Artemis Trojan

Questions and Answers : Windows : Artemis Trojan
Message board moderation

To post messages, you must log in.

AuthorMessage
Tom95134

Send message
Joined: 27 Nov 01
Posts: 216
Credit: 3,790,200
RAC: 0
United States
Message 927604 - Posted: 21 Aug 2009, 1:24:48 UTC

Today I ran a full sacn of my system using McAfee and it detected the subject Trojan in the AP_GRAPHICS_5.03_WINDOWS_INTELX86.exe file.

What does this file do?

I am running the current version of BOINC.

The file has been quarantined. If I download BOINC again I don't believe it will replace the current installed BOINC as they are the same Version.

Has anybody seen anything similar?

Suggestions?
ID: 927604 · Report as offensive
Aurora Borealis
Volunteer tester
Avatar

Send message
Joined: 14 Jan 01
Posts: 3075
Credit: 5,631,463
RAC: 0
Canada
Message 927608 - Posted: 21 Aug 2009, 2:16:02 UTC - in response to Message 927604.  
Last modified: 21 Aug 2009, 2:24:54 UTC

Today I ran a full sacn of my system using McAfee and it detected the subject Trojan in the AP_GRAPHICS_5.03_WINDOWS_INTELX86.exe file.

What does this file do?

I am running the current version of BOINC.

The file has been quarantined. If I download BOINC again I don't believe it will replace the current installed BOINC as they are the same Version.

Has anybody seen anything similar?

Suggestions?

That is part of the Seti application to analyze Astropulse WU. McAfee and other virus software often give false positive. It is best to exempt the Boinc folders from being scanned. The chance of a virus coming from a trusted project is virtually zero. Even then Boinc software limits application to reading and writing within the Boinc Data folder.

Boinc V7.2.42
Win7 i5 3.33G 4GB, GTX470
ID: 927608 · Report as offensive
John McLeod VII
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 15 Jul 99
Posts: 24806
Credit: 790,712
RAC: 0
United States
Message 927612 - Posted: 21 Aug 2009, 2:49:31 UTC

It is the executable that displays graphics for the screen saver for AP tasks. If you delete it, it will be downloaded again from S@H.


BOINC WIKI
ID: 927612 · Report as offensive
Profile BilBg
Volunteer tester
Avatar

Send message
Joined: 27 May 07
Posts: 3720
Credit: 9,385,827
RAC: 0
Bulgaria
Message 927625 - Posted: 21 Aug 2009, 3:41:14 UTC - in response to Message 927604.  
Last modified: 21 Aug 2009, 3:41:56 UTC

Today I ran a full scan of my system using McAfee and it detected the subject Trojan in the AP_GRAPHICS_5.03_WINDOWS_INTELX86.exe file.

What does this file do?

I am running the current version of BOINC.

The file has been quarantined. If I download BOINC again I don't believe it will replace the current installed BOINC as they are the same Version.

Has anybody seen anything similar?

Suggestions?



Please, report this obviously wrong identification (false positive) to McAfee
- they have to correct this (if not already)!

(this file is part of SETI@home project (auto downloaded) - Not part of BOINC)

.
 


- ALF - "Find out what you don't do well ..... then don't do it!" :)
 
ID: 927625 · Report as offensive
Profile Rudy Rothemund

Send message
Joined: 1 Aug 99
Posts: 1
Credit: 6,463,948
RAC: 14
United States
Message 927688 - Posted: 21 Aug 2009, 11:56:09 UTC - in response to Message 927625.  

I got the same trojan message on a scan performed my Mcafee today and on a scan on 8/14/09. IS this really a trojan? If this comes up on several machines perhaps it is.

R Rothemund

ID: 927688 · Report as offensive
Aurora Borealis
Volunteer tester
Avatar

Send message
Joined: 14 Jan 01
Posts: 3075
Credit: 5,631,463
RAC: 0
Canada
Message 927697 - Posted: 21 Aug 2009, 13:15:47 UTC - in response to Message 927688.  
Last modified: 21 Aug 2009, 13:25:03 UTC

I got the same trojan message on a scan performed my Mcafee today and on a scan on 8/14/09. IS this really a trojan? If this comes up on several machines perhaps it is.

R Rothemund

As posted earlier it is not a Trojan but a known part of the Seti software. Anti virus software work by looking for patterns. If it looks anything like something a virus or trojan would use it assumes that's what it is. They are wrong more often then they are right because it is difficult to distinguish a benign piece of code from one that is designed to cause problems with your system.

Complain to your AV software company, they should know by now to ignore this false positive.

Boinc V7.2.42
Win7 i5 3.33G 4GB, GTX470
ID: 927697 · Report as offensive
OzzFan Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Volunteer tester
Avatar

Send message
Joined: 9 Apr 02
Posts: 15691
Credit: 84,761,841
RAC: 28
United States
Message 927727 - Posted: 21 Aug 2009, 15:28:24 UTC - in response to Message 927688.  

I got the same trojan message on a scan performed my Mcafee today and on a scan on 8/14/09. IS this really a trojan? If this comes up on several machines perhaps it is.

R Rothemund


That's false logic because it's a false positive. Of course it's going to come up on several machines because it is being falsely identified by the AV program.

This sort of thing is actually relatively common. I've seen it happen on other virus scanners from F-Prot & Kaspersky as well. Often, the reason why it is considered a trojan is due to the AV's primitive methods of identifying the behavior. All the scanner "sees" is that one program (BOINC) is trying to download another program (any science app) without the user having started the download manually, such as from a website - then the program itself consumes all CPU cycles like what most programs do when a machine has been turned into a zombie as part of a botnet.

