Ransomware behaviour

Message boards : Questions and problems : Ransomware behaviour
Message board moderation

To post messages, you must log in.

AuthorMessage
Johan

Send message
Joined: 15 Apr 20
Posts: 1
Message 97698 - Posted: 15 Apr 2020, 15:28:48 UTC

Bitdefender constantly displays warnings that C:\ProgramData\BOINC\projects\boinc.bakerlab.org_rosetta\rosetta_4.15_windows_intelx86.exe is showing ransomware behaviour. Encrypted files are:
- boinc_checkpoint_count.txt
- csd_atom_properties.txt
- Default-5StepDown.txt

Why is Boinc trying to encrypt files??
ID: 97698 · Report as offensive
Profile Jord
Volunteer tester
Help desk expert
Avatar

Send message
Joined: 29 Aug 05
Posts: 15480
Netherlands
Message 97701 - Posted: 15 Apr 2020, 16:31:00 UTC - in response to Message 97698.  

BOINC isn't encrypting anything.
The files you refer to are made by the Rosetta science application, for storing a checkpoint, and progress of its files.

But this is essentially why we ask that you exclude the BOINC data directory from being actively scanned by your anti virus program. Set up a DMZ. Because a lot of what the science applications for the various projects do can be seen as suspect behaviour.

Only scan the data directory by hand when you aren't running BOINC.
And report any false positives, such as these, to Bitdefender and Rosetta.
ID: 97701 · Report as offensive

Message boards : Questions and problems : Ransomware behaviour

Copyright © 2024 University of California.
Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.