Trojan??

Dec 30, 2016 00:00

I've been using ljArchive with no problems for ages, but while I was downloading some entries just now, my antivirus popped up with this message:


Read more... )

Leave a comment

Comments 22

shirebound December 30 2016, 00:09:58 UTC
I'd hate to lose ljArchive, too! I just sync'd my recent posts (I don't sync comments, just posts) and didn't get any antivirus notice.

Reply

canadanne December 30 2016, 00:16:54 UTC
I sync both posts and comments. It didn't give me the message while I was actually syncing my journals, but just afterwards when I was looking at some posts/comments with embedded photos and videos in them - I don't know if it could be related to that? (I had already viewed those same posts a few weeks ago without any Trojan warning, though.)

Reply

shirebound December 30 2016, 00:32:14 UTC
Have you ever registered for a free Dreamwidth account? It's based on the LJ format and you can back up all your LJ posts and comments there using their "Dreamwidth importer". I do it once a month. If we ever lost LJ, that would be my for-real journal back-up.

Reply

canadanne December 30 2016, 01:17:59 UTC
I might have to, although it would be a poor substitute for ljArchive. (Apart from being my backup tool, the search facility is also incredibly useful, plus I have some old archives with comments from people whose journals have since been deleted.)

Reply


susandennis December 30 2016, 00:12:41 UTC
Read this entry and, like you, do NOT want to lose LJ Archive! So I ran it - on my windows machine - entries and comments. NO issues.

Whew. Good luck. I'm voting false positive.

Reply

canadanne December 30 2016, 00:19:02 UTC
I sure hope it's just a false positive, although I've just seen this comment which is a little concerning:
http://ljarchive.livejournal.com/89769.html?thread=488617#t488617

Reply

susandennis December 30 2016, 00:32:38 UTC
I hear ya. I still have the zip with the exe that I used most recently (the installation I just checked successfully), if you want a copy of the zip, lemme know and I'll send. susandennis@gmail.com

Reply

coth December 30 2016, 22:30:45 UTC
Just to add that I also checked after reading your post, and have no issues. Can't remember where I got the version I'm running though.

I also went and copied my entries into Dreamwidth for backup, just to be on the safe side.

Reply


canadanne December 30 2016, 01:05:54 UTC
Update: I tried clicking "Ignore", but it appears Kaspersky has already gone ahead and deleted ljArchive altogether! There's a report from a few hours ago which says "Application added to the Low Restricted group" - "Reason: according to calculated rating", whatever that means.

I still have the setup file so I could try reinstalling it, but I suspect it's just going to happen again. This sucks!

Reply


canadanne December 30 2016, 02:14:55 UTC
Update 2: Kaspersky wouldn't let me do anything until I ran the Disinfect process, so I did. "Rolling back actions of malicious program" involved restoring six registry values under "internet settings" (proxyenable, proxyserver, proxyoverride, autoconfigurl, autodetect, and connections\savedlegacysettings), and restoring 7 JPGs in my temporary internet files.

I am pretty clueless as to what this means. Is ljArchive *supposed* to change those registry values? And if not, what was the Trojan attempting to do?

Reply

kk1raven January 10 2017, 01:58:24 UTC
Did it say that the settings it rolled back were related to ljarchive specifically or could those changes have been related to something else it detected?

Do you have your computer set to use a proxy server of some sort? Proxyenable is a setting that switches back and forth between using a proxy and not using a proxy. The others are related to using proxy servers as well. I can see no sign that ljarchive wants to use a proxy server on my computer. If the changes to those settings were really related to ljarchive, it may be that yours is set to use one for some reason and it wants to temporarily switch it off while it does its thing. It is also possible that the security program is detecting a real problem but is failing to detect that correct cause for the problem.

Malware sometimes sets the computer to go through a proxy server as a way of serving up false or malicious content, which is why security programs watch for changes to those settings. There are plenty of legitimate programs that use proxy servers too.

Reply

canadanne January 10 2017, 23:38:21 UTC
Yes, ljArchive was the "malicious program".

I don't really know what a proxy server is, so presumably my computer is not set to use one!

Reply


ffutures December 30 2016, 02:32:25 UTC
Unfortunately LJ archive won't sync any comments post a date in October 2012 for me. I really have no idea why, it keeps saying that the server doesn't support exporting comments (but WILL download comments on entries prior to that date) and gives me this error message when I expand the message ( ... )

Reply

canadanne December 30 2016, 02:55:10 UTC
I've been using the fixed version that was provided here in Feb 2012. (Yikes, I just found a comment I left there, saying I had trouble downloading the setup file because my antivirus deemed it untrustworthy and deleted it. I guess I found a way round that, but now I'm wondering if it really was a bad idea to install it.)

Anyway, that version didn't give me any problems with downloading comments, so I don't know why it's not working for you. :/

Reply

ffutures December 30 2016, 10:24:25 UTC
Same version here - I've used it with a couple of different antivirus programs and never had a problem.

Reply

chris_warrior December 31 2016, 04:04:27 UTC
so i didn't get a virus warning with a clean download of the supposedly "fixed" version... but i AM getting the sync error when it goes to dl comments. dammit.

if anyone figures out a work-around, i hope they post it. lots of people seem fidgety to grab their journals, courtesy of all this diplomatic BS.

Reply


Leave a comment

Up