Aces High Bulletin Board

Help and Support Forums => Technical Support => Topic started by: turt21 on February 07, 2019, 07:20:01 PM

Title: MAlware attack
Post by: turt21 on February 07, 2019, 07:20:01 PM
Tonight with only AH3 running Windows Defender picked up something called bearfoos.A!ml. After a clean my shortcuts for the game are gone. I was playing fine earlier . Do I wipe everything and a fresh install?
Title: Re: MAlware attack
Post by: TequilaChaser on February 07, 2019, 09:53:21 PM
You have a Trojan Virus on your computer

in case your anti-virus on your computer has been compromised, if you are using one at all

try this: https://www.eset.com/us/home/online-scanner/

it is free, and it will uninstall itself when it's done.... just follow the directions and good luck

Hope This Helps

TC
Title: Re: MAlware attack
Post by: Bizman on February 08, 2019, 01:33:37 AM
With only AH running, you say? And after cleaning your AH shortcuts were gone? Sounds like a false positive to me! Trojans don't attach themselves into .exe files as far as I know.

If the shortcuts are the only items gone, you can create new ones by navigating to the Hitech Creations folder, right clicking aceshigh9.exe or aceshigh11.exe and choosing Send To. Click Desktop (create shortcut). If you can't find the .exe files, Defender has eaten your game.

Find the virus vault and see if the missing items are there. Take note of the original path for the files quarantined and restore them if they look like being valid. https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus (https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus). Update Defender and run a new scan to see if they still get wiped away. If not, it was a false positive.
Title: Re: MAlware attack
Post by: turt21 on February 08, 2019, 06:27:46 AM
This one is dirty. I went to the Hitech Creations directory  when my desktop shortcut no longer worked. The aceshigh_9 exec file  was gone from there too. I have the game backed up so I went there and when I opened it the game started updating then the Defender opened again to stop it. Aces High was the ONLY program running at the time and I had stepped away from the computer for maybe 30 min.
Title: Re: MAlware attack
Post by: TequilaChaser on February 08, 2019, 06:36:25 AM
I completely misread the original post, I did not notice the part where he said that his windows defender caught it and he "cleaned" it....

Still though, those Trojan viruses if not completely cleaned out, can be hiding in temp folders and other areas of the Windows filing structure to where one thinks they have "cleaned" their OS system, yet it will keep regenerating itself...

I went last night and looked up your virus, you posted above to see if it was malware or something worse.... First 4 results popped up "Trojan Virus" and all 4 were posted by Microsoft and had multiple links about it

Good luck

TC
Title: Re: MAlware attack
Post by: Bizman on February 08, 2019, 08:09:14 AM
So it looks like it's a false positive. If you can, restore the AH files and set them on the exceptions list of Defender. Then run the Eset Online Scanner from TC's link. If it finds the same files as infected, you're having a nasty virus. If it says you're clean at least for those files, a false positive has been confirmed.

If you feel like wanting to do a thorough scan there's a bunch of good online or on-demand scanners. If they keep finding something after several different scans, a bootable rescue cd or USB stick is the next step.
Title: Re: MAlware attack
Post by: Skuzzy on February 08, 2019, 03:24:30 PM
If a virus/malware attached to the game executable, then it was already on your computer just waiting for the right time to become active.  Just FYI.
Title: Re: MAlware attack
Post by: turt21 on February 09, 2019, 06:18:46 AM
I ran the ESET scan. 3 problems fixed.  I found another aceshigh9.exe but when I try to open It says Im missing a bunch of .dll files. d3dx9_43.dll     fmodstudio.dll among others.
attached dxdiag.
Title: Re: MAlware attack
Post by: Skuzzy on February 09, 2019, 06:28:01 AM
You are missing the motherboard chipset drivers and the native audio driver.  Should be able to get the chipset drivers from AMD.

The default supplied MIcrosoft audio drivers are not meant to be used with games and will cause some problems.