swizzor virus detected in einstein@home downloads

Bob Dorsett
Bob Dorsett
Joined: 22 May 06
Posts: 2
Credit: 2588367
RAC: 0
Topic 194960

My antivirus software reports swizzor gen 3 trojan in einstein@home downloads. Please scan / clean your machines, or advise me what to do.

Thanks.

Jord
Joined: 26 Jan 05
Posts: 2952
Credit: 5893653
RAC: 167

swizzor virus detected in einstein@home downloads

This happens with some AV programs at times. When coming from renowned projects such as Einstein, you can easily assume it's a false positive detection, due to the nature of the science application, the way that it calculates the data.

If you truly suspect something wrong, go to http://www.virustotal.com and upload the application there. This will test the application with several AV kits. If the outcome of that scan is that only your AV kit sees it, it's a false positive. When all or most of them see an infection, it's an infection. Not necessarily coming from the Einstein servers, it may become infected on your system.

Aside from that - as far as I know - the applications here for all platforms are made in Linux, which although not impossible, is very unlikely to give out infected applications.

Bob Dorsett
Bob Dorsett
Joined: 22 May 06
Posts: 2
Credit: 2588367
RAC: 0

OK. Will do.

Message 98324 in response to message 98323

OK. Will do. thanks.

Quote:

This happens with some AV programs at times. When coming from renowned projects such as Einstein, you can easily assume it's a false positive detection, due to the nature of the science application, the way that it calculates the data.

If you truly suspect something wrong, go to http://www.virustotal.com and upload the application there. This will test the application with several AV kits. If the outcome of that scan is that only your AV kit sees it, it's a false positive. When all or most of them see an infection, it's an infection. Not necessarily coming from the Einstein servers, it may become infected on your system.

Aside from that - as far as I know - the applications here for all platforms are made in Linux, which although not impossible, is very unlikely to give out infected applications.


Martin
Martin
Joined: 9 Jan 06
Posts: 1
Credit: 827514
RAC: 0

Hi, just thought I'd report I

Hi, just thought I'd report I had the same virus alert.

Antivirus is F-Secure 2010, fully up to date

Virus name the same: Swizzor.3

Infected file: ....\BOINIC Data\projects\einstein.phys.uwn.edu\einstein_S5R4_6.10_graphics_windows_intelx85.exe

Will try to upload to virustotal if I have time, but my antivirus seems to be pretty good so maybe there is a real infection???

All the best
Martin

Bernd Machenschalk
Bernd Machenschalk
Moderator
Administrator
Joined: 15 Oct 04
Posts: 4312
Credit: 250214833
RAC: 35613

einstein_S5R4_6.10_graphics_w

Message 98326 in response to message 98325

einstein_S5R4_6.10_graphics_windows_intelx85.exe is part of an outdated application. You could just delete this. If there are still tasks on your client that need this, abort them, you won't get any credit for them.

I don't remember this old App very well, it might be that this application was indeed built on a Windows system. But nowadays Apps are cross-compiled on a Linux system, I don't know how a virus could easily slip into this.

BM

BM

Jord
Joined: 26 Jan 05
Posts: 2952
Credit: 5893653
RAC: 167

7/41 see an 'infection'. I

Message 98327 in response to message 98325

7/41 see an 'infection'. I still think it's a false positive.

Phil
Phil
Joined: 24 Feb 05
Posts: 176
Credit: 1817881
RAC: 0

RE: einstein_S5R4_6.10_grap

Message 98328 in response to message 98326

Quote:

einstein_S5R4_6.10_graphics_windows_intelx85.exe is part of an outdated application. You could just delete this. If there are still tasks on your client that need this, abort them, you won't get any credit for them.

I don't remember this old App very well, it might be that this application was indeed built on a Windows system. But nowadays Apps are cross-compiled on a Linux system, I don't know how a virus could easily slip into this.

BM


I do the BOINC Skypey Helpline a few hours a week and this particular file has has been queried a few timea a year since it was current! It seems to have some content that confuses heuristic scanners.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.