Forum: Poser - OFFICIAL


Subject: Poser 6 install files infected by SpyBuddy 3.7 ?

drgonzo opened this issue on Dec 28, 2005 ยท 12 posts


drgonzo posted Wed, 28 December 2005 at 6:01 AM

A few days ago, i wanted to reinstall Poser 6 and was quite surprised to get a "Trojan Horse" warning from Pestpatrol. During the installation process Pespatrol discovers "SpyBuddy 3.7" in the setup routine. When P6 was released i downloaded it form efrontier - so i have no "orignal" P6 package - and created a backup CD. A manual scan of the files with Pestpatrol,Norton AV and PC-Cillin v12 reveals NO trojan horse. A manual scan of my system says as well that there is no problem. On the networking side i see NO unwanted connections to the internet (I checked the desktop firewall, my external firewall (professional one) and scanned the traffic with my network sniffer)- I am now not sure if this is just a false alarm or if there is really a trojan horse inside the P6 installation. Unfortunately CA didn't responded to my support email until today.
Does anybody here has Pestpatrol an tried recently to install the first P6 release ?

Message edited on: 12/28/2005 06:06


CODY posted Wed, 28 December 2005 at 7:36 AM

False positive?........Went through this awhile back with some flight simulator files. After the next updates for all the spyware and anti-virus stuff....it all stopped!


cryptojoe posted Wed, 28 December 2005 at 8:13 AM

Oh, I got more than false positives. I keep getting Virus's but my Spyware doesn't detect any malware. I'm using the Packages that came with System Mechanic Pro 5. Kaspersky is the name of the protection software.

However, I don't think its a poser issue. I haven't downloaded anything. It just started happening "The Night Before Christmas" coincidentally.

I've written to Kaspersky, and not heard back from them at all. If i bring up my browser, it will not go to my home page, it goes to some disinfection place, and I ain't falling for that one either.

I can follow ebots given to me by others with no problem. But if I hit Home on my browser, I'm back at that page that tells me I have spybots and infections etc...

Thi is just one of the many screens I got today.

I scan my system, disinfect, restart, scan the system, disinfect, restart... it just doesn't end!

Yank My Doodle, It's a Dandy!


CODY posted Wed, 28 December 2005 at 8:23 AM

Well you need to reset your home page. your using I.E. Explorer?.....


cedarwolf posted Wed, 28 December 2005 at 9:02 AM

Got much the same problem with this computer. Keeps crashing out and telling me I have a Sasser virus but none of my av software can find it....been to MicroSoft, downloaded the malware software, ran the av repeatedly...keeps crashing.


cryptojoe posted Wed, 28 December 2005 at 9:28 AM

CODY; I'd set the home page several times, changed the home page each time, but it took over my browser buttons and just kept going back to that same page. After three days, with no reply, I downloaded the latest Virus Definitions and now I've got my browser back.

This was a nasty little bug left by some Christmas Leprechauns!

Yank My Doodle, It's a Dandy!


CODY posted Wed, 28 December 2005 at 10:45 AM

Try Firefox....I got sick and tired of the crap that happens. It's really a bugger to get used to but thats' cause it's a real butt when it comes to let things in! I guess you are using I.E......I lost a hard drive to this kinda thing! Again I'd try to update Spyware/Anti-virus and re-run everything. If that does help....PM me and I can send you to a site with all kinds of goodies to help locate the problem.


pakled posted Wed, 28 December 2005 at 1:41 PM

I don't know if it's connected to your plight, but earlier versions of Poser would logon to the Internet, and search for duplicate keys, if one was found, it would disable Poser (as I understand), from a thread a couple years back..yup..IEEE!! is the 'hooker with a heart of gold' when it comes to virii and trojans..suspiro..:|

I wish I'd said that.. The Staircase Wit

anahl nathrak uth vas betude doth yel dyenvey..;)


EnglishBob posted Wed, 28 December 2005 at 5:49 PM

Attached Link: http://www.renderosity.com/messages.ez?Form.ShowMessage=2510483

Here's a link to a similar thread that was discussed recently. It seems false positives are the flavour of the month - but don't assume that's what you have without further research. The Cleaner seems like a good application, though I've only run the eval version. pakled: Poser searches local area networks for duplicate installations of itself, but it can't (and doesn't) attempt to search the entire Internet. However firewall programs generally can' tell the difference.

artistheat posted Wed, 28 December 2005 at 6:06 PM

Sometime the cause of the malice is in one of your java scripts....


pakled posted Wed, 28 December 2005 at 8:50 PM

thanks..well, 2 out of 3 brain cells were working..;)

I wish I'd said that.. The Staircase Wit

anahl nathrak uth vas betude doth yel dyenvey..;)


drgonzo posted Thu, 29 December 2005 at 5:45 AM

I received an official statement from efrontier in which they say, that this false alarm and a known issue with the installer they use... well i am willing to believe it :-)