Questions and Answers :
Windows :
Avast calling Cuda a virus and Seti@Home a bad site
Message board moderation
Author | Message |
---|---|
Silverdrake Send message Joined: 23 Mar 00 Posts: 14 Credit: 3,899,149 RAC: 0 |
Out of the blue, Avast alarmed and shut down Cuda processing. I told it to exclude the file from scanning and exited the alert popup. I opened the BOINC manager and found an Astropulus WU that said it was running, but neither time column was incrementing. I thought maybe that was the glitch, so I went to suspend it. It seems that this made BOINC try to contact the project, and I got another Avast alert. When I chose Details, it took me to Avast Security Center, which said: --------------------------------------- Infekce zablokována URL hxxp://boinc2.ssl.berkeley.edu/sah/download_fanout/setiathome_7.00_windows_intelx86__cuda50.exe|[UPX] Infection Win32:Evo-gen [Susp] --------------------------------------- Now *every* Seti@Home WU is showing "Computation Error." Avast has nothing in the virus vault, so I have no idea what it did. Here is the event log data from before and after: 6/17/2014 1:34:25 AM | SETI@home | Computation for task ap_27my08ah_B1_P0_00009_20140613_23702.wu_1 finished 6/17/2014 1:34:25 AM | SETI@home | Starting task 11ja09ac.20210.16023.438086664196.12.46_0 6/17/2014 1:34:28 AM | SETI@home | Started upload of ap_27my08ah_B1_P0_00009_20140613_23702.wu_1_0 6/17/2014 1:34:32 AM | SETI@home | Finished upload of ap_27my08ah_B1_P0_00009_20140613_23702.wu_1_0 6/17/2014 2:35:14 AM | SETI@home | Sending scheduler request: To report completed tasks. 6/17/2014 2:35:14 AM | SETI@home | Reporting 1 completed tasks 6/17/2014 2:35:14 AM | SETI@home | Not requesting tasks: don't need 6/17/2014 2:35:16 AM | SETI@home | Scheduler request completed 6/17/2014 3:26:54 AM | SETI@home | Computation for task 11ja09ac.20210.16023.438086664196.12.46_0 finished 6/17/2014 3:26:54 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:26:54 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:26:54 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:26:54 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:26:54 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:27:03 AM | SETI@home | Computation for task 10dc08ac.19978.15614.438086664196.12.163_1 finished 6/17/2014 3:27:03 AM | SETI@home | Output file 10dc08ac.19978.15614.438086664196.12.163_1_0 for task 10dc08ac.19978.15614.438086664196.12.163_1 absent 6/17/2014 3:27:03 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:27:03 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:27:03 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:27:03 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:27:03 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 3:27:06 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 3:27:06 AM | SETI@home | Started upload of 11ja09ac.20210.16023.438086664196.12.46_0_0 6/17/2014 3:27:06 AM | SETI@home | Computation for task 11ja09ac.20210.16023.438086664196.12.55_1 finished 6/17/2014 3:27:06 AM | SETI@home | Output file 11ja09ac.20210.16023.438086664196.12.55_1_0 for task 11ja09ac.20210.16023.438086664196.12.55_1 absent 6/17/2014 3:27:06 AM | SETI@home | [error] Process creation failed: The process cannot access the file because it is being used by another process. (0x20) 6/17/2014 3:27:06 AM | SETI@home | [error] Process creation failed: The process cannot access the file because it is being used by another process. (0x20) 6/17/2014 3:27:06 AM | SETI@home | [error] Process creation failed: The process cannot access the file because it is being used by another process. (0x20) 6/17/2014 3:27:06 AM | SETI@home | [error] Process creation failed: The process cannot access the file because it is being used by another process. (0x20) 6/17/2014 3:27:06 AM | SETI@home | [error] Process creation failed: The process cannot access the file because it is being used by another process. (0x20) 6/17/2014 3:27:13 AM | SETI@home | Computation for task 10dc08ac.19978.15614.438086664196.12.148_0 finished 6/17/2014 3:27:13 AM | SETI@home | Output file 10dc08ac.19978.15614.438086664196.12.148_0_0 for task 10dc08ac.19978.15614.438086664196.12.148_0 absent And on and on and on for every WU I had. Then, it went to this: 6/17/2014 3:30:28 AM | SETI@home | Computation for task 12mr09ab.27040.24612.438086664202.12.103_2 finished 6/17/2014 3:30:28 AM | SETI@home | Output file 12mr09ab.27040.24612.438086664202.12.103_2_0 for task 12mr09ab.27040.24612.438086664202.12.103_2 absent 6/17/2014 3:30:30 AM | SETI@home | Finished upload of 11ja09ac.20210.16023.438086664196.12.46_0_0 6/17/2014 3:30:32 AM | SETI@home | Temporarily failed download of setiathome_7.00_windows_intelx86__cuda50.exe: transient HTTP error 6/17/2014 3:30:32 AM | SETI@home | Backing off 00:02:16 on download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 3:30:36 AM | | Project communication failed: attempting access to reference site 6/17/2014 3:30:38 AM | | Internet access OK - project servers may be temporarily down. 6/17/2014 3:32:48 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 3:32:50 AM | SETI@home | Temporarily failed download of setiathome_7.00_windows_intelx86__cuda50.exe: transient HTTP error 6/17/2014 3:32:50 AM | SETI@home | Backing off 00:06:00 on download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 3:32:53 AM | | Project communication failed: attempting access to reference site 6/17/2014 3:32:54 AM | | Internet access OK - project servers may be temporarily down. 6/17/2014 3:38:51 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 3:38:53 AM | SETI@home | Temporarily failed download of setiathome_7.00_windows_intelx86__cuda50.exe: transient HTTP error 6/17/2014 3:38:53 AM | SETI@home | Backing off 00:11:01 on download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 3:38:56 AM | | Project communication failed: attempting access to reference site 6/17/2014 3:38:58 AM | | Internet access OK - project servers may be temporarily down. 6/17/2014 3:50:42 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 3:50:44 AM | SETI@home | Temporarily failed download of setiathome_7.00_windows_intelx86__cuda50.exe: transient HTTP error 6/17/2014 3:50:44 AM | SETI@home | Backing off 00:21:21 on download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 3:50:46 AM | | Project communication failed: attempting access to reference site 6/17/2014 3:50:48 AM | | Internet access OK - project servers may be temporarily down. It went to a 24-hour backoff for server contact. I tried a manual update: 6/17/2014 4:04:06 AM | SETI@home | update requested by user 6/17/2014 4:04:08 AM | SETI@home | Fetching scheduler list 6/17/2014 4:04:09 AM | SETI@home | Master file download succeeded 6/17/2014 4:04:14 AM | SETI@home | Sending scheduler request: Requested by user. 6/17/2014 4:04:14 AM | SETI@home | Reporting 80 completed tasks 6/17/2014 4:04:14 AM | SETI@home | Not requesting tasks: some download is stalled 6/17/2014 4:04:17 AM | SETI@home | Scheduler request completed I looked in transfers and found the stuck download and told it to retry: 6/17/2014 4:06:23 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 4:06:26 AM | SETI@home | Temporarily failed download of setiathome_7.00_windows_intelx86__cuda50.exe: transient HTTP error 6/17/2014 4:06:26 AM | SETI@home | Backing off 00:51:00 on download of setiathome_7.00_windows_intelx86__cuda50.exe 6/17/2014 4:06:29 AM | | Project communication failed: attempting access to reference site 6/17/2014 4:06:31 AM | | Internet access OK - project servers may be temporarily down. "setiathome_7.00_windows_intelx86__cuda50.exe" was what the first virus alert was about. So, um.... what the heck just happened? :-\ |
Silverdrake Send message Joined: 23 Mar 00 Posts: 14 Credit: 3,899,149 RAC: 0 |
