16.10.08

Panda antivirus exception for pthreadVC2.dll

Today a client of mine informed me of an issue opening videos from his email, turns out he is recieving .3gp files ( video format used by mobile phones ) and every time he opens one in quicktime on windows xp quicktime gives an error message and he couldn't get it to close.
The error speaks of a missing file "pthreadVC2.dll ," I looked up the file and found very mixed conclusions, it seemed to be part of serveral applications that had to do with video playback, and also used by Apple's Safari browser newly made available for windows.

To make matters worse he had a new cheapo video camcorder (if you can even call it that) known as a Flip . The camcorder stores 30 minutes of video on flash memory and the software to download and edit the video is stored on, and run from the device. I can't say too much bad about this all-in-one device, its not pro-grade or even consumer grade, its low quality, cheap and made so anyone can use it. For people with very minimal computer knowledge this little gizmo is pretty fool-proof.
But Windows environments are all fool, and no proof, as you may come to understand the underlying message of these rants. Apparently the second major issue the client was having was using the flip camera at all, every time he plugged it in Panda antivirus warned him of imminent doom, and proceeded to try to delete the same pthreadVC2.dll as quicktime was missing from the flip video's flash storage. the Flip video's application is write protected so Panda threw a fit and crashed Explorer and also tried to halt the Flip video's applications from loading.

I saw a pattern.

Panda called pthreadVC2.dll, a "Rouge Anti-Malware " application, Rouge Antimalware is bad news, and lately I've delt with this crap every week.

---------The Learning Corner---------
  • Malware is a all-encompassing term for any baddies that run on a windows system. Viruses, spyware, adware, toolbars, trojans and worms are all Mal-ware.
  • Anti-Malware is what gets rid of the junk, .antivirus software such as Panda, Norton, McAfee, and others are all Anti-malware.
  • But then what is Rouge AntiMalware? Its a program that pretends to be antivirus or anti-spyware but its really bad news. The most common Rouge AntiMalware our there is the dreaded "XP Antivirus 2008" this thing is nuts .... more on that later....

I know that Panda is misdiagnosing this issue, this dll file is used by safari, quicktime, and theis flip video camer, its not RougeAntimalware at all it just has the same dll filename as something far worse.
Nice thing about Panda is that exemptions are set-up extremely well and it was fairly easy to disable it from going insane every time this innocent dll tried to do its job.

Next step was to repair Quicktime, easier said that done. the Quicktime uninstaller has a repair feature, ran it and had the same issue. Next I tried uninstalling Quicktime completely using Revo Uninstaller, a great tool i always have on my flash drive.

-----Tech Tip----

  • Revo Uninstaller identifies registry entries related to or created by the app your ditching, so you dont have to do the whole f3 - delete - enter dance, a few people might know what I mean... haha.
But anyway completely removing Quicktime and getting the latest installer from Apple's site almost did the trick, I also poped the pthreadVC2.dll in the same directory as quicktime.exe and things worked like a charm. Strange issue but maybe this can help someone else.

No comments: