IPB

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> Problems with PopCap games
MJMoore
post 10.04.2005 15:48
Post #1


Member
**

Group: Members
Posts: 23
Joined: 10.04.2005




I have been playing some online games recently, with no problem. Many of the good ones are made by PopCap (Bejeweled, Insaniquarium etc). To play these online I had to download an ActiveX, which was fine.

On Friday, KAV informed me that C:\Windows\DownloadedProgramsFiles\popcaploader.dll was infected with not-a-virus:Porn-Downloader.Win32.PopCap.b, and it was deleted.

When I went back to play the games, I was prompted to install the AxtiveX again, but when I tried, KAV said access was blocked. Even though i chose 'Skip', it still stops me installing.

I find it very hard to believe that PopCap would have any sort of virus or porn downloader in, as they make many of the popular games. I also tried google, and can fine nothing about them containing any sort of 'nasty'.

My google search did however mention some sort of trojan with popcapdownloader in it.. is it possible that KAV is getting confused with this?

As I have paid for a years subscription to KAV, and I find it an otherwise good product, it appears I am now not able to access these games. Is there a solution at all?

Thank you,
Michelle


--------------------
Go to the top of the page
 
+Quote Post
Igor Kurzin
post 11.04.2005 14:42
Post #2


Security Expert
******

Group: Admin
Posts: 785
Joined: 4.04.2005
From: KL HQ




Hi Michelle,

To start troubleshooting the problem we need to gather some more information.
Do you have Kaspersky Anti-Virus Personal or Kaspersky Anti-Virus Personal Pro?

I will try to find out in our VirusLab, whether this could be a false alarm.

Kind regards,
Igor Kurzin

P.S. VirLab asks for the file. Can you send it?
Go to the top of the page
 
+Quote Post
LostAccount
post 28.05.2005 12:01
Post #3


Newbie
*

Group: Members
Posts: 7
Joined: 28.05.2005




Hello... I have the same problem too... I am using KAV 5 MP2 (upgrading to MP3 very soon) and use extended databases...

Should I submit the file to Kaspersky by quarantining it or should I send it to someone here directly?


--------------------
Go to the top of the page
 
+Quote Post
LostAccount
post 28.05.2005 12:07
Post #4


Newbie
*

Group: Members
Posts: 7
Joined: 28.05.2005




I couldn't get it from my test computer since the popcaploader.dll was in a temp directory and was gone as soon as I tried to copy it.

But here's a direct link... and I quarantined one copy and sent it to Kaspersky Labs.

hxxp://www.popcap.com/games/popcaploader_v6.cab

Deliberately unlinked...


--------------------
Go to the top of the page
 
+Quote Post
Don Pelotas
post 28.05.2005 12:11
Post #5


Global Moderator
***************

Group: Global moderators

Posts: 25601
Joined: 7.04.2005




QUOTE(LostAccount @ May 28 2005, 11:01 AM)
Hello... I have the same problem too... I am using KAV 5 MP2 (upgrading to MP3 very soon) and use extended databases...

Should I submit the file to Kaspersky by quarantining it or should I send it to someone here directly?
*

Hi LostAccount & elcome

Yes, submit it to newvirus@kaspersky.com, or through the link in the Supportsection of the main Kav-GUI.

In MP3 you will be asked if you wish to exclude upon detection.

You can update Kav with the update-exe (the one without antivirus databases):http://www.kaspersky.com/productupdates?chapter=146244099, you should probably exit Kav from the tray while doing it and reboot. smile.gif


--------------------
Go to the top of the page
 
+Quote Post
LostAccount
post 28.05.2005 12:16
Post #6


Newbie
*

Group: Members
Posts: 7
Joined: 28.05.2005




Quarantined and sent... smile.gif


--------------------
Go to the top of the page
 
+Quote Post
LostAccount
post 28.05.2005 12:36
Post #7


Newbie
*

Group: Members
Posts: 7
Joined: 28.05.2005




The reply:


QUOTE
Greetings.
The attached file is already detected by our extended bases as a potentially
risk program.
If you know purpose of this program then there's no need to bother, just add it
to exclusion list,
else there is unknown malicious software on your computer possibly. You can do
this:

Please unpack and run enclosed utility (TrojanFindInfo), press "Save" button to
create the
report and then send that report support at kaspersky dot com. This utility is also
available at
ftp://ftp.kaspersky.com/utils/trojans/TrojanFindInfo.rar. To unpack this utility
you need RAR
archiver which is availabe at http://www.rarsoft.com/download.htm

Please quote all when answering. Do not forget to include you registration data.
-----------------
Regards, Alexey Malanov
Virus Analyst, Kaspersky Lab.

