Aces High Bulletin Board

General Forums => Hardware and Software => Topic started by: RotBaron on February 12, 2014, 05:17:50 AM

Title: Virus behavior
Post by: RotBaron on February 12, 2014, 05:17:50 AM
Was about to login using my password to my bank account, and noticed my personal (selected) id image was not the one it's supposed to be. I have Avast free, so I fired it up and found one threat, a script with high level rating. I restarted afterward and ran a boot scan, in which numerous AH files were found to be corrupted and removed. Of course some of these ended up being launch files, so I'm reinstalling, and hoping my settings folder that I moved over doesn't have any corrupt files too.

Now to the topic, I noticed this script was installed on Dec 24, and only now became active or at least came to my attention. I suppose it could be a browser hijack too, but I tend not to download things. In fact the only thing I've downloaded in the past couple months besides AH stuff were some mods for Men of War Assault squad - from ModDB. It does appear that the mods are the source of the infection, not suggesting AH, but maybe it chose to infect AH files based of usage pattern/habits? The file path was in User/appdata/...These mods are several years old, however I suppose if they get stale maybe it's a ripe place to put malware.

The only out of normal behavior was the possible attempt to steal bank information. After the virus and boot scan, my correct personal id image appeared.

Strange that it waited 'til 6 weeks later to activate, or no? Events like this get me real paranoid that there are other instances that haven't been detected yet, even though I'm very careful in what I download and click on. Thoughts?  
Title: Re: Virus behavior
Post by: Skuzzy on February 12, 2014, 06:27:32 AM
Virus/malware/spyware typically hangs around on your computer for months before activating.  Makes it nearly impossible to track where it came from.  It will usually pick a program, you use often, to launch itself.

You do not have to download things to get infected.  Simply visiting an infected WEB site is usually all it takes to get some bad on your computer.  Anti-xxxx software is only as good as its last update.  Between those updates it is quite easy for a computer to get infected with a new virus/malware.
Title: Re: Virus behavior
Post by: RotBaron on February 12, 2014, 08:00:51 AM
Thanks for the reply Skuzzy.

Now that I've uninstalled and re-installed I am not able to launch the game, neither the desktop icon, or from the folder will allow me to. Keep getting the error "windows can not access the specified device, path or file. You may not have the appropriate permissions to access the item." 

I have tried running both from the run as administrator to no avail. I am the only user on this computer and I'm setup with administrator permissions. What should I do?
Title: Re: Virus behavior
Post by: Rich46yo on February 12, 2014, 09:55:54 AM
I had such a problem running Steam once. Let me ask do you have only one windows start profile and do you have it set so windows starts automatically? With no log in screen? If so then make another user profile, give it all the privileges, and start windows under that. Tell me if that solves everything.

Dont ask me why it worked but it worked.
Title: Re: Virus behavior
Post by: Bizman on February 12, 2014, 11:34:32 AM
Check the Avast! virus quarantine. You may find your freshly installed exe file there. Avast has been somewhat hyper-active lately handling totally sound and safe programs as viruses. If that's your problem, simply right click the quarantined file and choose to both revert it and put it on the exclusions list.
Title: Re: Virus behavior
Post by: RotBaron on February 13, 2014, 01:13:24 AM
Thanks for the replies gentlemen.

In reading my post again I noticed I just said "game" I can't launch. I'm referring to Aces High. I can not get AH to launch.

I looked in my virus vault and they are all [Trj] which I imagine are trojans. None of the files in the virus vault are related to AH. Yet I still have the "windows can not access the specified file, path or device. You may not have permissions..."

I haven't tried the method you mentioned Rich. Although it's an alternative that would work, I have never had to do anything that drastic and really would like to avoid doing so in this case. AH worked fine before now and shouldn't be too difficult to get back to norm.

Any more suggestions?

TIA
Title: Re: Virus behavior
Post by: RotBaron on February 13, 2014, 02:21:08 AM
Uninstalled Avast, reinstalled AH, reinstalled Avast. Problem fixed, I hope. I can get back to the game.

I forgot my skins folder though, no biggie but I think I'll make a folder that contains everything personalized for the future.

 :airplane:
Title: Re: Virus behavior
Post by: Bizman on February 13, 2014, 07:28:09 AM
I had such a problem running Steam once. Let me ask do you have only one windows start profile and do you have it set so windows starts automatically? With no log in screen? If so then make another user profile, give it all the privileges, and start windows under that. Tell me if that solves everything.

Dont ask me why it worked but it worked.
Sounds like Steam likes to run at administrative privileges. If you'd rather like to use a regular user account, each program can be given special privileges by right-clicking the .exe and choosing 'properties'. On the 'compatibility' tab there's a checkbox for running as administrator.