Malware

Message boards : Bug reports : Malware

To post messages, you must log in.

AuthorMessage
Mike Bray

Send message
Joined: 21 Mar 14
Posts: 2
Credit: 569,744
RAC: 0
Message 13461 - Posted: 19 Oct 2017, 10:54:42 UTC

I am getting reports of Malware within the enigma exe which my virus scanner quarantines. Is anyone else getting this?
ID: 13461 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Dr Who Fan

Send message
Joined: 6 May 11
Posts: 55
Credit: 231,548
RAC: 0
Message 13469 - Posted: 23 Oct 2017, 3:00:12 UTC - in response to Message 13461.  

Most likely a FALSE POSITIVE.
Best practice is to EXCLUDE ALL BOINC PROGRAM & BOINC DATA FOLDERS (including ALL SUB FOLDERS) from ACTIVE SCAN by the Anti-Virus/Anti-Malware program.

More details are required from you to help out. Let us stat with these 3 questions:
1) What is the NAME and VERSION NUMBER of your Anti-Virus/Anti-Malware PROGRAM?
2) What is the EXACT NAME of the supposed malware?
3) What is the FILE NAME the Anti-Virus/Anti-Malware claiming is INFECTED?

ID: 13469 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Mike Bray

Send message
Joined: 21 Mar 14
Posts: 2
Credit: 569,744
RAC: 0
Message 13476 - Posted: 24 Oct 2017, 17:09:55 UTC - in response to Message 13461.  

The anti-virus program is BullGuard Internet Security version 17.1.336.6
The program is C:\ProgramData\BOINC\slots\2\enigma_av.exe

The report is:

Risk: HIGH
Behaviour: The program enigma_av.exe attempted to modify a protected system setting.
Time: 2017/10/19 03:50:49

As you can see it is trying to change a system setting.

Regards
mike
ID: 13476 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Dr Who Fan

Send message
Joined: 6 May 11
Posts: 55
Credit: 231,548
RAC: 0
Message 13478 - Posted: 24 Oct 2017, 20:31:58 UTC - in response to Message 13476.  

"... attempted to modify a protected system setting" == FALSE POSITIVE.
ALL BOINC projects attempt to create, modify and delete FILES & FOLDERS WITHIN THE BOINC DATA FOLDER.
This particular application runs on your GPU and thus requires access to some system settings to run on the GPU.

Like I recommended before:
Best practice is to EXCLUDE ALL BOINC PROGRAM & BOINC DATA FOLDERS (including ALL SUB FOLDERS) from ACTIVE SCAN by the Anti-Virus/Anti-Malware program.

EXCLUDE FOLDERS
1) Whatever folder you have the MAIN BOINC PROGRAM INSTALLED IN INCLUDING ALL FILES and SUB DIRECTORIES of the folder.
2 C:\ProgramData\BOINC\ INCLUDING ALL FILES and SUB DIRECTORIES of the folder.

ID: 13478 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote

Message boards : Bug reports : Malware




Copyright © 2024 TJM