Author Topic: MAlware attack  (Read 1174 times)

Offline turt21

  • Nickel Member
  • ***
  • Posts: 623
MAlware attack
« on: February 07, 2019, 07:20:01 PM »
Tonight with only AH3 running Windows Defender picked up something called bearfoos.A!ml. After a clean my shortcuts for the game are gone. I was playing fine earlier . Do I wipe everything and a fresh install?

Offline TequilaChaser

  • AH Training Corps - Retired
  • Plutonium Member
  • *******
  • Posts: 10171
      • The Damned - founded by Ptero in 1988
Re: MAlware attack
« Reply #1 on: February 07, 2019, 09:53:21 PM »
You have a Trojan Virus on your computer

in case your anti-virus on your computer has been compromised, if you are using one at all

try this: https://www.eset.com/us/home/online-scanner/

it is free, and it will uninstall itself when it's done.... just follow the directions and good luck

Hope This Helps

TC
"When one considers just what they should say to a new pilot who is logging in Aces High, the mind becomes confused in the complex maze of info it is necessary for the new player to know. All of it is important; most of it vital; and all of it just too much for one brain to absorb in 1-2 lessons" TC

Online Bizman

  • Plutonium Member
  • *******
  • Posts: 9553
Re: MAlware attack
« Reply #2 on: February 08, 2019, 01:33:37 AM »
With only AH running, you say? And after cleaning your AH shortcuts were gone? Sounds like a false positive to me! Trojans don't attach themselves into .exe files as far as I know.

If the shortcuts are the only items gone, you can create new ones by navigating to the Hitech Creations folder, right clicking aceshigh9.exe or aceshigh11.exe and choosing Send To. Click Desktop (create shortcut). If you can't find the .exe files, Defender has eaten your game.

Find the virus vault and see if the missing items are there. Take note of the original path for the files quarantined and restore them if they look like being valid. https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus. Update Defender and run a new scan to see if they still get wiped away. If not, it was a false positive.
Quote from: BaldEagl, applies to myself, too
I've got an older system by today's standards that still runs the game well by my standards.

Kotisivuni

Offline turt21

  • Nickel Member
  • ***
  • Posts: 623
Re: MAlware attack
« Reply #3 on: February 08, 2019, 06:27:46 AM »
This one is dirty. I went to the Hitech Creations directory  when my desktop shortcut no longer worked. The aceshigh_9 exec file  was gone from there too. I have the game backed up so I went there and when I opened it the game started updating then the Defender opened again to stop it. Aces High was the ONLY program running at the time and I had stepped away from the computer for maybe 30 min.

Offline TequilaChaser

  • AH Training Corps - Retired
  • Plutonium Member
  • *******
  • Posts: 10171
      • The Damned - founded by Ptero in 1988
Re: MAlware attack
« Reply #4 on: February 08, 2019, 06:36:25 AM »
I completely misread the original post, I did not notice the part where he said that his windows defender caught it and he "cleaned" it....

Still though, those Trojan viruses if not completely cleaned out, can be hiding in temp folders and other areas of the Windows filing structure to where one thinks they have "cleaned" their OS system, yet it will keep regenerating itself...

I went last night and looked up your virus, you posted above to see if it was malware or something worse.... First 4 results popped up "Trojan Virus" and all 4 were posted by Microsoft and had multiple links about it

Good luck

TC
"When one considers just what they should say to a new pilot who is logging in Aces High, the mind becomes confused in the complex maze of info it is necessary for the new player to know. All of it is important; most of it vital; and all of it just too much for one brain to absorb in 1-2 lessons" TC

Online Bizman

  • Plutonium Member
  • *******
  • Posts: 9553
Re: MAlware attack
« Reply #5 on: February 08, 2019, 08:09:14 AM »
So it looks like it's a false positive. If you can, restore the AH files and set them on the exceptions list of Defender. Then run the Eset Online Scanner from TC's link. If it finds the same files as infected, you're having a nasty virus. If it says you're clean at least for those files, a false positive has been confirmed.

If you feel like wanting to do a thorough scan there's a bunch of good online or on-demand scanners. If they keep finding something after several different scans, a bootable rescue cd or USB stick is the next step.
Quote from: BaldEagl, applies to myself, too
I've got an older system by today's standards that still runs the game well by my standards.

Kotisivuni

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
Re: MAlware attack
« Reply #6 on: February 08, 2019, 03:24:30 PM »
If a virus/malware attached to the game executable, then it was already on your computer just waiting for the right time to become active.  Just FYI.
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline turt21

  • Nickel Member
  • ***
  • Posts: 623
Re: MAlware attack
« Reply #7 on: February 09, 2019, 06:18:46 AM »
I ran the ESET scan. 3 problems fixed.  I found another aceshigh9.exe but when I try to open It says Im missing a bunch of .dll files. d3dx9_43.dll     fmodstudio.dll among others.
attached dxdiag.

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
Re: MAlware attack
« Reply #8 on: February 09, 2019, 06:28:01 AM »
You are missing the motherboard chipset drivers and the native audio driver.  Should be able to get the chipset drivers from AMD.

The default supplied MIcrosoft audio drivers are not meant to be used with games and will cause some problems.
Roy "Skuzzy" Neese
support@hitechcreations.com