• Visit Rebornbuddy
  • Visit Panda Profiles
  • Visit LLamamMagic
  • Trojan found after update

    Discussion in 'Honorbuddy Support' started by honors, Nov 26, 2012.

    Thread Status:
    Not open for further replies.
    1. honors

      honors Member

      Joined:
      May 17, 2012
      Messages:
      92
      Likes Received:
      0
      Trophy Points:
      6
      Malwarebytes Anti-Malware 1.65.1.1000
      Malwarebytes : Free anti-malware download

      Database version: v2012.11.26.01

      Windows 7 Service Pack 1 x64 NTFS
      Internet Explorer 8.0.7601.17514
      dustin :: A-COMPUTER [administrator]

      11/26/2012 12:34:02 AM
      mbam-log-2012-11-26 (00-34-02).txt

      Scan type: Quick scan
      Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
      Scan options disabled: P2P
      Objects scanned: 222332
      Time elapsed: 2 minute(s), 42 second(s)

      Memory Processes Detected: 0
      (No malicious items detected)

      Memory Modules Detected: 0
      (No malicious items detected)

      Registry Keys Detected: 0
      (No malicious items detected)

      Registry Values Detected: 0
      (No malicious items detected)

      Registry Data Items Detected: 0
      (No malicious items detected)

      Folders Detected: 0
      (No malicious items detected)

      Files Detected: 5
      C:\Windows\Installer\AMDEx3.msi (Malware.Generic) -> Quarantined and deleted successfully.
      C:\Users\dustin\AppData\Local\Temp\buddyupdater14598437.exe (Trojan.MSIL) -> Quarantined and deleted successfully.
      C:\Users\dustin\AppData\Local\Temp\buddyupdater3250937.exe (Trojan.MSIL) -> Quarantined and deleted successfully.
      C:\Users\dustin\AppData\Local\Temp\buddyupdater48511625.exe (Trojan.MSIL) -> Quarantined and deleted successfully.
      C:\Users\dustin\AppData\Local\Temp\buddyupdater49189765.exe (Trojan.MSIL) -> Quarantined and deleted successfully.

      (end)


      Please don't give me that false positive reply. I want to know exactly what it is/does, specifically AMDEx3.msi.
       
      Last edited: Nov 26, 2012
    2. Aroxan

      Aroxan Banned

      Joined:
      Jul 25, 2012
      Messages:
      375
      Likes Received:
      3
      Trophy Points:
      0
      I'd say false positive, I don't think honorbuddy would really intend on putting viruses on their paying customer's computers.
       
    3. bambam922

      bambam922 Well-Known Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      6,071
      Likes Received:
      28
      Trophy Points:
      48
      False positive.
      As always
       
    4. Hybritian

      Hybritian New Member

      Joined:
      Dec 18, 2011
      Messages:
      106
      Likes Received:
      0
      Trophy Points:
      0
      Make a new installation if your not happy with the flase positive. because like stated above thats exactly what it is.
       
    5. honors

      honors Member

      Joined:
      May 17, 2012
      Messages:
      92
      Likes Received:
      0
      Trophy Points:
      6
      Last edited: Nov 26, 2012
    6. Gaz

      Gaz New Member

      Joined:
      Oct 22, 2012
      Messages:
      108
      Likes Received:
      0
      Trophy Points:
      0
      The bot is designed to "mess" with wow executable of course some AV will warn you, it is not a standard behavior for a program.
       
    7. lallezor

      lallezor New Member

      Joined:
      Jul 31, 2012
      Messages:
      119
      Likes Received:
      1
      Trophy Points:
      0
      HB injects to wow (like malicious programs do) its intented, nothing to worry
       
    8. honors

      honors Member

      Joined:
      May 17, 2012
      Messages:
      92
      Likes Received:
      0
      Trophy Points:
      6
      Thank you both for explaining that without being condescending, I really mean that.
       
    9. bambam922

      bambam922 Well-Known Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      6,071
      Likes Received:
      28
      Trophy Points:
      48
      Since you want a more in-depth explanation..

      Honorbuddy files are packed with something that is similiar to Themidia (If you know what that is).
      Packing the honorbuddy files prevents them from being easily decoded and copied.
      The files being packed alone could set off an anti virus, because said AV will not be able to read honorbuddy code to know what it does.

      Your antivirus is probably detecting the buddy auto updater as a trojan because it automatically will download files without requesting permission to do so, even though you must run it as admin to work correctly.

      As for AMDEx3.msi
      It is a windows installer file.
       
    10. Tony

      Tony "The Bee" Staff Member Moderator

      Joined:
      Jan 15, 2010
      Messages:
      128,834
      Likes Received:
      571
      Trophy Points:
      113
      as its already stated and explained many times,its a false positive

      thread closed
       
    Thread Status:
    Not open for further replies.

    Share This Page