![]() ![]() |
10.04.2005 15:48
Post
#1
|
|
![]() Member ![]() ![]() Group: Members Posts: 23 Joined: 10.04.2005 |
I have been playing some online games recently, with no problem. Many of the good ones are made by PopCap (Bejeweled, Insaniquarium etc). To play these online I had to download an ActiveX, which was fine.
On Friday, KAV informed me that C:\Windows\DownloadedProgramsFiles\popcaploader.dll was infected with not-a-virus:Porn-Downloader.Win32.PopCap.b, and it was deleted. When I went back to play the games, I was prompted to install the AxtiveX again, but when I tried, KAV said access was blocked. Even though i chose 'Skip', it still stops me installing. I find it very hard to believe that PopCap would have any sort of virus or porn downloader in, as they make many of the popular games. I also tried google, and can fine nothing about them containing any sort of 'nasty'. My google search did however mention some sort of trojan with popcapdownloader in it.. is it possible that KAV is getting confused with this? As I have paid for a years subscription to KAV, and I find it an otherwise good product, it appears I am now not able to access these games. Is there a solution at all? Thank you, Michelle -------------------- |
|
|
|
11.04.2005 14:42
Post
#2
|
|
![]() Security Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 785 Joined: 4.04.2005 From: KL HQ |
Hi Michelle,
To start troubleshooting the problem we need to gather some more information. Do you have Kaspersky Anti-Virus Personal or Kaspersky Anti-Virus Personal Pro? I will try to find out in our VirusLab, whether this could be a false alarm. Kind regards, Igor Kurzin P.S. VirLab asks for the file. Can you send it? |
|
|
|
28.05.2005 12:01
Post
#3
|
|
![]() Newbie ![]() Group: Members Posts: 7 Joined: 28.05.2005 |
Hello... I have the same problem too... I am using KAV 5 MP2 (upgrading to MP3 very soon) and use extended databases...
Should I submit the file to Kaspersky by quarantining it or should I send it to someone here directly? -------------------- Member of SWI...
Useful Software: Kaspersky, Housecall Trendmicro, a2 free edition, Kerio Personal Firewall, Ad-aware SE, Spybot S&D, HJT, CWShredder, MVPS HOSTS file by WinHelp2002, IE-SPYAD by eburger68, Spywareguard and Spywareblaster, Winpatrol, Mozilla & Firefox |
|
|
|
28.05.2005 12:07
Post
#4
|
|
![]() Newbie ![]() Group: Members Posts: 7 Joined: 28.05.2005 |
I couldn't get it from my test computer since the popcaploader.dll was in a temp directory and was gone as soon as I tried to copy it.
But here's a direct link... and I quarantined one copy and sent it to Kaspersky Labs. hxxp://www.popcap.com/games/popcaploader_v6.cab Deliberately unlinked... -------------------- Member of SWI...
Useful Software: Kaspersky, Housecall Trendmicro, a2 free edition, Kerio Personal Firewall, Ad-aware SE, Spybot S&D, HJT, CWShredder, MVPS HOSTS file by WinHelp2002, IE-SPYAD by eburger68, Spywareguard and Spywareblaster, Winpatrol, Mozilla & Firefox |
|
|
|
28.05.2005 12:11
Post
#5
|
|
![]() Global Moderator ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Global moderators Posts: 25602 Joined: 7.04.2005 |
QUOTE(LostAccount @ May 28 2005, 11:01 AM) Hello... I have the same problem too... I am using KAV 5 MP2 (upgrading to MP3 very soon) and use extended databases... Should I submit the file to Kaspersky by quarantining it or should I send it to someone here directly? Hi LostAccount & elcome Yes, submit it to newvirus@kaspersky.com, or through the link in the Supportsection of the main Kav-GUI. In MP3 you will be asked if you wish to exclude upon detection. You can update Kav with the update-exe (the one without antivirus databases):http://www.kaspersky.com/productupdates?chapter=146244099, you should probably exit Kav from the tray while doing it and reboot. -------------------- |
|
|
|
28.05.2005 12:16
Post
#6
|
|
![]() Newbie ![]() Group: Members Posts: 7 Joined: 28.05.2005 |
Quarantined and sent...
-------------------- Member of SWI...
Useful Software: Kaspersky, Housecall Trendmicro, a2 free edition, Kerio Personal Firewall, Ad-aware SE, Spybot S&D, HJT, CWShredder, MVPS HOSTS file by WinHelp2002, IE-SPYAD by eburger68, Spywareguard and Spywareblaster, Winpatrol, Mozilla & Firefox |
|
|
|
28.05.2005 12:36
Post
#7
|
|
![]() Newbie ![]() Group: Members Posts: 7 Joined: 28.05.2005 |
The reply:
QUOTE Greetings. The attached file is already detected by our extended bases as a potentially risk program. If you know purpose of this program then there's no need to bother, just add it to exclusion list, else there is unknown malicious software on your computer possibly. You can do this: Please unpack and run enclosed utility (TrojanFindInfo), press "Save" button to create the report and then send that report support at kaspersky dot com. This utility is also available at ftp://ftp.kaspersky.com/utils/trojans/TrojanFindInfo.rar. To unpack this utility you need RAR archiver which is availabe at http://www.rarsoft.com/download.htm Please quote all when answering. Do not forget to include you registration data. ----------------- Regards, Alexey Malanov Virus Analyst, Kaspersky Lab. Ph.: +7(095) 797-8700 E-mail: newvirus at kaspersky dot com http://www.kaspersky.com http://www.viruslist.com Have a good day! Edited to munge email addresses that are harvested by spam bots - LostAccount This post has been edited by LostAccount: 29.05.2005 18:22 -------------------- Member of SWI...
