possible malware flaged in wcgrid files

Message boards : Questions and problems : possible malware flaged in wcgrid files
Message board moderation

To post messages, you must log in.

AuthorMessage
jwr1

Send message
Joined: 10 Sep 17
Posts: 2
United States
Message 98517 - Posted: 15 May 2020, 14:41:00 UTC

Running BOINC 7.16.5 (x64) on Windows 10 Home with Intel i7-2600. Acronis True Image 2020 build 25700 apparently has Active Protection running which blocked process C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_opn1_autodock_7.17_windows_x86_64 because several folders were modified with a suspicious pattern. The files were C:\ProgramData\BOINC\slots\5\wcg_checkpoint.dat
wcg_ad4-result_sub.xml
receptor.CI.map
receptor.C.map
receptor.Br.map
receptor.A.map
If that process and files are normal, this may not be a problem. Not knowing, I blocked (blacklisted) this program. Does this seem normal?
ID: 98517 · Report as offensive
Dr Who Fan
Avatar

Send message
Joined: 10 May 07
Posts: 1348
United States
Message 98519 - Posted: 15 May 2020, 15:39:48 UTC - in response to Message 98517.  

Running BOINC 7.16.5 (x64) on Windows 10 Home with Intel i7-2600. Acronis True Image 2020 build 25700 apparently has Active Protection running which blocked process C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_opn1_autodock_7.17_windows_x86_64 because several folders were modified with a suspicious pattern.
...
If that process and files are normal, this may not be a problem. Not knowing, I blocked (blacklisted) this program. Does this seem normal?

The chances of malicious activity are extremely rare. BOINC projects do a lot of writing to many sub folders within each specific projects data folders / directories. You should EXCLUDE ALL BOINC DATA FOLDERS from any antivirus / anti-malware scans to prevent false positives.

If you have any questions about World Community Grid possible suspicious activity please post a question on the projects forum. They can reassure you that everything is going to be fine.
Forum: OpenPandemics - COVID-19 Project
ID: 98519 · Report as offensive
Profile Dave
Help desk expert

Send message
Joined: 28 Jun 10
Posts: 2534
United Kingdom
Message 98528 - Posted: 15 May 2020, 20:11:04 UTC

The same happens from time to time with CPDN files. In the past this has been down to a small section of code matching a code section in a virus. I imagine that with the number of lines of code written and then compiled this happens occasionally in most projects. It is worth reporting this to the anti-virus people as a false positive so they can mark the file as safe.

Though of course excluding boinc folders from the scans will solve the issue locally.
ID: 98528 · Report as offensive
ProDigit

Send message
Joined: 8 Nov 19
Posts: 718
United States
Message 98537 - Posted: 16 May 2020, 4:16:17 UTC

With the amount of data written, it's inevitable that occasionally virus scanners get triggered (with a false positive), but it's also possible that a data bit errored, and the virus scanner confirmed a real virus.. You never know.
If your AV has a cloud upload option (to further analyze the 'positive'), you should enable that.
Hopefully more false positives will be removed, and AV scanners will continue to allow certain bit-combinations without being triggered.
ID: 98537 · Report as offensive
Richard Haselgrove
Volunteer tester
Help desk expert

Send message
Joined: 5 Oct 06
Posts: 5081
United Kingdom
Message 98539 - Posted: 16 May 2020, 6:22:54 UTC - in response to Message 98537.  

I also believe that AV scanners have moved on a long way beyond simple pattern-matching of bit strings in files stored on your hard disk. Two other things they do (there may be more):

1) Monitor internet traffic, especially file downloads. If they spot a problem there, the file will never reach your hard disk. No amount of folder exclusion will make any difference, but your BOINC tasks will fail.

2) Test-run executable files in a sandbox environment. Some of the things that the BOINC client does (communicates over the internet; downloads and runs executable files; doesn't have a visible user interface - that's in the separate Manager) look to AV very suspicious and very much like a virus.

Things you can do:

a) If AV objects to a file, submit it for further analysis.
b) Whitelist BOINC and project domains as trusted download sources.
c) Wait a few days before you download any new version of anything. Particularly the 'heuristic' (test-run) warnings are often triggered when the AV company has not seen this version of a program before. It goes into lockdown until further information is available. Well-known and popular applications are allowed to pass unhindered - it takes a while for BOINC and project applications to reach this status.
ID: 98539 · Report as offensive
ProDigit

Send message
Joined: 8 Nov 19
Posts: 718
United States
Message 98556 - Posted: 16 May 2020, 15:47:18 UTC

I would agree on whitelisting the directory.
Should it be a real virus, expanding beyond the whitelisted directory, then I would become suspicious.
But even if it's a virus, if it's trapped inside one directory, it'll probably be able to do very little damage.
ID: 98556 · Report as offensive
Profile Jord
Volunteer tester
Help desk expert
Avatar

Send message
Joined: 29 Aug 05
Posts: 15480
Netherlands
Message 98580 - Posted: 17 May 2020, 13:54:47 UTC - in response to Message 98556.  
Last modified: 17 May 2020, 13:55:30 UTC

The server that BOINC talks to runs Linux, so if that's hacked to provide viruses the project has a far greater problem than that it's sending out viruses to BOINC clients.
And even then, the clients that talk to the server don't all run Linux as well, some do Windows, others FreeBSD, others Android, others Mac OS, others other exotics. This makes the chance that your system gets a virus that can run on your system pretty low. Because the payload is either for Linux, or Windows, or Mac OS or... and those can't run on other OSes.

Yes, it's possible a project is hacked and it sends out viruses for Windows systems only, but the chance that it does that for long is pretty slim.
ID: 98580 · Report as offensive

Message boards : Questions and problems : possible malware flaged in wcgrid files

Copyright © 2024 University of California.
Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.