Forum Home
Press F1
 
Thread ID: 91566 2008-07-11 05:28:00 Games virus kjaada (253) Press F1
Post ID Timestamp Content User
687843 2008-07-11 05:28:00 My partner plays a lot of Big Fish games and this afternoon Avast detected a virus in the game she opened . Since then Avast does the same for any game she opens and can not repair .
Here is the HJT log .

Logfile of Trend Micro HijackThis v2 . 0 . 2

Scan saved at 4:32:17 PM, on 7/11/2008

Platform: Windows XP SP2 (WinNT 5 . 01 . 2600)

MSIE: Internet Explorer v7 . 00 (7 . 00 . 6000 . 16674)

Boot mode: Normal



Running processes:

C:\WINDOWS\System32\smss . exe

C:\WINDOWS\system32\winlogon . exe

C:\WINDOWS\system32\services . exe

C:\WINDOWS\system32\lsass . exe

C:\WINDOWS\system32\svchost . exe

C:\WINDOWS\System32\svchost . exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv . exe

C:\Program Files\Alwil Software\Avast4\ashServ . exe

C:\WINDOWS\Explorer . EXE

C:\WINDOWS\system32\spoolsv . exe

C:\WINDOWS\System32\svchost . exe

C:\WINDOWS\system32\DRIVERS\WtSrv . exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv . exe

C:\Program Files\Alwil Software\Avast4\ashWebSv . exe

C:\WINDOWS\system32\wuauclt . exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp . exe

C:\WINDOWS\system32\hkcmd . exe

C:\WINDOWS\system32\igfxpers . exe

C:\Program Files\Mouse Driver\MouseDrv . exe

C:\Program Files\Common Files\Real\Update_OB\realsched . exe

C:\WINDOWS\system32\WService . EXE

C:\Program Files\Skype\Phone\Skype . exe

C:\WINDOWS\system32\igfxsrvc . exe

C:\WINDOWS\system32\ctfmon . exe

C:\Program Files\Skype\Plugin Manager\SkypePM . exe

C:\Program Files\bfgclient\bfggameservices . exe

C:\Program Files\Trend Micro\HijackThis\HijackThis . exe

C:\Program Files\Trend Micro\HijackThis\HijackThis . exe



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www . dell . com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home . nzcity . co . nz/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www . dell . com/

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper . dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx . dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1 . 6 . 0_05\bin\ssv . dll

O4 - HKLM\ . . \Run: [ avast! ] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp . exe

O4 - HKLM\ . . \Run: [igfxtray] C:\WINDOWS\system32\igfxtray . exe

O4 - HKLM\ . . \Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd . exe

O4 - HKLM\ . . \Run: [igfxpers] C:\WINDOWS\system32\igfxpers . exe

O4 - HKLM\ . . \Run: [CreativeMouse ] C:\Program Files\Mouse Driver\MouseDrv . exe

O4 - HKLM\ . . \Run: [WService] WService . EXE

O4 - HKLM\ . . \Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched . exe" -osboot

O4 - HKCU\ . . \Run: [Skype] "C:\Program Files\Skype\Phone\Skype . exe" /nosplash /minimized

O4 - HKCU\ . . \Run: [ctfmon . exe] C:\WINDOWS\system32\ctfmon . exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1 . 6 . 0_05\bin\ssv . dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1 . 6 . 0_05\bin\ssv . dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag . exe

O9 - Extra 'Tools' menuitem: @xpsp3res . dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag . exe

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1 . DLL

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv . exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ . exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv . exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv . exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService . exe

O23 - Service: WinTab Service (WinTabService) - Tablet Driver - C:\WINDOWS\system32\DRIVERS\WtSrv . exe



--

End of file - 4381 bytes
kjaada (253)
687844 2008-07-11 05:43:00 I would email Avast with the report, so they can see if its a false + Speedy Gonzales (78)
687845 2008-07-11 05:57:00 Thanks Speedy.All my interfering and "adjusting" has done something and all is OK.
My life has been spared and I am something of a hero at present.
kjaada (253)
687846 2008-07-11 10:20:00 I had the same problem, and found the temporary fix at Avast.

Does this sort of thing happen very often, as I have only just changed to Avast, second day in and it stops me playing all my games.
supergran (108)
687847 2008-07-11 10:49:00 Doesn't matter what the AV it will sometimes pick up something as a virus or suspect activity and class it as a bug = maybe false positive.

Take Nod32 - great AV, BUT even the latest version is picking up something in Both Zone Alarm, and Even Comodo firewall as a infection, and promptly kills the download in ZA and stops Comodo installing. (ad Block or something like that)
wainuitech (129)
687848 2008-07-11 18:09:00 I had the same problem, and found the temporary fix at Avast .

Does this sort of thing happen very often, as I have only just changed to Avast, second day in and it stops me playing all my games .
Have had Avast since we started playing BFGames (about 3 years) and this is the first problem .
kjaada (253)
1