Antivirus changes? menu

User Tag List

Results 1 to 10 of 10
  1. #1
    bg4u's Avatar Member
    Reputation
    1
    Join Date
    Apr 2017
    Posts
    5
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Antivirus changes?

    Hey John, I posted here;
    http://www.ownedcore.com/forums/diab...ml#post3714400 ([HOW TO] Solve your antivirus problems)

    To paraphrase, your old release detected at 8/81, now you/re at 25/62. Your traffic does not appear to be malicious and I looked over your files with peid (pretty familiar with the tool) and the file doesn't appear to be malicious. It doesn't seem like you changed packers, what gives?

    Antivirus changes?
  2. #2
    KillerJohn's Avatar TurboHUD HUDmaster CoreCoins Purchaser Authenticator enabled
    Reputation
    3693
    Join Date
    Jul 2012
    Posts
    2,532
    Thanks G/R
    46/3335
    Trade Feedback
    0 (0%)
    Mentioned
    16 Post(s)
    Tagged
    0 Thread(s)
    Your virustotal link does not match to the latest release's hash. Current release is 6/58.

  3. #3
    bg4u's Avatar Member
    Reputation
    1
    Join Date
    Apr 2017
    Posts
    5
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Are we looking at the same file? Here's the current release of Thud out of the current package
    TurboHUD 17.4.2.10 (v7.2) STABLE for Diablo III 2.5.0.44247 (DX11).zip with a checksum of 0be3ef1daafe58c89edfef959fbb0f4d right?
    Antivirus scan for 67c833585487f374fd7fd98399259055c1071aa2ab095cd65db403ac6f898a04 at
    2017-04-02 19:19:09 UTC - VirusTotal
    12/62 for me


    The version that generated quite a bit of noise was 17.3.30.10 with a md5 of d4299c757d49f2221785fa0fa2ad5977


    I was actually going to ask, now that you don't control the forum and its easy for people to edit your posts and place malware, would you consider having a pgp signature to verify authenticity by perhaps?

  4. #4
    KillerJohn's Avatar TurboHUD HUDmaster CoreCoins Purchaser Authenticator enabled
    Reputation
    3693
    Join Date
    Jul 2012
    Posts
    2,532
    Thanks G/R
    46/3335
    Trade Feedback
    0 (0%)
    Mentioned
    16 Post(s)
    Tagged
    0 Thread(s)
    Define 'people'. I don't think that anybody could edit my posts without visible proof, except the highest admins. You should not worry about the download links...

  5. #5
    KillerJohn's Avatar TurboHUD HUDmaster CoreCoins Purchaser Authenticator enabled
    Reputation
    3693
    Join Date
    Jul 2012
    Posts
    2,532
    Thanks G/R
    46/3335
    Trade Feedback
    0 (0%)
    Mentioned
    16 Post(s)
    Tagged
    0 Thread(s)
    You are posting virustotal links for the .exe file, while I post the link for the .zip, so everything is included. The difference between your (12 false positives) and mine (6) is probably caused by those 6 does not support the zip files somehow (this is an educated guess).

    Peace

  6. #6
    NeoCGS's Avatar Member
    Reputation
    1
    Join Date
    Apr 2017
    Posts
    1
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by KillerJohn View Post
    You are posting virustotal links for the .exe file, while I post the link for the .zip, so everything is included. The difference between your (12 false positives) and mine (6) is probably caused by those 6 does not support the zip files somehow (this is an educated guess).

    Peace
    Latest scan of the ZIP shows 18/58.

    Antivirus scan for 7bdb09c18ba2507321e910eccebd1d2f7cf28e45cec19e5950b06365fbf21f0b at
    UTC - VirusTotal


    Note the identical checksum.

    Even Avast doesn't like it now even after it working fine for a long time with the older ones.
    Last edited by NeoCGS; 04-03-2017 at 11:57 AM.

