Heroes & Generals

Heroes & Generals

Este tópico foi fechado
[UPDATE: ISSUE FIXED] Malware found on Prototype/Stable/Test servers, Steam/Live servers are safe
UPDATE: This is NOT A PROBLEM ANY LONGER
BUT we wanted to keep the thread and not delete it


-----
We have just discovered a piece of malware in parts of our test environment and identified a trojan.

We want to emphasize that the live servers on Steam and game.heroesandgenerals.com are fine and have NOT been affected.

The problem has been identified and has now been dealt with on the test servers. This is most likely NOT a problem for you, but IF you have accessed and downloaded files from prototype.heroesandgenerals.com, stable.heroesandgenerals.com or test.heroesandgenerals.com there is a risk and we want to make sure you are aware of the issue[/b].

The issue stems from a new trojan identified as Trojan.GenericKD.2797049 (apparently a new variant of Trojan.Win32.Bublik) – as of around midnight (October 14th/October 15th) no antivirus could detect it, but during today (October 15th 2015) more and more have started detecting it, but right now it seems that only around 25% of the available Anti-Virus software out there detects this malware (please see list below).

How to find and remove it?
The free stand-alone Emsisoft Emergency Kit is able to detect this specific trojan (in the version from 04:00 this morning)

What should YOU do?
  1. Go to – https://www.emsisoft.com/en/software/eek/
  2. Download the The Emsisoft Emergency Kit (approx 160mb)
  3. RUN the downloaded file and extract the program.
  4. START the program (default icon on desktop)
  5. UPDATE it (to make sure you have the correct data files from after 04:00 today)
  6. Do a MALWARE SCAN on your machine and let it remove any infected files it might find.
  7. DELETE all test server files located in ‘C:\Program Files (x86)\Heroes & Generals prototype’, ‘C:\Program Files (x86)\Heroes & Generals stable’ and ‘C:\Program Files (x86)\Heroes & Generals test’.

We are not sure what this piece of malware might do as it IS a brand new variant, but we wanted you to know as fast as possible so that it has as little time as possible to create any problems for you. We expect most other anti-virus software to be able to detect and remove it when they get updated over the coming days.

At the time of writing these other anti-malware/anti-virus programs can also detect the Trojan (but ONLY with the most recent and up-to-date data files):

Updated list with the software that has been updated overnight
  • ALYac (16OCT15)
  • AVware (16OCT15)
  • Ad-Aware
  • Antiy-AVL
  • Arcabit
  • Baidu-International
  • BitDefender
  • CAT-QuickHeal
  • Emsisoft
  • F-Secure
  • Fortinet (16OCT15)
  • GData
  • Ikarus
  • Jiangmin
  • Kaspersky
  • MicroWorld-eScan
  • Panda
  • VIPRE (16OCT15)
  • ViRobot (16OCT15)
  • nProtect
Última alteração por Reto.Robotron3000; 20 jan. 2016 às 1:10
< >
A mostrar 46-60 de 61 comentários
[95th]Dave 26 out. 2015 às 13:39 
Norton disabled the game and would not let me load. I deleted all the files and reinstalled from steam; and it is still blocking it as a threat.
76561198141010487 26 out. 2015 às 13:43 
Originalmente postado por 95thDave:
Norton disabled the game and would not let me load. I deleted all the files and reinstalled from steam; and it is still blocking it as a threat.
Yea that should be saying somthing to the devs but of course they are still claiming the steam servers are clean. IM not tryin to troll, but seriously...the devs saying everyhting is clean is a big joke.
bastar89 ✠ 26 out. 2015 às 13:45 
Originalmente postado por Leinöl Richie:
Everytime i want to update Heroes&Generals my Avira detects a trojan

Program Files (x86)\Steam\steamapps\downloading\227940\hng.exe
[FUND] Ist das Trojanische Pferd TR/Crypt.XPACK.Gen2

same here.... AVIRA detect: " TR/Crypt.XPACK.Gen2 " (hng.exe) :wasted:
21:32 MEZ 26.10.15 Auto. Steam Update !!! :facepunch:
biLoo™ 26 out. 2015 às 14:14 
Originalmente postado por MyName'sJeff:
wait we need to do that because i get kicked from game its say ICR or IRC server cannot connect ??

same here, and low fps (on steam only)
FD_Stalker 26 out. 2015 às 23:39 
Looks like devs forgot to run the virus killer after they downloaded the porn and updated it with .9G update
bastar89 ✠ 26 out. 2015 às 23:45 
:steambored:
Daddy-oh 27 out. 2015 às 0:49 
After young update I had no in game chat or Main Chat (null0) in main chat. In game chat you could type words but the didnt diaplay when enter was pressed. Cant acess game in steam run.exe was identified as a trojan by AVG 1hr ago.




Originalmente postado por Reto.Robotron3000:
We have just discovered a piece of malware in parts of our test environment and identified a trojan.

We want to emphasize that the live servers on Steam and game.heroesandgenerals.com are fine and have NOT been affected.

The problem has been identified and has now been dealt with on the test servers. This is most likely NOT a problem for you, but IF you have accessed and downloaded files from prototype.heroesandgenerals.com, stable.heroesandgenerals.com or test.heroesandgenerals.com there is a risk and we want to make sure you are aware of the issue[/b].

