PDA

View Full Version : AVG Detection Alert with latest UpdaterEngine.exe



Stinky
October 7th, 2017, 05:13
When I received the latest UpdaterEngine.exe my AntiVirus "AVG" alarmed.

Object name: c:\program Files (x86)\Steam\steamapps\comm\Fantasy Grounds\UpdaterEngine.exe

Threat: Win32/Heri [More Info] (https://www.avgthreatlabs.com/en-us/virus-and-malware-information/pu/paid/?AI=-1&BE=27&CTRY=us&IDN=YzpcUHJvZ3JhbSBGaWxlcyAoeDg2KVxTdGVhbVxzdGVhbW FwcHNcY29tbW9uXEZhbnRhc3kgR3JvdW5kc1xVcGRhdGVyRW5n aW5lLmV4ZQ&IDNT=QEVJRF9GaV92aXJ8JW5hbWUlPVdpbjMyL0hlcmk&LNG=us&PRTYPE=PROT&V=2016&utm_medium=RS&utm_source=TDPU)

Info on UpdaterEngine.exe:
Size: 2.74MB
Digital Signature: Smite Works USA | sha1 | Signing time: ‎Tuesday, ‎September ‎5, ‎2017 3:59:16 PM
Issused by: COMODO RSA Code Signing CA
Valid from 5/23/2017 to 5/24/2021

LordEntrails
October 7th, 2017, 06:16
Hey Stinky, welcome to the forums :)

SmiteWorks submits their updates to the major AV engines, but it takes time for things to get reviewed etc. You can go into AVG and whitelist FG and the installation directory. That should remove it from the alert and prevent it from being tagged in the future.

Moon Wizard
October 7th, 2017, 08:07
In fact, AVG just got back to me for that one, saying that it was cleared. It's renamed on Steam from FGUpdaterEngine.exe to UpdaterEngine.exe. I wonder if that's enough to trigger their filters. Is there a quick submit button?

Thanks,
JPG

Stinky
October 7th, 2017, 17:49
Thanks for replying that this is just a false positive.