theHunter Classic

theHunter Classic

View Stats:
LabStephane Mar 24, 2017 @ 12:08pm
Trojan Patch ?
Bitdefender a detecté Gen:TROJAN.HEUR2.GZ.@FW@BIO6LEO.
< >
Showing 1-9 of 9 comments
Alf Tupper Mar 24, 2017 @ 12:37pm 
Nothing detected here. (Norton). Anyone else?
76561198349709834 Mar 27, 2017 @ 8:36am 
I am using Norton at home and it went through absolutely fine for me. It's possible that it takes a day or two for the anti virus software to catch up though.
PvtDGrif May 13, 2017 @ 8:40am 
I get Gen:Trojan.Heur2.GZ.@FX@b40jwDc from Bit Defender. It's Launcher.exe that is being quarantined.
PvtDGrif May 13, 2017 @ 9:01am 
I ran it through VirusTotal.com, an online file scanning site that runs it against 61 virus products and here are the results:

VirusTotal
Your file is being analysed.
SHA256: 0aa94e965a8a3934e69a4b6bf05467e4d0f688b7a0736b1b329cecc8214f9942
File name: launcher.exe
Detection ratio: 10 / 61

Antivirus Result Update
Ad-Aware Gen:Trojan.Heur2.GZ.@FX@b40jwDc 20170513
AhnLab-V3 Malware/Gen.Generic.C1913175 20170513
Arcabit Trojan.Heur2.GZ.E541AD 20170513
BitDefender Gen:Trojan.Heur2.GZ.@FX@b40jwDc 20170513
Bkav W32.HfsAutoB.870F 20170513
Emsisoft Gen:Trojan.Heur2.GZ.@FX@b40jwDc (B) 20170513
Endgame malicious (high confidence) 20170503
F-Secure Gen:Trojan.Heur2.GZ.@FX@b40jwDc 20170513
GData Gen:Trojan.Heur2.GZ.@FX@b40jwDc 20170513
eScan Gen:Trojan.Heur2.GZ.@FX@b40jwDc 20170513

The below 51 AV products passed the file as nothing detected:
AegisLab 20170513
ALYac 20170513
Antiy-AVL 20170513
Avast 20170513
AVG 20170513
Avira (no cloud) 20170513
AVware 20170513
Baidu 20170503
CAT-QuickHeal 20170513
ClamAV 20170513
CMC 20170512
Comodo 20170513
CrowdStrike Falcon (ML) 20170130
Cyren 20170513
DrWeb 20170513
ESET-NOD32 20170513
F-Prot 20170513
Fortinet 20170513
Ikarus 20170513
Invincea 20170413
Jiangmin 20170513
K7AntiVirus 20170513
K7GW 20170513
Kaspersky 20170513
Kingsoft 20170513
Malwarebytes 20170513
McAfee 20170513
McAfee-GW-Edition 20170513
Microsoft 20170513
NANO-Antivirus 20170513
nProtect 20170513
Palo Alto Networks (Known Signatures) 20170513
Panda 20170513
Qihoo-360 20170513
Rising 20170513
SentinelOne (Static ML) 20170330
Sophos 20170513
SUPERAntiSpyware 20170513
Symantec 20170513
Tencent 20170513
TheHacker 20170508
TrendMicro 20170513
TrendMicro-HouseCall 20170513
VBA32 20170512
VIPRE 20170513
ViRobot 20170513
Webroot 20170513
Yandex 20170512
Zillya 20170511
ZoneAlarm by Check Point 20170513
Zoner 20170513
PvtDGrif May 13, 2017 @ 9:03am 
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.

FileVersionInfo properties
Signature verification The digital signature of the object did not verify.
Signing date 4:47 PM 5/13/2017

PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2017-03-15 07:26:21
Entry Point 0x0C5A4310
Number of sections 7
PvtDGrif May 13, 2017 @ 12:15pm 
I deleted it and scanned my whole system nothing else comes up as infected. I then allowed steam to download it again and yet again it came up as infected. I told Bit Defender to not block it and steam installed the update. Now nothing reports infected across my system. I'm guessing it's a false positive from bit defender.
76561198349709834 May 15, 2017 @ 1:32am 
For me it came up clean as well. I checked with Norton and Avast on 2 different PC's. Try what HaddockA recommended and let us know what you find out.
PvtDGrif May 15, 2017 @ 12:25pm 
Just rescanned it with virustotal to be sure, it's clear. As I said, it was clear in the installed location. It was the downloaded but not installed version that said it was infected. I believe it was bit defender finding a false positive (as it happened 3 times in total) I think virustotal showing it as 6 out of 61 was my fault; I uploaded the file that bit defender quarantined and it had added ".svsefsfs." on the end of the file name, I just took the extra bit off the name and uploaded it to virustotal. Which will have changed the hash value. Sorry for the false alarm!
76561198349709834 May 16, 2017 @ 8:38am 
No worries, better be safe than sorry. Especially in a time when vicious viruses and ransomware are going around. Have fun! :steamhappy:
< >
Showing 1-9 of 9 comments
Per page: 1530 50

Date Posted: Mar 24, 2017 @ 12:08pm
Posts: 9