Virus found.
|
|
Jenshae Werefox
T-ease
Join date: 3 Mar 2009
Posts: 376
|
11-12-2009 05:21
Anyone else got their anti-virus picking up file "pjd5gtqvce4t.dll" as having Trojan Mespam? Second Life refuses to run without this file and my anti-virus is going nuts over it, not even backing down and admitting it is a heuristic find or anything.
|
|
Pserendipity Daniels
Assume sarcasm as default
Join date: 21 Dec 2006
Posts: 8,839
|
11-12-2009 05:24
Which anti-virus package and version?
Pep (Narrow it down?)
_____________________
Hypocrite lecteur, — mon semblable, — mon frère!
|
|
Ephraim Kappler
Reprobate
Join date: 9 Jul 2007
Posts: 1,946
|
11-12-2009 05:25
Which anti-virus program are you using and do you have a report or log?
@Pep: Snap!
|
|
Jenshae Werefox
T-ease
Join date: 3 Mar 2009
Posts: 376
|
11-12-2009 05:26
Avira Antivir version 9.
I am wondering if other anti-viruses are picking it up too.
|
|
Viktoria Dovgal
…
Join date: 29 Jul 2007
Posts: 3,593
|
11-12-2009 05:36
That name pjd5gtqvce4t.dll doesn't look familiar, where did that come from/where is it located?
|
|
Seven Okelli
last days of pompeii
Join date: 4 Dec 2008
Posts: 2,300
|
11-12-2009 05:38
If you try to start the SL viewer, you get a message asking for that DLL?
|
|
Brenda Connolly
Un United Avatar
Join date: 10 Jan 2007
Posts: 25,000
|
11-12-2009 05:47
From: Viktoria Dovgal That name pjd5gtqvce4t.dll doesn't look familiar, where did that come from/where is it located? Not even teh Googelz could find it. /me tacklehugs Seven
|
|
Jenshae Werefox
T-ease
Join date: 3 Mar 2009
Posts: 376
|
11-12-2009 05:53
I even re-installed Second Life to try and get around it. No change.
|
|
Raudf Fox
(ra-ow-th)
Join date: 25 Feb 2005
Posts: 5,119
|
11-12-2009 06:00
I can't even find such a dll on my computer. What version of viewer are you using?
_____________________
DiamonX Studios, the place of the Victorian Times series of gowns and dresses - Located at http://slurl.com/secondlife/Fushida/224/176
Want more attachment points for your avatar's wearing pleasure? Then please vote for
https://jira.secondlife.com/browse/VWR-1065?
|
|
Milla Janick
Empress Of The Universe
Join date: 2 Jan 2008
Posts: 3,075
|
11-12-2009 06:01
I can't find it on my PC, either.
|
|
Viktoria Dovgal
…
Join date: 29 Jul 2007
Posts: 3,593
|
11-12-2009 06:05
YEah, it kind of looks like the machine may actually be infected, but perhaps the scanner is misidentifying what infection it is. Some malware will install itself with randomized names, and that's kind of what that looks like. It wouldn't hurt to try some of the other scanners out there to get a sort of second opinion on what's happening.
|
|
Yumi Murakami
DoIt!AttachTheEarOfACat!
Join date: 27 Sep 2005
Posts: 6,860
|
11-12-2009 06:06
That seems like a randomly generated .dll name. Look up the properties of the trojan on your AV software's info database and see if it generates such files.
|
|
Jenshae Werefox
T-ease
Join date: 3 Mar 2009
Posts: 376
|
11-12-2009 06:15
Thanks but why is a fresh install of the latest standard viewer demanding to use that file? Not in my definition file, it might be out of date or they forgot to add it?
Trojan.Mespam sends malicious website address through instant messaging software
|
|
Viktoria Dovgal
…
Join date: 29 Jul 2007
Posts: 3,593
|
11-12-2009 06:21
If the infection has also replaced some legitimate system file that SL depends on, you can see errors like that, even if you reinstall the application. Try some other scanners and see what they say.
|
|
Rafe Phoenix
AKA Rafe Zessinthal
Join date: 15 Nov 2004
Posts: 490
|
11-12-2009 06:25
A really good AV is AVAST home edition. Its free too. Find it here... http://www.avast.com/eng/download-avast-home.htmlIf removing the virus still cripples SL uninstall your client and shred every installer and folder related to SL that you have. Re-download a new client and see if that works.
|
|
Couldbe Yue
one unhappy customer
Join date: 30 Mar 2008
Posts: 1,532
|
11-12-2009 06:29
What viewer are you trying to use?
