Avast WEBforum

Other => Viruses and worms => Topic started by: randuser2002 on May 13, 2013, 03:02:39 PM

Title: (Test server) Planetside2.exe.part Win32:Hoblig : False positive, or virus?
Post by: randuser2002 on May 13, 2013, 03:02:39 PM
My machine has been virus free according to Avast and Malware, until today when I tried updating my Planetside 2 game client.

The update halted and the file shield gave me the warning that it was Win32:Hoblig and promptly moved it to the chest.

I uploaded the file to Virustotal.com and the only detections are from Avast and GData.

https://www.virustotal.com/en/file/b7c555f8a4c4ae8c3d5c242218790861f676e98f45f4d4c22232502c76be3d66/analysis/1368449663/

Does anybody know if this is a false positive, or a real virus?

The tech support on the game forums is sadly incompetent and condescending (not taking the report seriously, although everybody using Avast is reporting the same thing), so that is why I am posting it here.

Thank you in advance.

Edit: This only applies to the test server version for me with the recent update
Title: Re: (Test server) Planetside2.exe.part Win32:Hoblig : False positive, or virus?
Post by: DavidR on May 13, 2013, 05:08:53 PM
If only GData and avast detect it - GData uses avast as one of its two scanners so counts as 1 detection and almost certainly an FP.
Send the sample to avast as a False Positive:
Open the chest and right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update. A link to this topic wouldn't hurt.

Or
You can send the sample to avast as a False Positive. From the avastUI > Support > scroll down to the 'Report files to the avast! virus lab' Submit to virus lab... button, use the next window to navigate to the suspect file.
@@@@
A .part file is an incomplete download, so I don't know if this could also have an impact on what is meant to be a Heuristic detection.
Title: Re: (Test server) Planetside2.exe.part Win32:Hoblig : False positive, or virus?
Post by: REDACTED on October 19, 2013, 04:26:42 AM
Just wanted to note this seems to be back with the new Avast 2014.  I am getting a false positive while trying to install planetside 2.
Title: Re: (Test server) Planetside2.exe.part Win32:Hoblig : False positive, or virus?
Post by: DavidR on October 19, 2013, 04:00:03 PM
Then follow the above procedure, confirm using virustotal and report to avast for correction.
Title: Re: (Test server) Planetside2.exe.part Win32:Hoblig : False positive, or virus?
Post by: Rob_Thompson on October 24, 2013, 12:52:17 AM
Greetings -

Sony Online Entertainment has reached out to Avast and opened a support ticket for this False Positive.
Our internal forums address the issue here and have listed some known work arounds.

https://forums.station.sony.com/ps2/index.php?threads/planetside-exe-virus-win32-hoblig-heur.124951/page-7 (https://forums.station.sony.com/ps2/index.php?threads/planetside-exe-virus-win32-hoblig-heur.124951/page-7)

SOE also checked the latest PlanetSide2.exe with Virus Total and received similar results: 
https://www.virustotal.com/en/file/113662e24dd95de28536dbfa56396afd76f2a99e34d2186e18ea25922d1e0cf8/analysis/ (https://www.virustotal.com/en/file/113662e24dd95de28536dbfa56396afd76f2a99e34d2186e18ea25922d1e0cf8/analysis/)
Avast is the only hit on the list.

We're eager to find a suitable solution for everyone encountering this issue and are currently awaiting word back from Avast.

Thanks

Rob Thompson
Sr. QA Director
Sony Online Entertainment
www.soe.com (http://www.soe.com)
Title: Re: (Test server) Planetside2.exe.part Win32:Hoblig : False positive, or virus?
Post by: Rob_Thompson on October 24, 2013, 06:42:07 PM
This should now be resolved.
If you encounter any other issues with Avast please post in these forums or on the official SOE Tech Support forums here:  https://forums.station.sony.com/ps2/index.php?forums/general-technical-support.29/ (https://forums.station.sony.com/ps2/index.php?forums/general-technical-support.29/)

Thanks

Rob Thompson
Sr. QA Director
Sony Online Entertainment
www.soe.com