Help - Search - Members - Calendar
Full Version: Big Kahuna Reef 2 Game gets Blocked
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive False Postive Issues
Idaho_Biker
Everytime I attempt to Open this Game, Ad Aware BLOCKS it, keeps saying it is a PCK/Armadillo-Packer_with a TAI of 7
Here's what the Log Shows:
MSG [2216] 2009/09/19 04:30:49: C:\program files\oberon media\big kahuna reef 2\big kahuna reef 2.exe (diagnosis: Malware family: PCK/Armadillo) => Block
I installed this Game 2 Years BEFORE I ever got Ad-Aware AE, never had No Problems with my "other" Security Programs.
As a Back-up I ran a Registry Scan-Found Nothing, Ran a Secondary AV program and it came back Clean too.
I even contacted Support at Oberon Media, and was Informed that ALL their Downloads are Scanned during transmission.
WHY? does AE keep coming up with this as Opposed to ALL the other Programs that Don't??
How? to keep this from repeating itself?
LS Pekka
QUOTE(Idaho_Biker @ Sep 20 2009, 12:15 AM) *
Everytime I attempt to Open this Game, Ad Aware BLOCKS it, keeps saying it is a PCK/Armadillo-Packer_with a TAI of 7
Here's what the Log Shows:
MSG [2216] 2009/09/19 04:30:49: C:\program files\oberon media\big kahuna reef 2\big kahuna reef 2.exe (diagnosis: Malware family: PCK/Armadillo) => Block
I installed this Game 2 Years BEFORE I ever got Ad-Aware AE, never had No Problems with my "other" Security Programs.
As a Back-up I ran a Registry Scan-Found Nothing, Ran a Secondary AV program and it came back Clean too.
I even contacted Support at Oberon Media, and was Informed that ALL their Downloads are Scanned during transmission.
WHY? does AE keep coming up with this as Opposed to ALL the other Programs that Don't??
How? to keep this from repeating itself?


Hi!

The process is most likely blocked by the Process Watch module in Ad-Watch. All processes that are detected as malicious are blocked by default but users have the option to edit the rules for Process Watch. That can be done by clicking on the "Ad-Watch" icon in Ad-Aware and then by clicking on the "Edit Rules" button under "Processes:". The rule for the specific process can then be changed by toggling the "Action" for the listed process.

Would it be possible for you to post the log-file from your latest Ad-Aware scan, where the object is detected, using the latest definitions i.e. 0149.0053? Posting the Ad-Aware logfile and/or the detected file (C:\program files\oberon media\big kahuna reef 2\big kahuna reef 2.exe) would be helpful for further analysis of the object. If you are able to post the file in this thread please zip the file and password protect it with "infected". More info on how to locate the Ad-Aware log-file and on posting false positives can be found at http://www.lavasoftsupport.com/index.php?showtopic=18033

Regards,

LS Pekka

Lavasoft Malware Labs
Idaho_Biker
QUOTE(LS Pekka @ Sep 19 2009, 05:31 PM) *
Hi!

The process is most likely blocked by the Process Watch module in Ad-Watch. All processes that are detected as malicious are blocked by default but users have the option to edit the rules for Process Watch. That can be done by clicking on the "Ad-Watch" icon in Ad-Aware and then by clicking on the "Edit Rules" button under "Processes:". The rule for the specific process can then be changed by toggling the "Action" for the listed process.

Would it be possible for you to post the log-file from your latest Ad-Aware scan, where the object is detected, using the latest definitions i.e. 0149.0053? Posting the Ad-Aware logfile and/or the detected file (C:\program files\oberon media\big kahuna reef 2\big kahuna reef 2.exe) would be helpful for further analysis of the object. If you are able to post the file in this thread please zip the file and password protect it with "infected". More info on how to locate the Ad-Aware log-file and on posting false positives can be found at http://www.lavasoftsupport.com/index.php?showtopic=18033

Regards,

LS Pekka

Lavasoft Malware Labs



Yes, I will do that, when I run the Next Full Scan.
LS Pekka
Thanks smile.gif

LS Pekka

Lavasoft Malware Labs
Idaho_Biker
QUOTE(LS Pekka @ Sep 20 2009, 08:12 PM) *
Thanks smile.gif

LS Pekka

Lavasoft Malware Labs

Here is the Log File (Zipped) for your Review.
I ran another Full Scan, this Same entry came up. I ticked on "Ignore" (Do Nothing) However, I still can't Launch this Game without getting a "Blocked Process" Pop-Up Window... the ONLY way to get this Game to Launch is to Disable the Adware Alert Program, I shouldn't have to do that should I, after ticking off "Ignore"??
Awaiting your Response.
Wanted to point out That I Use to have Lavasoft SE at the time when I got this Game, and NEVER had a Problem from an SE Scan...

Rick
LS Andy
Hi Rick,

Thanks for your report - you have found a bug in Ad-Aware which has been reported to the development team. A work around is to disable the Process Watch, which while not ideal, will allow the process to run.

The bug has been placed in the development queue and will be reviewed. Thanks for bringing this to our attention.

Regards,

Andy
Lavasoft Malware Labs
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.