Trojan blocking HM2
Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1. #1
    Junior Member
    Join Date
    Sep 2010
    Posts
    22

    Default Trojan blocking HM2

    Hi,

    I have sent you an email but I further investigated my issue and am gonna ask here again.

    I tried starting my HM2 and got the following error:
    "The item Holdemmanager.x86.exe has been changed or moved".

    When I try to run HM2 from my HM2 folder I receive the following:
    "This App cannot run on your PC"
    "To find a version for your PC please check with the software publisher"

    It seems I got the following trojan/malware or whatever it is:
    Trojan:Win32/Zpevdo.A

    I then checked my Windows Defender Threat history and found out the following:

    unknown.png

    Could you please tell me whether I can fix this without reinstalling my HM2?
    I have the option to "Allow" the threat but I'm not sure whether it will help, even if it's a false threat.

    Thank you

  2. #2
    You're out! udbrky's Avatar
    Join Date
    Jul 2008
    Posts
    20,898

    Default

    If you download from us, it is always clean. This is a false positive.

    Report the false positive.

    Add all the files to the exceptions, as well as the update file, and run it as admin. Tell them the files are ok and move them back.

    Please see this FAQ to alleviate any security bottlenecks - http://hm2faq.holdemmanager.com/ques...olders+HM2+use

    http://hm2faq.holdemmanager.com/ques...+Problems#7881
    Regards udbrky (Chris)

  3. #3
    Junior Member
    Join Date
    Sep 2010
    Posts
    22

    Default

    I updated my HM2 to the latest version and it works fine again.

    Thank you

  4. #4
    You're out! udbrky's Avatar
    Join Date
    Jul 2008
    Posts
    20,898

    Default

    You are very welcome. Thank you for letting us know it solved your problems. It helps us when crafting future replies to other customers with similar problems.

    Good luck at the tables. If you have any further questions or problems do not hesitate to ask us.
    Regards udbrky (Chris)

  5. #5
    Junior Member
    Join Date
    Mar 2012
    Posts
    6

    Exclamation HoldemManager.x86.exe trojan

    Quote Originally Posted by udbrky View Post
    If you download from us, it is always clean.
    No, it's not. Today my windows defender:
    trojan-defender.png

    Virustotal: https://www.virustotal.com/gui/file/...53c5/detection
    trojan-virustotal.png

    HoldemManager.x86.exe is a latest version 2.0.0.8673:
    trojan-version.png

    downloaded by HEM's itself (autoupdater). The same version can be downloaded from here:
    https://www.holdemmanager.com/store/...ds-manuals.php

    Holdem Manager 2 Full Setup = https://edgecdn.holdemmanager.com/Do...Setup_8673.exe
    Holdem Manager 2 Update = https://edgecdn.holdemmanager.com/Do...pdate_8673.exe

    all HoldemManager.x86.exe files are the same as my file (checked by hash):
    trojan-hash.png

    Please fix it as soon as possible. Thank you.

  6. #6
    You're out! udbrky's Avatar
    Join Date
    Jul 2008
    Posts
    20,898

    Default

    Please update to this version
    http://www.holdemmanager.com/Downloa...pdate_8695.exe

    I've never seen them show us as a virus.

    virustotal.PNG
    Regards udbrky (Chris)

  7. #7
    Junior Member
    Join Date
    Mar 2012
    Posts
    6

    Default

    Thanks for reply udbrky.

    This new version is not clean. You can try yourself. Install 8695 version and try to check the executable file HoldemManager.x86.exe (or if you dont wanna install, you can just extract this file from installattion "archive" Hm2AutoUpdate_8695.exe by using 7-Zip or something like that). This is the result:
    trojan-virustotal2.png

    8695: https://www.virustotal.com/gui/file/...0e84/detection
    8673: https://www.virustotal.com/gui/file/...53c5/detection

  8. #8
    Junior Member
    Join Date
    Mar 2012
    Posts
    6

    Angry

    today (8695 version):
    trojan-defender2.png
    Please, please, fix it as soon as possible.

  9. #9
    *** HM3! *** fozzy71's Avatar
    Join Date
    Jun 2005
    Location
    HM Support
    Posts
    32,814

    Default

    It is a false positive. I just submitted it to MS as a false positive.

    That is a false positive alert and you should report the false positive, remove it from quarantine and/or add exceptions for it and the installer and install the update/patch again.

    Sometimes security software can prevent Holdem Manager communicating with PostgreSQL and the Poker sites. This can cause many issues including import, hud issues and issues with launching Holdem Manager. Please follow the instructions in this FAQ that creates exceptions for Holdem Manager and PostgreSQL to avoid these issues - http://hm2faq.holdemmanager.com/ques...%28Firewall%29

    Open your Windows Defender (or chosen AntiVirus program) > History tab:

    1) Select the files if they are from holdemmanager with that checkbox on the left side, then in the bottom right of the window click 'Allow Item'.
    2) Start HM2.

    Please let us know if that solved the problems.

    If you continue to have problems:

    Please zip/attach your HM2Logs folder with a detailed description of what you were doing and what problems you were experiencing - http://hm2faq.holdemmanager.com/ques...ger+Support%3F

  10. #10
    Junior Member
    Join Date
    Apr 2020
    Location
    CZ
    Posts
    1

    Unhappy

    Hi,

    I have the same problem.

Similar Threads

  1. Windows defender blocking HM2 all of a suddem?
    By machine1984 in forum General Support
    Replies: 5
    Last Post: 05-28-2016, 01:10 PM
  2. Replies: 5
    Last Post: 11-02-2009, 11:51 AM
  3. stats blocking hole cards @ stars
    By randomuser1 in forum Manager General
    Replies: 5
    Last Post: 02-15-2009, 09:14 AM
  4. HUD stats blocking tourney stacks / unmovable when tiling
    By Scotty12 in forum Manager General
    Replies: 3
    Last Post: 10-05-2008, 06:35 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •