HomeSecurityStoned virus false detections in Bitcoin files widespread

Widespread false detections of Stoned virus in Bitcoin files

bitcoin2Researcher Didier Stevens writes on his blog that he has confirmed the anti-virus of false positive detections on Bitcoin files. Stevens submitted samples to VirusTotal and received positive detections from several, including many reputable companies such as Symantec, Sophos, and Trend Micro.

The programs detect the Stoned virus, an ancient domain boot virus created in 1987. A user report to Microsoft about the problem in May correctly points out that the detection is incorrect and that it appears to be the result of a hoax: Someone entered the virus signature as a string associated with a transaction. Stevens detected two transactions, both dated 4/4/2014, but he thinks there are others.

As Stevens explains: “[S]tuffing messages into the output address of a transaction is a well-known method for inserting messages into the Bitcoin blockchain.” The string does not contain a virus executable, nor would it ever be executed even if it were in the code.

As Microsoft says, Stoned is ancient. He remembers “cleaning up” a large outbreak at a project in 1990. In those days, such viruses were a more serious problem. Now the real Stoned virus can’t do any damage, but simply displays the message “YOUR COMPUTER HAS BEEN STONED” every eight computer starts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS