Forum: Poser - OFFICIAL


Subject: Can it with the viruses.

XFX3d opened this issue on May 05, 2006 · 115 posts


Whimsical posted Fri, 05 May 2006 at 10:46 PM

as stormrage has stated.. polip attacks exe (and scr files).. some of the av companies have also been a little 'slow' in including it in their virus defs.. chances are you've been infected with it before the definitions were available... it was discovered on april 21 which means it would have been in circulation prior to that...

its also polymorphic.. meaning.. it changes its virus signature  (i.e., its binary pattern) every time it replicates and infects a new file in order to keep from being detected by an antivirus program.

From the Symantec site:

When W32.Polip is installed, it performs the following actions:

  1. Infects .scr and .exe files when they are opened or executed on the compromised computer.
  2. Hides its presence on the compromised computer by injecting its code into running processes.
  3. Attempts to spread by sharing infected files on the Gnutella file sharing network, even if the Gnutella software isn't installed on the compromised computer.
  4. Tries to lower security settings by deleting certain files relating to antivirus software.

I got hit with this one too.. and i update my defs every day!  My computer had been acting screwy for a few weeks and i had no idea what was wrong with it.  I did a full reinstall of my av with up to date definitions coz it was one of the programs playng up and i was able to see it had attached itself to over 200 exe files on my system.. windows utilities. daz installers.. and other programs.. nothing was left untouched by it.

Also maks sure to turn off system restore...  AV cant scan or remove threats from inside system restore.. and it does get into that too.  And scan in safe mode.. as that way you dont have any extra processes running.. less for it to impersonate.. or hijack.