Planetside.exe virus Win32: Hoblig [Heur]

Discussion in 'Player Support' started by Renegade, May 11, 2013.

  1. Artifex78

    Problem is gone with the latest Test Server build (or new Avast virus definitions).
  2. CharlieTwoZero

    i got this warning today, trying to install the latest patch.
  3. JonboyX


    * either side of something used to be the shorthand for bold text iirc.
  4. WTSherman

    Back in ye olde days before e-mails supported HTML formatting, putting a word between *'s represented bold text, and as such was used for emphasis because it was considered more polite than all caps. It's a little quirk that has stuck around, since even after e-mails adopted HTML support many IM and IRC clients did not. Then as those started getting more modern, texting came along. Twitter also doesn't support formatting IIRC, so the use of ** for emphasis persists there too.

    As a result, many people still have a habit of using *bold* to represent bold, even when the feature is available. Though some schools of etiquette have it representing italics, though only in the context of emphasis.

    Oh, and in the same context, if you're not actually quoting something then putting a word in "quotes" usually indicates sarcasm or skepticism. Just like air quotes.

    Now you know, and knowing is half the battle!
  5. cykro

    Adding an exception is never a good idea. Before we know it, your update server is actually compromised and we all get f*****d because of it. Don't say it wil never happen, you can't guarantee that. It happens. I mean, you don't even need an external security breach; all it would take is a disgruntled employee. Just fix it either through Avast or your code.
    • Up x 1
  6. sagolsun

    I know, right? That's Sony Music Entertainment's job - formerly Sony BMG.
    http://www.networkworld.com/news/2010/110110-sonybmg-rootkit-fsecure-drm.html

    Antivirus signatures don't pop up randomly like that - it's either due to optimization or new anti-cheat functionality. Neither UI changes nor the stuff mentioned in patchnotes should result in virus detection.
    • Up x 2
  7. Loui5D

    If your whining about creating an exclusion, temporarily stop on access scanning, then retry the download.
  8. Leer

    • Up x 1
  9. sagolsun

  10. Leer

    BTW: I see you posted this first. Thunder is yours.
  11. Sovereign533

    Is there a work around for this issue?
  12. Crashtopher

    avast! Workaround for windows 7:

    **Note, I take no responsibility for bad things happening to you.**

    In the menu bar at the bottom of your monitor, click on the small triangle , which will open your "notification area Icons". You should see an avast! logo (small orange circle with an a in it). Right click on it and right click on the avast! Icon, select"avast! shields control" then "Disable for 10 minutes". You may have a popup box that warns you are about to disable your antivirus software. Click okay then run the Planetside Launchpad as normal and the game should update.

    Then, to prevent the file from being read as a virus during a system scan, go into avast! exclusions and add the Planetside2 folder per the instructions below.

    Just tried this and it works fine now.
  13. Sovereign533

    I was hoping for a way without doing that =\
  14. Pazzonni

    Well, i guess i'm playing something else tonight. No way i'm adding an exception to Avast, i've never had virus problems since i installed it, so i prefer to trust it. Better fix it quickly, my SOE friends, a virus problem is gonna scare a lot of ppl. (not me, i'll just wait - love the game too much)
    • Up x 1
  15. sagolsun


    SOE has probably already contacted Avast to put PS2 on the whitelist. Now it's up to Avast.
  16. Firnion

    Still having problems all fixes listed above and from other threads have not been helpful :(
  17. 6pecx

    Create an exclusion for the planetside 2 install directory until a solution is present then the Anti-virus will not scan or detect the main
    executable file or create the exclusion just for the main executable file its flagging.

    I do recommend looking for a better anti-virus program as the one your using has higher then normal false positive strike rate.

    Bitdefender would be one good option
  18. Dave Mercer

    no matter what i do i cant get my antivirus to stop blocking it
  19. GlorifiedMurderer

    Heuristics is something that acts or seems like a virus. So its possible especially in this case, its a false positive. If it keeps coming back that's because the patcher keeps adding it. Move it to your virus chest then add it to exceptions or restore it. Also, do not use Norton/Symantec; they're one of the worst antivirus programs available.
  20. Jakes

    Sony must revisit this patch immediately, this may not be a false positive as suggested.

    After installing the patch last night I was able to detect the same Hoblig-B virus which is not just your average day virus, it is a rootkit and MBR infector and is able to conceal itself upon successful infection. After removing the patch file and shutting down for the evening I returned to boot my computer this morning and found that the Hoblig-B virus had jumped from the deleted patch file to the Planetside2.exe file and attempted to access itype.exe and accompanying dll's. This is suggestive of a keylogger as the itype.exe is a primary function of Microsoft keyboard driver loader. Further more if this were a false positive it would not have executed itself upon a computer booting up, which unfortunately alludes to my computer's MBR already being infected.

    My trust for SOE's development staff has diminished from zero to negative territory as this would not be the first time Sony was involved in MBR based rootkits (Sony settled a lawsuit only 7 years ago). This type of situation is completely unnecessary, avoidable, and truly displays a development team that is lacking heavily in any form of testing or quality control.

    There should be absolutely no reason that a Planetside2 patch file would try to execute and take over the itype.exe keyboard process and drivers upon a computer boot up. I cannot stress this enough, this should NOT be occurring if it is a 'false positive.'
    • Up x 6