Bitcoin Forum
April 26, 2024, 11:08:38 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Virus protection has quarantined my Bitcoin Core wallet  (Read 1646 times)
nrgBitmagic (OP)
Newbie
*
Offline Offline

Activity: 51
Merit: 0


View Profile
June 05, 2017, 05:01:32 PM
Last edit: June 05, 2017, 05:20:57 PM by nrgBitmagic
 #1

Dyna:BitCoinMiner-CR [PUP]||mul is the name given to the threat.

When I attempt to open it from the shortcut, it says "Error Opening Block Database. Do I want to abort?"

Now I need to know what is going on here and what my options are.

This has been used as a hot wallet, so it doesn't have a high balance. But, I would really like to recover it, if possible.

Any help is greatly appreciated!

Edit: I have been reading other threads about antivirus software flagging Core as a false positive. I am not seriously techie; so, I may need some guidance as to how to determine if there is a true threat.

What should I do first?

1714129718
Hero Member
*
Offline Offline

Posts: 1714129718

View Profile Personal Message (Offline)

Ignore
1714129718
Reply with quote  #2

1714129718
Report to moderator
The forum strives to allow free discussion of any ideas. All policies are built around this principle. This doesn't mean you can post garbage, though: posts should actually contain ideas, and these ideas should be argued reasonably.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714129718
Hero Member
*
Offline Offline

Posts: 1714129718

View Profile Personal Message (Offline)

Ignore
1714129718
Reply with quote  #2

1714129718
Report to moderator
1714129718
Hero Member
*
Offline Offline

Posts: 1714129718

View Profile Personal Message (Offline)

Ignore
1714129718
Reply with quote  #2

1714129718
Report to moderator
1714129718
Hero Member
*
Offline Offline

Posts: 1714129718

View Profile Personal Message (Offline)

Ignore
1714129718
Reply with quote  #2

1714129718
Report to moderator
zend7
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501

Hackers please hack me .... if you can :)


View Profile
June 05, 2017, 05:35:43 PM
 #2

Dyna:BitCoinMiner-CR [PUP]||mul is the name given to the threat.

When I attempt to open it from the shortcut, it says "Error Opening Block Database. Do I want to abort?"

Now I need to know what is going on here and what my options are.

This has been used as a hot wallet, so it doesn't have a high balance. But, I would really like to recover it, if possible.

Any help is greatly appreciated!

Edit: I have been reading other threads about antivirus software flagging Core as a false positive. I am not seriously techie; so, I may need some guidance as to how to determine if there is a true threat.

What should I do first?



I don't know what kind of antivirus you are using, but I am using Avira and I open up Avira from the task bar, press F8 to enter the configuration and find where it is located the bitcoin core wallet folder and I add it as an exception to the database. I do so with almost every mining software.

No matter what antivirus you are using, you should find the folder where bitcoin core is located and add an exception to your antivirus. Another thing to be done is to go the quarantined files and click restore from there. These are a few options to try.
nrgBitmagic (OP)
Newbie
*
Offline Offline

Activity: 51
Merit: 0


View Profile
June 05, 2017, 08:24:22 PM
 #3

Dyna:BitCoinMiner-CR [PUP]||mul is the name given to the threat.

When I attempt to open it from the shortcut, it says "Error Opening Block Database. Do I want to abort?"

Now I need to know what is going on here and what my options are.

This has been used as a hot wallet, so it doesn't have a high balance. But, I would really like to recover it, if possible.

Any help is greatly appreciated!

Edit: I have been reading other threads about antivirus software flagging Core as a false positive. I am not seriously techie; so, I may need some guidance as to how to determine if there is a true threat.

What should I do first?



I don't know what kind of antivirus you are using, but I am using Avira and I open up Avira from the task bar, press F8 to enter the configuration and find where it is located the bitcoin core wallet folder and I add it as an exception to the database. I do so with almost every mining software.

No matter what antivirus you are using, you should find the folder where bitcoin core is located and add an exception to your antivirus. Another thing to be done is to go the quarantined files and click restore from there. These are a few options to try.

I use AVG Internet Security.

I just ran a full scan using AVG and it has now identified two more files that are associated with the Ethereum wallet that I attempted to sync a month ago. I was not happy with the Ethereum wallet and decided to not send any ether there, as it was very slow. Does the Ethereum wallet also cause the antivirus to generate false positives?

The notable thing is the dates shown on all 3 files are Mar 5, May 21 and 23. Why would AVG just now be flagging these files?

My questions now are -
1) How likely is it that these are false positives?
2) If I now uninstall the Ethereum wallet, shouldn't those files also go away?
3) If I want to get more comfortable that this Core wallet file is not malicious, what are some things I could do to make sure?
nrgBitmagic (OP)
Newbie
*
Offline Offline

Activity: 51
Merit: 0


View Profile
June 05, 2017, 08:54:09 PM
 #4

The 2 Ethereum files that have been quarantined are -

C:\Users\L**t\AppData\Roaming\Ethereum\geth\chaindata\018709.ldb

C:\Users\L**t\AppData\Roaming\Ethereum\geth\chaindata\118445.ldb

I cannot do an uninstall on the Ethereum wallet because it does not appear in the Programs Control Panel, which is something you all understand way better than I do.

