> Forest of True Sight > Questions & Answers Reload this Page Texmod containing a malware trojan
Reply
Old May 26, 2008, 02:49 PM // 14:49   #1
Forge Runner
 
N1ghtstalker's Avatar
 
Join Date: Dec 2007
Profession: E/
Advertisement

Disable Ads
Default Texmod containing a malware trojan

hi,

i'm going for my cartographer title and decided to use texmod since my friend suggested it
i downloaded it on the link at the wiki but when i download i get message that it contains a trojan
any advice what i should do?
N1ghtstalker is offline   Reply With Quote
Old May 26, 2008, 02:53 PM // 14:53   #2
Jungle Guide
 
miskav's Avatar
 
Join Date: Jun 2005
Guild: None
Profession: Mo/
Default

if it's used it'll give a warning on anti-spyware scanners about a file called wtf###.pl or something like that, it's just that texmod alters some files in GW, and the anti-spyware see it as spyware lol.

By the way, be sure you downloaded it from a legit place, and not a suspicous link.
miskav is offline   Reply With Quote
Old May 26, 2008, 02:56 PM // 14:56   #3
Academy Page
 
Ras Kass's Avatar
 
Join Date: Aug 2005
Location: Waterloo, Canada
Guild: FF
Profession: W/A
Default

I remember seeing this in the texmod thread. It turned out to be some sort of bug that the anti-virus software will pick up on. I am no techie, so I am sure someone will be posting the specifics which you will find more settling. Either way its harmless.
Ras Kass is offline   Reply With Quote
Old May 26, 2008, 02:58 PM // 14:58   #4
Forge Runner
 
N1ghtstalker's Avatar
 
Join Date: Dec 2007
Profession: E/
Default

it's about this filename: http://38.118.213.252/7waa9ktmhx+/pe...X6\Texmod.exe\[NsPack]\[ASPack]\[Embedded#30050]

walmare name: Win32:Trojan-gen {Other}

type is virus/worm

it came from filrefront where wiki directed you too
N1ghtstalker is offline   Reply With Quote
Old May 26, 2008, 03:00 PM // 15:00   #5
Forge Runner
 
pamelf's Avatar
 
Join Date: Aug 2006
Location: Australia
Guild: Lost Templars [LoTe]
Profession: Me/Mo
Default

Texmod creates temporary files which are picked up as trojans by some anti virus programs, but are in fact not...
pamelf is offline   Reply With Quote
Old May 26, 2008, 03:01 PM // 15:01   #6
Forge Runner
 
N1ghtstalker's Avatar
 
Join Date: Dec 2007
Profession: E/
Default

so i won't try to log on one day to find my account has been hacked?
then it'll be fine i guess (:
N1ghtstalker is offline   Reply With Quote
Old May 26, 2008, 03:03 PM // 15:03   #7
Forge Runner
 
snaek's Avatar
 
Join Date: Mar 2006
Profession: N/
Default

definately not a threat
snaek is offline   Reply With Quote
Old May 26, 2008, 03:12 PM // 15:12   #8
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT??0 ??1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Default

It's a false-positive that keeps popping up. I even reported it myself a while back because of the current spate of account thefts.

It's due to the nature of TexMod - because of the way it works, interrupting data between Guild Wars and the display, a lot of malware scanners see it as very trojan-like behaviour.

Yes, your account is safe - but, in the current climate, take extra precautions anyway. Cahnge your password to a strong one - something like gy4$ i(]e5ld; m03-=+f[/ for example.
__________________
Si non confectus, non reficiat
Snograt is offline   Reply With Quote
Old May 26, 2008, 03:26 PM // 15:26   #9
Ascalonian Squire
 
Kaide's Avatar
 
Join Date: Apr 2008
Location: Finland
Guild: Cold Summer Breeze
Profession: W/
Default

And now you say it :P I already deleted the textmod, scanned pc, and was about to format...(I had the same problem obviosly :P)
Kaide is offline   Reply With Quote
Old May 26, 2008, 03:42 PM // 15:42   #10
Krytan Explorer
 
fusa's Avatar
 
Join Date: Mar 2007
Default

Which AV programs are giving the warnings? I've scanned the texmod I downloaded several months ago with nod32, avast, avg, ad-aware and spybot search & destroy, non have shown warnings.
fusa is offline   Reply With Quote
Old May 26, 2008, 04:32 PM // 16:32   #11
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT??0 ??1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Default

I have a feeling that it depends on when the malware scan is done. As Miskav and Pamelf pointed out, it's the temporary files tha trigger the alert - wtf213.dll or whatever (wtf = Windows Temporary File, by the way). As these files reside in TEMP and are deleted after use, it's likely that they're not detected at all if the scanner runs when TexMod isn't running.

AVG picked it up for me - will test NOD later by scanning when TexMod's running to see if that does it too.
__________________
Si non confectus, non reficiat
Snograt is offline   Reply With Quote
Old May 26, 2008, 04:43 PM // 16:43   #12
Desert Nomad
 
Tatile's Avatar
 
Join Date: Sep 2007
Guild: Stygian Disciples of Tenebrasus
Profession: N/Me
Default

Quote:
Originally Posted by fusa
Which AV programs are giving the warnings?
I've got AVG Free Edition (either the latest or the one before that 7.5, can't remember) and it pops Texmod up as a false positive. It worried me at first but then googling WTF##.tmp fixed that.

Yeah, Mircoshaft knows really well how to name their files.

