Bitcoin Forum

Bitcoin => Bitcoin Technical Support => Topic started by: Dr. Sekxy on May 16, 2014, 09:38:06 AM



Title: Virus:DOS/Stoned from Bitcoin Core
Post by: Dr. Sekxy on May 16, 2014, 09:38:06 AM
So I was updating my full node today when suddenly this pops up

https://i.imgur.com/RNrC90h.png

What's going on? Did anyone also experienced this?


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: nitehawk on May 16, 2014, 09:46:36 AM
the stoned virus.. wow i havnt seen that in ages..  for the record DOS in that case is not Denial of Service. its actually MS DOS  the " stoned " virus is  that old.  your normal virus scanner should take care of it .. however if it works the same way it use to DO NO REBOOT unless youve fixed it.

if it doesnt your going to have to fix your MBR as thats what the virus affects if you reboot you'll see a message " this pc is STONED" its already to late at that point time to format and start over


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: jl2012 on May 16, 2014, 09:57:13 AM
false positive. someone put the signature of the virus to the blockchain.


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: stergium on May 16, 2014, 10:04:19 AM
stoned? I suddently feel so old :(
a friend of mine had an alert for another virus while updating the blockchain (he too into a chainstate file). at the same time i was updating.
His av poped up mine didnt. Same av... we assumed it was a false positive like this one


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: sirky on May 16, 2014, 01:21:14 PM
I had this too - it crashed my core client because MSE automatically quarantined the blockchain file.

I saw people suggesting not scanning .sst files, or not scanning your blockchain dir in the github comments, but those don't really seem like acceptable solutions to overcautious me. I mean, I do have my (somewhat meager amount of) bitcoins accessible to the core client.

I love the idea of helping bitcoin out by running a full node, but don't really want to put this PC or my bitcoins at risk, and exempting locations and files in AV seems to be doing that to me. On the other hand, not exempting them will just allow annoying kids to crash my node over and over by putting these signatures into the blockchain at will.

Am I looking at something wrong? Should I just move my full node somewhere else to a PC I don't care about so I can make these exemptions, and keep my wallet with some other software on a more protected computer?

Sorry for seeming somewhat uptight about this, but my greatest fear as a bitcoin owner is viruses somehow taking my unlocked wallet so anytime I see anything with viruses and bitcoin it sort of psyches me out.


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: knightcoin on May 16, 2014, 04:38:40 PM
is that why 80 bytes is too much  ??? ::)


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: Raize on May 16, 2014, 08:40:47 PM
It would appear others have been having this issue as well. Here's a clamAV report from a month ago:
http://www.opendevs.org/mvkwt/virus-infection-alerts-from-files-in-bitcoin-chainstate.html

I ran into this issue on my Synology which I rsync with my blockchain as well. I imagine they use clamAV for their virus scanning engine. We'll probably have to start excluding .SST files from virus scanners, which isn't too horrible because they aren't executables, but like sirky mentions, this isn't a great solution long-term for the average home user.


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: m5j0r on May 16, 2014, 09:58:54 PM
We urgently need a statement from the bitcoin core developers.

Has anyone found one yet?

This is an absolute DEFCON 1 situation for bitcoin. I uploaded the sst file to virustotal.com and it gets recognized by all the common AV products so millions of Bitcoin users are going to see this!


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: knightcoin on May 16, 2014, 10:29:22 PM
We urgently need a statement from the bitcoin core developers.

Has anyone found one yet?

This is an absolute DEFCON 1 situation for bitcoin. I uploaded the sst file to virustotal.com and it gets recognized by all the common AV products so millions of Bitcoin users are going to see this!


yep, rebels .. the empire strikes back ..


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: m5j0r on May 16, 2014, 10:37:14 PM
I wonder what the intentions were. A serious attack can't be realized as far as I know. And just for trolling? Why?


Title: Re: Virus:DOS/Stoned from Bitcoin Core
Post by: lateblooming on May 17, 2014, 01:20:05 AM
https://answers.microsoft.com/en-us/protect/forum/mse-protect_updating/microsoft-security-essentials-reporting-false/0240ed8e-5a27-4843-a939-0279c8110e1c?tm=1400189799602