Update Avast just did the same on our other computer, this time with Cuda42. This time, I found it in the virus vault, and restored and excluded it. It had already errored out all of my Cuda WUs, though. CPU WUs appear unaffected. Also alerted on the website, again: --------------------------- Infekce zablokována URL hxxp://boinc2.ssl.berkeley.edu/sah/download_fanout/setiathome_7.00_windows_intelx86__cuda42.exe|[UPX] Infection Win32:Evo-gen [Susp] --------------------------- Event log data: 6/16/2014 8:59:07 PM | SETI@home | Sending scheduler request: To report completed tasks. 6/16/2014 8:59:07 PM | SETI@home | Reporting 1 completed tasks 6/16/2014 8:59:07 PM | SETI@home | Not requesting tasks: don't need 6/16/2014 8:59:09 PM | SETI@home | Scheduler request completed 6/17/2014 12:44:36 AM | SETI@home | Computation for task 15oc08ab.3998.18886.438086664207.12.204_0 finished 6/17/2014 12:44:36 AM | SETI@home | Starting task 15oc08ab.3998.18886.438086664207.12.246_0 6/17/2014 12:44:38 AM | SETI@home | Started upload of 15oc08ab.3998.18886.438086664207.12.204_0_0 6/17/2014 12:44:41 AM | SETI@home | Finished upload of 15oc08ab.3998.18886.438086664207.12.204_0_0 6/17/2014 12:59:43 AM | | Suspending GPU computation - computer is in use 6/17/2014 1:29:44 AM | | Resuming GPU computation 6/17/2014 1:44:48 AM | SETI@home | Sending scheduler request: To report completed tasks. 6/17/2014 1:44:48 AM | SETI@home | Reporting 1 completed tasks 6/17/2014 1:44:48 AM | SETI@home | Not requesting tasks: don't need 6/17/2014 1:44:50 AM | SETI@home | Scheduler request completed 6/17/2014 4:48:59 AM | SETI@home | Computation for task 15oc08ab.3998.18886.438086664207.12.246_0 finished 6/17/2014 4:48:59 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:48:59 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:48:59 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:48:59 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:48:59 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:49:20 AM | SETI@home | Computation for task 15oc08ab.3998.18886.438086664207.12.89_0 finished 6/17/2014 4:49:20 AM | SETI@home | Output file 15oc08ab.3998.18886.438086664207.12.89_0_0 for task 15oc08ab.3998.18886.438086664207.12.89_0 absent 6/17/2014 4:49:20 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:49:20 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:49:20 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:49:20 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:49:20 AM | SETI@home | [error] Process creation failed: The system cannot find the file specified. (0x2) 6/17/2014 4:49:22 AM | | [error] Can't create HTTP response output file projects/setiathome.berkeley.edu/setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 4:49:22 AM | SETI@home | Backing off 00:02:50 on download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 4:49:22 AM | SETI@home | Started upload of 15oc08ab.3998.18886.438086664207.12.246_0_0 6/17/2014 4:49:22 AM | SETI@home | Computation for task 15oc08ab.3998.18886.438086664207.12.249_0 finished 6/17/2014 4:49:22 AM | SETI@home | Output file 15oc08ab.3998.18886.438086664207.12.249_0_0 for task 15oc08ab.3998.18886.438086664207.12.249_0 absent 6/17/2014 4:49:22 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:22 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:22 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:22 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:22 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:30 AM | SETI@home | Computation for task 16no08ac.9616.18886.438086664204.12.175_1 finished 6/17/2014 4:49:30 AM | SETI@home | Output file 16no08ac.9616.18886.438086664204.12.175_1_0 for task 16no08ac.9616.18886.438086664204.12.175_1 absent 6/17/2014 4:49:30 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:30 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:30 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:30 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:30 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:32 AM | SETI@home | Computation for task 