Thu, Nov 7, 4:18 AM CST

Renderosity Forums / Poser - OFFICIAL



Welcome to the Poser - OFFICIAL Forum

Forum Coordinators: RedPhantom

Poser - OFFICIAL F.A.Q (Last Updated: 2024 Nov 05 9:36 pm)



Subject: Possible virus?


drackliffe ( ) posted Sun, 07 September 2008 at 6:28 PM · edited Thu, 07 November 2024 at 4:16 AM

Last night my poser program froze and after several attempts would not start.  I thought OK I might need to re-install it so I backed up my runtime to a separate drive.  When I went to back up the downloads directory I noticed that it had 0 files but still lots of folders.  Weird.  Went back to look at my runtime which when I copied it had 7.62 Gb of files was now empty.  All my folders are still present under the library folder.  All character, pose etc folders with all the sub folders still show, but no files inside the folder.  Rechecked my back-up and they were empty too.   Also every jpg and poser file I've ever created is gone as well.  Seems only my poser files are affected.  All other programs still have files in them as normal.  Anyone run across this?

Any help would be appreciated.

Thanks,

Dana


patorak ( ) posted Sun, 07 September 2008 at 6:42 PM · edited Sun, 07 September 2008 at 6:42 PM

JEEFO is a virus that attacks Poser files.  I just got it in an e mail from a member here.  Norton couldn't do anything with it because it's in an e mail attachment.  I figure as long as I don't open it I'll be safe.



Byrdie ( ) posted Sun, 07 September 2008 at 6:48 PM

First I've heard of that one. It specifically targets Poser files? Hmmm.....


patorak ( ) posted Sun, 07 September 2008 at 7:00 PM

That was always my impression of it.  Maybe I'm wrong.



cherokee69 ( ) posted Sun, 07 September 2008 at 8:28 PM · edited Sun, 07 September 2008 at 8:29 PM

It infects Windows Portable Executable files.

en.wikipedia.org/wiki/Jeefo_(computer_virus)


Byrdie ( ) posted Sun, 07 September 2008 at 8:29 PM

Well, I did a Google for it and according to Symantec it's a Windows Portable Executable (PE) file infector. Files infected by W32.Jeefo increase in size by 36,352 bytes.
Said to be very low risk.

Symptoms: 1. Memory Usage is High 2. Executables do not launch 3. Multiple instances of svchost.exe launched in the task manager.

Sophos has a detector/removal tool for it here:

http://www.sophos.com/support/disinfection/jeefoa.html
http://www.sophos.com/security/analyses/viruses-and-spyware/w32jeefoa.html

Just ran it on my system, which has been misbehaving lately -- and I was on Rendo a couple times during the virus attacks last week -- but so far all scans keep coming up clean. Not sure if that's good or bad as I still have the problems : Memory usage suddenly going very high, up to 100% of my CPU, and the dreaded low-battery error at startup day before yesterday. Then again it might not have anything to do with a virus, these Dell 8300s have been known to be lemons in disguise.


BAR-CODE ( ) posted Mon, 08 September 2008 at 7:24 AM

Quote - JEEFO is a virus that attacks Poser files.  I just got it in an e mail from a member here.  Norton couldn't do anything with it because it's in an e mail attachment.  I figure as long as I don't open it I'll be safe.

You got it from a member here by email... and how did he got your email then ?
There is no way to email from this site to a other  email adres...
And IF you had a email true this site ...there is NO way to attach anything true this site to emails
Only Vendors can sent to your email adres ..but those messages are checked by RO..

So how did you get tthat virus true a member here ???

And there Are NO ! viruses specialy for poser files... things like that make myths and fables...

99% of virusses you get from opening bad email from hackers etc etc and spam
And from using unfair files..

So im realy waiting to hear how you got a virus from here....

 

IF YOU WANT TO CONTACT BAR-CODE SENT A  PM to 26FAHRENHEIT  "same person"

Chris

 


My Free Stuff



PhilC ( ) posted Mon, 08 September 2008 at 7:42 AM

"And there Are NO ! viruses specialy for poser files... things like that make myths and fables... "

On reflection, maybe not. See these threads.

