heRO-Server Forum

Full Version: HEUR/AGEN.1006745 Avira detection issue
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hello everybody;
I am (or well, had) Avira as an antivirus installed on my machine and two days ago, after reopening my hero client during the evening, Avira blocked it as it detected a malware model named HEUR AGEN.1006745.

Searching on the web, apparently a "HEUR" virus got discovered at the beginning of march of this year. My first thought was "i got a malware from somewhere and it attached/attacked this executable (heRO.exe), and being a recent one it slipped my defenses until now."

So i started running system's scans, registry's scans, using various antimalware programs, etcetera.
Spent basically 4 straight hours doing that and... i found nothing relative to this HEUR on my machine.

For precaution, the very next morning i copied all my important files and documents onto an external HDD, dug up my backup OS disks, noted down all the softwares i wanted to reinstall and prepared mentally to format the laptop.

But before doing that, the fact that only Avira antivirus detected it and that im usually very cautious clicking stuff on the internet, it was bugging me pretty hard all this situation. I started to think it could be a case of false positive from Avira, which apparently got its database recently updated with informations about this newly discovered HEUR virus.

As some friends of mine also suggested, i tried another antivirus. Now i installed AVG, got again the hero.exe, launched it, everything is fine.

Since my first encounter with this issue, two days ago, up 'til now a total of 4 people i know got the problem and all of four had Avira as their antivirus.

Dont take my words as molten gold but from this experience i concluded thats a false positive from Avira.

I felt to write this on forum as other people than me encountered this really annoying issue, so its not an only mine situation, and maybe it could promptly help whoever from now meets this issue.

WARNING: THE BASIC RULE IS ALWAYS SCAN YOUR SYSTEM AND REGISTRY WITH PROPER PROGRAMS TO SEE IF EFFECTIVELY YOUR MACHINE CAUGHT SOMETHING NASTY

BE WISE

:D
Thanks for informing others who have had, or may have this issue in the future. I will stick this thread so it stays visible on the first page of this subsection.
Reference URL's