Suspicious file detection in the FAH client

Moderators: Site Moderators, FAHC Science Team

Post Reply
abdalla.lima
Posts: 2
Joined: Mon Jun 01, 2020 12:07 pm

Suspicious file detection in the FAH client

Post by abdalla.lima »

Esteemed,

When performing a full scan today with McAfee Internet Security, it detected the file "HideConsole.exe" as suspicious and sent it to quarantine.

However, I continue to use and collaborate with the processing, both through web control and FAH Control. At first nothing has changed.

Is there any known reason why the antivirus made this decision?

I found the project proposal very interesting, but I was afraid that my participation could compromise the integrity of my information or cause damage to my devices.

Thank you in advance.
bruce
Posts: 20824
Joined: Thu Nov 29, 2007 10:13 pm
Location: So. Cal.

Re: Suspicious file detection in the FAH client

Post by bruce »

HideConsole is used in the Windows client to emulate a background task that could easily be called a daemon. I suppose it could also be used by a hacker, so McAfee is probably right to flag it. I suggest you modify your AV configuration to avoid scanning FAH's files.
abdalla.lima
Posts: 2
Joined: Mon Jun 01, 2020 12:07 pm

Re: Suspicious file detection in the FAH client

Post by abdalla.lima »

Okay, for your explanation it runs as a windows service, correct?

What would be the implication of him being quarantined in this case?

Which FAH functionality would stop working?

I confirm that I am still online and processing tasks normally, both on the web console and on the Client.
Joe_H
Site Admin
Posts: 7951
Joined: Tue Apr 21, 2009 4:41 pm
Hardware configuration: Mac Pro 2.8 quad 12 GB smp4
MacBook Pro 2.9 i7 8 GB smp2
Location: W. MA

Re: Suspicious file detection in the FAH client

Post by Joe_H »

Not exactly a Windows service. The default install is sort of emulating being a Windows service, but due to restrictions on access to the video subsystem that MS has imposed can't be installed as a service if someone wants to do GPU folding. An option does install FAHClient as a service, but it can then only be used to fold on the CPU.

As to the other effects, someone who uses Windows will need to comment, it has been a while since I had any active Windows folding system.
Image

iMac 2.8 i7 12 GB smp8, Mac Pro 2.8 quad 12 GB smp6
MacBook Pro 2.9 i7 8 GB smp3
bruce
Posts: 20824
Joined: Thu Nov 29, 2007 10:13 pm
Location: So. Cal.

Re: Suspicious file detection in the FAH client

Post by bruce »

abdalla.lima wrote:What would be the implication of him being quarantined in this case?

Which FAH functionality would stop working?

I confirm that I am still online and processing tasks normally, both on the web console and on the Client.
I don't understand your use of the word quarantined.

Of course both Web Console and FAHClient are expected to run concurrently. FAHClient's output steam is expected to become part of the FAH's log rather than occupying a foreground window, though there's nothing wrong with leaving it open if that's what you want to do.
HugoNotte
Posts: 66
Joined: Tue Apr 07, 2020 7:09 pm

Re: Suspicious file detection in the FAH client

Post by HugoNotte »

When an antivirus places an infected file in quarantine, it deletes the file from its original location and makes changes to it so that it cannot run as a program. It then transfers it to a hidden folder that other programs (or yourself as the user) cannot access where it stays until you choose to deal with it.

https://www.safetydetectives.com/blog/h ... 0with%20it.
Post Reply