Bitcoin Forum
May 08, 2024, 07:19:31 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: About virus!  (Read 1722 times)
is7 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 23, 2014, 01:45:16 PM
Last edit: April 23, 2014, 02:07:04 PM by is7
 #1

Help!
I use bitcoin-qt 0.9.1.
And last sunday,after I downloaded the data as usual,I used "avast!" and "Clamwin" to scan my system,and i found virus in  chainstate and blocks.

Avast! scan report:
1. blk00129.dat  was reported as virus:Diskspoiler
2. the other 8 ".sst" files were reported as virus,such as:Oropax,Murphy,Syslock,Diskspoiler,Attention,Yankee Doodle,PrtScr1024,Raubkopie
(sorry,I`m in China,I can`t find a website to save the pictures that can be showed on bitcointalk)

Clamwin`s scan report:
C:\Bitcoin\chainstate\063497.sst: Peace.1 FOUNC
C:\Bitcoin\chainstate\063504.sst: Italian.1 FOUNC
C:\Bitcoin\chainstate\063505.sst: Chren-4016 FOUNC
C:\Bitcoin\chainstate\063514.sst: Boot.Gen.10past3 FOUNC
C:\Bitcoin\chainstate\063545.sst: Gen.805 FOUNC
C:\Bitcoin\chainstate\063581.sst: StoneC.1 FOUNC
C:\Bitcoin\chainstate\063590.sst: Gergana.9 FOUNC
C:\Bitcoin\chainstate\063641.sst: Vienna-645.A FOUNC

----------------------------------------------------------------------------------------------------------------------

Could anyone help me,and explain what`s up?
Thank you!
If you want to be a moderator, report many posts with accuracy. You will be noticed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
April 23, 2014, 01:48:30 PM
 #2

The proxy is blocking the images. Can you post a link?

There is a lot of data in the blockchain, so some of these might trigger the signature of a virus.

Another question: Do you use two anti virus? or did you scan from an external dvd and used first avast and then clamwin?
Because two antivirus systems might interfere with eachother.

Im not really here, its just your imagination.
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
April 23, 2014, 01:55:01 PM
 #3

Use http://imgur.com for image uploads.

Ps: It's a false positive.
https://bitcointalk.org/index.php?topic=554738.0
is7 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 23, 2014, 02:12:09 PM
 #4

The proxy is blocking the images. Can you post a link?

There is a lot of data in the blockchain, so some of these might trigger the signature of a virus.

Another question: Do you use two anti virus? or did you scan from an external dvd and used first avast and then clamwin?
Because two antivirus systems might interfere with eachother.

first of all,thank you for Re
I`m in China,I can`t find a website to save the pictures that can be showed on bitcointalk.
I used first avast and then clamwin.

this is scan report:

Avast! scan report:
1. blk00129.dat  was reported as virus:Diskspoiler
2. the other 8 ".sst" files were reported as virus,such as:Oropax,Murphy,Syslock,Diskspoiler,Attention,Yankee Doodle,PrtScr1024,Raubkopie

Clamwin`s scan report:
C:\Bitcoin\chainstate\063497.sst: Peace.1 FOUNC
C:\Bitcoin\chainstate\063504.sst: Italian.1 FOUNC
C:\Bitcoin\chainstate\063505.sst: Chren-4016 FOUNC
C:\Bitcoin\chainstate\063514.sst: Boot.Gen.10past3 FOUNC
C:\Bitcoin\chainstate\063545.sst: Gen.805 FOUNC
C:\Bitcoin\chainstate\063581.sst: StoneC.1 FOUNC
C:\Bitcoin\chainstate\063590.sst: Gergana.9 FOUNC
C:\Bitcoin\chainstate\063641.sst: Vienna-645.A FOUNC

is7 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 23, 2014, 02:23:08 PM
 #5

Use http://imgur.com for image uploads.

Ps: It's a false positive.
https://bitcointalk.org/index.php?topic=554738.0

3q! let me try again
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
April 23, 2014, 03:52:45 PM
 #6


What escrow.ms posted is that you dont have a virus. Its a fake report.

-snip-
The result: The blockchain will contain occurences of 23 bytes that will match a Anti-Virus definition.
If the def matches a small virus and also the antivirus uses heuristics, then the antivirus will react violently on the blockchain.