  7. #7
    bg4u's Avatar Member
    Reputation
    1
    Join Date
    Apr 2017
    Posts
    5
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Yep, something changed. Either one of the packers you are using is listed now as being very suspicious now in AV's or something else. I don't actually think you injected much if any code because the exe is still pretty much the same as the previous versions.

    Edit: To be specific for those who have no idea: I'm saying I don't think KJ has done anything malicious.

    Also, John, NeoCGS is correct;
    x@nope:/tmp$ wget http://www53.zippyshare.com/d/nNp80G...%28DX11%29.zip
    --2017-04-02 11:33:16-- http://www53.zippyshare.com/d/nNp80G...%28DX11%29.zip
    Resolving www53.zippyshare.com (www53.zippyshare.com)... 46.166.139.211
    Connecting to www53.zippyshare.com (www53.zippyshare.com)|46.166.139.211|:80... connected.
    HTTP request sent, awaiting response... 200 OK
    Length: 52395858 (50M) [application/x-download]
    Saving to: ‘TurboHUD 17.4.2.10 (v7.2) STABLE for Diablo III 2.5.0.44247 (DX11).zip’

    100%[================================================================================ ================================================================================ ================================================================================ ===================================>] 52,395,858 7.22MB/s in 8.4s

    2017-04-02 11:33:25 (5.93 MB/s) - ‘TurboHUD 17.4.2.10 (v7.2) STABLE for Diablo III 2.5.0.44247 (DX11).zip’ saved [52395858/52395858]

    x@nope:/tmp$ sha256sum TurboHUD\ 17.4.2.10\ \(v7.2\)\ STABLE\ for\ Diablo\ III\ 2.5.0.44247\ \(DX11\).zip
    7bdb09c18ba2507321e910eccebd1d2f7cf28e45cec19e5950b06365fbf21f0b TurboHUD 17.4.2.10 (v7.2) STABLE for Diablo III 2.5.0.44247 (DX11).zip

    And obviously virus total links by the sha256 hash;
    Antivirus scan for 7bdb09c18ba2507321e910eccebd1d2f7cf28e45cec19e5950b06365fbf21f0b at
    2017-04-03 16:49:04 UTC - VirusTotal

  8. #8
    Blueice22's Avatar Active Member
    Reputation
    71
    Join Date
    Oct 2010
    Posts
    275
    Thanks G/R
    5/5
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I actually noticed the same thing when my AV program did not do anything for the previous version, but this version my AV program would auto delete and I had to go create an exception for the file

  9. #9
    KillerJohn's Avatar TurboHUD HUDmaster CoreCoins Purchaser Authenticator enabled
    Reputation
    3693
    Join Date
    Jul 2012
    Posts
    2,532
    Thanks G/R
    46/3335
    Trade Feedback
    0 (0%)
    Mentioned
    16 Post(s)
    Tagged
    0 Thread(s)
    well, I use the same build toolchain since years, so nothing changed on my side.

  10. #10
    bg4u's Avatar Member
    Reputation
    1
    Join Date
    Apr 2017
    Posts
    5
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Super bizarre. I'm guessing the packer you use is triggering the AV's rule definitions. So ****ing lazy that AV companies use packers for signature analysis.

Similar Threads

  1. How to change models and textures client side only
    By Matt in forum World of Warcraft Guides
    Replies: 9
    Last Post: 11-29-2006, 12:35 AM
  2. Change flight path easily
    By Matt in forum World of Warcraft Exploits
    Replies: 8
    Last Post: 07-27-2006, 04:59 AM
  3. Rep Power change
    By Shanaar in forum Suggestions
    Replies: 25
    Last Post: 05-17-2006, 12:42 PM
  4. Name Change Exploit
    By Matt in forum World of Warcraft Exploits
    Replies: 3
    Last Post: 05-16-2006, 12:50 PM
  5. MMOwned's Server Move + Forum Change
    By Matt in forum OC News
    Replies: 0
    Last Post: 03-25-2006, 04:52 AM
All times are GMT -5. The time now is 05:15 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search