it was still there.[/b]
ID: 1081974 · Report as offensive
-BeNt-
Avatar

Send message
Joined: 17 Oct 99
Posts: 1234
Credit: 10,116,112
RAC: 0
United States
Message 1081978 - Posted: 27 Feb 2011, 9:35:15 UTC
Last modified: 27 Feb 2011, 9:36:30 UTC

I believe you may have gotten a false positive. I would think these are compressed format files which a virus can not be attached to, could be wrong on that though. Did your machine redownload the same WU by any chance? Next time something like that happens upload the file to a website like http://virusscan.jotti.org/en and see what the other engines think.
Traveling through space at ~67,000mph!
ID: 1081978 · Report as offensive
Profile Helli_retiered
Volunteer tester
Avatar

Send message
Joined: 15 Dec 99
Posts: 707
Credit: 108,785,585
RAC: 0
Germany
Message 1081981 - Posted: 27 Feb 2011, 9:38:48 UTC
Last modified: 27 Feb 2011, 9:41:20 UTC

Normally he will get this Virus.. err...Workunit back via Resent lost Workunit. hehe

No, seriously - i think also this is a kind of false positive. ;-)

Helli
A loooong time ago: First Credits after SETI@home Restart
ID: 1081981 · Report as offensive
Profile Dave Barstow

Send message
Joined: 14 May 99
Posts: 76
Credit: 15,064,044
RAC: 0
Philippines
Message 1081985 - Posted: 27 Feb 2011, 9:44:22 UTC - in response to Message 1081978.  

Thanks for responding... I also suspect that it was a false-positive, but better safe than sorry.

I also thought it would be prudent to let others here know... just in case...

It also seemed odd, that since I have been running S&H, I have never had this occur before.
ID: 1081985 · Report as offensive
Profile 52 Aces
Avatar

Send message
Joined: 7 Jan 02
Posts: 497
Credit: 14,261,068
RAC: 67
United States
Message 1081990 - Posted: 27 Feb 2011, 9:50:52 UTC - in response to Message 1081981.  
Last modified: 27 Feb 2011, 9:51:27 UTC

Sounds like the "Independence Day" virus authored by Jeff Goldblum .. sorry, I couldn't resist.

Sooner or later a WU was bound to have the arbitrary characters of a virus signature ... none-the-less, it is a false positive since it's not executable code.

.. but if it really keeps you up at night, select the WU in Boinc, select Abort, double check that's the one ya wanna nix, and click ok. I'll crunch it if you won't ;-)
ID: 1081990 · Report as offensive
Profile soft^spirit
Avatar

Send message
Joined: 18 May 99
Posts: 6497
Credit: 34,134,168
RAC: 0
United States
Message 1081992 - Posted: 27 Feb 2011, 9:53:09 UTC

There looked to be some "compromised" DNS servers a few days ago.. so anything is possible. I agree on the "better safe than sorry" philosophy.
Janice
ID: 1081992 · Report as offensive
kittyman Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer tester
Avatar

Send message
Joined: 9 Jul 00
Posts: 51468
Credit: 1,018,363,574
RAC: 1,004
United States
Message 1082008 - Posted: 27 Feb 2011, 10:50:33 UTC

I really have to follow this lead.....

May take me a long ways from here.

So, follow me if you dare......

Politics.......

Se ya there.

Meow now.
"Freedom is just Chaos, with better lighting." Alan Dean Foster

ID: 1082008 · Report as offensive
Odysseus
Volunteer tester
Avatar

Send message
Joined: 26 Jul 99
Posts: 1808
Credit: 6,701,347
RAC: 6
Canada
Message 1082014 - Posted: 27 Feb 2011, 11:26:38 UTC - in response to Message 1082007.  

Anybody got a bead on who the lead singer was?
Or 'where is she now'?

Her name was Mariska Veres; she died of cancer in 2006.

ID: 1082014 · Report as offensive
kittyman Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer tester
Avatar

Send message
Joined: 9 Jul 00
Posts: 51468
Credit: 1,018,363,574
RAC: 1,004
United States
Message 1082020 - Posted: 27 Feb 2011, 11:46:37 UTC - in response to Message 1082014.  

Anybody got a bead on who the lead singer was?
Or 'where is she now'?

Her name was Mariska Veres; she died of cancer in 2006.

Sorry to hear that, but thanks for the closure.


