Author |
Message |
|
I don't imagine this happens all that often, and I suppose this is most likely a false positive, but thought I would post to pass along the info:
The AT&T Internet Security Suite powered by McAfee
reported the following:
McAfee has automatically blocked and removed a Trojan.
About this Trojan
Detected: Artemis!C85FB5F93D9A (Trojan), Artemis!C85FB5F93D9A (Trojan)
Location: C:\Documents and Settings\All Users\Application Data\BOINC\projects\www.primegrid.com\primegrid_llr_wrapper_5.09_windows_intelx86.exe
Has anyone else gotten this or similar from the same or other AntiAV systems?
This is the first time I've experienced any BOINC app has been identified as such.
Boinc shows this as "Download Failed', which makes total sense. For now I'm moving on to other WUs. |
|
|
|
Others have encountered your problem:
http://setiathome.berkeley.edu/forum_thread.php?id=55142
http://setiathome.berkeley.edu/forum_thread.php?id=55050
I would also recommend that you change your AV as McAfee has failed to protect my PC more than once in the past. It uses a lot of memory/CPU compared to other AVs as well.
____________
|
|
|
|
I had the same thing tonight using the AT&T Internet Security Suite powered by McAfee. I unatached and reatached to the project and it is going correct now. |
|
|
|
Ahh. I had wondered why my computer was suddenly killing off tasks. I just told McAfee to restore the quarantined files instead of detaching/reattaching, so we'll see if that works. I'd change AV's, but most of the other ones available only make things worse on my system. :(
____________
~It only takes one bottle cap moving at 23,000 mph to ruin your whole day~
|
|
|
|
Yeah, I just wrote a post on this a few days ago.
http://primegrid.com/forum_thread.php?id=1466 |
|
|
|
It's happening to me now, too, with McAfee from Comcast. It looks like it started happening with the new signature file that came out at around 1 AM EDT today. I'll switch to AP26 until it gets cleared up.
____________
|
|
|
|
Have been getting the trojan alert for the past couple of days now, but this morning was the first time the alert message stayed up long enough for me to read it completely.
Yes it is Artemis and then the downloads fail.
AP26 Search and Sophie Germain Prime Search are fine. It is the third sub project I'm signed up for, Proth Prime Search that McAfee is have a fit over.
Will try the suggestion of a detaching and reattaching to project.
Edit : Tired detaching and reattaching to project. The first unit the client tried to download was a PPS and the Trojan alert was triggered and the download failed. Am going to go to preferrences and stop crunching PPS for a while to see if this gets cleared up.
Edit #2 : Now the AV is triggered by the Sophie Germain units and their downloads are failing.
____________
|
|
|
|
Hey guys. I just spent the last half an hour talking with the McAfee service reps to get this thing sorted out. Once I get a copy of all the files that are falsely triggering a positive and send it to them, they said they'll try and get the stuff de-listed. I'll update you when I know more.
[edit] *Update: I've submitted both llr wrappers 5.09 and 5.10 to McAfee so they can get this fixed. Hopefully I'll hear back from them soon. [/edit]
____________
~It only takes one bottle cap moving at 23,000 mph to ruin your whole day~
|
|
|
|
I noticed yesterday I had 27 tasks arriving at the same time (very high amount than the usual 2 or 3) and only 8 arrived correctly as the other 19 should the same virus on macafee
____________
[img]http://stats.free-dc.org/pgridtag.php |
|
|
John Honorary cruncher
 Send message
Joined: 21 Feb 06 Posts: 2875 ID: 2449 Credit: 2,681,934 RAC: 0
                 
|
I noticed yesterday I had 27 tasks arriving at the same time (very high amount than the usual 2 or 3) and only 8 arrived correctly as the other 19 should the same virus on macafee
Hopefully McAfee will resolve the issue soon. If not, then more contacts by their users might help facilitate the issue: McAfee Threat Center
http://vil.nai.com/vil/submit-sample.aspx
____________
|
|
|
|
Two days ago the detach and reatach worked. Today this hit all three systems and that dues not work. Will have to look into that more. |
|
|
rroonnaalldd Volunteer developer Volunteer tester
 Send message
Joined: 3 Jul 09 Posts: 1213 ID: 42893 Credit: 34,634,263 RAC: 0
                 
|
The problem is not McAfee alone, i had tested most scanners in the market and depended of your project attachments all had a false positiv detected.
The solution is simple, make an exception for the entire boinc-folder(s) and all should be fine. Or somebody have to send every change of crunching appz to all producers of scanner-sw.
____________
Best wishes. Knowledge is power. by jjwhalen
|
|
|
|
I too have submitted the following files to mcafee's Avert (webimmune.net)
primegrid_llr_wrapper_5.09_windows_intelx86.exe
primegrid_llr_wrapper_5.10_windows_intelx86.exe
primegrid_psp_sr2sieve_wrapper_1.11_windows_intelx86.exe
primegrid_sr2sieve_wrapper_1.11_windows_intelx86.exe
as all four of these have been triggering alerts for me.
web immune case numbers (Analysis Numbers) are:
5521053:primegrid_llr_wrapper_5.09_windows_intelx86.exe
5521061:primegrid_llr_wrapper_5.10_windows_intelx86.exe
5521066:primegrid_psp_sr2sieve_wrapper_1.11_windows_intelx86.exe
5521079:primegrid_sr2sieve_wrapper_1.11_windows_intelx86.exe
I hope this helps...
|
|
|
|
The solution is simple, make an exception for the entire boinc-folder(s) and all should be fine.
I've combed over the the AV app: AT&T Internet Security Suite powered by McAfee. I've not been able to find a way to exclude files, folders, or even exclude looking for the particular trojan that McAfee is identifying these to be. It's a pretty basic AV/firewall app; Free with AT&T's internet service, not real feature rich.
If you know of a way on this particular software, by all means, let me know.
|
|
|
|
Also if its not that big of a deal check out this posting others were talking about this issue in the General Chat : Antivirus-Issue's
____________
John M. Johnson "Novex" |
|
|
|
I tried again this morning and was able to download PPS and SGS LLR work. It looks like Mcafee has finally analyzed the submitted files and updated their DB to mark it as not a virus.
____________
|
|
|
RytisVolunteer moderator Project administrator
 Send message
Joined: 22 Jun 05 Posts: 2653 ID: 1 Credit: 86,414,269 RAC: 1,016
                     
|
Actually, we have released updated versions of the applications, with hopes that updated code will go through McAfee this time. They haven't done a thing to whitelist this false positive :(
____________
|
|
|
|
Actually, we have released updated versions of the applications, with hopes that updated code will go through McAfee this time. They haven't done a thing to whitelist this false positive :(
Thanks for this.
I've seen no progress on the false positives reported to McAfee.
I've also have gotten no response from my support request about how to manually exclude files/folders/trojans from being included in the scan.
On the detection from: one computer has had no detections the 9/26, another had hits on primegrid modules this AM during its periodic scan but may have been older exe files.. I'll keep an eye out on it and report here on any further updates. |
|
|
|
Actually, we have released updated versions of the applications, with hopes that updated code will go through McAfee this time. They haven't done a thing to whitelist this false positive :(
I haven't experienced any further 'download errors' due to the AV False Positives since 9/27. So, what ever change you've made must have done the trick.
Thanks for taking this on!
Bruce |
|
|