Jump to content


Photo

Big Kahuna Reef 2 Game gets Blocked


  • Please log in to reply
5 replies to this topic

#1 Idaho_Biker

Idaho_Biker

    Newbie

  • Members
  • Pip
  • 3 posts

Posted 19 September 2009 - 11:15 PM

Everytime I attempt to Open this Game, Ad Aware BLOCKS it, keeps saying it is a PCK/Armadillo-Packer_with a TAI of 7
Here's what the Log Shows:
MSG [2216] 2009/09/19 04:30:49: C:\program files\oberon media\big kahuna reef 2\big kahuna reef 2.exe (diagnosis: Malware family: PCK/Armadillo) => Block
I installed this Game 2 Years BEFORE I ever got Ad-Aware AE, never had No Problems with my "other" Security Programs.
As a Back-up I ran a Registry Scan-Found Nothing, Ran a Secondary AV program and it came back Clean too.
I even contacted Support at Oberon Media, and was Informed that ALL their Downloads are Scanned during transmission.
WHY? does AE keep coming up with this as Opposed to ALL the other Programs that Don't??
How? to keep this from repeating itself?

#2 LS Pekka

LS Pekka

    Advanced Member

  • Members
  • PipPipPip
  • 452 posts

Posted 20 September 2009 - 12:31 AM

Everytime I attempt to Open this Game, Ad Aware BLOCKS it, keeps saying it is a PCK/Armadillo-Packer_with a TAI of 7
Here's what the Log Shows:
MSG [2216] 2009/09/19 04:30:49: C:\program files\oberon media\big kahuna reef 2\big kahuna reef 2.exe (diagnosis: Malware family: PCK/Armadillo) => Block
I installed this Game 2 Years BEFORE I ever got Ad-Aware AE, never had No Problems with my "other" Security Programs.
As a Back-up I ran a Registry Scan-Found Nothing, Ran a Secondary AV program and it came back Clean too.
I even contacted Support at Oberon Media, and was Informed that ALL their Downloads are Scanned during transmission.
WHY? does AE keep coming up with this as Opposed to ALL the other Programs that Don't??
How? to keep this from repeating itself?


Hi!

The process is most likely blocked by the Process Watch module in Ad-Watch. All processes that are detected as malicious are blocked by default but users have the option to edit the rules for Process Watch. That can be done by clicking on the "Ad-Watch" icon in Ad-Aware and then by clicking on the "Edit Rules" button under "Processes:". The rule for the specific process can then be changed by toggling the "Action" for the listed process.

Would it be possible for you to post the log-file from your latest Ad-Aware scan, where the object is detected, using the latest definitions i.e. 0149.0053? Posting the Ad-Aware logfile and/or the detected file (C:\program files\oberon media\big kahuna reef 2\big kahuna reef 2.exe) would be helpful for further analysis of the object. If you are able to post the file in this thread please zip the file and password protect it with "infected". More info on how to locate the Ad-Aware log-file and on posting false positives can be found at http://www.lavasofts...showtopic=18033

Regards,

LS Pekka

Lavasoft Malware Labs

#3 Idaho_Biker

Idaho_Biker

    Newbie

  • Members
  • Pip
  • 3 posts

Posted 20 September 2009 - 09:01 PM

Hi!

The process is most likely blocked by the Process Watch module in Ad-Watch. All processes that are detected as malicious are blocked by default but users have the option to edit the rules for Process Watch. That can be done by clicking on the "Ad-Watch" icon in Ad-Aware and then by clicking on the "Edit Rules" button under "Processes:". The rule for the specific process can then be changed by toggling the "Action" for the listed process.

Would it be possible for you to post the log-file from your latest Ad-Aware scan, where the object is detected, using the latest definitions i.e. 0149.0053? Posting the Ad-Aware logfile and/or the detected file (C:\program files\oberon media\big kahuna reef 2\big kahuna reef 2.exe) would be helpful for further analysis of the object. If you are able to post the file in this thread please zip the file and password protect it with "infected". More info on how to locate the Ad-Aware log-file and on posting false positives can be found at http://www.lavasofts...showtopic=18033

Regards,

LS Pekka

Lavasoft Malware Labs



Yes, I will do that, when I run the Next Full Scan.


#4 LS Pekka

LS Pekka

    Advanced Member

  • Members
  • PipPipPip
  • 452 posts

Posted 21 September 2009 - 03:12 AM

Thanks :)

LS Pekka

Lavasoft Malware Labs

#5 Idaho_Biker

Idaho_Biker

    Newbie

  • Members
  • Pip
  • 3 posts

Posted 23 September 2009 - 12:27 AM

Thanks :)

LS Pekka

Lavasoft Malware Labs

Here is the Log File (Zipped) for your Review.
I ran another Full Scan, this Same entry came up. I ticked on "Ignore" (Do Nothing) However, I still can't Launch this Game without getting a "Blocked Process" Pop-Up Window... the ONLY way to get this Game to Launch is to Disable the Adware Alert Program, I shouldn't have to do that should I, after ticking off "Ignore"??
Awaiting your Response.
Wanted to point out That I Use to have Lavasoft SE at the time when I got this Game, and NEVER had a Problem from an SE Scan...

Rick

Attached Files



#6 LS Andy

LS Andy

    Lavasoft Staff/Forum Overlord

  • Root Admin
  • 1425 posts

Posted 28 September 2009 - 04:40 PM

Hi Rick,

Thanks for your report - you have found a bug in Ad-Aware which has been reported to the development team. A work around is to disable the Process Watch, which while not ideal, will allow the process to run.

The bug has been placed in the development queue and will be reviewed. Thanks for bringing this to our attention.

Regards,

Andy
Lavasoft Malware Labs
irc.geekshed.net /join #MalwareLab

Twitter: @LSAndyB




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users