Page 1 of 1

Suspicious file detection in the FAH client

Posted: Mon Jun 01, 2020 6:22 pm
by abdalla.lima
Esteemed,

When performing a full scan today with McAfee Internet Security, it detected the file "HideConsole.exe" as suspicious and sent it to quarantine.

However, I continue to use and collaborate with the processing, both through web control and FAH Control. At first nothing has changed.

Is there any known reason why the antivirus made this decision?

I found the project proposal very interesting, but I was afraid that my participation could compromise the integrity of my information or cause damage to my devices.

Thank you in advance.

Re: Suspicious file detection in the FAH client

Posted: Mon Jun 01, 2020 9:38 pm
by bruce
HideConsole is used in the Windows client to emulate a background task that could easily be called a daemon. I suppose it could also be used by a hacker, so McAfee is probably right to flag it. I suggest you modify your AV configuration to avoid scanning FAH's files.

Re: Suspicious file detection in the FAH client

Posted: Mon Jun 01, 2020 10:58 pm
by abdalla.lima
Okay, for your explanation it runs as a windows service, correct?

What would be the implication of him being quarantined in this case?

Which FAH functionality would stop working?

I confirm that I am still online and processing tasks normally, both on the web console and on the Client.

Re: Suspicious file detection in the FAH client

Posted: Tue Jun 02, 2020 12:31 am
by Joe_H
Not exactly a Windows service. The default install is sort of emulating being a Windows service, but due to restrictions on access to the video subsystem that MS has imposed can't be installed as a service if someone wants to do GPU folding. An option does install FAHClient as a service, but it can then only be used to fold on the CPU.

As to the other effects, someone who uses Windows will need to comment, it has been a while since I had any active Windows folding system.

Re: Suspicious file detection in the FAH client

Posted: Tue Jun 02, 2020 4:07 am
by bruce
abdalla.lima wrote:What would be the implication of him being quarantined in this case?

Which FAH functionality would stop working?

I confirm that I am still online and processing tasks normally, both on the web console and on the Client.
I don't understand your use of the word quarantined.

Of course both Web Console and FAHClient are expected to run concurrently. FAHClient's output steam is expected to become part of the FAH's log rather than occupying a foreground window, though there's nothing wrong with leaving it open if that's what you want to do.

Re: Suspicious file detection in the FAH client

Posted: Tue Jun 02, 2020 4:15 pm
by HugoNotte
When an antivirus places an infected file in quarantine, it deletes the file from its original location and makes changes to it so that it cannot run as a program. It then transfers it to a hidden folder that other programs (or yourself as the user) cannot access where it stays until you choose to deal with it.

https://www.safetydetectives.com/blog/h ... 0with%20it.