16no08ac.9616.18886.438086664204.12.236_0 finished 6/17/2014 4:49:32 AM | SETI@home | Output file 16no08ac.9616.18886.438086664204.12.236_0_0 for task 16no08ac.9616.18886.438086664204.12.236_0 absent 6/17/2014 4:49:32 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:32 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:32 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:32 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:32 AM | SETI@home | [error] Process creation failed: Access is denied. (0x5) 6/17/2014 4:49:36 AM | | Suspending GPU computation - computer is in use 6/17/2014 4:49:36 AM | SETI@home | Computation for task 15oc08ab.3998.18886.438086664207.12.243_0 finished 6/17/2014 4:49:36 AM | SETI@home | Output file 15oc08ab.3998.18886.438086664207.12.243_0_0 for task 15oc08ab.3998.18886.438086664207.12.243_0 absent 6/17/2014 4:49:39 AM | SETI@home | Finished upload of 15oc08ab.3998.18886.438086664207.12.246_0_0 6/17/2014 4:52:13 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 4:52:16 AM | SETI@home | Temporarily failed download of setiathome_7.00_windows_intelx86__cuda42.exe: transient HTTP error 6/17/2014 4:52:16 AM | SETI@home | Backing off 00:05:29 on download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 4:52:17 AM | | Project communication failed: attempting access to reference site 6/17/2014 4:52:19 AM | | Internet access OK - project servers may be temporarily down. 6/17/2014 4:57:46 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 4:58:10 AM | SETI@home | Finished download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 4:58:10 AM | SETI@home | [error] Checksum or signature error for setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 5:04:43 AM | SETI@home | update requested by user 6/17/2014 5:04:45 AM | SETI@home | Fetching scheduler list 6/17/2014 5:04:47 AM | SETI@home | Master file download succeeded 6/17/2014 5:04:52 AM | SETI@home | Sending scheduler request: Requested by user. 6/17/2014 5:04:52 AM | SETI@home | Reporting 30 completed tasks 6/17/2014 5:04:52 AM | SETI@home | Requesting new tasks for NVIDIA 6/17/2014 5:04:54 AM | SETI@home | Scheduler request completed: got 31 new tasks 6/17/2014 5:04:56 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 5:04:56 AM | SETI@home | Started download of 22au08ae.1377.14103.438086664200.12.32 6/17/2014 5:04:58 AM | SETI@home | Finished download of 22au08ae.1377.14103.438086664200.12.32 6/17/2014 5:04:58 AM | SETI@home | Started download of 22au08ae.1377.14103.438086664200.12.53 6/17/2014 5:04:59 AM | SETI@home | Temporarily failed download of setiathome_7.00_windows_intelx86__cuda42.exe: transient HTTP error 6/17/2014 5:04:59 AM | SETI@home | Backing off 00:03:24 on download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 5:04:59 AM | SETI@home | Finished download of 22au08ae.1377.14103.438086664200.12.53 6/17/2014 5:04:59 AM | SETI@home | Started download of 22au08ae.1377.14103.438086664200.12.56 6/17/2014 5:04:59 AM | SETI@home | Started download of 22au08ae.1377.14103.438086664200.12.65 6/17/2014 5:05:01 AM | SETI@home | Finished download of 22au08ae.1377.14103.438086664200.12.56 6/17/2014 5:05:01 AM | SETI@home | Started download of 22au08ae.1377.14103.438086664200.12.34 6/17/2014 5:05:01 AM | | Project communication failed: attempting access to reference site 6/17/2014 5:05:02 AM | | Internet access OK - project servers may be temporarily down. 6/17/2014 5:05:02 AM | SETI@home | Finished download of 22au08ae.1377.14103.438086664200.12.34 Continued downloading new workunits.... 6/17/2014 5:05:24 AM | SETI@home | Finished download of 22au08ae.1377.14103.438086664200.12.45 6/17/2014 5:08:25 AM | SETI@home | Started download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 5:08:26 AM | SETI@home | Temporarily failed download of setiathome_7.00_windows_intelx86__cuda42.exe: transient HTTP error 6/17/2014 5:08:26 AM | SETI@home | Backing off 00:06:55 on download of setiathome_7.00_windows_intelx86__cuda42.exe 6/17/2014 5:08:28 AM | | Project communication failed: attempting access to reference site 6/17/2014 5:08:29 AM | | Internet access OK - project servers may be temporarily down. |
