| Index | Recent Threads | Unanswered Threads | Who's Active | Guidelines | Search |
| World Community Grid Forums
|
| No member browsing this thread |
|
Thread Status: Active Total posts in this thread: 6
|
|
| Author |
|
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
I was suprised when I came home by a computer that was in quarantine mode because worldcommunitygrid\udtapi.dll had been updated to contain the Win32/Anserin!HookDLL.Variant Trojan.
I did not check to see what the other three computers where running as the Grid project, instead I just stopped the process and removed the software. I find it ironic that a few days after this machine picked up the FightAids project it gets a computer virus downloaded (today). I have been to Rwanda, Africa and have seen people there die from Aids that they contracted during the genecide. During that period tribes killed the men and raped the women. In 2001, 30% of the women giving birth had Aids / HIV and I do believe a cure is needed ... but please make this project safe for my computer!!! --Loren |
||
|
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
Hello LorenM,
Computer viruses infect randomly selected programs on the hard disk. The WCG programs are just as vulnerable as any others. Be sure to scan your computer for viruses in other locations. mycrofth |
||
|
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
I was suprised when I came home by a computer that was in quarantine mode because worldcommunitygrid\udtapi.dll had been updated to contain the Win32/Anserin!HookDLL.Variant Trojan. I did not check to see what the other three computers where running as the Grid project, instead I just stopped the process and removed the software. I find it ironic that a few days after this machine picked up the FightAids project it gets a computer virus downloaded (today). I have been to Rwanda, Africa and have seen people there die from Aids that they contracted during the genecide. During that period tribes killed the men and raped the women. In 2001, 30% of the women giving birth had Aids / HIV and I do believe a cure is needed ... but please make this project safe for my computer!!! --Loren I can assure you that your virus was in your system already and that the DLL file was infected by that virus. A computer virus will try very hard to stay alive in your system and to do so it will infect as many files/pieces of software that the programer thinks of infecting (DLL files, Image Files, Sound Files, Text Files...you name it) either that or your Anti-Virus software is CRAZY hehehe |
||
|
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
Sorry, this was the only file infected, scanned both hard drives and nothing else is infected. And, it seems to be infected on download not execution, occurance was at 7:35 PM PST today.
|
||
|
|
Former Member
Cruncher Joined: May 22, 2018 Post Count: 0 Status: Offline |
This is a very rare trojan, it is currently listed as wild: low, damage: low, distribution: low. If ($DEITY forbid) the WCG server antivirus had let it slip through and sent it to all the clients, then we would all have the darned thing. Clearly we don't, and you got infected by some other means. Sorry.
|
||
|
|
Viktors
Former World Community Grid Tech Joined: Sep 20, 2004 Post Count: 653 Status: Offline Project Badges:
|
Which antivirus program are you using? We have seen at least one less often used virus checker falsely tag some portion of World Community Grid files. If you truly have been infected with the virus you mention, you might want to scan your system with a second antivirus product, just to check if the first virus checker missed something. In particular, there may be another file somewhere on your system which contains the original infection.
If you run md5sum on the udtapi.dll file, it should show the following value: dd39700773325b2651ed9e878c366a5c If this file is modified or deleted, the agent software restores it to the correct content the next time the agent runs. |
||
|
|
|