Jump to content

win32/heur trojan


Recommended Posts

AVG antivirus was detecting the shock force.exe as a win32/heur trojan.

I have had both running on my machine for months now with no problem. Why would AVG all of a sudden recognize the .exe files as trojans? Is anyone else having this problem? Just asking thinking AVG updated itself and caused this. I went into AVG and set it to ignore all of my shockforce .exe files and it works now.

Link to comment
Share on other sites

AVG antivirus was detecting the shock force.exe as a win32/heur trojan.

I have had both running on my machine for months now with no problem. Why would AVG all of a sudden recognize the .exe files as trojans? Is anyone else having this problem? Just asking thinking AVG updated itself and caused this. I went into AVG and set it to ignore all of my shockforce .exe files and it works now.

Had this as well. Hoping that it's AVG ;)

Link to comment
Share on other sites

Yeah I'm getting this as well.

For me it seems to be the Nato module. The exe icon is funny with the Nato module, its not the same as the British or Marines.

I have been playing the game with no problem for the past week or so since i downloaded the bundle.

Link to comment
Share on other sites

No, it's not. win32/heur is not a virus. "heur" stands for "heuristic" which is equivalent to "unknown". It seems that AVG has released an update today or yesterday which is creating a lot of false positives like this based on unknown virus signatures.

You can turn off "heuristic" scanning and see if it helps, and/or use the AVG feature to set exceptions and whitelist specific files it erroneously flags or even whole folders.

Martin

Link to comment
Share on other sites

Well:

1. It impacts on the paid version too, and

2. Setting to exempt is fine if you only have CM:SF or even CM:SF and CM:A but as I have some 99 *.exe files (spread across various builds of CM:SF / CM:USMC, CM:UK, CM:NATO, CM:A and CM:BN - I know because it just listed them all [and wanted to delete them]) its a PITA.

I've just changed the scanning pref to warn me of an "infected" file not automatically clean / quarantine it.

Link to comment
Share on other sites

Just noticed this too. How do I go about exempting CM from AVG? I can run CMSF alright but it seems to have eaten NATO.

It may have moved it into the quarantine area (I think that's the default setting).

If you open AVG, select "History" and then "Virus Vault" you can return the "suspect" application to where it should be.

Link to comment
Share on other sites

Yes, most eLicense protected games seem to be affected. We've notified eLicense to make sure AVG knows about it. Probably will get fixed in the next definition updates. I've cursed about AVG a lot since they do tend to generate a bunch of false positives with their heuristic filters, but then at least they do tend to listen and are fairly quick to solve problems, unlike some other companies (cough-spersky)...

Link to comment
Share on other sites

  • 4 years later...

You need to 'whitelist' the CMSF executables (the main executable, all module executables and the 'Runservice.exe' copy-protection executable) within AVG. Typically it is the 'active protection' (I can't recall what AVG calls theirs) that is the culprit. These instructions for whitelisting within AVG are for an older version and hopefully they are still accurate. Otherwise you may want to search for 'AVG 2015 whitelisting', etc. and see what results you get (preferably from AVG's site).

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...