Useful Software: Kaspersky, Housecall Trendmicro, a2 free edition, Kerio Personal Firewall, Ad-aware SE, Spybot S&D, HJT, CWShredder, MVPS HOSTS file by WinHelp2002, IE-SPYAD by eburger68, Spywareguard and Spywareblaster, Winpatrol, Mozilla & Firefox |
|
|
|
28.05.2005 13:58
Post
#8
|
|
![]() Newbie ![]() Group: Members Posts: 7 Joined: 28.05.2005 |
I have a feeling it's a false positive
My computer most likely does not have (active) spyware... I do not notice any sluggishness (though I know how some spyware hides itself)... and I don't see how spyware can load itself since it is not in most of the Windows loading keys... (using Autoruns)... Your product (KAV) is great! -------------------- Member of SWI...
Useful Software: Kaspersky, Housecall Trendmicro, a2 free edition, Kerio Personal Firewall, Ad-aware SE, Spybot S&D, HJT, CWShredder, MVPS HOSTS file by WinHelp2002, IE-SPYAD by eburger68, Spywareguard and Spywareblaster, Winpatrol, Mozilla & Firefox |
|
|
|
28.05.2005 18:28
Post
#9
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() Group: KL Russia Posts: 587 Joined: 7.04.2005 |
QUOTE(LostAccount @ May 28 2005, 02:58 PM) I have a feeling it's a false positive My computer most likely does not have (active) spyware... I do not notice any sluggishness (though I know how some spyware hides itself)... and I don't see how spyware can load itself since it is not in most of the Windows loading keys... (using Autoruns)... Your product (KAV) is great! And to make it even more great, could you please send the falsely detected file to newvirus@kaspersky.com once again with a short explanation of why you think the detection is false. |
|
|
|
29.05.2005 10:05
Post
#10
|
|
![]() Newbie ![]() Group: Members Posts: 7 Joined: 28.05.2005 |
I can't... but you might want to see this link:
hxxp://www.popcap.com/games/popcaploader_v6.cab for more information... I don't even understand why it was detected as riskware not-a-virus:Porn-Downloader.Win32.PopCap.b... After all, it's just an installed ActiveX control... only Ewido and kaspersky detect it as something wrong... Can you explain why it is malicious? -------------------- Member of SWI...
Useful Software: Kaspersky, Housecall Trendmicro, a2 free edition, Kerio Personal Firewall, Ad-aware SE, Spybot S&D, HJT, CWShredder, MVPS HOSTS file by WinHelp2002, IE-SPYAD by eburger68, Spywareguard and Spywareblaster, Winpatrol, Mozilla & Firefox |
|
|
|
2.06.2005 12:12
Post
#11
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() Group: KL Russia Posts: 587 Joined: 7.04.2005 |
QUOTE(LostAccount @ May 29 2005, 11:05 AM) I can't... but you might want to see this link: hxxp://www.popcap.com/games/popcaploader_v6.cab for more information... I don't even understand why it was detected as riskware not-a-virus:Porn-Downloader.Win32.PopCap.b... After all, it's just an installed ActiveX control... only Ewido and kaspersky detect it as something wrong... Can you explain why it is malicious? If it were malicious by nature, it wouldn't have been detected as only a riskware. At the moment it is detected as 'not-a-virus:Downloader.Win32.PopCap'. That normally means that a virus analyst considered its ability to (silently?) download files potentially risky. |
|
|
|
21.09.2005 01:49
Post
#12
|
|
|
Newbie ![]() Group: Members Posts: 1 Joined: 21.09.2005 |
I read over these posts, but I don't really see an answer as to how to fix this, or allow the ActiveX install. I, too, have been playing popcap games for a long time, and have to lose this option. I am only on a trial version, and other than this, I am almost convinced to purchase. Any info is appreciated. Thanks bunches!
|
|
|
|
21.09.2005 02:08
Post
#13
|
|
![]() Global Moderator ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Global moderators Posts: 25602 Joined: 7.04.2005 |
QUOTE(eyoresnorz @ Sep 21 2005, 12:49 AM) I read over these posts, but I don't really see an answer as to how to fix this, or allow the ActiveX install. I, too, have been playing popcap games for a long time, and have to lose this option. I am only on a trial version, and other than this, I am almost convinced to purchase. Any info is appreciated. Thanks bunches! Hi eyoresnorz & welcome The solution is simple, either add it to the exclusionslist by using the link found in the warning: ![]() or not use the extendedbases, but i wouldn't, i would just add it to the exclusions. Basicly the catagory with an "Not-a-virus" is informational, it's up to you if you want to continue using it. -------------------- |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22.11.2009 10:02 |