PDA

View Full Version : backdoor trojan warning when using tablescanner



zwacke
10-06-2009, 09:18 PM
Hey!

When using the table scanner I get a warning by my anitvirus software, which says that a possible dangerous backdoor trojan of the type "BDS/poison.ardm" is found in

c:\User\XXX\AppData\Local\Xenocode\ApplianceCaches \HoldemManager.exe_v236B29B5\Native\STUBEXE\@SYSTE M@\conime.exe

Im naturally paranoic and deleted the file, which only results in it apperaing again when starting HM.

Does anybody have any idea about that?

ScannerSupport
10-06-2009, 10:24 PM
HoldemManager is protected by Xenocode.

This must be a false positive.
That's not unusual, and happens from time to time.
Unfortunately there's nothing we can do about.
That's a problem of your antivirus software.

Gmucci
01-20-2013, 01:29 PM
HoldemManager is protected by Xenocode.

This must be a false positive.
That's not unusual, and happens from time to time.
Unfortunately there's nothing we can do about.
That's a problem of your antivirus software.


Kaspersky automatically removed the TableScanner Dll -- it's not anywhere on my system as I searched the entire disk, including hidden files. When I got the severe threat warning from Kaspersky, I expected it to quarantine the file until I checked it out, but the file is gone. Can I download the TableScannerDllLoader.exe from your site?

Gmucci
01-20-2013, 04:47 PM
Kaspersky automatically removed the TableScanner Dll -- it's not anywhere on my system as I searched the entire disk, including hidden files. When I got the severe threat warning from Kaspersky, I expected it to quarantine the file until I checked it out, but the file is gone. Can I download the TableScannerDllLoader.exe from your site?

This is an update to my earlier post. I found the solution to my problem thanks to a similar post in the forum. In fact I was able to locate the TableScannerDllLoader.exe in the Kaspersky Quarantined Files tab and successfully restored it. I added it as a trusted application and all is working fine now. I now know that quarantined files are not subject to a full system search. :o