Avira's interesting detection

Discussion in 'other anti-virus software' started by bonedriven, Nov 15, 2008.

Thread Status:
Not open for further replies.
  1. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    565
    Today,when I ran garena.exe(A game platform client),Avira popped up saying pluginkernell.dll a virus(TR/PSW.OnlineGames.tsoe).I thought it was a FP.So I added the file to exception list.
    Afterthat,I let Virustotal checked the file.Only these 5 AVs found it as a virus:
    AVG(PSW.OnlineGames.BHAR),
    F-Secure(Trojan-GameThief.Win32.OnLineGames.tsoe),
    SecureWeb-Gateway(Trojan.PSW.OnlineGames.tsoe),
    ViRobot(Spyware.PSW.OnLineGames.78848.C).
    However,when I tried to start garena.exe again,OA popped up saying "GPE3.tmp by garena wants to start automatically with my computer.)I clicked "block" for sure.
    Then I notice garena.exe was updating itself and the file it had updated was only "pluginkernel.dll".
    So what I think now is THE OFFICIAL GARENA WAS INFECTED WITH VIRUS WHICH AVIRA DETECTED IT.
    What do you think?
     
  2. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    565
    I checked Garena's forum.The administrator there has made a sticky thread saying their application is clean while some gamers still believe their AVs rathan the admin.It seems Kaspersky treated it as infected too.
     
  3. emperordarius

    emperordarius Registered Member

    Joined:
    Apr 27, 2008
    Posts:
    1,218
    Location:
    Who cares
    Obviously Kav detects it too since the F-Secure detection is in the AVP format.;)

    You can try uploading the file here:

    http://analysis.avira.com/samples/index.php

    In the file type select: Suspected False Positive (Not Malware)
     
  4. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Yep trust your Antivirus but to be sure, summit samples to Avira for analysis worst case senario a FP.
     
  5. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    565
    I forgot to send it there.I've updated the application so the virus seems gone by now.
     
Loading...
Thread Status:
Not open for further replies.