Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Started SL, Got Trojan attack detected, Crashed, Can't Log in

MadamG Zagato
means business
Join date: 17 Sep 2005
Posts: 1,402
09-18-2006 12:56
I tried to start SL, I got an Antivirus warning that said an incoming attack was detected from xx.x.xx.xx

Then it crashed.
Everytime I tried to log in...it logged me in....then crashed.

Now the database is offline.
What's going on?
_____________________
MadamG Zagato
means business
Join date: 17 Sep 2005
Posts: 1,402
Details
09-18-2006 22:05
Details:Rule "Default Block Portal of Doom Trojan horse" blocked (72.5.12.28,3700).
Inbound UDP packet.

Local address,service is (XXXXXXX(192.168.0.100),3700).
Remote address,service is (72.5.12.28,12035).
Process name is "N/A".

Details:Rule "Default Block Portal of Doom Trojan horse" blocked (userserver.agni.lindenlab.com(66.150.244.151),370 0).
Inbound UDP packet.
Local address,service is (XXXXXXX(192.168.0.100),3700).
Remote address,service is (userserver.agni.lindenlab.com(66.150.244.151),120 36).
Process name is "N/A".

/139/65/138414/1.html
Sansarya Caligari
BLEH!
Join date: 25 Apr 2005
Posts: 1,206
09-18-2006 22:13
Do you mean that SL is downloading a virus on my computer when I log in w/ my anti-virus and firewall turned off to "improve" performance?
_____________________
Usagi Musashi
UM ™®
Join date: 24 Oct 2004
Posts: 6,083
09-18-2006 22:34
ok i am lost here.....its assumed that its just you here.
Eddy Stryker
libsecondlife Developer
Join date: 6 Jun 2004
Posts: 353
09-18-2006 22:36
False positives are what make application-level firewalls so fun!
_____________________
http://www.libsecondlife.org

From: someone
Evidently in the future our political skirmishes will be fought with push weapons and dancing pantless men. -- Artemis Fate
MadamG Zagato
means business
Join date: 17 Sep 2005
Posts: 1,402
09-18-2006 23:22
From: Usagi Musashi
ok i am lost here.....its assumed that its just you here.

I don't know. That's why I posted. I really hope it IS an isolated incident. But if anyone else had this happen, I sure would like to know about it.

Why would my avntivirus pickup SL as a Trojan? Doesn't make sense. LOL
Usagi Musashi
UM ™®
Join date: 24 Oct 2004
Posts: 6,083
09-19-2006 01:55
I got the same message...........the next time i loge in
Scanned my system and i got no virus.......
Nakomis Lycia
woof
Join date: 14 Jan 2006
Posts: 28
09-19-2006 03:07
Its called a False positive. Software firewalls are no where near 100% perfect and will detect trojans/worms/etc on files that are perfectly legit.
Thili Playfair
Registered User
Join date: 18 Aug 2004
Posts: 2,417
09-19-2006 03:35
Software tends to belive anything is a trojan if it tries to connet to your pc, trying to find new trojans usually ends up it flags connections as a trojan.
Usagi Musashi
UM ™®
Join date: 24 Oct 2004
Posts: 6,083
09-19-2006 03:43
I understand this But I have not had this happen to me before on sl.......Thisi s what bothers me...........Since when does SL made my virus program jump :rolleyes: .......Oh well whatelse is new these days on sl.........expect the unexpected... :cool:
MadamG Zagato
means business
Join date: 17 Sep 2005
Posts: 1,402
You'd think they would respond a lil quicker!
09-20-2006 07:12
From: Usagi Musashi
I understand this But I have not had this happen to me before on sl.......Thisi s what bothers me...........Since when does SL made my virus program jump :rolleyes: .......Oh well whatelse is new these days on sl.........expect the unexpected... :cool:
For me it happened RIGHT when that grid attack was occurring. I personally, would like to hear from Linden Lab. You'd think they would want to reassure us that they have not injected malicious code in the software, or that there is no way anyone else could either.

But I guess this is just not on their priority list either. It's probably right after fix all the bugs. Somewhere between task #38,849 and task #GAZILLION!
_____________________
Taco Rubio
also quite creepy
Join date: 15 Feb 2004
Posts: 3,349
09-20-2006 07:22
Which methods did you try in the last 36 hours to contact them with?
_____________________
From: Torley Linden
We can't be clear enough, ever, in our communication.
MadamG Zagato
means business
Join date: 17 Sep 2005
Posts: 1,402
09-20-2006 07:47
From: Taco Rubio
Which methods did you try in the last 36 hours to contact them with?
Could not get anyone on the phone yesterday...I'll try again today. I dare not send an email...waste of time from what I hear.

But NOW check this out. I can't log in under this account. I created an alt account and can log in fine with that. But I just get connecting to region. It sticks there. I contacted a Linden using the alt account, and was told to try logging into a different region. That didnt work either.

Funny I was logged in then I posted this post:
/158/03/138666/1.html

Now my login is stuck? Did I piss on somebody's Cheerios this morning?
MadamG Zagato
means business
Join date: 17 Sep 2005
Posts: 1,402
09-20-2006 08:16
From: Taco Rubio
Which methods did you try in the last 36 hours to contact them with?
Hmmmm, none except the blog and the forums. I'm sure if I call, I'll get "Send an email to [email]blahblahblah@lindenlab.com[/email]" Then a generic email response.

They are aware of the problem. They read and deleted my blog entry.
Usagi Musashi
UM ™®
Join date: 24 Oct 2004
Posts: 6,083
09-20-2006 08:28
From: MadamG Zagato
For me it happened RIGHT when that grid attack was occurring. I personally, would like to hear from Linden Lab. You'd think they would want to reassure us that they have not injected malicious code in the software, or that there is no way anyone else could either.

But I guess this is just not on their priority list either. It's probably right after fix all the bugs. Somewhere between task #38,849 and task #GAZILLION!


After doing a scan I found nothing.....LLAbs does seem to understand it does exist but where inteh list of importent things to do is not yet clear.
Lets hope it is soon.