Ph.: +7(095) 797-8700
E-mail: newvirus at kaspersky dot com
http://www.kaspersky.com  http://www.viruslist.com


Have a good day! smile.gif

Edited to munge email addresses that are harvested by spam bots - LostAccount

This post has been edited by LostAccount: 29.05.2005 18:22


--------------------
Go to the top of the page
 
+Quote Post
LostAccount
post 28.05.2005 13:58
Post #8


Newbie
*

Group: Members
Posts: 7
Joined: 28.05.2005




I have a feeling it's a false positive smile.gif so I'll leave it alone...

My computer most likely does not have (active) spyware... I do not notice any sluggishness (though I know how some spyware hides itself)... and I don't see how spyware can load itself since it is not in most of the Windows loading keys... (using Autoruns)...

Your product (KAV) is great!


--------------------
Go to the top of the page
 
+Quote Post
Wordmonger
post 28.05.2005 18:28
Post #9


Advanced Member
*****

Group: KL Russia
Posts: 587
Joined: 7.04.2005




QUOTE(LostAccount @ May 28 2005, 02:58 PM)
I have a feeling it's a false positive smile.gif so I'll leave it alone...

My computer most likely does not have (active) spyware... I do not notice any sluggishness (though I know how some spyware hides itself)... and I don't see how spyware can load itself since it is not in most of the Windows loading keys... (using Autoruns)...

Your product (KAV) is great!
*

And to make it even more great, could you please send the falsely detected file to newvirus@kaspersky.com once again with a short explanation of why you think the detection is false.
Go to the top of the page
 
+Quote Post
LostAccount
post 29.05.2005 10:05
Post #10


Newbie
*

Group: Members
Posts: 7
Joined: 28.05.2005




I can't... but you might want to see this link:

hxxp://www.popcap.com/games/popcaploader_v6.cab

for more information...

I don't even understand why it was detected as riskware not-a-virus:Porn-Downloader.Win32.PopCap.b... After all, it's just an installed ActiveX control... only Ewido and kaspersky detect it as something wrong... Can you explain why it is malicious?


--------------------
Go to the top of the page
 
+Quote Post
Wordmonger
post 2.06.2005 12:12
Post #11


Advanced Member
*****

Group: KL Russia
Posts: 587
Joined: 7.04.2005




QUOTE(LostAccount @ May 29 2005, 11:05 AM)
I can't... but you might want to see this link:

hxxp://www.popcap.com/games/popcaploader_v6.cab

for more information...

I don't even understand why it was detected as riskware not-a-virus:Porn-Downloader.Win32.PopCap.b... After all, it's just an installed ActiveX control... only Ewido and kaspersky detect it as something wrong... Can you explain why it is malicious?
*

If it were malicious by nature, it wouldn't have been detected as only a riskware.

At the moment it is detected as 'not-a-virus:Downloader.Win32.PopCap'. That normally means that a virus analyst considered its ability to (silently?) download files potentially risky.
Go to the top of the page
 
+Quote Post
eyoresnorz
post 21.09.2005 01:49
Post #12


Newbie
*

Group: Members
Posts: 1
Joined: 21.09.2005




I read over these posts, but I don't really see an answer as to how to fix this, or allow the ActiveX install. I, too, have been playing popcap games for a long time, and have to lose this option. I am only on a trial version, and other than this, I am almost convinced to purchase. Any info is appreciated. Thanks bunches!
Go to the top of the page
 
+Quote Post
Don Pelotas
post 21.09.2005 02:08
Post #13


Global Moderator
***************

Group: Global moderators

Posts: 25601
Joined: 7.04.2005




QUOTE(eyoresnorz @ Sep 21 2005, 12:49 AM)
I read over these posts, but I don't really see an answer as to how to fix this, or allow the ActiveX install.  I, too, have been playing popcap games for a long time, and have to lose this option.  I am only on a trial version, and other than this, I am almost convinced to purchase.  Any info is appreciated.  Thanks bunches!
*

Hi eyoresnorz & welcome

The solution is simple, either add it to the exclusionslist by using the link found in the warning:


or not use the extendedbases, but i wouldn't, i would just add it to the exclusions. Basicly the catagory with an "Not-a-virus" is informational, it's up to you if you want to continue using it. smile.gif


--------------------
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 22.11.2009 01:40