Zalster Send message Joined: 27 May 99 Posts: 5517 Credit: 528,817,460 RAC: 242 |
If you search the message boards I think you will see that it's happen to others before with anti-virus programs. For some reason Seti and all the work units get listed as viruses and then get quarantined or deleted. You did right with the exclude folders. Sorry to hear that it happened. That part about the Http Error, I'm not sure. I remember seeing that just after the seti@home Enhanced were being resent last week but that shouldn't have anything to do with the 42 or the 50s so i'm not sure what is going on. Hopefully one of the others will have an idea and post it here. |
Jord Send message Joined: 9 Jun 99 Posts: 15184 Credit: 4,362,181 RAC: 3 |
The only idea I can come up with is that Avast is blocking downloads from Seti. It shows the URL as being hxxp://boinc2.ssl.berkeley.edu/sah/download_fanout/setiathome_7.00_windows_intelx86__cuda42.exe, hxxp instead of http. Can you download setiathome_7.00_windows_intelx86__cuda42.exe from a browser? |
Cat Send message Joined: 2 Apr 12 Posts: 3 Credit: 1,425,786 RAC: 0 |
I'm having the same problem. I've been using Avast since before I started with Seti and this is the first time this has happened. About the only thing I can think to do is simply exclude the BOINC data folder from scanning and trust that The Powers That Be already ensure no viruses/malware are included in the Seti files. |
Jord Send message Joined: 9 Jun 99 Posts: 15184 Credit: 4,362,181 RAC: 3 |
Since the science applications are built and maintained in a Linux environment, the possibility that the applications are all of a sudden infected by a virus, is smaller than 1. This doesn't mean that your system can't have an infection that causes the warnings to happen, especially not if the application worked perfectly yesterday and today Avast thinks it's infected. But even so, just consider it a flase positive. It's why we (the helpers) advise to always exclude the BOINC data directory and all files therein from being actively scanned by anti-virus and other anti-malware products. And to do so before you AV goes and tells you there's something wrong. If you still don't trust it, throw the executable into https://www.virustotal.com/, where it will be scanned by 52+ virus scanners. When most of those flag it as being suspicious, it is. |
Silverdrake Send message Joined: 23 Mar 00 Posts: 14 Credit: 3,899,149 RAC: 0 |
@ Zalster -- it was those others that told me about excluding the folders, but none of them described the same occurrence that I had just had. I thought that posting my results might help Seti work with Avast to prevent this from happening. @ Ageless -- I had wondered about that "hxxp" since I had never seen a url come up like that, before. I downloaded and saved cuda42.exe without a problem. I'm on my computer that had the alert on cuda50.exe, though. I'll try that on my husband's computer after he goes to work as a double-check. His computer had put cuda42.exe in the virus vault and I reported it to Avast as a false positive. Turns out my Avast was set to automatically repair, so it probably just deleted it. I've changed it to "Ask." Thank you for the link to https://www.virustotal.com/. I bookmarked it. I have been running BOINC since Seti@Home went to it. This is the third or fourth antivirus program it has run under, and this is the first time I've had anything like this happen. So it looks like it was caused by a recent update from Avast. |
Silverdrake Send message Joined: 23 Mar 00 Posts: 14 Credit: 3,899,149 RAC: 0 |
Just tested the download on my husband's computer. No problem at all downloading and saving cuda42.exe. |
©2024 University of California
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.