Trojan in Core??? [No. False Postive from AVAST]

Moderators: Site Moderators, PandeGroup

Trojan in Core??? [No. False Postive from AVAST]

Postby caintry_boy » Thu Apr 02, 2009 5:55 pm

Got up today and checked my Folding Farm out. 2 out of 6 rigs had pop-ups that a Trojan Win32:Swizzor was found in C:\FAH\FahCore_a1.exe...........
My antivirus on both of those machines is Avast4. Is this an Avast problem or is it possible that something is coming in with the core??? I cleaned both, and restarted (meaning it had to download new Core's) and on downloading new Core's Avast goes crazy!!! I can't get a new core downloaded and running.


Help please......


:eo
caintry_boy
 
Posts: 99
Joined: Wed Feb 13, 2008 4:10 am

Re: Trojan in Core???

Postby MysticGold04 » Thu Apr 02, 2009 6:09 pm

See my post on this subject... no trojans. Just add the folder where the F@H files reside to the exclusions in Avast. I scanned the core with another AV, plus Spybot and Anti-Malware, no issues...
Image
MysticGold04
 
Posts: 11
Joined: Thu Apr 02, 2009 4:45 pm

Re: Trojan in Core???

Postby 7im » Thu Apr 02, 2009 6:29 pm

Avast is a known offender for giving false positives. There are many such posts on this forum, and when the system is scanned again with other AV softwares, none of them turn up the same problem.

The big three AV vendors have online scans for free, try one of those to confirm.
User avatar
7im
 
Posts: 7067
Joined: Thu Nov 29, 2007 5:30 pm

Re: Trojan in Core???

Postby caintry_boy » Thu Apr 02, 2009 6:33 pm

MysticGold04 wrote:See my post on this subject... no trojans. Just add the folder where the F@H files reside to the exclusions in Avast. I scanned the core with another AV, plus Spybot and Anti-Malware, no issues...


Didn't work for me....still popping up with a warning.....


:e(

edit: thanks 7iM! I'm pretty sure it's a false positive, I just need to get the right info in my Avast settings so it'll quit this.
edit #2: I think I got it straightened out......
caintry_boy
 
Posts: 99
Joined: Wed Feb 13, 2008 4:10 am

Re: Trojan in Core???

Postby StrategyFreak » Thu Apr 02, 2009 9:20 pm

I got this as well; I added this to the exclusions list and it went away.
StrategyFreak
 
Posts: 10
Joined: Sat Mar 28, 2009 5:42 am

Re: Trojan in Core???

Postby MtM » Thu Apr 02, 2009 10:07 pm

If you have a suspicious file and want to be sure about wether it's an actual virus or not, http://www.virustotal.com/ is a good place to go. It will scan your submitted file with a long list of known anti virus packages and will show you the complete results. This has helped me allot in the past, as some av's are indeed giving false positives, where others allowed files which my fw for instance notified me of potential security issues and they turned out to be suspicious atleast when scanned with more solutions.

Offcourse, even scanning with 20+ known virus scanner and coming up as clean doesn't mean it's 100% clean, but it's as close as it can get.
MtM
 
Posts: 2303
Joined: Fri Jun 27, 2008 3:20 pm
Location: The Netherlands

Re: Trojan in Core???

Postby caintry_boy » Thu Apr 02, 2009 10:12 pm

Yup! I did that and only got two "hits", my antivirus and one other. That pretty much verified my feeling that it was an FP.


:mrgreen:
caintry_boy
 
Posts: 99
Joined: Wed Feb 13, 2008 4:10 am

Re: Trojan in Core???

Postby Drewpy » Fri Apr 03, 2009 12:27 am

Got this too.

Tried adding the directory to the exclusions list. But it kept popping up with a Trojan warning anyways, even after restarting Avast, and multiple reboots. Software that doesn't do what I tell it to, or uses obscure methods to accomplish what I want is one of my pet peeves. Setting up a directory exclusion should be straightforward. Type in the directory, and hit OK... Apparently not the case with Avast.

My solution as of 5 minutes ago: Avira Free Personal Antivirus

Now I'm safe(r?) and folding again! :D
Drewpy
 
Posts: 10
Joined: Thu Aug 28, 2008 6:42 pm

Re: Trojan in Core???

Postby jebo_4jc » Fri Apr 03, 2009 2:45 am

I can't get Avast to ignore the FAH directory either.

Caintry boy, did you really get it working?
jebo_4jc
 
Posts: 19
Joined: Wed Jun 18, 2008 8:09 pm

Re: Trojan in Core???

Postby Goobee » Fri Apr 03, 2009 3:14 am

What you do is disable "on-access protection" and let the core fully download and start. Then go into Avast, browse to the "offending" file and check it and exit. Then you can restart "on-access protection" and the warnings will no longer occur.
I Fold like a Jack Knife. Or was it a Jack A**?
Goobee
 
Posts: 6
Joined: Thu Dec 06, 2007 1:03 am
Location: Sunny California

Re: Trojan in Core???

Postby caintry_boy » Fri Apr 03, 2009 4:39 am

jebo_4jc wrote:I can't get Avast to ignore the FAH directory either.

Caintry boy, did you really get it working?



Yes, but only after doing exactly what Goobee said in the post above this....../\


8-)

edit: Thanks Goobee!!! Thanks to everyone else too, I just wasn't adding the "Exclusion" properly.....
caintry_boy
 
Posts: 99
Joined: Wed Feb 13, 2008 4:10 am

Re: Trojan in Core??? [No. False Postive from AVAST]

Postby Golden Dragoon » Fri Apr 03, 2009 8:25 am

Was having the same issue, stopping the on access protection briefly then starting up F@H seems to work, they should have sorted it out in the next avast update, I submitted the fahcore_a1.exe to them as a false positive anyway.
Golden Dragoon
 
Posts: 12
Joined: Sat Mar 14, 2009 8:41 pm

Re: Trojan in Core??? [No. False Postive from AVAST]

Postby toTOW » Fri Apr 03, 2009 11:32 am

I've seen a similar report on my team forums ... several reports about this trojan in the A1 core :(
If you test this core with another AV, you'll notice that there's nothing wrong with it.

Avast has always caused troubles with false positives with FAH (usually on work files), and I always advised to use Avira AntiVir instead of Avast ... (I use it on all my machines, I never faced issue with FAH and I never got any infection)
Folding@Home beta tester since 2002. Folding Forum moderator since July 2008.

FAH-Addict : latest news, tests and reviews about Folding@Home project.

Image
User avatar
toTOW
Super Moderator
 
Posts: 9214
Joined: Sun Dec 02, 2007 11:38 am
Location: Bordeaux, France

Re: Trojan in Core??? [No. False Postive from AVAST]

Postby Golden Dragoon » Sat Apr 04, 2009 2:42 pm

I used to use AVG, until it decided to stop updating itself, even reinstalling wouldn't let it stick to its scheduled update and scan, so I got frustrated and tried avira, but it constantly bothers you to upgrade to a non free version, plus when scanning it would slow my machine to a crawl (which on a highly oc'ed quad you wouldn't expect) avast seems to run much faster, and uses next to no system resourses with it's resident scanner, this false positive is the only problem I have ever had, and it's not like it is hard to exclude the fah folder, though I do plan to take it out of the excluded folder as soon as the new definitions update comes out, as I don't like the fact that a virus could reside there but not be found.
Golden Dragoon
 
Posts: 12
Joined: Sat Mar 14, 2009 8:41 pm


Return to Windows v6.24 Beta with -smp specified (core_a1)

Who is online

Users browsing this forum: No registered users