• Visit Rebornbuddy
  • Visit Panda Profiles
  • Visit LLamamMagic
  • Attention to all users that have no AV installed and downloaded HB/DB past 24 hours

    Discussion in 'Archives' started by bossland, May 7, 2013.

    1. foam_follower

      foam_follower Member

      Joined:
      Dec 3, 2011
      Messages:
      282
      Likes Received:
      4
      Trophy Points:
      18
      Given the circumstances I wouldn't be prepared to accept anything as a false positive. HB is an incredible product but like a lot of commercial sites it's now the victim of cyber attacks. Such a shame.
       
    2. Halfred

      Halfred New Member

      Joined:
      May 3, 2013
      Messages:
      13
      Likes Received:
      0
      Trophy Points:
      0
      It must have installed something on pc... and the only reason I let down my AV is because someone made a forum post telling me that it was OK because its like a aimbot where it gives malware errors...

      newho... my wow account has been locked again due to some random IP trying to access it while i was at work today...
       
    3. geels12

      geels12 New Member

      Joined:
      Dec 18, 2012
      Messages:
      10
      Likes Received:
      0
      Trophy Points:
      0
    4. TreeEskimo

      TreeEskimo Member

      Joined:
      Apr 22, 2013
      Messages:
      105
      Likes Received:
      0
      Trophy Points:
      16
      Okay, to get this straight:

      The 557 version people are referring to (which was the clean and working version of hb that they rolled out yesterday after the infection) is now infected again?
      Some guy was talking about a 558 version too - whats up?
       
    5. Ilja Rogoff

      Ilja Rogoff Well-Known Member

      Joined:
      Jan 25, 2010
      Messages:
      1,848
      Likes Received:
      38
      Trophy Points:
      48
      Don't know if it's infected, Virustotal shows 1 infection of 44 scan engines. Maybe false positive. May not.
       
    6. brainAbuddy

      brainAbuddy Active Member

      Joined:
      Aug 12, 2010
      Messages:
      2,180
      Likes Received:
      11
      Trophy Points:
      38
    7. xenn88

      xenn88 New Member

      Joined:
      May 4, 2010
      Messages:
      83
      Likes Received:
      2
      Trophy Points:
      0
      Does anyone know what exactly this 558 file did? i installed it earlier today, but whiped my hd afterwards for security.

      anything else i should do?
       
    8. Tompost

      Tompost Member

      Joined:
      Mar 24, 2013
      Messages:
      306
      Likes Received:
      0
      Trophy Points:
      16
      I just saw the thread which says that 557 was infected. I downloaded the new .557 yesterday just before I made the post "nvm i didnt know there's an update to HB". Am I still safe? Or is the infected part already there prior to that?

      This is the post that I am talking about.
       
    9. hellnation13

      hellnation13 New Member

      Joined:
      Dec 19, 2011
      Messages:
      55
      Likes Received:
      0
      Trophy Points:
      0
      they didnt touch the beta versions ? .227 ?
       
    10. bambam922

      bambam922 Well-Known Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      6,071
      Likes Received:
      28
      Trophy Points:
      48
      Bossland's post updated.
       
    11. Lautaro

      Lautaro New Member

      Joined:
      Feb 1, 2012
      Messages:
      95
      Likes Received:
      0
      Trophy Points:
      0
      Honorbuddy 2.5.7016.562 downloaded from Home 20 minutes ago STILL CONTAINS a trojan of some sorts. I believe it starts in "THUMB.DB", it then creates a file called AMDEx3.msi which is detected as a trojan, and has been stated many times that this file is NOT a part of Honorbuddy.

      AVG detects both THUMB.DB and the AMDEx3.msi as malicious files..

      Not completely sure what's so hard to remove about it - unless you guys have no idea which files the malicious code is in.
       
    12. bambam922

      bambam922 Well-Known Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      6,071
      Likes Received:
      28
      Trophy Points:
      48
      Interesting that you say that. The .562 version I downloaded from updates.buddywing.com does not create THUMBS.db nor AMDEx3.msi
      Also, the .zip passes all virus scans.
       
    13. Timmid

      Timmid New Member

      Joined:
      Oct 19, 2012
      Messages:
      45
      Likes Received:
      0
      Trophy Points:
      0
      All of the links on the website do not link to the new website with the updates. They seem to redirect to the old infected version of Honorbuddy.
       
    14. CodenameG

      CodenameG New Member

      Joined:
      Jan 15, 2010
      Messages:
      38,369
      Likes Received:
      231
      Trophy Points:
      0
      Last edited: May 9, 2013
    15. Lautaro

      Lautaro New Member

      Joined:
      Feb 1, 2012
      Messages:
      95
      Likes Received:
      0
      Trophy Points:
      0
      EDIT: @MODS...


      The FILE that I downloaded from Home about 40mins ago now was named "Honorbuddy 2.5.7016.562." which contains THUMB.DB.

      The FILE I downloaded 2 minutes ago named "Honorbuddy 2.5.7016.562" contains NO THUMB.DB.


      One version has a .
       
      Last edited: May 9, 2013
    16. bambam922

      bambam922 Well-Known Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      6,071
      Likes Received:
      28
      Trophy Points:
      48
      Either way, the releases have been cleaned and both update servers should be good to go for download.
       
    17. lickalime

      lickalime New Member

      Joined:
      Feb 8, 2010
      Messages:
      1,071
      Likes Received:
      4
      Trophy Points:
      0
      As my father used to say "Sh*t happens". If your so concerned with the security in place for honorbuddy don't use it. Thanks for getting a clean version back up guys.
       
    18. CodenameG

      CodenameG New Member

      Joined:
      Jan 15, 2010
      Messages:
      38,369
      Likes Received:
      231
      Trophy Points:
      0
      i just got word that all the releases from all build server
      updates.buddywing.com
      and
      updates.buddyauth.com

      are clean at this point.
       
    19. Lautaro

      Lautaro New Member

      Joined:
      Feb 1, 2012
      Messages:
      95
      Likes Received:
      0
      Trophy Points:
      0
      Yup confirmed. Current release is now clean. As stated above - the infected file ended with a full stop. Barely noticeable. And contains THUMB.DB and Honoebuddy.bak.

      If you download this file, do not extract it.
       
    20. CodenameG

      CodenameG New Member

      Joined:
      Jan 15, 2010
      Messages:
      38,369
      Likes Received:
      231
      Trophy Points:
      0
      if you have old releases just delete them.
      if your not sure if you've been infected then run a local virus scan with avast or comodo (if your using comodo just use the anti-virus not the entire suite, its full of bloat) unfortunately AVG and MSE wont pick it up. (at least according to virus total)
       

    Share This Page