AVG is flagging AP6_win_x86_SSE2_OpenCL_NV_r1761.exe

Message boards : Number crunching : AVG is flagging AP6_win_x86_SSE2_OpenCL_NV_r1761.exe
Message board moderation

To post messages, you must log in.

AuthorMessage
Profile Mr. Kevvy Crowdfunding Project Donor*Special Project $250 donor
Volunteer moderator
Volunteer tester
Avatar

Send message
Joined: 15 May 99
Posts: 3777
Credit: 1,114,826,392
RAC: 3,319
Canada
Message 1359803 - Posted: 22 Apr 2013, 12:56:12 UTC
Last modified: 22 Apr 2013, 12:57:09 UTC



Using Lunatics platform. The module catching this is Identity Protection. Unfortunately there are no details provided. (The field cut off on the right edge just says "File or folder" as the object type, not what is triggering the detection.)

I ensured it wasn't quarantined, yet I can no longer find this file at the location indicated, but instead in the oldApp_backup subfolder. For some reason the C:\ProgramData\BOINC\projects\setiathome.berkeley.edu has become read-only.

I ran it through VirusTotal after re-extracting it from the original download archive, verified it has the same hash as the one in oldApp_backup, and it came up clean with 0/46. So it's probably a false positive.
ID: 1359803 · Report as offensive
Profile Link
Avatar

Send message
Joined: 18 Sep 03
Posts: 834
Credit: 1,807,369
RAC: 0
Germany
Message 1359806 - Posted: 22 Apr 2013, 12:59:41 UTC - in response to Message 1359803.  

Always exclude the entire BOINC data directory from scanning, that keeps all problems regarding AV away.
ID: 1359806 · Report as offensive
Darth Beaver Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Avatar

Send message
Joined: 20 Aug 99
Posts: 6728
Credit: 21,443,075
RAC: 3
Australia
Message 1359807 - Posted: 22 Apr 2013, 13:02:05 UTC - in response to Message 1359803.  

mm no prob's here with AVG I noticed it says reboot to finish action !! AVG hadn't just done a update did it just before it flaged it ?????
ID: 1359807 · Report as offensive
Profile Mr. Kevvy Crowdfunding Project Donor*Special Project $250 donor
Volunteer moderator
Volunteer tester
Avatar

Send message
Joined: 15 May 99
Posts: 3777
Credit: 1,114,826,392
RAC: 3,319
Canada
Message 1359812 - Posted: 22 Apr 2013, 13:05:30 UTC - in response to Message 1359807.  
Last modified: 22 Apr 2013, 13:09:48 UTC

mm no prob's here with AVG I noticed it says reboot to finish action !! AVG hadn't just done a update did it just before it flaged it ?????


I think it means by that because it's a running process that it needs a reboot to remove or quarantine it.

Always exclude the entire BOINC data directory from scanning, that keeps all problems regarding AV away.


I'm sure the developers are trustworthy, but what if their compilers are compromised, for example? (Yes, this has happened.)
ID: 1359812 · Report as offensive
Darth Beaver Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Avatar

Send message
Joined: 20 Aug 99
Posts: 6728
Credit: 21,443,075
RAC: 3
Australia
Message 1359815 - Posted: 22 Apr 2013, 13:10:52 UTC - in response to Message 1359812.  

Your prob right .
Have you done a reboot lately and has AVG updated lately I have had big trouble with updates from AVG over the last couple of yrs and told them so
ID: 1359815 · Report as offensive
Profile Raistmer
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 16 Jun 01
Posts: 6325
Credit: 106,370,077
RAC: 121
Russia
Message 1359837 - Posted: 22 Apr 2013, 14:05:15 UTC

AVG gave false positives before too.
I would use some another scanner, like Avira or NOD32 or DrWEB.

Also you could upload this binary to online service and check with few dozens different antiviruses available there.
Until that I will not bother to check. I refused to use AVG long ago.

SETI apps news
We're not gonna fight them. We're gonna transcend them.
ID: 1359837 · Report as offensive
Darth Beaver Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Avatar

Send message
Joined: 20 Aug 99
Posts: 6728
Credit: 21,443,075
RAC: 3
Australia
Message 1359840 - Posted: 22 Apr 2013, 14:13:10 UTC - in response to Message 1359837.  

