Sun, Feb 16, 8:20 AM CST

Renderosity Forums / Poser - OFFICIAL



Welcome to the Poser - OFFICIAL Forum

Forum Coordinators: RedPhantom

Poser - OFFICIAL F.A.Q (Last Updated: 2025 Feb 15 11:01 am)



Subject: Lmir trojan - Poser 6 updates?


shadownet ( ) posted Mon, 19 December 2005 at 7:15 PM ยท edited Sun, 21 July 2024 at 11:57 PM

Has anyone come across the Lmir trojan in any of the Poser 6 updates. Doing a deep scan on my desktop (which rarely goes on line fortunately) I found both the Poser 6 SR1 and Content Updater reported as having this virus. Trojan scanner I use is The Cleaner 3.5 I downloaded the files from Content Paradise and the trojan (on scanning) showed up in both the original zip file and also in my working copy of Poser 6. It is possible that the The Cleaner gave a false read on an okay file as I do know this sometimes can happen - however, since the Lmi trojan is a password stealer I felt I would mention it here to see if anyone else has encountered this - or would like to check their P6 files with whatever anti-trojan prog they use and see if it shows up. I be interested in knowing more on this. Rob


EnglishBob ( ) posted Tue, 20 December 2005 at 4:45 AM

I haven't had any alerts from Poser 6 - I use AVG. However it did come up with a false trojan alert (nothing to do with Poser) last week after I downloaded a faulty update. I reinstalled Windows on one machine before I found out what the trouble really was. It had it coming, anyway. :( You're right to be careful though. How often do they issue updates?


shadownet ( ) posted Tue, 20 December 2005 at 9:11 AM

I get daily updates on the Cleaner, though I am using an older but still supported version. In the past it has found trojans that every other program I have tried has missed (in some instances these were actual tests I did where I infected a file to try out the different progs - in one case, however, I was caught by surprise and theCleaner found a nasty I did not know about - where none of the others had) Needless to say I have stayed with it over the years. May be better out there now, but well I am an old dog. And so far it seems to be doing a good job still. I also use AVG and it did not detect the Lmi trojan. I have a lot of faith in AVG which made me wonder if I might have gotten a false read so wanted to check with others.


EnglishBob ( ) posted Tue, 20 December 2005 at 9:43 AM

I'll check out The Cleaner - I assume MooSoft aren't connected with the MooTools who make some nifty 3D stuff? I could certainly have done with a second opinion last week, although if The Cleaner had said there were no trojans when AVG did, I probably wouldn't have believed it. :/ Anyway, I've downloaded The Cleaner 4.1 - I'll try it out when I get home and see what happens.


lmckenzie ( ) posted Tue, 20 December 2005 at 11:57 AM

Attached Link: http://www.f-secure.com/v-descs/lmir_aeu.shtml

According to a couple of Virus lists I Googled: "This family of Trojans steals passwords to the online game Legend of Mir." - Which seems like a pretty specialized threat. F-Secure only mentions password stealing. One thing I like to do is find out what changes these things make to your system. In this case, if you don't have the htdll.dll or a 51kb file named Explorer.exe in the system32 directory, then you're probably not infected.

"Democracy is a pathetic belief in the collective wisdom of individual ignorance." - H. L. Mencken


shadownet ( ) posted Tue, 20 December 2005 at 12:08 PM

Thanks for the info. Again, I am no mental giant when it comes to understanding computer viruses etc. I'll look and see if I have the Explorer.exe 51kb floating around in my system32 directory.


EnglishBob ( ) posted Wed, 21 December 2005 at 10:47 AM

I ran The Cleaner 4.1 on my PC, and it didn't find anything connected with Poser. There was one false positive, which was Gibson Research's Leak Test. As it's designed to test your firewall, that may be understandable. I'm not sure where that leaves you - wary alertness would probably be a good state to be in. :)


shadownet ( ) posted Wed, 21 December 2005 at 10:52 AM

Thanks EB, its possible I picked up an infected file at some point or else got a false read. I'm showing clean now, and Poser 6 works, so I guess all is ok. Particularly since I only rarely go online with the desktop. Thanks for the feedback.


Privacy Notice

This site uses cookies to deliver the best experience. Our own cookies make user accounts and other features possible. Third-party cookies are used to display relevant ads and to analyze how Renderosity is used. By using our site, you acknowledge that you have read and understood our Terms of Service, including our Cookie Policy and our Privacy Policy.