Bitcoin Forum

Bitcoin => Bitcoin Technical Support => Topic started by: 0x54444e on January 18, 2015, 02:08:31 PM



Title: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: 0x54444e on January 18, 2015, 02:08:31 PM
So, just installed my wallet a week or so ago, and around "1 year and 17 weeks behind" my AV ( Bitdefender 2015 ) detected an virus inside the chainstate, how is that possible?

https://i.imgur.com/8h3xQw8.png


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Meuh6879 on January 18, 2015, 02:09:11 PM
what is "your wallet" ... ?  ::)


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: tokeweed on January 18, 2015, 02:12:32 PM
this is how hackers backdoor your cold storage.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Bitcoinpro on January 18, 2015, 02:13:22 PM
https://bitcointalk.org/index.php?topic=811290.0


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: 0x54444e on January 18, 2015, 02:16:10 PM
what is "your wallet" ... ?  ::)

Bitcoin Core (desktop)


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Meuh6879 on January 18, 2015, 02:31:27 PM
from this area ?
https://bitcoin.org/bin/


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: 0x54444e on January 18, 2015, 02:32:35 PM
from this area ?
https://bitcoin.org/bin/
From the bitcoin official site on the download section, last version.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Meuh6879 on January 18, 2015, 02:35:16 PM
OK, so ... create exception in your AV for the folder of bitcoin core.
AV are bad because they use somes counter fighting strategies (and they fail ... usually).

http://www.bitdefender.com/support/how-do-i-exclude-a-folder-from-being-scanned-1011.html


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: ranochigo on January 18, 2015, 02:43:59 PM
It is a false positive, a signature in the blockchain matches the signature in the virus database. Just whitelist the folder and continue, the 'virus' cannot do anything to harm your computer.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Flashman on January 18, 2015, 02:47:50 PM
Since the blockchain is a variation on the infinite monkeys/typewriters theme, in that shit in it is so well encrypted it's kinda random, every virus signature will eventually be in it.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Kazimir on January 18, 2015, 02:48:41 PM
Sounds like a retarded viruskiller, as the blockchain data is just data, it's never being executed.There can be anything in there, it just doesn't matter.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Sempruls on January 18, 2015, 02:53:39 PM
no problem at all
just make exception for your bitcoin-core folder blockchain


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: pozmu on January 18, 2015, 06:22:49 PM
That's normal, people are storing a lot of different types of data in the blockchain, including viruses.
I don't think making blockchain folder an exception is very good idea from the security point of view, some malware can make use of that... Better use AV software that takes care of this issue without having to create an exception.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: SargeR33 on January 19, 2015, 07:14:30 AM
As other suggest, make an exception in your AV. I had the same issue, after some research it seems back in the day there were viruses designed to run scripts on your PC to mine for somebody else. These signatures probably pick up on something like that or something that isn't even remotely related.

I would be cautious though, I'd use another AV and do a scan just to be sure.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Newar on January 19, 2015, 09:22:04 AM

Report the false positive to Bitdefender.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Rannasha on January 20, 2015, 06:04:28 AM
Since the blockchain is a variation on the infinite monkeys/typewriters theme, in that shit in it is so well encrypted it's kinda random, every virus signature will eventually be in it.

False, there is nothing encrypted in the blockchain. All transaction data is directly readable.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: cr1776 on January 20, 2015, 10:18:15 AM
It is a false positive, a signature in the blockchain matches the signature in the virus database. Just whitelist the folder and continue, the 'virus' cannot do anything to harm your computer.

This.  It is a false positive.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: Flashman on January 20, 2015, 11:24:28 AM
Since the blockchain is a variation on the infinite monkeys/typewriters theme, in that shit in it is so well encrypted it's kinda random, every virus signature will eventually be in it.

False, there is nothing encrypted in the blockchain. All transaction data is directly readable.

Yah, I wasn't terribly clear that I meant that there are some products of encryption in it, like block hashes. Anyway, lots of essentially randomish strings.


Title: Re: While doing sync on my wallet, my AV detected virus in the blockchain
Post by: crazyearner on January 25, 2015, 05:01:12 PM
This is a false positive caused by many anti virus and many treat it as a virus or malware due to how it works. Simple solution to that white list it in your anti virus and should be fine. But I would also look it up to be on the safe side or back up all wallets and delete it all and start fresh and import your old wallets first. Then id do a scan of full system to make sure their is nothing on system that might cause a threat to your coin.