_____________________
Satiated Desires: Toys for Grown Ups. Inworld: http://slurl.com/secondlife/Norf%20Haven/186/132/55 XSL: https://www.xstreetsl.com/modules.php?name=Marketplace&MerchantID=77743&&sort=age&dir=asc Blog: http://satiateddesires.wordpress.com/
|
|
Pserendipity Daniels
Assume sarcasm as default
Join date: 21 Dec 2006
Posts: 8,839
|
11-12-2009 06:36
You need to get rid of the trojan completely. I would suggest you download the free software from http://www.malwarebytes.org/ and run it until you are sure that the infection has been removed. There are other actions you could take to ensure your machine is clean, but I won't go into that here. Only after you are sure that your machine is clean (and don't trust virus checkers) should you reinstall SL. Pep (You might want to consider installing SpyWareBlaster from http://www.javacoolsoftware.com/spywareblaster.html as well.)
_____________________
Hypocrite lecteur, — mon semblable, — mon frère!
|
|
Rafe Phoenix
AKA Rafe Zessinthal
Join date: 15 Nov 2004
Posts: 490
|
11-12-2009 06:36
From: Couldbe Yue What viewer are you trying to use? From: Jenshae Werefox Thanks but why is a fresh install of the latest standard viewer demanding to use that file? Not in my definition file, it might be out of date or they forgot to add it?
Trojan.Mespam sends malicious website address through instant messaging software Latest standard viewer.
|
|
Couldbe Yue
one unhappy customer
Join date: 30 Mar 2008
Posts: 1,532
|
11-12-2009 06:46
From: Rafe Phoenix Latest standard viewer. doh.. I did actually read that but obviously suffer from selective comprehension blindness.
_____________________
Satiated Desires: Toys for Grown Ups. Inworld: http://slurl.com/secondlife/Norf%20Haven/186/132/55 XSL: https://www.xstreetsl.com/modules.php?name=Marketplace&MerchantID=77743&&sort=age&dir=asc Blog: http://satiateddesires.wordpress.com/
|
|
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
|
11-12-2009 06:54
There's about a zillion ways a virus might be hiding itself in a freshly installed program and using a randomly generated file name to hide the bulk of the virus. If your system is so compromised that a complete virus scan doesn't eliminate it, it's probably time to back up your data files, reformat the hard disk, and reinstall everything from CDs or fresh downloads.
No, I'm not taking the piss. When I was a system admin, we regularly had to reimage user's computers (laptops, mostly) when they'd managed to catch something nasty on a hotel WLAN.
|
|
Rhonda Huntress
Kitteh Herder
Join date: 21 Dec 2008
Posts: 1,823
|
11-12-2009 07:09
From: Jenshae Werefox Anyone else got their anti-virus picking up file "pjd5gtqvce4t.dll" as having Trojan Mespam? Second Life refuses to run without this file and my anti-virus is going nuts over it, not even backing down and admitting it is a heuristic find or anything. Malware out these days are good at mucking up the system files and hiding in the regestry. Most antivirus will only find the virus on disk and delete the file, but the consequences are still there including letting the malware re-install itself any time there is an internet connection. Spybot, among others, also scans through the registry and other places looking for these on load and bogus dependencies. But the end results are not often that great. Download Spybot or some other malicious software removal tool. Install and update the tool. Then DISSCONNECT any network connections. Run the tool. Clean what you can and then, reboot and run the tool again. Reboot, reconnect and you should be as clean as you can make it. But if it were my machine, I would blow the whole mess away and reformat back to factory image. You have about a 50|50 chance of requiring that in the end anyway.
|
|
Jenshae Werefox
T-ease
Join date: 3 Mar 2009
Posts: 376
|
11-12-2009 10:21
I need to try avoid the format, I lost my Windows media disk.
|
|
Kira Cuddihy
Registered User
Join date: 29 Nov 2006
Posts: 1,375
|
11-12-2009 10:27
Jenshae, the http://www.malwarebytes.org/ that Pep (Pserendipity Daniels) posted above works great. I would give that a try before doing anything else. It is probably free also. I had a red screen on my computer for months, ran that anti-virus software and it was gone.
|
|
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
|
Lost the media?
11-12-2009 10:34
 That's bad. I make multiple copies of mine, and keep the original box and disks in the closet...
|
|
Rhonda Huntress
Kitteh Herder
Join date: 21 Dec 2008
Posts: 1,823
|
11-12-2009 11:07
From: Argent Stonecutter  That's bad. I make multiple copies of mine, and keep the original box and disks in the closet... That is one good thing about being in the tech business. There are more OS disks floatig around I can always get a copy of the version I need.
|