SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > Silent Hunter 3 - 4 - 5 > Silent Hunter III
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 02-25-14, 12:35 PM   #1
Dave Kay
Gunner
 
Join Date: Apr 2005
Location: AZ
Posts: 93
Downloads: 25
Uploads: 0
Default Trojan malware targets SH3 utils.dll (SOLVED)

WARNING!!

Hope I'm in the right forum for this:

Had this Trojan target both desktop and laptop installs of my SH3 and game won't start now because MalwareBytes software quarantines utils.dll.

Anybody seen this before?

OK, this IS a false positive or whatever. Malwarebytes targeted it because, as I've learned, DLL's are executables and that casued the quraentine. SO--- I found a clean utils.dll on another backup drive and copied/pasted to SH3 folder and set Malwarebytes to ignore this file and all seems to be well.

Thanks to all for the helpful suggestions.
Attached Images
File Type: jpg SH3_malware.JPG (74.9 KB, 33 views)

Last edited by Dave Kay; 02-26-14 at 01:25 PM.
Dave Kay is offline   Reply With Quote
Old 02-25-14, 04:07 PM   #2
Herr-Berbunch
Kaiser Bill's batman
 
Herr-Berbunch's Avatar
 
Join Date: May 2010
Location: AN72
Posts: 13,203
Downloads: 76
Uploads: 0
Default

Delete the utils.dll files and get them again by using Google to find the second half of the following post - http://www.subsim.com/radioroom/showthread.php?t=160118

Once downloaded turn off System Restore and reboot, put the .dll into the correct location - you shouldn't need to reinstall SH3, it should just accept it nicely.

Reboot again, scan and then turn on System Restore.
__________________
Herr-Berbunch is offline   Reply With Quote
Old 02-25-14, 05:36 PM   #3
Dave Kay
Gunner
 
Join Date: Apr 2005
Location: AZ
Posts: 93
Downloads: 25
Uploads: 0
Default

Thank you, thank you and THANK YOU~!

Was not looking forward to a reinstall as I only recently did this along with GWX and SH3 Commander.

Now to the Starforce fix
Dave Kay is offline   Reply With Quote
Old 02-25-14, 06:33 PM   #4
Herr-Berbunch
Kaiser Bill's batman
 
Herr-Berbunch's Avatar
 
Join Date: May 2010
Location: AN72
Posts: 13,203
Downloads: 76
Uploads: 0
Default

There is no guarantee, implied or otherwise, that this will work, but I just plucked my best guess out the air.

Let us know how you get on.
__________________
Herr-Berbunch is offline   Reply With Quote
Old 02-25-14, 06:42 PM   #5
TG626
Lieutenant
 
Join Date: Jan 2014
Location: USS Seal - Somewhere in the Pacific
Posts: 268
Downloads: 141
Uploads: 3
Default

Sh3 seems like an unlikely target, sure its not a false positive?
__________________
T. E. Thompson, LTCDR
Commanding Officer, U.S.S. Seal (formerly S-40 (SS-145))
TG626 is offline   Reply With Quote
Old 02-26-14, 01:24 PM   #6
Dave Kay
Gunner
 
Join Date: Apr 2005
Location: AZ
Posts: 93
Downloads: 25
Uploads: 0
Default

Quote:
Originally Posted by TG626 View Post
Sh3 seems like an unlikely target, sure its not a false positive?

Sure enough~!

Muchos Gracias~!
Dave Kay is offline   Reply With Quote
Old 02-26-14, 01:34 PM   #7
IchBin1
Nub
 
Join Date: Apr 2013
Posts: 3
Downloads: 41
Uploads: 0
My game SH3 won't open and gives this message:

"The instruction at 0x04e7a60 referenced memory at 0x1201e2d4. The memory could not be written."
..i wonder if this could be a result of Malwarebytes also?
IchBin1 is offline   Reply With Quote
Old 02-26-14, 01:35 PM   #8
BigWalleye
Sea Lord
 
Join Date: Jul 2012
Location: On the Eye-lond, mon!
Posts: 1,987
Downloads: 465
Uploads: 0


Default

Quote:
Originally Posted by Dave Kay View Post
Sure enough~!