The issue stems from a new trojan identified as Trojan.GenericKD.2797049 (apparently a new variant of Trojan.Win32.Bublik) – as of around midnight (October 14th/October 15th) no antivirus could detect it, but during today (October 15th 2015) more and more have started detecting it, but right now it seems that only around 25% of the available Anti-Virus software out there detects this malware (please see list below).

How to find and remove it?
The free stand-alone Emsisoft Emergency Kit is able to detect this specific trojan (in the version from 04:00 this morning)

What should YOU do?
  1. Go to – https://www.emsisoft.com/en/software/eek/
  2. Download the The Emsisoft Emergency Kit (approx 160mb)
  3. RUN the downloaded file and extract the program.
  4. START the program (default icon on desktop)
  5. UPDATE it (to make sure you have the correct data files from after 04:00 today)
  6. Do a MALWARE SCAN on your machine and let it remove any infected files it might find.
  7. DELETE all test server files located in ‘C:\Program Files (x86)\Heroes & Generals prototype’, ‘C:\Program Files (x86)\Heroes & Generals stable’ and ‘C:\Program Files (x86)\Heroes & Generals test’.

We are not sure what this piece of malware might do as it IS a brand new variant, but we wanted you to know as fast as possible so that it has as little time as possible to create any problems for you. We expect most other anti-virus software to be able to detect and remove it when they get updated over the coming days.

At the time of writing these other anti-malware/anti-virus programs can also detect the Trojan (but ONLY with the most recent and up-to-date data files):

Updated list with the software that has been updated overnight
  • ALYac (16OCT15)
  • AVware (16OCT15)
  • Ad-Aware
  • Antiy-AVL
  • Arcabit
  • Baidu-International
  • BitDefender
  • CAT-QuickHeal
  • Emsisoft
  • F-Secure
  • Fortinet (16OCT15)
  • GData
  • Ikarus
  • Jiangmin
  • Kaspersky
  • MicroWorld-eScan
  • Panda
  • VIPRE (16OCT15)
  • ViRobot (16OCT15)
  • nProtect
Última alteração por Daddy-oh; 27 out. 2015 às 0:49
Twister 57 27 out. 2015 às 15:40 
I hear they are looking for Bigfoot hunters ... if you find you need to fill up some freed up extra time ... you would be good at that ... bigfoot are attracted to nuts .
https://youtu.be/n6RoOwSKI7M
Good_ShotMan 27 out. 2015 às 15:48 
Do I have this too? I need to know cause I don't want to get a computer virus.
76561198141010487 27 out. 2015 às 15:53 
Originalmente postado por LOLWUTZ XD:
Do I have this too? I need to know cause I don't want to get a computer virus.
I suggest you just do a scan using one of their suggest virus scan programs listed above or use a paid one if u have it. Its the best way to get peace of mind. As for me, i just uninstalled the game while yesterday's update was still in que and probably wont play for awhile until this mess is fixed permenetly. People are saying that the update had a "false possitive" file that antivirus programs were picking up as a possible malware. Now the antivirus programs are saying it really is a virus, or so people are saying on the forums :(
Twister 57 27 out. 2015 às 16:08 
Its a false positive hoax this guys has been promoting . Scroll back about 4,5,6 pages and you will see reto has locked threads on this topic several times and you can read retos response - just scroll back and find threads then start from there - false positive -no one is getting infected from this sight .. lots playing -this is old bogus news !
Daddy-oh 27 out. 2015 às 17:22 
I am also running the Windows version and it seems clean nothing detected when i ran a scan it was just the steam version that scanned positive,
bastar89 ✠ 27 out. 2015 às 18:06 
nothing is old...its actual trojan ( TR.Crypt.Gen2 ) its your own risk, I would not play until they are officially fix it ( on steam ) .... !!! wtf :wasted:
Última alteração por bastar89 ✠; 27 out. 2015 às 18:08
toonforce 27 out. 2015 às 18:34 
Last night i uploaded the suspicious file to avira. The first check said trojan detected but at 12:40 (24h) I got a mail of avira, that its false positive and the Detection is removed from virus definition file (VDF) with the version 8.12.21.92.

So actual.
Última alteração por toonforce; 27 out. 2015 às 18:36
76561198141010487 27 out. 2015 às 21:00 
Originalmente postado por Twister 57:
Its a false positive hoax this guys has been promoting . Scroll back about 4,5,6 pages and you will see reto has locked threads on this topic several times and you can read retos response - just scroll back and find threads then start from there - false positive -no one is getting infected from this sight .. lots playing -this is old bogus news !
Twister, if it is a false possitive then explain why most antivirus programs and players finding it as malicious? Im far from the only one. Even if it is indeed a false possitive, and ill be the first to appaulaize (if it trully is) the facts remain, the devs still should have done a better job with both in protecting the test servers as well as making sure nothing in their update files wuld be taged as malware or even a possible false possitive. It shows disrespect for us players and blatant lack of proper work ethic and respectability, let alone responsibility to own up to their mistakes on the dev's side.
< >
A mostrar 46-60 de 61 comentários
Por página: 1530 50

Postado a: 15 out. 2015 às 8:36
Comentários: 61