Trojan alert at BOINC 7.6.9

Message boards : Questions and problems : Trojan alert at BOINC 7.6.9
Message board moderation

To post messages, you must log in.

AuthorMessage
João Francisco Borba

Send message
Joined: 14 Sep 15
Posts: 2
Brazil
Message 64233 - Posted: 14 Sep 2015, 12:01:24 UTC

"Gateway Anti-Virus Alert

This request is blocked by the SonicWALL Gateway Anti-Virus Service. Name: VB.A_77 (Trojan)"
ID: 64233 · Report as offensive
Richard Haselgrove
Volunteer tester
Help desk expert

Send message
Joined: 5 Oct 06
Posts: 5082
United Kingdom
Message 64234 - Posted: 14 Sep 2015, 12:09:08 UTC - in response to Message 64233.  

It's likely to be a false positive, but we should check it out. I'm assuming Windows, but can you confirm whether 32-bit or 64-bit, with or without VBox?

Then we can check it with a service like https://www.virustotal.com/ - or you could reassure yourself by running your own scan there.

Many anti-virus programs these days flag a warning for an application which is new and untested, even if it doesn't carry any malicious payload.
ID: 64234 · Report as offensive
João Francisco Borba

Send message
Joined: 14 Sep 15
Posts: 2
Brazil
Message 64235 - Posted: 14 Sep 2015, 12:41:09 UTC - in response to Message 64234.  

Windows 64 bits without V-Box...
ID: 64235 · Report as offensive
SekeRob2

Send message
Joined: 6 Jul 10
Posts: 585
Italy
Message 64236 - Posted: 14 Sep 2015, 12:53:37 UTC - in response to Message 64234.  

False positive, little doubt. Interesting though is the conhost.exe process, or should we say conhost.exe processes that only recently I noticed filling up the Task Manager list. My 8 core has 9 running, one for BOINC, 64 bit and 8 for the sciences, too all 64 bit. Seemingly only BOINC has these going. WUWAT?

This BFS article [url]http://boincfaq.mundayweb.com/index.php?language=1&view=584[/url\] implies there's also BOINC jobs that do not this middlemen, but as only doing WCG, would not be able to tell if that's seen.

Anyway, this one has never been giving any alerts. Just in case someone asks again.
Coelum Non Animum Mutant, Qui Trans Mare Currunt
ID: 64236 · Report as offensive
Richard Haselgrove
Volunteer tester
Help desk expert

Send message
Joined: 5 Oct 06
Posts: 5082
United Kingdom
Message 64237 - Posted: 14 Sep 2015, 13:07:58 UTC - in response to Message 64235.  

Windows 64 bits without V-Box...

Here's a link to the VirusTotal analysis report:

https://www.virustotal.com/en/file/a1ea3f31a420dc9db2013ae42320a886e8b001f6f642f056d57438d1d7052d8e/analysis/1441827908/

Looks clean to me.
ID: 64237 · Report as offensive

Message boards : Questions and problems : Trojan alert at BOINC 7.6.9

Copyright © 2024 University of California.
Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.