Is it better to allow AVG to delete these 2 offending files or attempt to delete all the files Ethereum installed during my failed attempt to sync?
webweave
Newbie
*
Offline Offline

Activity: 16
Merit: 0


View Profile
June 05, 2017, 09:21:56 PM
 #5

Its a false positive, because there are sometimes miners in virusses.
Its safe to whitelist the bitcoin core wallet and its files.
freebutcaged
Hero Member
*****
Offline Offline

Activity: 588
Merit: 541


View Profile
June 05, 2017, 10:13:27 PM
 #6

Don't delete or uninstall them mate, download only from Ethereum.org and Bitcoin.org any wallet you are trying to install always download

From a trusted source. but now you already installed them and suddenly anti virus is showing you alerts? well you past the important part

Already mate, restore them and continue as before.
terrate
Full Member
***
Offline Offline

Activity: 362
Merit: 100

Newbie in online currency , love learning


View Profile
June 05, 2017, 10:26:32 PM
 #7

If u not so sure try other antivirus and disable this antivirus.

If ur install source are no issue then just do like above said, whitelist the file.
nrgBitmagic (OP)
Newbie
*
Offline Offline

Activity: 51
Merit: 0


View Profile
June 05, 2017, 11:22:56 PM
 #8

If u not so sure try other antivirus and disable this antivirus.

If ur install source are no issue then just do like above said, whitelist the file.

Install source was good. Wallet had been syncing properly for months and transactions working.

In using AVG, I have learned that they are over zealous in their identification of threats and will quarantine things that are not infected and are essential for health of the computer. So, they can really screw things up.

Furthermore, when I go to restore the falsely quarantined file, I get the message "You are trying to restore a file from the Quarantine. The file already exists. Should the program overwrite the existing file?"

Do I want to overwrite or not? My guess is no; but, I'm not sure what I will get.
nrgBitmagic (OP)
Newbie
*
Offline Offline

Activity: 51
Merit: 0


View Profile
June 05, 2017, 11:58:34 PM
 #9

I swear! Someone needs to come up with an Ulcercoin!

This is the 2nd noobie freakout in 2 days. I need a break! And Ive been doing these crazy coins since 2013!!

Oh yes, I restored and overwrote the wallet file and it's fine. Will definitely whitelist with AVG, so they don't mess with my wallet(s) again. Should do it for all of them.

KoriSmith
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
March 21, 2019, 01:47:04 PM
 #10

I had the same problem last week. Installed Avast and he blocked access somehow to my wallet. I deleted it and I can`t still log in, can he change my password?
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
March 21, 2019, 01:56:17 PM
Last edit: March 26, 2019, 07:03:33 PM by Carlton Banks
Merited by LFC_Bitcoin (1)
 #11

What should I do first?



1. Backup the wallet

2. Uninstall the anti-virus software


Anti-virus is a scam really. Either your OS is secure, or it's not. Anti-virus makes no difference to computer security.

Vires in numeris
Pajonk
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
April 04, 2019, 07:38:11 AM
 #12

I had the same problem last week. Installed Avast and he blocked access somehow to my wallet. I deleted it and I can`t still log in, can he change my password?
Hm, maybe you should check avast pro antivirus review to find whats wrong with your antivirus. I think that the main problem is in authenticity of your antivirus. You shouldn`t download from foreign resources only because this version is for free. If you would buy the original one you will lose your headache for a long time.
KoriSmith
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
April 04, 2019, 07:47:38 AM
 #13

I had the same problem last week. Installed Avast and he blocked access somehow to my wallet. I deleted it and I can`t still log in, can he change my password?
Hm, maybe you should check avast pro antivirus review to find whats wrong with your antivirus. I think that the main problem is in authenticity of your antivirus. You shouldn`t download from foreign resources only because this version is for free. If you would buy the original one you will lose your headache for a long time.

Yea thanks, I have already found solution and it was all because antivirus was virused:D
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
April 04, 2019, 08:49:26 AM
 #14

I had the same problem last week. Installed Avast and he blocked access somehow to my wallet. I deleted it and I can`t still log in, can he change my password?
Hm, maybe you should check avast pro antivirus review to find whats wrong with your antivirus. I think that the main problem is in authenticity of your antivirus. You shouldn`t download from foreign resources only because this version is for free. If you would buy the original one you will lose your headache for a long time.

*sigh*

It's like this

When you're using Windows, the computer tell you what to do half the time, often the half where what you want is actually something that helps you

Anti virus is another layer of Windows telling you what to do, in essence. Windows is not and never has been secure on it's own, anti-virus doesn't fix it, it just makes the machine so difficult to use that viruses can't do their job. But then neither can you; everything's slower, and the AV is always stopping you from doing something that isn't even unsafe.

Vires in numeris
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!