[FAQ] Blizzard Game Trojan Alerts (AVG)

by Sixen | 24/09/2009 08:39:42

Sixen

UPDATE 5/11 9:10PM PST
Issue is back for War3.exe.

UPDATE 2/25 5:10PM PST
Looks like this issue is back, but for Diablo II's D2Win.dll.
Version: 9.0.851
Definitions: 271.1.1/3120 (as of Tuesday, September 7th, 2010 11:43AM PST)

Information on how to avoid the problem can be found below.

---

The Solution
Aside from waiting for AVG to solve that issue, you can add an exception to AVG so that you do not get an alert every time the "virus" is found. To add Diablo II.exe as an exception, do the following:
1) Open up the AVG Control Center
2) Navigate to Tools > Advanced Settings > PUP Exceptions > Click "Add Exception"
3) For "File", click the "..." and browse to your Diablo II.exe file, the default path is "C:\Program Files\Diablo II\Diablo II.exe" for XP and below, and "C:\Program Files (x86)\Diablo II\Diablo II.exe" for Vista and above.
4) Leave "Checksum" and "File Info" blank, they will be filled in automatically after you input an application. Leave "Any location - do not use full path" unchecked.

And/or go to AVG Control Center -> Overview -> Resident Shield, click manage exceptions, and add your C:\ whatever-path-you-have-to-you-Warcraft III/TFT-directory.

As Chuck said, if the file was deleted [and the Virus Vault was cleared], you will need to do a reinstall. However, if your Virus Vault was not cleared, you can retrieve the file by doing the following:
1) Open up the AVG Control Center
2) Navigate to History > Virus Vault
3) Select the Diablo II.exe and click the "Restore" button

The Problem
Users running AVG 8.5.409, with the newest Virus Definitions, 270.13.112/2391 from September 23rd at 11:00AM, will receive a false-positive Warning displaying Diablo II.exe infected with a Trojan horse.Backdoor.Generic11.ATGA virus. A false-positive result means that the anti-virus program is falsely displaying an application with a positive virus infection. There is no need to worry, you don't have a virus. From what I have heard, it has been reported by other users to the Database already.


Q u o t e:
Originally posted by Datth [Blizzard Poster] @ 09/23/2009 04:42:50 PM GMT-07:00

It looks like an AVG update flagged some of Diablo 2's files as a trojan. It seems to be a false positive but you'll want to check your executable's modified date to make sure it didn't get changed today. If it's older, it's fine. If you reinstalled, patched or restored the game today, you'll have a modified date of today so the checking-the-date idea won't apply in those cases.

Source: http://forums.battle.net/thread.html?topicId=20122733027#3

How to report the issue to AVG
Follow the steps below:
1) Open up the AVG Control Center
2) Navigate to History > Virus Vault
3) Right-click the Diablo II.exe and select the "Send to analysis" option
4) Fill in your e-mail address and confirm the dialog
Source: http://forums.avg.com/cz-en/avg-free-forum?sec=thread&act=show&id=395

[ Post edited by Sixen ]


The Chat Gem Lives!
http://www.Sixen.org/

by Charlesps | 24/09/2009 19:48:11

Charlesps

We are receiving reports that it has been resolved and they have posted as such in their forums:
http://forums.avg.com/ww.avg-free-forum?sec=thread&act=show&;id=19403#post_19403

If the file was deleted you will probably need to reinstall the game.

Edit: Hi Sixen.

[ Post edited by Charlesps ]


Technical support needs your feedback. Please take the time to fill out a survey using the link below and tell me how I am doing:
https://www.surveymk.com/s.aspx?sm=aW04S5FAdACKYEK_2f1kLKxQ_3d_3d

by Charlesps | 31/12/2009 03:04:12

Charlesps

Thanks for the updates guys. I have not seen many reports of it but yeah it looks like it is happening again.

Technical support needs your feedback. Please take the time to fill out a survey using the link below and tell me how I am doing:
https://www.surveymk.com/s.aspx?sm=aW04S5FAdACKYEK_2f1kLKxQ_3d_3d

by Charlesps | 31/12/2009 19:52:39

Charlesps

Thanks for the updates guys. I believe if the file was deleted then you will need to reinstall the game. Not familiar with their system but other AV programs have had similar requirements when the quarantined file has been deleted.

[ Post edited by Charlesps ]


Technical support needs your feedback. Please take the time to fill out a survey using the link below and tell me how I am doing:
https://www.surveymk.com/s.aspx?sm=aW04S5FAdACKYEK_2f1kLKxQ_3d_3d

by Charlesps | 26/02/2010 01:32:30

Charlesps

Thanks Sixen, Linked it in the other thread too since you brought it up from its deep slumber.


Technical support needs your feedback. Please take the time to fill out a survey using the link below and tell me how I am doing:
https://www.surveymk.com/s.aspx?sm=aW04S5FAdACKYEK_2f1kLKxQ_3d_3d

by Datth | 08/09/2010 17:37:35

Datth

There was one bug where it's possible to make code run on War3 but that was patched a couple days later. It can't do that anymore :P

Tech Support/Billing

All of a sudden....VOID RAY! Pew!
https://www.surveymk.com/s/H2S6NPZ 

Last 7 Days Last 7 Days

 

Most Viewed Most Viewed Threads This Week

 



Loaded in 0.06122 seconds