My HEM has a trojan
Page 1 of 3 123 LastLast
Results 1 to 10 of 23
  1. #1
    Junior Member
    Join Date
    May 2009
    Posts
    1

    Default My HEM has a trojan

    Every time I try to open my HoldemManager, my antivirus pops up and says that a Trojan was found.

    File Name: C:\Documents and Settings\Keith\Local Settings\Temporary Internet Files\Content.IE5\3KY9GGK7\rvgsoftware_com[1].htm

    Malware name: JS:Redirector-H [Trj]

    Malware type: Trojan Horse

    VPS version: 090506-0, 05/06/2009
    My antivirus client also won't let me "move the malware to virus chest", which is the recommended option, because the file is "in use by another program".

    I have run several virus scans while HEM was not open, which have come up clean.

    I have also uninstalled/reinstalled HEM several times, and tried to update my version to the most recent by using the link in the other forum thread, but it fails to update certain parts of the program.

    If I choose to delete the file or "not respond" and just open tables/auto import, the program does not import any hands, but the table manager does recognize my being seated at the tables.

    If I just ignore the virus alert by clicking no response and sit at tables/auto import, the HUD does not work even though table manager seems to be working.

    This is a thread from the forums of the antivirus client that I use: http://forum.avast.com/index.php?topic=44728.0

    another thread talking about the malware: http://forum.avast.com/index.php?topic=44728.0
    Last edited by <j3ezy>; 05-07-2009 at 01:26 AM.

  2. #2
    Tech Support Manager morny's Avatar
    Join Date
    Jul 2008
    Location
    Ireland
    Posts
    20,888

    Default

    In the vast majority of cases this is a false positive however there are some viruses that can attach themselves to .exe files and when you run it instead of running HM it will run the virus. The safest thing to do is 1) Make a backup of your C:\Program Files\RVG Software\Holdem Manager\Config folder
    2) Uninstall HM via the Control Panel
    3) Go to Program Files and delete the RVG Software directory, or the equivalent for Vista
    4) Reboot your computer
    5) Install the complete setup of HM: http://www.holdemmanager.com/downloa...demmanager.zip
    7) Download the latest patch HM: http://www.holdemmanager.com/downloads/HmUpdate.exe
    8) Test if it for a while and see if it work
    9) Close down Holdem Manager and copy the config folder from step 1 and copy and overwrite it to your C:\Program Files\RVG Software\Holdem Manager\Config folder
    10) Test if it works again for a while

    If the problem persists it may be worth conidering changing to another antivirus but usually when a virus attaches to an .exe file it will infest most of the computer so its most likely a false positive if its an isolated incident
    --------------------------------------------------------------------------------------------------------------------
    We welcome any feedback on any solutions we provide, this helps us to provide better quality solutions in the future.

  3. #3
    Junior Member
    Join Date
    May 2009
    Posts
    9

    Default

    Hi,

    I just got the same problem as OP. I tried the same exact procedure as Morny described, but to no avail, I still get the trojan warning as soon as I start HEM (step 8 in Morny's list). I use Avast as my antivirus and don't really intend to change it since it's considered a real good one. Also, I have kinda huge monies on my various poker accounts, and with all the hacking stories lately, I'm scared to even open a pokerroom lobby right now.

    I'd really like to know how OP got to solve his problem. Could it be possible for an admin to send him a mail for him to come check this thread back? Since he's got only 1 message, I suppose he's not cheking around here regularly.

    Thanks in advance.

  4. #4
    Member LostCause's Avatar
    Join Date
    Mar 2009
    Location
    NY
    Posts
    60

    Default

    I am having the same issue.

  5. #5
    Member
    Join Date
    Dec 2008
    Posts
    54

    Default

    Same here,

    I got these 2 messages from Avast:



    Followed the steps above, but I still got these messages.

  6. #6
    Member
    Join Date
    Jan 2009
    Posts
    51

    Default

    I have the same issue.
    Antivir: Avast
    Version of HEM: 1.08.03

  7. #7
    Junior Member
    Join Date
    May 2009
    Posts
    9

    Default

    Feels a bit better to know that it's not my (or all you guys') particular computer that is targeted, and that instead it seems something related to RVG's website, whose source code seems to have been infested by 'pirate' redirections to other websites containing malicious content.

  8. #8
    Member LostCause's Avatar
    Join Date
    Mar 2009
    Location
    NY
    Posts
    60

    Default

    Here are the results of a scan I ran on the rvgsoftware.com

    http://www.unmaskparasites.com/secur...ntversion.html

  9. #9
    Junior Member
    Join Date
    Jan 2009
    Posts
    10

    Default

    Same with HM 1.08.04 and Avast

  10. #10
    Junior Member
    Join Date
    May 2009
    Posts
    3

    Default

    Same Problem with GData:

    Trojan
    Adresse: www.rvgsoftware.com
    Virus: JS:Redirector-H7 [Trj] (Engine B)

    It seems to be a false positive, but I would like to have that be assured/explained.

Similar Threads

  1. Trojan
    By NoTurns in forum Manager General
    Replies: 4
    Last Post: 01-12-2009, 04:53 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •