Avira's interesting detection

Discussion in 'other anti-virus software' started by bonedriven, Nov 15, 2008.

Thread Status:
Not open for further replies.
  1. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    566
    Today,when I ran garena.exe(A game platform client),Avira popped up saying pluginkernell.dll a virus(TR/PSW.OnlineGames.tsoe).I thought it was a FP.So I added the file to exception list.
    Afterthat,I let Virustotal checked the file.Only these 5 AVs found it as a virus:
    AVG(PSW.OnlineGames.BHAR),
    F-Secure(Trojan-GameThief.Win32.OnLineGames.tsoe),
    SecureWeb-Gateway(Trojan.PSW.OnlineGames.tsoe),
    ViRobot(Spyware.PSW.OnLineGames.78848.C).
    However,when I tried to start garena.exe again,OA popped up saying "GPE3.tmp by garena wants to start automatically with my computer.)I clicked "block" for sure.
    Then I notice garena.exe was updating itself and the file it had updated was only "pluginkernel.dll".
    So what I think now is THE OFFICIAL GARENA WAS INFECTED WITH VIRUS WHICH AVIRA DETECTED IT.
    What do you think?
     
  2. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    566
    I checked Garena's forum.The administrator there has made a sticky thread saying their application is clean while some gamers still believe their AVs rathan the admin.It seems Kaspersky treated it as infected too.
     
  3. emperordarius

    emperordarius Registered Member

    Joined:
    Apr 27, 2008
    Posts:
    1,218
    Location:
    Who cares
    Obviously Kav detects it too since the F-Secure detection is in the AVP format.;)

    You can try uploading the file here:

    http://analysis.avira.com/samples/index.php

    In the file type select: Suspected False Positive (Not Malware)
     
  4. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Yep trust your Antivirus but to be sure, summit samples to Avira for analysis worst case senario a FP.
     
  5. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    566
    I forgot to send it there.I've updated the application so the virus seems gone by now.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.