Page 1 of 1

virus suspects in 7.6.9 and 7.6.10?

Posted: Tue Apr 21, 2020 8:54 am
by FoldingNator
I had standard installed Unchecky on my machine. This little program told me there is potential unwanted software in the installer.

So I did check this at Virustotal: (as a new user a can't post urls :?)
- the 7.6.9:

Code: Select all

https://www.virustotal.com/gui/file/39b8dca4ab06c219c63654c74ef4f19ad0d4e4a59a1c2aba98364910f89ef0bf/detection
- the 7.6.10:

Code: Select all

https://www.virustotal.com/gui/file/7eddefb2c2252571d6fb0ced35612f326271b6feae312f390d3d738e48f0a2c7/detection
The other client (7.5.1) I installed before is relative clean, no message from unchecky and just 1 suspect at virustotal:

Code: Select all

https://www.virustotal.com/gui/file/e97aeccbf3692001dafe16612b1cae6a90cb6c22dbf57e947d9c13ff4e1b5715/detection


The virusses named in 7.6.9 and 7.6.10 are Artemis, TrojanBanker, Presenoker. Are these all false positives and is the software save to install?

Hoping someone can give me some explanation.

FoldingNator :wink:

Re: virus suspects in 7.6.9 and 7.6.10?

Posted: Tue Apr 21, 2020 9:00 am
by PantherX
Welcome to the F@H Forum FoldingNator,

The current release is 7.6.9 and it is safe to install. It is my guess that since it's a recently developed application, it will take a bit of time for the AV engines to rectify the false positives. Ensure that you're downloading from the trusted source: https://foldingathome.org/alternative-downloads/

Re: virus suspects in 7.6.9 and 7.6.10?

Posted: Fri Apr 24, 2020 9:17 am
by FoldingNator
Hi PantherX,

Thanks for your (fast) explanation. That could be possible, just some false positives. :)
I did install the beta from the trusted source (https://foldingathome.org/beta/).
After the strange messages when installing I didn't noticed anything else, it runs fine.

- FoldingNator

Re: virus suspects in 7.6.9 and 7.6.10?

Posted: Fri Apr 24, 2020 8:38 pm
by PantherX
Please note that some Anti-virus/anti-malware/anti-ransomware/anti-spyware applications may detect the working directory as "suspicious" due to the random nature of the binary files. I would suggest that you exclude the correct location as per your OS. The defaults are:
Windows: %AppData%\FAHClient
Linux: /var/lib/fahclient
macOS: /Library/Application Support/FAHClient