PDA

View Full Version : MS Defender: Trojan:Win32/Tiggre!plock found



bluffsport
11-02-2019, 01:36 AM
Bought and installed HM3 today, then MS Security Essentials found Trojan.

I assume this is a false positive, please confirm that.

Affected elements:
C:\Program Files\Holdem Manager 3\HoldemManager.Server.x86.exe

C:\Program Files\Holdem Manager 3\HoldemManager.Server.exe

C:\Users\Username\AppData\Roaming\Max Value Software\Holdem Manager\3.0\HoldemManager.Server.lnk

C:\Users\UserNameAppData\Roaming\Microsoft\Windows \Start Menu\Programs\Holdem Manager 3\HM3 HUD Only.lnk
(...and more)

fozzy71
11-02-2019, 07:29 AM
Yes, Defender and a few other AV programs are still falsely detecting some of our files because it isn't something they have seen many downloads/reports from since it was in beta until just recently. I just submitted both server exe files from the latest internal version I have installed.

https://www.microsoft.com/en-us/wdsi/filesubmission


https://www.microsoft.com/en-us/wdsi/submission/28382b37-af00-456a-8283-be27bfd4e840

File name Final determination Protection Current detection Definition version
Tree View holdemmanager.server.x86.exe
/ Pending Not malware Cloud
Not malware Client No malware detected
No malware detected Online
1.305.1222.0


https://www.microsoft.com/en-us/wdsi/submission/c2184152-34e4-4336-8d00-39732bfa05b9

File name Final determination Protection Current detection Definition version
Tree View holdemmanager.server.exe
/ Pending Not malware Cloud
Not malware Client No malware detected
No malware detected Online
1.305.1222.0




This is common with new software like ours that hasn't been downloaded**by a lot of customers yet that can report the false positives to antivirus companies. *You need to report it as a false positive to your antivirus vendor so it won't affect other HM3 users with the same antivirus in the future, then remove the file from quarantine and/or reinstall the software and make sure to exclude HM3 from scanning by by your AntiVirus.


a) Open your Windows Defender (or chosen AntiVirus program) > History tab:

1) Select the files if they are from holdemmanager with that checkbox on the left side, then in the bottom right of the window click 'Allow Item'.
2) Start HM2.

Please let us know if that solved the problems.


b) If you continue to have problems:

- Export any custom HUD profiles from the HUD - HUD Editor using the 'Options' button.
- Uninstall any 3rd party security software bundles.
- Reboot your computer
- Please try to uninstall HM3 from your Control Panel - Programs and Features menu.
- Delete all the files/folders from your C:\Users\UserName\AppData\Roaming\Max Value Software\Holdem Manager\3.0 folder*
* If you can't see it, turn off the windows option that is hiding that directory. http://faq.holdemmanager.com/questions/130/How+to+See+Hidden+Files+in+Windows+
- Delete C:\Program Files (x86)\Holdem Manager 3\ if you see it.
- Download and install HM3 again from this link - https://www.holdemmanager.com/download/index.php?product=HM3&channel=stable
- Enable Windows Firewall's recommended settings through your Control Panel, turn off Windows Defender (unless you are using Windows 10, in which case it should be enabled).
- Install Microsoft Security Essentials (unless you are using Windows 10) for antivirus/malware protection and update it - https://support.microsoft.com/en-us/help/14210

Please let us know if that does or does not solve your issues.

bluffsport
11-03-2019, 01:09 AM
Thank you, Fozzy. All I had to do was to allow the 'threats' in Defender/ MS Security Essentials.