Bitcoin Forum
December 13, 2024, 11:46:13 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Microsoft Security Essentials detects DOS/Invader in chainstate files  (Read 1513 times)
wzaker (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
May 11, 2014, 01:19:57 PM
 #1

Hi,

I noticed since 8:54am EST, MSE is detecting a virus in the chainstate files in my Bitcoin wallet. It seems it's deleting the files one by one  Smiley

At this point, I'm not sure if this is a false detection or there's actually a virus on my machine as I wasn't able to find anything about this.

Note that MSE update its definition at 7:24am EST on my machine.

Any comments?

Thanks

The following error occurred: Error code 0x80508023. The program could not find the malware and other potentially unwanted software on this computer.
Category: Virus
Description: This program is dangerous and replicates by infecting other files.
Recommended action: Remove this software immediately.
Items:
file:C:\Users\~~~\AppData\Roaming\Bitcoin\chainstate\282352.sst
Get more information about this item online. ==> http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?name=Virus%3aDOS%2fInvader&threatid=2147492097
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1540


No I dont escrow anymore.


View Profile
May 11, 2014, 01:52:57 PM
Last edit: May 12, 2014, 12:32:20 AM by shorena
 #2

this is a false positive. Im pretty sure, you are not the first. Two reasons:

- the data in the blockchain is bound to match the signature of a virus over time
- there have been attempts to DoS bitcoins with specially crafted transactions that match the signature of a virus. (thread can be found by using search)

Im not really here, its just your imagination.
wzaker (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
May 12, 2014, 12:31:00 AM
 #3

Thx
Dare
Hero Member
*****
Offline Offline

Activity: 508
Merit: 500


Techwolf on #bitcoin and Reddit


View Profile WWW
May 12, 2014, 02:19:31 AM
 #4

this is a false positive. Im pretty sure, you are not the first. Two reasons:

- the data in the blockchain is bound to match the signature of a virus over time
- there have been attempts to DoS bitcoins with specially crafted transactions that match the signature of a virus. (thread can be found by using search)

Specifically, antivirus software looks for specific sequences of bytes to identify viruses, and some of those byte sequences end up stored in the blockchain (both unintentionally from random generation and intentionally from people attempting to trigger this deliberately). There have been several threads about it if you want to confirm this, but as a false positive it's nothing to worry about.

BTC: 1M8oUcBnkRDEhWWgV8ZXLTB6p1mgnejVbX
How Forum Activity Works
Bitcointalk Forum Rules
|
|
|
Firstbits (lucky vanitygen): 1WoLfRUGDx1
How Forum Trust Works
Bitcoin Source Code
Kluge
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1015



View Profile
May 12, 2014, 02:36:52 AM
 #5

I wonder if there are any ongoing pet projects trying to insert a large file into the blockchain which is executed by calling up complete blk files and executing certain lines.

You get - what is it - 140 arbitrary bytes per .0001BTC fee? Let's say you want to put, Idunno, a 40MB Cosby Show episode in the blockchain. .0001BTC=.0001335MB, so ... ~30BTC to get an episode of the Cosby Show distributed to hundreds of thousands of people forever? Everyone should have the same blk files, so you just need a program with precompiled lists for where to find the code to play back the episode. Can you trick a central lite-wallet server into feeding you just the relevant transactions so you can stream it?
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!