This has already been identified by another user in this thread.
ID: 927727 · Report as offensive
TommyGun

Send message
Joined: 3 Jun 99
Posts: 2
Credit: 2,765,103
RAC: 0
United States
Message 928785 - Posted: 26 Aug 2009, 13:13:38 UTC

I just received a message from Comodo AV that astropulse_5.05_windows_intelx86.exe was labeled as Backdoor.Win32.Hupigon.RAA trojan. I wonder if this was the same behavior as above, a false positive? I just started using this AV recently, so I suspect so, but just in case, has anyone verified his?

Regards,
ID: 928785 · Report as offensive
Aurora Borealis
Volunteer tester
Avatar

Send message
Joined: 14 Jan 01
Posts: 3075
Credit: 5,631,463
RAC: 0
Canada
Message 928794 - Posted: 26 Aug 2009, 14:18:26 UTC - in response to Message 928785.  
Last modified: 26 Aug 2009, 14:20:44 UTC

I just received a message from Comodo AV that astropulse_5.05_windows_intelx86.exe was labeled as Backdoor.Win32.Hupigon.RAA trojan. I wonder if this was the same behavior as above, a false positive? I just started using this AV recently, so I suspect so, but just in case, has anyone verified his?

Regards,

Since it is known that the file comes from a trusted source 'SETI' which has not been compromised, then there is only one conclusion possible, it is a false positive. We are beginning to see that several different AV view this file as a virus, but they come up with different types. It is obvious that they are detecting a general pattern or behavior but can't identify it to a specific type of infection. They are doing 'best guess' and making false assumptions.
ID: 928794 · Report as offensive
TommyGun

Send message
Joined: 3 Jun 99
Posts: 2
Credit: 2,765,103
RAC: 0
United States
Message 928813 - Posted: 26 Aug 2009, 16:02:21 UTC - in response to Message 928794.  

Yep, I agree it is a false positive. Also, I was just reading reviews where Comodo AV (free version) is ranked as one of the worst, or best ;-), in producing false positives. It looks as though, I will remove it and use a more reliable AV scanner. I just needed an interim solution to AV anyway as my old (paid) AV broke after upgrading to Windows Vista SP2. Thanks for the help here.
ID: 928813 · Report as offensive
Profile Steven Coldwell

Send message
Joined: 14 Oct 08
Posts: 2
Credit: 2,173,018
RAC: 0
United States
Message 934086 - Posted: 17 Sep 2009, 20:50:47 UTC - in response to Message 927604.  

Yes I have!!!! My McAfee is going crazy & now my pc is going very slow!!!!!
[/b]
ID: 934086 · Report as offensive
Profile Steven Coldwell

Send message
Joined: 14 Oct 08
Posts: 2
Credit: 2,173,018
RAC: 0
United States
Message 934094 - Posted: 17 Sep 2009, 21:08:48 UTC - in response to Message 927604.  

What you have to do is uninstall the Boinc your pc & then reinstall it that should take care of the problem. Because Boinc I think will keep your data current.
ID: 934094 · Report as offensive
Profile Jord
Volunteer tester
Avatar

Send message
Joined: 9 Jun 99
Posts: 15184
Credit: 4,362,181
RAC: 3
Netherlands
Message 934096 - Posted: 17 Sep 2009, 21:10:49 UTC - in response to Message 934086.  
Last modified: 17 Sep 2009, 21:14:44 UTC

Best not read the rest of the thread... ;-)

If you don't trust what's being said in the thread, about this being a false positive detection by your anti virus software, you can run the file through http://www.virustotal.com/, which tests it against 30+ anti virus products.

Edit: I tested it just a moment ago and only McAfee finds something. Since the rest doesn't, you can conclude that it's not infected and what you see is a false positive that has to be fixed by McAfee.
ID: 934096 · Report as offensive
Profile skildude
Avatar

Send message
Joined: 4 Oct 00
Posts: 9541
Credit: 50,759,529
RAC: 60
Yemen
Message 934257 - Posted: 18 Sep 2009, 14:07:11 UTC - in response to Message 934094.  

What you have to do is uninstall the Boinc your pc & then reinstall it that should take care of the problem. Because Boinc I think will keep your data current.

This is not a solution to a problem that starts with the AV.


In a rich man's house there is no place to spit but his face.
Diogenes Of Sinope
ID: 934257 · Report as offensive
Profile Sterling_Aug
Avatar

Send message
Joined: 27 Sep 02
Posts: 54
Credit: 14,105,725
RAC: 0
United States
Message 934289 - Posted: 18 Sep 2009, 15:13:19 UTC

Dump McAfee and get a reliable and FREE AV solution such as Avira AntiVIR.
ID: 934289 · Report as offensive
Profile BilBg
Volunteer tester
Avatar

Send message
Joined: 27 May 07
Posts: 3720
Credit: 9,385,827
RAC: 0
Bulgaria
Message 934762 - Posted: 20 Sep 2009, 8:07:59 UTC - in response to Message 934289.  
Last modified: 20 Sep 2009, 8:12:39 UTC

Dump McAfee and get a reliable and FREE AV solution such as Avira AntiVIR.


I like most NOD32 Antivirus

http://www.eset.com/

http://www.eset.com/products/compare-NOD32-vs-competition.php
 


- ALF - "Find out what you don't do well ..... then don't do it!" :)
 
ID: 934762 · Report as offensive

Questions and Answers : Windows : Artemis Trojan


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.