PDA

View Full Version : virus with HEM? (Win32.TrojanSpy.Keylogger)



jvpelikaan
12-22-2009, 07:21 PM
hey all,

i was playing poker and running holdemmanger when i got the blue screen of death followed by half an hour of trying to get the pc back on properly (there had been a 'corrupt windows file' message on reboot). did some virus scans and adaware said there was a high security risk removed requiring a reboot, which was this (c+p from the quarantine log):

Quarantined items:
Description: c:\windows.0\system32\hook.dll Family Name: Win32.TrojanSpy.Keylogger Engine: 1 Clean status: Reboot required Item ID: 526155 Family ID: 2372
Description: C:\Documents and Settings\Administrator\Local Settings\Application Data\Xenocode\ApplianceCaches\HoldemManager.exe_v6 5ED1E19\TheApp\STUBEXE\@DOCUMENTS@Poker\HEM\HMImpo rt.exe Family Name: Win32.Backdoor.Poison Engine: 1 Clean status: Success Item ID: 1688369 Family ID: 1566 MD5: a3174786bb5e5ae2d964be40d7a2d15d

the problem has gone now (said 'hook failed to load' on reboot) but i was kind of concerned about this. i've changed most of my passwords and stuff but have you heard of this kind of thing before?

thanks,

jv

fozzy71
12-22-2009, 09:44 PM
It sounds like the old false positive bug.

Close HEM and your anti-virus and delete any \xenocode\appliance cache folders and any other possible false positive files.

1. Enable "Show hidden files and folders" under Control Panel -> Folder Options -> View
2. Go to C:\Users\%USERPROFILE%\AppData\Local\Xenocode\Appl iance Cache and delete every folder you can find in there

If you are on XP, that location is C:\Documents and Settings\%USERPROFILE%\Local\Application Data\xenocode\appliance cache

Empty your recycle bin.

reboot

Please update to the latest beta - http://www.holdemmanager.com/downloads/HmBetaUpdate.exe

jvpelikaan
12-23-2009, 07:40 PM
thank you very much for your quick help.