He have already done a list of 442 adresses that each is a found entry in a antivirus def database for a specific AV vendor.
-snip-

tl;dr no virus, you are fine (probably)

Im not really here, its just your imagination.
is7 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 24, 2014, 06:19:31 AM
 #7

Thank you,shorena! Smiley
Silvercube146
Newbie
*
Offline Offline

Activity: 32
Merit: 0


View Profile
June 06, 2014, 08:36:00 PM
 #8

From experience Clamwin and avast had higher false positives than some of the other free options. Microsoft security essentials had lower false positives but its also not as good as avast at detecting actual viruses.

There are a few antivirus comparison sites you can can check out to see how they handle false positives. if you go to av-comparatives.orghttp://www.av-comparatives.org scroll down to reports and select charts and statistics http://chart.av-comparatives.org/chart1.php. From the test drop down take a look at the different types to see how different antivirus's compare. Once you select false alarm test you'll see which antivirus's are more prone to them in their tests.

av-test.org http://www.av-test.org/en/home/ also does its own tests but they bundle false positives with scan times,etc under usability. You would need to sort by usability, then click to each one see its specs.

The goal would be to find an antivirus that does well at everything. Detecting virus's but also is not prone to high amounts of false positives (many antiviruses will have false positives from time to time)
paythrough_team
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
June 15, 2014, 09:26:03 AM
 #9

Virus is very terrible, you can go to the official download bitcoin wallet.
joshraban76
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250



View Profile
June 15, 2014, 11:11:28 AM
 #10

Don't worry, I've googled these for you now.

As escrow.ms said, it's a false positive, like what happen with games trainers.

You are fine, don't panic Smiley

\   \  \ \\\\\\\\\\\\\\\\◥◣◢◤//////////////// /  /   /
Win88.me ❖ Fair, Trusted Online BTC Gambling ❖
/   /  / ////////////////◢◤◥◣\\\\\\\\\\\\\\\\ \  \   \
rarkenin
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500



View Profile
June 15, 2014, 12:45:16 PM
 #11

Technically, if the offending data in the blockchain is properly sanitized before being processed (including correct buffer allocation), and never executed directly, it should be fine, right?
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
June 15, 2014, 01:04:58 PM
 #12

Technically, if the offending data in the blockchain is properly sanitized before being processed (including correct buffer allocation), and never executed directly, it should be fine, right?

There is no virus anyways. The data just matches with the signature of a virus. But yes the blockchain data does not get executed thus even if there would be a full fledged virus it would not be no problem.

Virus is very terrible, you can go to the official download bitcoin wallet.

The source is the "official" blockchain data.

Im not really here, its just your imagination.
ranochigo
Legendary
*
Offline Offline

Activity: 2968
Merit: 4168



View Profile
June 15, 2014, 02:00:47 PM
 #13

I believe the anti virus actually searches some signatures of the virus. The blocks mined might contain the signature of that virus since the encryption used is sha256. Just a wild guess though, please correct me if I am wrong.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
rarkenin
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500



View Profile
June 15, 2014, 04:12:59 PM
 #14

I believe the anti virus actually searches some signatures of the virus. The blocks mined might contain the signature of that virus since the encryption used is sha256. Just a wild guess though, please correct me if I am wrong.

First, SHA512 isn't a form of encryption. A hash by itself isn't really a virus. However, certain parts of the blockchain do contain patterns that might appear to be parts of viruses, although as most antivirus programs do not understand the structure of the blockchain, they're likely not aware of what the "meaning" of such signatures is in certain contexts and flag it down nonetheless.
vm1990
Legendary
*
Offline Offline

Activity: 1540
Merit: 1002



View Profile
June 15, 2014, 04:24:54 PM
 #15

Turn it off hide it in a cubbord and hide under the blankets until it goes away

Or plan b if its from official bitcoin.org then your fine and just shout at avast. If its not official software grab any back up keys you need and setup an official version

bridgeknocker
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
June 16, 2014, 06:46:24 PM
 #16

Next time better update first.
ranochigo
Legendary
*
Offline Offline

Activity: 2968
Merit: 4168



View Profile
June 17, 2014, 02:24:09 AM
 #17

Next time better update first.
He is already at the latest version. There is a signature that matches a certain virus's signature. It is only false positive.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!