What's new
  • Visit Rebornbuddy
  • Visit Panda Profiles
  • Visit LLamamMagic
  • Visit Resources
  • Visit Downloads
  • Visit Portal

Attention to all users that have no AV installed and downloaded HB/DB past 24 hours

They got me the bastards! and im just 3 days new to this botting :(

Greetings,

Due to an unusual change in your access pattern, the Battle.net account *************** has been locked. This can be caused by logging in from a new location, but it may also signal an attempt to compromise your account


I dont know if they gained access to my ingame stuff.. but this is horrid..

when i saw this thread in the morning i instantly scanned my pc with comodo and changed evrything they didnt got my golds:)
 
I'm glad I never us HB before I have deobfuscated and reprotected the app, as I don't like your protection methods, you doesn't even hide from the process list which is easy with RunPE injection, and you use smartassembly to obfuscate which is shit.
But didn't have time to re-protect it this morning so didn't use it.

I wonder why you don't even hide your update address, string encrypt it or something so stuff like this don't happen.
just to be clear, they didnt change the honorbuddy executible, as far as i know they added some nasties in the zip file any script kiddy can do that.
 
They got me the bastards! and im just 3 days new to this botting :(

Greetings,

Due to an unusual change in your access pattern, the Battle.net account *************** has been locked. This can be caused by logging in from a new location, but it may also signal an attempt to compromise your account


I dont know if they gained access to my ingame stuff.. but this is horrid..


Probably not if it got locked, but that really sucks regardless. :(
 
I used the new beta, am I safe?
you should be fine, like i said if you got a warning on you AV and just dismissed it, then chances are you have it. if your paranoid then run a scan and you should be fine.
 
just to be clear, they didnt change the honorbuddy executible, as far as i know they added some nasties in the zip file any script kiddy can do that.
Aaah okay, thought they binded something to the exe.
but i don't understand why don't u use string encryption in the program? Tp prevent people to retrieve the update address.
 
im kind of wondering, they are getting access to your server, which shouldnt be that easy, but then they're
just using public trojans and shit? sounds like theres an unpub exploit for your server/software, which is sold / given away
to noobs ^^ well its greats that its easy to detect, but what if they start use better tools?
lets see, they infect our pc, use it as *****, kill our account and what can we do ? nothing!
cuz blizz tells us, oh no, it must have been you, else the ip system would be triggerd!!!
 
Can someone say which AVs detect the Malware and what "Codename" it got?

I tried Malware Bytes and Avira AntiVir... nothing found.

Does it maybe copy itself into any System-Folder?
 
Well.. i got an update, update it like 5 times couse i keept spamming checked this thread and seems like i have a trojan now? I do not have a AV... 557 build is effected?
 
Home links to build 557 again.

didnt notice at first, was promted to update when I ran it, got some error and the .exe was deleted.
 
Last edited:
Whats up with the download section linking to build 557 again?

Got some errors with quest behaviors because I have build 560, wanna update to 561.
 
Whats the current Release Version .557? .560? or 561? ... first i got an Update from .557 to .560 later i got a downgrade info to go back from .560 to an older version.
 
All version's where updated at 15:00 GMT today. If this is correct or not is not for me to decide.

Code:
<Buddy> New Release : Demonbuddy 1.0.1397.200 Beta http://updates.buddyauth.com/GetNewest?filter=DemonbuddyBETA
<Buddy> New Release : Honorbuddy 2.5.7005.227 Beta http://updates.buddyauth.com/GetNewest?filter=HonorbuddyBETA
<Buddy> New Release : Tankleader 1.0.492.136
<Buddy> New Release : BuddyWing 1.0.988.381
<Buddy> New Release : Demonbuddy 1.0.1395.305
<Buddy> New Release : Honorbuddy 2.5.6948.557
 
Can someone say which AVs detect the Malware and what "Codename" it got?

I tried Malware Bytes and Avira AntiVir... nothing found.

Does it maybe copy itself into any System-Folder?

Both of them would have detected it.
 
Whats the current Release Version .557? .560? or 561? ... first i got an Update from .557 to .560 later i got a downgrade info to go back from .560 to an older version.

i think version 560 had a bug when you standing with the vendor it keeps saying Interactingwith debug bla bla and kept it spamming and it didnt moved.
 
awsome i downloaded version 577 and my internet keeps dcing again and comes back
 
Back
Top