Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > Other Topics > Computer Technical Help
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #61  
Old 02-02-2006, 07:18 AM
Pinga Pinga is offline
Senior Member
 
Join Date: Jan 2005
Posts: 165
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

I spent a little time on this but didn't come up with anything special. I'll spend some time on it tonight if it hasn't been resolved - can't do it this morning.

I don't feel good about the dll file DrSavage found. Have you tried to use process explorer to see what is using it? Also, run the dll-type file through Virus Total or a similar service?

I could use a copy to work with - please zip the file and put a password on it. pinga@adelphia.net

Side note:
I strongly recommend anyone with more than a couple of K at risk use a separate computer purely for poker playing.

The poker computer should be user for poker ONLY. No 2+2, no pr0n, no reading email. Poker playing only.

I know some of you do this, but I think there are a lot of high stakes players who use the same computer for everything.

A new computer to surf the web and read mail is very cheap.
Reply With Quote
  #62  
Old 02-02-2006, 08:05 AM
LazyRobot LazyRobot is offline
Senior Member
 
Join Date: Aug 2004
Posts: 204
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

Okay, I had a chance to look at this again tonight.

Party has failed to respond to me and I am not sure what that is about but you know how Party support is.

I used ProcessExplorer to verify that Party was using the .tmp file in question. (Mine in this example is named c62.tmp) See that here (process view) ProcessExplorer has highlighted it yellow to indiciate it is a moved DLL.

This moved dll has the same md5 sum as it's good buddy llh.dll which is found in the Party poker clients install folder. You can view that here (hash of moved dll vs llh.dll)

Additionally this is a shot from a clean install of PartyPoker beta install. Notice the date of the llh.dll file. View Image of Party folder

The original 34.tmp has the same md5 sum as the c62.tmp and is the same file that MAS was flagging indicating it is a copy of llh.dll which is found in your Party folder and is listed under the copy files directive in the install.log. This file only get's flagged as a Trojan by MAS when named 34.tmp.

If someone else would please contact Party, I think I am on their do-not give cust support list.
Reply With Quote
  #63  
Old 02-02-2006, 08:23 AM
BOTW BOTW is offline
Senior Member
 
Join Date: Sep 2002
Posts: 320
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

This is a false positive, but you should still keep everything up-to-date and scan often.

I logged into Party and let it create the temp files. I renamed one that was 28K and created on 1/5/05 and MAS detected it when it was named 34.tmp. It will not detect it with the original file name, nor will it detect it in other locations. It has the same hash that others have noted.

Party sucks and they also suck for not cleaning up after themselves--I had hundreds of these 28K files dated 1/5/05.

jotti scanners and Norman sandbox also found nothing.

Edit: What LazyRobot said.
Reply With Quote
  #64  
Old 02-02-2006, 08:32 AM
edtost edtost is offline
Senior Member
 
Join Date: Feb 2004
Posts: 2,971
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

i have a bunch of tmp files in that directory modified 1/5/2005 11:56 am, and havent logged in to party since before the split. ugh.
Reply With Quote
  #65  
Old 02-02-2006, 11:30 AM
KaneKungFu123 KaneKungFu123 is offline
Senior Member
 
Join Date: Feb 2005
Location: Eating Dead Animal
Posts: 6,449
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

You guys seem to be missing something. This 1/5/2005 date is just made up. I bought this notebook last month.

The file keeps coming back after I delete it with Microsoft Anti Spyware. Really starting to get bothered.
Reply With Quote
  #66  
Old 02-02-2006, 12:09 PM
astroglide astroglide is offline
Senior Member
 
Join Date: Sep 2002
Posts: 13,836
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

i'm clean at home too, and i was one of the "lucky 100" that actually got invited into the party beta.
Reply With Quote
  #67  
Old 02-02-2006, 12:28 PM
KaneKungFu123 KaneKungFu123 is offline
Senior Member
 
Join Date: Feb 2005
Location: Eating Dead Animal
Posts: 6,449
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

[ QUOTE ]
i'm clean at home too, and i was one of the "lucky 100" that actually got invited into the party beta.

[/ QUOTE ]

diablo never downloaded beta.
Reply With Quote
  #68  
Old 02-02-2006, 01:19 PM
TheRover TheRover is offline
Senior Member
 
Join Date: Feb 2005
Posts: 5,910
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

fwiw,

I scanned my system yesterday with zonealarm security suite, avast, and came up clean. Just installed and ran Microsoft antispyware and got nothin'.

I haven't opened my Party client in months.
Reply With Quote
  #69  
Old 02-02-2006, 01:20 PM
EMc EMc is offline
Senior Member
 
Join Date: Feb 2005
Location: LETS GO YANKEES!!
Posts: 7,663
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

Neither have I.
Reply With Quote
  #70  
Old 02-02-2006, 02:28 PM
Pinga Pinga is offline
Senior Member
 
Join Date: Jan 2005
Posts: 165
Default Re: Microsoft Anti-Spyware just found trojan.backdoor.small.fb

I have verified these results - this is a false alert.

If you copy any dll to %TEMP%/34.tmp MAS will issue the alert.

Party copies a dll to this location. It is not malware.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 03:46 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.