• Visit Rebornbuddy
  • Visit Panda Profiles
  • Visit LLamamMagic
  • Attention to all users that have no AV installed and downloaded HB/DB past 24 hours

    Discussion in 'Archives' started by bambam922, May 9, 2013.

    1. bambam922

      bambam922 Well-Known Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      6,071
      Likes Received:
      28
      Trophy Points:
      48
      To all users of HB and DB,

      Our releases server, update.buddyauth.com was attacked around 24 hours ago and latest Release builds of HB and DB where infected with a trojan directly targeting us.

      If you have ran a AV, it has detected the Trojan and eliminated it.

      If you have not ran an AV, please do so now, and please never turn that off!

      What happened:

      The Release Server was targeted and infected, only DB and HB where the target. The trojan targets game accounts, like D3, WOW, GW, Runescape

      We were exposed for around or less than 24 hours. All the users that downloaded HB / DB out of updates.buddyauth.com since then should now check their systems and especially the HB / DB folder for an infection.

      Please excuse this failure from our side, we took countermeasures and hope that this will never happen again.

      Download the latest builds from The Buddywing Update Server and extract them in a new folder.


      Again we are very sorry for that attack on our systems, if you have any Anti-virus running, you would have been completely fine, if not make sure and change your Games passwords and scan your compute for trojans and or malware.
       
    2. Polyester

      Polyester New Member

      Joined:
      Jun 18, 2012
      Messages:
      927
      Likes Received:
      1
      Trophy Points:
      0
    3. Crotaphytus112

      Crotaphytus112 New Member

      Joined:
      Jan 15, 2010
      Messages:
      81
      Likes Received:
      0
      Trophy Points:
      0
      Any advice on what software we should use? Would MSE and Malwarebytes do the job?
       
      Last edited: May 9, 2013
    4. bambam922

      bambam922 Well-Known Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      6,071
      Likes Received:
      28
      Trophy Points:
      48
      Malwarebytes is the AV I use. AVs such as comodo and avast will work as well.

      The releases have been cleaned and both update servers should be good to go for download.

      Sorry about the inconvenience.
       
    5. Seero

      Seero Member

      Joined:
      May 6, 2013
      Messages:
      140
      Likes Received:
      9
      Trophy Points:
      18
      well now i see why my comp freaked out when it found the trojan -_-


      but glad my comp didnt get screwed lol
       
    6. aaron913

      aaron913 New Member

      Joined:
      Dec 8, 2011
      Messages:
      453
      Likes Received:
      1
      Trophy Points:
      0
      Code:
      Malwarebytes Anti-Malware (PRO) 1.75.0.1300
      www.malwarebytes.org
      
      Database version: v2013.05.09.01
      
      Windows 7 Service Pack 1 x64 NTFS
      Internet Explorer 10.0.9200.16540
      AARON :: AARONPC [administrator]
      
      Protection: Enabled
      
      5/9/2013 1:25:27 AM
      mbam-log-2013-05-09 (01-25-27).txt
      
      Scan type: Custom scan (C:\Users\AARON\Desktop\Demonbuddy 1.0.1399.306|)
      Scan options enabled: File System | Heuristics/Shuriken | PUP | PUM
      Scan options disabled: Memory | Startup | Registry | Heuristics/Extra | P2P
      Objects scanned: 264
      Time elapsed: 5 second(s)
      
      Memory Processes Detected: 0
      (No malicious items detected)
      
      Memory Modules Detected: 0
      (No malicious items detected)
      
      Registry Keys Detected: 0
      (No malicious items detected)
      
      Registry Values Detected: 0
      (No malicious items detected)
      
      Registry Data Items Detected: 0
      (No malicious items detected)
      
      Folders Detected: 0
      (No malicious items detected)
      
      Files Detected: 0
      (No malicious items detected)
      
      (end)
      
      
      guess it is elsewhere?
       
      Last edited: May 9, 2013
    7. CodenameG

      CodenameG New Member

      Joined:
      Jan 15, 2010
      Messages:
      38,369
      Likes Received:
      231
      Trophy Points:
      0
      unfortunately we're a big target, thats not going to change anytime soon. all we can do is take care of things as they happen, and it sucks it had to happen, but it did.

      as far as the releases go, they are all clean at this point.
      if you want to double check yourself you can upload it to www.virustotal.com and check it for your self,
      if you think you've been infected then download Comodo or Avast (unfortunately MSE and AVG are not detecting it) and run a scan, both are free.
       
    8. Crotaphytus112

      Crotaphytus112 New Member

      Joined:
      Jan 15, 2010
      Messages:
      81
      Likes Received:
      0
      Trophy Points:
      0
      aaron913, got the same report after scanning. Maybe we have a uninfected version of the release?
       
    9. aaron913

      aaron913 New Member

      Joined:
      Dec 8, 2011
      Messages:
      453
      Likes Received:
      1
      Trophy Points:
      0
      I grabbed mine Yesterday, ‎May ‎08, ‎2013, ‏‎1:11:46 AM EST so just about 24 hrs ago
       
    10. CodenameG

      CodenameG New Member

      Joined:
      Jan 15, 2010
      Messages:
      38,369
      Likes Received:
      231
      Trophy Points:
      0
      or you didn't get infected.

      if you feel paranoid you can run a scan with Avast or Comodo but malware bytes should of caught it, at least acording to www.virustotal.com
       
    11. aaron913

      aaron913 New Member

      Joined:
      Dec 8, 2011
      Messages:
      453
      Likes Received:
      1
      Trophy Points:
      0
      alright thanks, I wasn't too worried
       
    12. jewcie101

      jewcie101 New Member

      Joined:
      May 9, 2013
      Messages:
      23
      Likes Received:
      0
      Trophy Points:
      1
      I've deleted all the files and changed my pws am I safe or is the virus imbeded into my computer somewhere

      running full scan with kaspersky atm havn't found anything
       

    Share This Page