PDA

View Full Version : HEM Tagged As Backdoor.Trojan by Norton Internet Security



DawnToDusk
10-23-2009, 07:05 PM
So its been about two weeks since I played cards and I went to play today and I loaded up HEM.

It loads and the database get initialized and then takes me to the Import page/tab and then closes. The Norton Internet Security Auto-Protect feature then pops up and tells me it has "blocked security risk Backdoor.Trojan" and my computer is secure.

I then looked into the problem further and 4 files are affected. Their paths are:
c:\users\chris\appdata\local\xenocode\appliancecac hes\holdemmangager.exe_v006bc2f\native\stubexe\@ap pdir@\dbcontrolpanel.exe
c:\users\chris\appdata\local\xenocode\appliancecac hes\holdemmangager.exe_v006bc2f\native\stubexe\@ap pdir@\hmhud.exe
c:\users\chris\appdata\local\xenocode\appliancecac hes\holdemmangager.exe_v512d2084\native\stubexe\@a ppdir@\hmhud.exe
c:\users\chris\appdata\local\xenocode\appliancecac hes\holdemmangager.exe_v7bc20518\native\stubexe\@a ppdir@\dbcontrolpanel.exe

I am wondering if anyone else has gotten these problems? I scaned more areas of my computer and have nothing infected. I am running Vista with Norton Internet Security with the latest definition updates.

I dont know if these files are infact infected. Any help would be much appreciated. :D

fozzy71
10-23-2009, 08:24 PM
Close HEM and your anti-virus and delete any \xenocode\appliance cache folders and any other possible false positive files.

1. Enable "Show hidden files and folders" under Control Panel -> Folder Options -> View
2. Go to C:\Users\YourUserName\AppData\Local\Xenocode\Appli ance Cache and delete every folder you can find in there

Empty your recycle bin.

reboot

Please update to the latest beta - http://www.holdemmanager.com/downloads/HmBetaUpdate.exe

matpo
10-28-2009, 02:10 PM
I have the same problem with hm+nis. I did all you wrote above but its still the same problem. Als update to latest version is not able. Show everytime V23. What should I do?

netsrak
10-28-2009, 02:37 PM
Install the update to your original installation folder (which i guess is not the default Path in your case).

ez2cy
10-28-2009, 07:39 PM
Trying to do this, but can't even find the "users" part after looking in C:

fozzy71
10-28-2009, 07:53 PM
Trying to do this, but can't even find the "users" part after looking in C:

Then windows is probably installed to a different hard drive or partition on your machine. Try a general search. What operating system?

Here are my revised instructions to fix the false positive.

Close HEM and your anti-virus and delete any \xenocode\appliance cache folders and any other possible false positive files.

1. Enable "Show hidden files and folders" under Control Panel -> Folder Options -> View
2. Go to C:\Users\%USERPROFILE%\AppData\Local\Xenocode\Appl iance Cache and delete every folder you can find in there

If you are on XP, that location is C:\Documents and Settings\%USERPROFILE%\Local\Application Data\xenocode\appliance cache

Empty your recycle bin.

reboot

Please update to the latest beta - http://www.holdemmanager.com/downloads/HmBetaUpdate.exe

ez2cy
10-28-2009, 08:02 PM
Thanks but I finally found it. Nothing like the path you had up but I got it. Thanks.

fozzy71
10-29-2009, 12:18 AM
Feel free to tell us where you found it, so it may be of help to other customers.