Muchos Gracias~!
I'm sorry, Dave, but I don't knoe how to interpret your response. Do you mean that, sure enough, TG626 is right and it WAS a false positive, or that you are sure enough (that is, convinced) that it WAS NOT a false positive?
BigWalleye is offline   Reply With Quote
Old 02-26-14, 02:20 PM   #9
Dave Kay
Gunner
 
Join Date: Apr 2005
Location: AZ
Posts: 93
Downloads: 25
Uploads: 0
Default

Quote:
Originally Posted by BigWalleye View Post
I'm sorry, Dave, but I don't knoe how to interpret your response. Do you mean that, sure enough, TG626 is right and it WAS a false positive, or that you are sure enough (that is, convinced) that it WAS NOT a false positive?
YES--- I meant that it seems Malwarebytes WAS giving false positive and file was not malware. When it quarantines a file it gives you the option to restore the file but when I did that option as soon as I tried to start SH3 again it quarantined the file again and game won't start. After that your only other option is to delete it. So the fix was to slip a clean backup utils.dll into SH3's folder and tell Malwarebytes, in a separate tab-option, to specifically ignore that file.

Now my game starts and plays perfectly and all seems well. Well I say because I haven't been 'attacked' by anything--- yet~!
Dave Kay is offline   Reply With Quote
Old 02-26-14, 02:24 PM   #10
Dave Kay
Gunner
 
Join Date: Apr 2005
Location: AZ
Posts: 93
Downloads: 25
Uploads: 0
Default

Quote:
Originally Posted by IchBin1 View Post
"The instruction at 0x04e7a60 referenced memory at 0x1201e2d4. The memory could not be written."
..i wonder if this could be a result of Malwarebytes also?
Tough question to answer without more info but I would recommend doing some kind of base memory test on the RAM. Is you PC a brand name like HP or Dell? Utilities like that are usually included somewhere on disk or drive.
Dave Kay is offline   Reply With Quote
Old 02-26-14, 04:49 PM   #11
Herr-Berbunch
Kaiser Bill's batman
 
Herr-Berbunch's Avatar
 
Join Date: May 2010
Location: AN72
Posts: 13,203
Downloads: 76
Uploads: 0
Default

@IchBin1 - if it's a one-off event I wouldn't be overly concerned, if it's more regular then read this thread from the Steam fora - https://support.steampowered.com/kb_...1274-uohk-5653

@Dave Kay - glad you're sorted and not now spamming the globe with Nigerian 'bank/prince/government/lottery' (delete as applicable) emails.
__________________
Herr-Berbunch is offline   Reply With Quote
Old 02-28-14, 06:50 PM   #12
Dave Kay
Gunner
 
Join Date: Apr 2005
Location: AZ
Posts: 93
Downloads: 25
Uploads: 0
Default

Quote:
Originally Posted by Herr-Berbunch View Post
@IchBin1 - if it's a one-off event I wouldn't be overly concerned, if it's more regular then read this thread from the Steam fora - https://support.steampowered.com/kb_...1274-uohk-5653

@Dave Kay - glad you're sorted and not now spamming the globe with Nigerian 'bank/prince/government/lottery' (delete as applicable) emails.
Thanks Herr-Berbunch, will now restrict my efforts to only spamming the Kenyan Prince we currently have in the White House for my share of the govt run lottery I've paid into for over 45 years in hopes there will still be some left for me when time comes...
Dave Kay is offline   Reply With Quote
Old 02-28-14, 09:44 PM   #13
BigWalleye
Sea Lord
 
Join Date: Jul 2012
Location: On the Eye-lond, mon!
Posts: 1,987
Downloads: 465
Uploads: 0


Default

Dave, however much I might agree with you, please, please, please let's keep politics off SubSum! This is the only place I know, other than the biffy, where I can escape from being reminded about that subject. An' that makes it a special place for me!
BigWalleye is offline   Reply With Quote
Old 03-01-14, 07:56 AM   #14
RConch
Captain
 
RConch's Avatar
 
Join Date: Jul 2002
Location: No. Virginia
Posts: 619
Downloads: 518
Uploads: 0


Default

Agreed-keep that stuff off these boards.
__________________
"Noch und Noch"
Prowling the Nord Atlantik with GWX 3.0.
RConch is offline   Reply With Quote
Old 03-01-14, 10:02 AM   #15
Sailor Steve
Eternal Patrol
 
Sailor Steve's Avatar
 
Join Date: Nov 2002
Location: High in the mountains of Utah
Posts: 50,369
Downloads: 745
Uploads: 249


Default

And a third - and official - request for no politics in the SH forums. We have a forum called General Topics for that sort of thing.
__________________
“Never do anything you can't take back.”
—Rocky Russo
Sailor Steve is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 08:45 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright © 1995- 2025 Subsim®
"Subsim" is a registered trademark, all rights reserved.