Thank you.
"Freedom is just Chaos, with better lighting." Alan Dean Foster

ID: 1082020 · Report as offensive
Profile Fred J. Verster
Volunteer tester
Avatar

Send message
Joined: 21 Apr 04
Posts: 3252
Credit: 31,903,643
RAC: 0
Netherlands
Message 1082026 - Posted: 27 Feb 2011, 12:46:48 UTC - in response to Message 1082020.  
Last modified: 27 Feb 2011, 13:24:07 UTC

It was a Dutch Band, in the late 60's and seventies, called Shocking Blue, I've seen them play before their first 'hit single', on an isle in the North of the Netherlands, Ameland.

Nice memories and a long time ago, about 40 years.
(And some more names pop up, like Captain Beefheart (Don van Vliet) and his Magic Band, Jethro Tull, Tiny Tim, Jefferson Airplane, Frank Zappa, etc. :) )

But back on topic, you can exclude the BOINC Projects Folder from an
virus scan.
ID: 1082026 · Report as offensive
Profile Raistmer
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 16 Jun 01
Posts: 6325
Credit: 106,370,077
RAC: 121
Russia
Message 1082118 - Posted: 27 Feb 2011, 18:09:52 UTC - in response to Message 1081974.  


Got this message today and removed the file manually since even though the anti-virus program said it was removed, it was still there.[/b]


Much better if you would remove SETI project directory from AV scan paths.
It will increase your PC speed and save you from high blood pressure from such false alarms.
WU contains data, it's not executable. Roughly it's the same as to find worm inside WAV file...
ID: 1082118 · Report as offensive
Profile ML1
Volunteer moderator
Volunteer tester

Send message
Joined: 25 Nov 01
Posts: 20289
Credit: 7,508,002
RAC: 20
United Kingdom
Message 1082181 - Posted: 27 Feb 2011, 22:00:30 UTC - in response to Message 1081974.  
Last modified: 27 Feb 2011, 22:02:13 UTC

Renocide.gen!G

Category: Worm

Description: This program is dangerous and self-propagates over a network connection.

Recommended action: Remove this software immediately.

[...]
Items:
file:C:\ProgramData\BOINC\projects\setiathome.berkeley.edu\06no10ad.29815.22153.7.10.73


Got this message today and removed the file manually...


Oh... One of those Microsoft Windows things...

There's enough random data from s@h (and any other project) that you are very likely to get a false positive detection from a virus scanner at some time or other. Best is to exclude the Boinc data folders from the virus scanning. Should speed up your processing a little due to removing a little unnecessary wasted overhead.


I run all my machines with no virus scanner at all. Some hosts don't even need or run a firewall either.

Happy clean fast crunchin',
Martin
See new freedom: Mageia Linux
Take a look for yourself: Linux Format
The Future is what We all make IT (GPLv3)
ID: 1082181 · Report as offensive
John McLeod VII
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 15 Jul 99
Posts: 24806
Credit: 790,712
RAC: 0
United States
Message 1083134 - Posted: 3 Mar 2011, 5:25:46 UTC - in response to Message 1081974.  

Renocide.gen!G

Category: Worm

Description: This program is dangerous and self-propagates over a network connection.

Recommended action: Remove this software immediately.

Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.

Items:
file:C:\ProgramData\BOINC\projects\setiathome.berkeley.edu\06no10ad.29815.22153.7.10.73


Got this message today and removed the file manually since even though the anti-virus program said it was removed, it was still there.[/b]

That is a data file, and since the contents are fairly random, you are going to get an occasional hit if all files are scanned. Nothing in the file is executed - ever.


BOINC WIKI
ID: 1083134 · Report as offensive
-BeNt-
Avatar

Send message
Joined: 17 Oct 99
Posts: 1234
Credit: 10,116,112
RAC: 0
United States
Message 1083168 - Posted: 3 Mar 2011, 9:58:29 UTC
Last modified: 3 Mar 2011, 10:01:30 UTC

Steps of using a forum:
#1 Read the thread, not just the first post. At least scan the entire thread.
#2 Has anyone already said what you plan on saying or has it not been covered?
#3 If it has already been covered, discussed,passed out, hinted on etc there is no need for your post. However if it hasn't been go to step #4.
#4 Post your helpful thought and progress the discussion.
Traveling through space at ~67,000mph!
ID: 1083168 · Report as offensive

Message boards : Number crunching : VIRUS ALERT! ???


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.