I'm with you Ras got quite peed off with AVG but they convinced me that was in the past so like a dumass I listened didn't I

oh well i'm now i'm warned I could be having trouble with avg
ID: 1359840 · Report as offensive
Profile Wiggo
Avatar

Send message
Joined: 24 Jan 00
Posts: 35184
Credit: 261,360,520
RAC: 489
Australia
Message 1359844 - Posted: 22 Apr 2013, 14:20:06 UTC - in response to Message 1359840.  

This pops up now and again with some peoples' AVG but so far I've never experienced myself in over 12 years of using it.

Cheers.
ID: 1359844 · Report as offensive
Darth Beaver Crowdfunding Project Donor*Special Project $75 donorSpecial Project $250 donor
Avatar

Send message
Joined: 20 Aug 99
Posts: 6728
Credit: 21,443,075
RAC: 3
Australia
Message 1359847 - Posted: 22 Apr 2013, 14:26:38 UTC - in response to Message 1359844.  

wiggo never even when It did a update on the ap itself cose I have they called it a update but they changed everything dam thing just installed over the older 1 and would crash and then I couldn't uninstall the bloody thing had to use a special program to uninstall all versions
ID: 1359847 · Report as offensive
Profile Mr. Kevvy Crowdfunding Project Donor*Special Project $250 donor
Volunteer moderator
Volunteer tester
Avatar

Send message
Joined: 15 May 99
Posts: 3777
Credit: 1,114,826,392
RAC: 3,319
Canada
Message 1359853 - Posted: 22 Apr 2013, 14:37:57 UTC - in response to Message 1359837.  

AVG gave false positives before too.
I would use some another scanner, like Avira or NOD32 or DrWEB.
Also you could upload this binary to online service and check with few dozens different antiviruses available there.
Until that I will not bother to check. I refused to use AVG long ago.


Yup, I linked to VirusTotal's results in the OP... no detections, even from AVG's main engine. But I think it's still better to have this info posted so it's a known issue.
ID: 1359853 · Report as offensive
Profile Raistmer
Volunteer developer
Volunteer tester
Avatar

Send message
Joined: 16 Jun 01
Posts: 6325
Credit: 106,370,077
RAC: 121
Russia
Message 1359857 - Posted: 22 Apr 2013, 14:42:40 UTC - in response to Message 1359853.  

But I think it's still better to have this info posted so it's a known issue.


And even better it would be to post this to AVG forum and their support, cause it's known issue... in their scanner ;)

SETI apps news
We're not gonna fight them. We're gonna transcend them.
ID: 1359857 · Report as offensive
TBar
Volunteer tester

Send message
Joined: 22 May 99
Posts: 5204
Credit: 840,779,836
RAC: 2,768
United States
Message 1371033 - Posted: 23 May 2013, 18:57:49 UTC
Last modified: 23 May 2013, 19:27:24 UTC

I had this happen last night with AP6_win_x86_SSE2_OpenCL_ATI_r1812.exe. The BOINC Folder WAS on the Exclude list, AVG flagged it anyway under 'General behavioral detection', then hung when I told AVG to allow and restore. It looks like the only way to prevent it from being flagged under 'Identity Protection' is to exclude the specific App. If you just exclude the Folder, you are not given the option to exclude the Folder from 'Identity Protection'.

All ~80 ATI APs were trashed when AVG removed the App. I was able to preform a Project Reset before all the "Errors" were reported. During the Reset, the Scheduler once again decided to Time-Out all my Cuda tasks. This time, I think the Scheduler resent 100 old APs as ATI APs, then began resending the more recent APs as CPU APs, and by the time it got to the Cuda 23s it was out of 'allotted' space for GPU tasks. Every time I've had to do a reset, the Cuda tasks get "Expired". Oh well...
ID: 1371033 · Report as offensive

Message boards : Number crunching : AVG is flagging AP6_win_x86_SSE2_OpenCL_NV_r1761.exe


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.