DAZ Forum Thread Similar in Renderosity thread

Another DAZ form post.

Mostly although the posts were commented upon no solution was given.


BAR-CODE ( ) posted Mon, 08 September 2008 at 8:32 AM

I stand corrected.. after talking with Co workers here..
I must say that lately we see things that actualy shows illigal Poser files and zips
That have being invected with nasty's ...
And i have read the threads in the links above...
it seems NO solution to the nasty's can be found or given.
--

Stil i like to know how some one get a virus true the Renderosity email system...
Impossible to me so please tell me ...

Chris

 

IF YOU WANT TO CONTACT BAR-CODE SENT A  PM to 26FAHRENHEIT  "same person"

Chris

 


My Free Stuff



dbowers22 ( ) posted Mon, 08 September 2008 at 12:05 PM

Quote - I stand corrected.. after talking with Co workers here..
I must say that lately we see things that actualy shows illigal Poser files and zips
That have being invected with nasty's ...
And i have read the threads in the links above...
it seems NO solution to the nasty's can be found or given.

See if this helps:

http://www.sophos.com/support/disinfection/jeefoa.html



BAR-CODE ( ) posted Mon, 08 September 2008 at 12:40 PM

Quote -

See if this helps:

http://www.sophos.com/support/disinfection/jeefoa.html

Thnx but i dont ned the info...
i have only legit. files and so i dont have to deal with this kind of virus..
Its a shared virus.. its only spread true sharing infected files so i have nothing to fear from it..

But maybe someone else can...

 

IF YOU WANT TO CONTACT BAR-CODE SENT A  PM to 26FAHRENHEIT  "same person"

Chris

 


My Free Stuff



Byrdie ( ) posted Mon, 08 September 2008 at 1:15 PM

Maybe the site mail got whammied during that business with the infected banner thingie last week. If so, something could have gotten out then before it was all cleaned up and some folks had the bad luck to be on the receiving end.

Meanwhile, my gear checks out all clean after numerous scans. I found one of the problems -- an incorrect program setting I'd forgotten to fix. However, the other nuisance is either entirely Dell's fault or else Windoze has gone wonky again.


patorak ( ) posted Mon, 08 September 2008 at 5:35 PM · edited Mon, 08 September 2008 at 5:36 PM

*Stil i like to know how some one get a virus true the Renderosity email system...
Impossible to me so please tell me ...

It wasn't from rendo e mail system.  It was an e mail from this individuals personal e mail address to my yahoo address. 

Still don't know what I should do with it.  I haven't opened it,  so my computer isn't infected.  Norton identified it,  but won't do anything since it's an e mail attachment. 



BAR-CODE ( ) posted Mon, 08 September 2008 at 5:37 PM

Quote - *Stil i like to know how some one get a virus true the Renderosity email system...
Impossible to me so please tell me ...

It wasn't from rendo e mail system.  It was an e mail from this individuals personal e mail address to my yahoo address. 

Still don't know what I should do with it.  I haven't opened it,  so my computer isn't infected.  Norton identified it,  but won't do anything since it's an e mail attachment. 

DELETE it and Empty the trash bin... simple..
And then tell the sender you like the email again without nasty's..

 

IF YOU WANT TO CONTACT BAR-CODE SENT A  PM to 26FAHRENHEIT  "same person"

Chris

 


My Free Stuff



patorak ( ) posted Mon, 08 September 2008 at 5:40 PM

*DELETE it and Empty the trash bin... simple..
And then tell the sender you like the email again without nasty's..

Cool!  Thanks!



Faery_Light ( ) posted Mon, 08 September 2008 at 7:38 PM · edited Mon, 08 September 2008 at 7:42 PM

Even if you just put it in the trash bin, yahoo deletes after so many days. BTW: Question for someone who knows about system files...what is svchost.exe anyway? I have several instances runing and wonder if I should delete them.


Let me introduce you to my multiple personalities. :)
     BluEcho...Faery_Light...Faery_Souls.


