Cake Poker
Home
News
Articles
Site Reviews
Book Reviews
Interviews
Chat
Tournaments
60% Rakeback
50% RakebackNew!
125% Rakeback
Probabilities
Glossary
Poker Gear
Links
Advertise
User Name  
 
Password
Cookie?  
 
 
Poker Players on Launchpoker.com
LaunchPoker.com provides you with all the information you need about this year's WSOP event, from the 2008 WSOP schedule to the latest 2008 WSOP updates.
Online poker reviews of rooms such as Full Tilt Poker, Poker Stars and Titan Poker.
Extras

RakeBack
PokerListings

Go Back PokerForums.org > Strategy Discussion > General Poker Strategy > SNGPowerTools WARNING: URGENT.

Notices

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-14-2006, 03:03 AM
xxdemexx's Avatar
Poker Professional
 
Join Date: Aug 2004
Location: UK
Posts: 1,815
Trade Rating: (0)
Default SNGPowerTools WARNING: URGENT.

I got this about ten days ago. Theres another thread where I reviewed it. Its an OK tool. It's debatable whether its worth $79 but for a novice it would pay for itself.

BUT.... Over the last three days I have had a major virus on my PC - and Not a funny one.

This thing is a subset of Tulu (msconfig32.exe is embedded in a file). The virus is in fact a Trojan - and a serious one. In operation:

1] After a few days your cable line will begin to struggle and your pc will often lock up

2] AVG antivirus software flags a problem under the "Heuristic" - Unfortunately AVG knows its there but can't shift it.

3] It seems to using an IRC channel to access your passwords and stuff...

This is not very nice. What makes it worse is that this virus has been mutated by a programmer (that's why AVG cant't kill it its not out in the broader domain). You need a pro-level virus remover to get shot of it (I eventually got a trial version of some software that did the job [I hope] - I'll post it when I get back home). I know more or less what I'm doing on PC's and it took three days to kill it AND I couldn't play poker because the thing locks the pc after ten minutes.


The software I used nailed the source of the virus as Unisnt.000 as supplied by SngPowertools.

Now I don't know what's happened here.. SnGpowertoools is ok but if you have it. Do a virus scan with AVG and set the heuristic running. Leave you machine for 20 minutes. If a virus warning with "MSconfig32" comes up and you can't heal it then come back here to find the software I used to remove it. (I'll post later). I would advise against leaving your PC on and connected to the net if you find its there...
__________________
See me playing $10/$20NL like it was play money

http://video.google.co.uk/videoplay?...405&q=xxdemexx

Doberman: "but Sarge, isn't poker gambling and just luck?"
Sgt. Bilko:" not the way I play it"
Reply With Quote
Sponsored Links
Personal Poker Pal
  #2 (permalink)  
Old 03-14-2006, 04:46 AM
Marm's Avatar
PokerForums God
 
Join Date: Oct 2004
Location: Cleveland
Posts: 9,296
Trade Rating: (0)
Send a message via AIM to Marm Send a message via MSN to Marm
Default

www.kaspersky.com has an free online scanner that doesnt requrie a client to use. They also have a free one month trial client version too, it killed a few bugs that norton couldn't even touch. Highly recommended.
__________________

Reply With Quote
  #3 (permalink)  
Old 03-14-2006, 05:01 AM
PowerfulRog's Avatar
Banned
 
Join Date: Sep 2005
Location: North Adams, MA
Posts: 1,453
Trade Rating: (0)
Send a message via AIM to PowerfulRog Send a message via Yahoo to PowerfulRog
Default

Well I know what program I'm not getting anytime soon.
Reply With Quote
  #4 (permalink)  
Old 03-14-2006, 06:53 AM
PokerForums God
 
Join Date: Sep 2004
Posts: 8,170
Trade Rating: (0)
Default

Bob,

Are you running a firewall?
Reply With Quote
  #5 (permalink)  
Old 03-14-2006, 07:20 AM
Mr.McJ's Avatar
Stu Ungar
 
Join Date: Jan 2006
Location: Toronto, Ontario
Posts: 2,404
Trade Rating: (0)
Default

Quote:
Originally Posted by xxdemexx
The software I used nailed the source of the virus as Unisnt.000 as supplied by SngPowertools.
Do you know the folder that this file was located in?
Reply With Quote
  #6 (permalink)  
Old 03-14-2006, 08:06 AM
xxdemexx's Avatar
Poker Professional
 
Join Date: Aug 2004
Location: UK
Posts: 1,815
Trade Rating: (0)
Default

Firewall..: I just got cable - we live in a rural area... and I networked through a router with a built in fiewall (but its not that great). Zonealarm doesnt work (unless you pay) with networks.

The software that I think/hope killed it is found here

http://www.prevx.com/

it is a 60 day free trial.There may be others that kill it. AVG doesn't.

Just deleting this file:

\sngpt\sng pokertools\unins000.exe

I'm not sure will work - the bloody thing will just respawn. BUT if you have the above file then do something about it....
__________________
See me playing $10/$20NL like it was play money

http://video.google.co.uk/videoplay?...405&q=xxdemexx

Doberman: "but Sarge, isn't poker gambling and just luck?"
Sgt. Bilko:" not the way I play it"
Reply With Quote
  #7 (permalink)  
Old 03-14-2006, 08:19 AM
Mr.McJ's Avatar
Stu Ungar
 
Join Date: Jan 2006
Location: Toronto, Ontario
Posts: 2,404
Trade Rating: (0)
Default

The reason why I ask is because unins000.exe is a farily common file and could be found in numerous directories on your PC, not just SNGPowertools. Did you download SNG from their website or from somewhere else (torrents, perhaps?)

I know you're not necessarily saying this but I doubt SNGPowertools is allowing people to download an infected version of their software from their website as it would be pretty bad for business. The infected file in question could have come from a number of different places. Don't get me wrong, it's definitely a good idea to check your system for viruses if you've downloaded this program but I wouldn't be too worried to download it myself if I was interested.
Reply With Quote
  #8 (permalink)  
Old 03-14-2006, 08:30 AM
PokerForums God
 
Join Date: Sep 2004
Posts: 8,170
Trade Rating: (0)
Default

I never had any problems running free ZA through a router.

Built in firewalls won't stop stuff from connecting from your competer. ZA would let you isolate the file so I could not connect to the net. If the free version doesnt work for, buy somthing. It is better than having to reinstall Windows.

I was able to run my system fine with a couple of worms and trojans I couldn't get rid of by isolating them with the firewall. That is until I turned it off and connected to the net one day. I lasted about 15sec.
Reply With Quote
  #9 (permalink)  
Old 03-14-2006, 12:05 PM
tightagressive's Avatar
Mike McDermott
 
Join Date: Jan 2006
Location: Michigan
Posts: 3,063
Trade Rating: (1)
Limits Played: Play Money
Send a message via AIM to tightagressive
Default

i have sng pwr tools. no virus here.
Reply With Quote
  #10 (permalink)  
Old 03-14-2006, 03:40 PM
Eclipse86's Avatar
Poker Professional
 
Join Date: May 2005
Location: Toronto, Canada
Posts: 1,583
Trade Rating: (0)
Default

deme,

I think it would be alot safer if u reformatted ur comp instead. The last thing u would want is to think the virus is gone, then login to ur poker account only to get it hacked a few days later and lose all ur money. Back up ur comp, and reformat it would be alot better.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 03:41 AM.

   Designed by
      
No Deposit Bonus
Poker Strategy
Poker Rooms
PartyPoker Bonus Codes
Online Poker Strategy
Online Casino Bonuses
Pokerspiele
Casinos That Accept USA Players
Poker Rakeback
Full Tilt bonus code
Rakeback
Poker Site USA
Nowadays in the Internet the Players are looking for a good Casino Bonus to find the best possible options for online Roulette.There is now the option of RtlPoker and a nice Casino Bonus to play some other games then just Poker.
The ideal casino site for gokkasten and even online poker including online casino games that can be found on mijn online casino, your casino information site for when gambling online or even offline.
Party Poker bonus code & room review
Tony G talks about his experinces in his blog
REVIEW OF PARADISE POKER WEBSITE
Online Poker Room Directory and latest poker news
Best Online Poker info on Internet!
Ultimate Bet new 40% deposit bonus
Copyright © 2004-2008 PokerForums.org, a Merendi Networks Inc. project.
Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.