Edit: Wait, Trojan warning during startup (of Texmod)? I don't get that, just wtf##.tmp's appearing in the daily scan. How odd.

Last edited by Tatile; May 26, 2008 at 04:49 PM // 16:49..
Tatile is offline   Reply With Quote
Old May 26, 2008, 04:46 PM // 16:46   #13
Ascalonian Squire
 
Cyric The Liar's Avatar
 
Join Date: Mar 2008
Guild: [MBA]
Profession: N/Mo
Default

It's funny, but I've had texmod on my PC for one month now and never had a problem, but today I suddenly get the trojan warning like the others have reported when I try to run it. Something is weird here and I think I'll take a break from using it.
Cyric The Liar is offline   Reply With Quote
Old May 26, 2008, 05:44 PM // 17:44   #14
Ascalonian Squire
 
wyrd's Avatar
 
Join Date: Feb 2008
Guild: Halo
Profession: P/
Default

Ive been using Texmod a while now and haven't gotten any virus warning but today avast detected a virus mentioned above "Win32:Trojan-gen {Other}"
Probably after a recent definition update. after running Texmod and avast detects it wont run gw.exe there is just a popup window saying "D'OH"

A virus scan afterwards however detects nothing probably because as mentioned above is in a temp directory and doesn't go beyond that.

Edit:Note Texmod runs Gw.exe normally if no tpf file is loaded the virus alert only happens when a tpf file is loaded no matter which one.

Last edited by wyrd; May 26, 2008 at 05:51 PM // 17:51..
wyrd is offline   Reply With Quote
Old May 26, 2008, 05:49 PM // 17:49   #15
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT??0 ??1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Default

Quote:
Originally Posted by wyrd
Probably after a recent definition update.
That, I suspect, is the answer.
__________________
Si non confectus, non reficiat
Snograt is offline   Reply With Quote
Old May 26, 2008, 05:58 PM // 17:58   #16
Desert Nomad
 
Mr. G's Avatar
 
Join Date: Jul 2006
Location: S. Wales
Profession: Mo/Me
Default

ive been using texmod since the GW modding community started...and tbh im tired of telling people its clean...its clean DAMMIT

it alters files so cheap and tbh...crap scanning software (AVG comes to mind) think it has to be a trojan of some sort
Mr. G is offline   Reply With Quote
Old May 26, 2008, 06:06 PM // 18:06   #17
Forge Runner
 
kvndoom's Avatar
 
Join Date: Jul 2005
Location: Communistwealth of Virginia
Guild: Uninstalled
Profession: W/Mo
Default

Quote:
Originally Posted by wyrd
Ive been using Texmod a while now and haven't gotten any virus warning but today avast detected a virus mentioned above "Win32:Trojan-gen {Other}"
Probably after a recent definition update. after running Texmod and avast detects it wont run gw.exe there is just a popup window saying "D'OH"

A virus scan afterwards however detects nothing probably because as mentioned above is in a temp directory and doesn't go beyond that.

Edit:Note Texmod runs Gw.exe normally if no tpf file is loaded the virus alert only happens when a tpf file is loaded no matter which one.
It won't run on my main system either unless I disable AVG's real-time virus protection. Which is fine, if all I'm doing is playing GW. Seems to work if I disable AV, open GW with texmod, then re-enable AV.
kvndoom is offline   Reply With Quote
Old May 26, 2008, 06:29 PM // 18:29   #18
Desert Nomad
 
Join Date: May 2006
Profession: Mo/E
Default

ok,so I have used textmod since like almost 1.5year now..and today when I used textmod again..the wtf...thing went up on my screen, so I saw DOH and sh*** happens appear on my screen,so I thought I got the keylogger,but I dont know,so I post here for a answer...
OS T is offline   Reply With Quote
Old May 26, 2008, 07:18 PM // 19:18   #19
Ascalonian Squire
 
wyrd's Avatar
 
Join Date: Feb 2008
Guild: Halo
Profession: P/
Default

Some viruses activate on a particular day today being U.S Memorial day it seems suspicious but more likely it is caused by a virus definition update. It seems it has suddenly occured today to many people using different av programs so anyone using it should be cautious.

If you want to use Texmod turn anti-virus off until Guild Wars loads or dont use it.
wyrd is offline   Reply With Quote
Old May 26, 2008, 07:42 PM // 19:42   #20
Hell's Protector
 
Quaker's Avatar
 
Join Date: Aug 2005
Location: Canada
Guild: Brothers Disgruntled
Default

My advice, use Texmod to do your Cartography titles and then put it away - it's too dam glitchy to use for much else. And who knows what version is "clean", when.

As far as the rest of the graphics stuff you can do with it goes, only you can see it anyway, so why bother.
Quaker is offline   Reply With Quote
Reply


Share This Forum!  
 
Thread Tools
Display Modes

Similar Threads
Thread Thread Starter Forum Replies Last Post
Texmod and wtf*.tmp trojan horse hyunsik Questions & Answers 36 Apr 29, 2009 07:52 PM // 19:52
Serious malware/trojan problem Malice Black Technician's Corner 27 Oct 12, 2006 05:11 PM // 17:11
victor Technician's Corner 6 Dec 28, 2005 07:27 PM // 19:27
Elistan Theocrat Off-Topic & the Absurd 10 Oct 19, 2005 03:17 AM // 03:17


All times are GMT. The time now is 01:29 AM // 01:29.