PokerOffice Users Forum  

Go Back   PokerOffice Users Forum > PokerOffice > Support
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

 

LinkBack Thread Tools Search this Thread Display Modes
Old 2008-02-07, 21:40   #31 (permalink)
macmac100
Junior Member
 
Join Date: Sep 2007
Posts: 6
Default

I've been using PO for almost a year and the ptnhandler.dll was fine so far.

The ptnhandler.dll alert has just occured after today's anti virus update.

I assume most anti visrus programms share virus definitions (or rip them of from each other). This would explain why the alert has occured on many different anti virus programms.

I also assume there is a 95% chance that this alert is a false positive, since the ptnhandler.dll file did not change recently at all.

Last edited by macmac100 : 2008-02-07 at 21:42.
macmac100 is offline   Reply With Quote
Old 2008-02-07, 22:39   #32 (permalink)
Molinero
Junior Member
 
Join Date: Feb 2008
Posts: 2
Default

Quote:
Originally Posted by Hanuse View Post
Same Problem here - I use AVG 7.5 Antivirus-Programm.

On January 23 it find a "trojaner" named InjLib.dll in the PO\bin-folder - I put it to the Quarantäne and PO worked without problems.

Today it find the "Backdoor Agent" pnthandler.dll and I do it in Quarantäne - PO do not open. I write it back and then ignore it, but PO still not open...

I wrote to support and send you the Infos of my Virus-Scanner - please help quick!
I had the same problem but fixed it.

First recover both files from the virus vault (if you haven't deleted them - then there isn't much to do). Then open the control panel of AVG and turn off the resident shield. Now open pokeroffice. Turn on resident shield again.

Pressing "ignore" to the files when opening pokeroffice will not help - the programs access to the dll's will still be blocked.
Molinero is offline   Reply With Quote
Old 2008-02-08, 11:10   #33 (permalink)
Administrator
Administrator
 
Join Date: Jan 1970
Posts: 128
Default

First of all sorry for beeing a bit late in answering.

The file(s) in question does of course not have any trojan/virus or other malicious code in it at least not when we release the file from us. I guess there is a small chance that people who are infected with a virus could get files in PO infected too.

However since everyone seem to have got a warnig on the same file at the same time I think it is just a false positive.

I will look into this right away (prio 1) and get back here as soon as I can. I will also contact some antivirus companies about this issue so that you should not even get a warning message (this will of course take some time)

First of all I will verify 100% that there are no problems with pnthandler.dll and get back here ASAP.



PS
On January 23 it find a "trojaner" named InjLib.dll in the PO\bin-folder is one such case where we have 100% verified that it is a false positive and the fille is OK
DS

PSS
Can you please let us know if there are any other file than pnthandler.dll that give you this?
(updatexxx.exe contains the pnthandler file since it is a install file and does notcount
DSS
__________________
----------------------------------
Elevate your online poker experience to the next level
http://www.pokeroffice.com
----------------------------------
Administrator is offline   Reply With Quote
Old 2008-02-08, 11:12   #34 (permalink)
Administrator
Administrator
 
Join Date: Jan 1970
Posts: 128
Default

If some one would be able to post the file to Fsecure or similar it would be very good too thank you.
__________________
----------------------------------
Elevate your online poker experience to the next level
http://www.pokeroffice.com
----------------------------------
Administrator is offline   Reply With Quote
Old 2008-02-08, 12:21   #35 (permalink)
Administrator
Administrator
 
Join Date: Jan 1970
Posts: 128
Default

I have now scanned the complete PokerOffice program folder (c:\program files\pokeroffice\) with both Trend Micro Antivirus and F-secure Anti-Virus 2008 (using definition version 2008-02-08_02). Neither antivirus can find anything wrong with any file.

This raises a few questions; are you using the same (2008-02-08_02) definition file? If you are, have your version of pnthandler been infected by a virus?

My suggestion is that you try to install the latest patch: www.pokeroffice.com/update.exe

Directly after the install make a virus scan and see if you get the same result as before. Also try to start PO and see if it works.

Even if you do not get a warning after updating and PO works the virus that infected your computer can still be present in the registry and in your system folder. So a complete virus scan clean up might be needed.

Again it would be very good if some people could send in the files to F-secure etc, both the file you get a varning for and if you do not get a warning for the file after you reinstalled maybe send that file too.

You can also send the infected file to us so we can compare it to our own original one.

I will keep monitoring this thread today and in the weekend to see what evolves.
__________________
----------------------------------
Elevate your online poker experience to the next level
http://www.pokeroffice.com
----------------------------------
Administrator is offline   Reply With Quote
Old 2008-02-08, 12:29   #36 (permalink)
DeBuX
Junior Member
 
Join Date: Jun 2007
Posts: 9
Default

Quote:
Originally Posted by Administrator View Post

PSS
Can you please let us know if there are any other file than pnthandler.dll that give you this?
(updatexxx.exe contains the pnthandler file since it is a install file and does notcount
DSS
another "infected" file is chatcontainer.dll

PS Yesterday the support was sending the two files to me, but AVG automatically blocked recieving that e-mail. And when I try to install PO with the latest patch I get the warnings through the installation process that these two files are infected.
DeBuX is offline   Reply With Quote
Old 2008-02-08, 12:49   #37 (permalink)
Administrator
Administrator
 
Join Date: Jan 1970
Posts: 128
Default

Ok, can you tell me exactly what security program you are using please.
__________________
----------------------------------
Elevate your online poker experience to the next level
http://www.pokeroffice.com
----------------------------------
Administrator is offline   Reply With Quote
Old 2008-02-08, 13:00   #38 (permalink)
draseler
Junior Member
 
Join Date: Jan 1970
Posts: 10
Default

Hi, sorry my english, I hope that understand.

I am sure that is a false positive. The problem is that I cannot start PO already by any means. I have tried to reinstall everything, with the AVG closed , restoring the file, with file copied of another computer... and at nothing. I do not achieve that PO works.

I can do what?
draseler is offline   Reply With Quote
Old 2008-02-08, 14:26   #39 (permalink)
Dubbsen
Junior Member
 
Join Date: Feb 2008
Posts: 1
Default Backdoor problems

Hello.

(I am using Avira AntiVir PersonalEdition Classic including the latest virus update and I am using the most recent version of Poker Office.
I did not have any problems until yesterday morning.
Since yesterday ptnhandler.dll and chatcontainer.dll cause problems with my AntiVir.
Because of the quarantine PO does not start anymore.
I am quite sure, that my system has not been infected otherwise, because I reinstalled it only 2 weeks ago. I am quite cautious and never had any problems with viruses.)

P.S.: Good news!!! I checked the files again and now they are ok!

Last edited by Dubbsen : 2008-02-08 at 14:32.
Dubbsen is offline   Reply With Quote
Old 2008-02-08, 15:15   #40 (permalink)
viggosen
Junior Member
 
Join Date: Jan 1970
Posts: 9
Default

My F-secure antivirus found virus and I let Fsecure delete it, and then I couldn´t start PO.
Tried to download and the update file, you linked to, now it works again.
(and no virus warning)

I then ran a virus check of the entire PO folder.
Nothing found.

Here is a screenshot
(Its in Danish but I hope you can see the results)


Last edited by viggosen : 2008-02-08 at 15:33.
viggosen is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +2. The time now is 18:52.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0