DarkEdge ( ) posted Mon, 08 September 2008 at 7:40 PM · edited Mon, 08 September 2008 at 7:40 PM

Pat, open it and embrace the warm liquidy fluid that comes forth! 😉

It's probably been a while since you had to reinstall everything...such fun. :lol:

Comitted to excellence through art.


Khai ( ) posted Mon, 08 September 2008 at 7:51 PM
Faery_Light ( ) posted Mon, 08 September 2008 at 8:01 PM

Thank you, Khai.
Now I know how to deal with it. :)


Let me introduce you to my multiple personalities. :)
     BluEcho...Faery_Light...Faery_Souls.


RedPhantom ( ) posted Mon, 08 September 2008 at 8:24 PM
Site Admin

Drakke, after you get the virus removed, try downloading a deleted file recovery program. It will help find things that aren't in you recycle bin. You can get a demo at http://www.easeus.com/. Good luck.


Available on Amazon for the Kindle E-Reader Monster of the North and The Shimmering Mage

Today I break my own personal record for the number of days for being alive.
Check out my store here or my free stuff here
I use Poser 13 and win 10


patorak ( ) posted Tue, 09 September 2008 at 5:09 PM

*Pat, open it and embrace the warm liquidy fluid that comes forth!

It's probably been a while since you had to reinstall everything...such fun.

LOL!  It's been 4 years since I've had to reformat and reinstall.  Got the gator toolbar from elf bowling.



Nance ( ) posted Tue, 09 September 2008 at 9:39 PM

Thanks khai - great site & article.  (I too had long wondered about all the svchost.exe's running.)


Faery_Light ( ) posted Tue, 09 September 2008 at 10:13 PM

I downloaded the free Process Explorer and found out most of mine are from my AV program.

What a relief!
I was worried I might have a trojan the escaped notice.
 

 


Let me introduce you to my multiple personalities. :)
     BluEcho...Faery_Light...Faery_Souls.


Nance ( ) posted Wed, 10 September 2008 at 1:33 AM

If you'll allow me to drift a little farther OT, "the How-To Geek" page Khai mentioned above also has an article telling how to disable 'ctfmon.exe' in Windows.

http://www.howtogeek.com/howto/windows-vista/what-is-ctfmonexe-and-why-is-it-running/


Quote:
"Ctfmon is the Microsoft process that controls Alternative User Input and the Office Language bar. It's how you can control the computer via speech or a pen tablet, or using the onscreen keyboard inputs for asian languages."


It can slow or hang the system, and sounds unnecessary for most folks, so I'm considering killing it.    The replies there indicate that  only folks using multiple language keyboard fonts were really using it - as far as I could tell.

Q: Anyone aware of any overlooked reason why disabling ctfmon.exe might be a bad idea?   


bopperthijs ( ) posted Wed, 10 September 2008 at 6:46 AM

D***, I misread the title I thought someone had made a posable virus, Now I can my forget my new hospital render in which Vicky gets the flue...

Bopper.

-How can you improve things when you don't make mistakes?


Khai ( ) posted Wed, 10 September 2008 at 6:56 AM

CTFMON is also used for items like a WACOM Tablet... other than that, kill that sucker...


Nance ( ) posted Wed, 10 September 2008 at 11:52 PM

Poof! -- It's gone.  Thanks Khai.


Daidalos ( ) posted Thu, 11 September 2008 at 12:53 AM

Bopperthijs,

Try RDNA they used to have a decent virus/dna model for download.

Zygote at one time had one too, I don't know if they still do though.

And at one time there were some pollen or alien spores for download here in the freestuff as well.

Hope that helps you with finding something you can use.

Daidalos


"The Blood is the life!"

 


Privacy Notice

This site uses cookies to deliver the best experience. Our own cookies make user accounts and other features possible. Third-party cookies are used to display relevant ads and to analyze how Renderosity is used. By using our site, you acknowledge that you have read and understood our Terms of Service, including our Cookie Policy and our Privacy Policy.