Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Inner Circle > The Riverside Inn

Notices

Reply
 
Thread Tools Display Modes
Old May 13, 2008, 10:57 PM // 22:57   #1
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Advertisement

Disable Ads
Default Virus alert - PWS Lineage

I am one of three people in my far-flung family who's virus checker has detected the PWS Lineage trojan recently. It was originally designed to steal passwords from Lineage , but over the years has gradually been altered to gather logins from several other games - see here http://vil.nai.com/vil/content/v_130590.htm

Usual advice applies - make sure you have a good virus checker installed and that it's definitions are up to date. And let the bugger finish its scan - I know how annoying virus scans can be, but they're a necessary evil.

Apologies if this is the texmod false-positive again - it's a possibility, but it's better to be safe than sorry, Especially with all the recent account thefts.

The trojan was detected by AVG 8.0 - not sure where mine was, but my cousin-in-law's was in her GW folder
__________________
Si non confectus, non reficiat

Last edited by Snograt; May 14, 2008 at 12:14 AM // 00:14..
Snograt is offline   Reply With Quote
Old May 13, 2008, 11:01 PM // 23:01   #2
Wilds Pathfinder
 
tommarrow's Avatar
 
Join Date: Dec 2005
Guild: Shyft Machine [MYTH]
Profession: E/
Default

Thanks for the heads up Snograt.
tommarrow is offline   Reply With Quote
Old May 13, 2008, 11:06 PM // 23:06   #3
Forge Runner
 
Darkobra's Avatar
 
Join Date: Aug 2006
Location: Scotland
Guild: Type like an idiot, I'll treat you like an idiot
Profession: E/Me
Default

The more security awareness, the better. Now I have a specific target to look for.
Darkobra is offline   Reply With Quote
Old May 13, 2008, 11:09 PM // 23:09   #4
Krytan Explorer
 
fusa's Avatar
 
Join Date: Mar 2007
Default

Which virus scanner did you use? What files were infected?
fusa is offline   Reply With Quote
Old May 13, 2008, 11:13 PM // 23:13   #5
Desert Nomad
 
Sarevok Thordin's Avatar
 
Join Date: Apr 2006
Location: Scotland
Profession: W/N
Default

How does infection take place.
Sarevok Thordin is offline   Reply With Quote
Old May 13, 2008, 11:14 PM // 23:14   #6
Wilds Pathfinder
 
NoXiFy's Avatar
 
Join Date: Aug 2007
Location: ★☆٭Ńēŵ~ŶờЯК٭☆★
Guild: The Benecia Renovatio [RenO]
Profession: Mo/Me
Default

keyloggers suck
NoXiFy is offline   Reply With Quote
Old May 13, 2008, 11:47 PM // 23:47   #7
Lion's Arch Merchant
 
Dylananimus's Avatar
 
Join Date: Mar 2007
Guild: The Eternal Champions
Profession: W/Mo
Default

I got that virus the other week, on a brand new comp that was fully protected :/

I had to reformat just to be on the safe side.

AVG picked it up, and quarantined it. I couldn't see that it had escaped the Temp folder and done anything to the registry, but that's apparently what it would have done if undetected.

I scan twice a day now, both Virus and Spyware programs.

And no...I didn't have Textmod on the comp.
Dylananimus is offline   Reply With Quote
Old May 14, 2008, 12:12 AM // 00:12   #8
Lion's Arch Merchant
 
Join Date: Oct 2005
Location: Mexico
Guild: Go for the eyes [jizz]
Profession: W/Mo
Default

Looks like the only reasonable explanation for all the "hacking" goin' around.
Taurus is offline   Reply With Quote
Old May 14, 2008, 12:35 AM // 00:35   #9
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Default

Edited the OP with more info - detected by AVG 8.0 and in one instance in the GW folder.

I am unaware what specific file was involved - probably PWS-Lineage.dll, according to online databases. I think that, like Dylananimus, mine was in my Temp folder, which would be typical of this particular Trojan.
__________________
Si non confectus, non reficiat
Snograt is offline   Reply With Quote
Old May 14, 2008, 12:39 AM // 00:39   #10
Desert Nomad
 
Join Date: Jun 2006
Location: Look out!
Profession: E/
Default

Wow, I used to play lineage, nowadays you probably couldn't give your US account away since nobody plays it anymore. Guess I'll go update my AVG.
crazybanshee is offline   Reply With Quote
Old May 14, 2008, 01:00 AM // 01:00   #11
Furnace Stoker
 
MisterB's Avatar
 
Join Date: Oct 2005
Location: Planet Earth, Sol system, Milky Way galaxy
Guild: [ban]
Profession: W/
Default

I just ran a scan with AVG 7.5, and turned up a report for PWS Lineage, but I'm fairly certain it's a false positive in my case. The file was wtf(#).tmp in my local temp folder, where (#) was a number I don't remember. I use TexMod, hence my suspicion it was a false positive. None of the other files associated with PWS Lineage were found in the scan. Updating to AVG 8.0 now.
MisterB is offline   Reply With Quote
Old May 14, 2008, 03:32 AM // 03:32   #12
Popcorn Fetish
 
Zehnchu's Avatar
 
Join Date: Dec 2005
Guild: [GODS]
Profession: Mo/Me
Default

Trojan Horse PSW.Linage.AGX

View your scan history in AVG 8.0
Computer Scanner->Scan History->any blue colored scheduled scan (will indicate which scans have infections.)->Infections

Location
C:\Users\Name Of User\AppData\Local\Temp\
Files It's been named
wtfD8D6.tmp
wtf1BAE.tmp
wtf2091.tmp
wtf41A1.tmp
wtf2E5.tmp
wtf674B.tmp
wtf715A.tmp
wtfA2CA.tmp
wtfDF75.tmp
Wtf9686.tmp
Wtf8A03.tmp
Wtf7A41.tmp
wtf6831.tmp
WtfEBEB.tmp

And it's only been found in the Temp folder. I ran a texmod a few ways then scanned the temp folder and Guild Wars folders and found nothing. But I'll Keep an eye on it.
Zehnchu is offline   Reply With Quote
Old May 14, 2008, 03:35 AM // 03:35   #13
Major-General Awesome
 
fenix's Avatar
 
Join Date: Aug 2005
Location: Aussie Trolling Crew HQ - Event Organiser and IRC Tiger
Guild: Ex Talionis [Law], Trinity of the Ascended [ToA] ̖̊̋̌̍̎̊̋&#
Profession: W/
Default

Has anyone detected this with an anti-virus that ISN'T AVG? I know it shows some false-positives...but this is ridiculous. Someone try with NOD32 or something decent.
fenix is offline   Reply With Quote
Old May 14, 2008, 04:01 AM // 04:01   #14
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Default

Good point.

Incidentally, my AVG found wtf# files too - forgot until Zehnchu mentioned it.

[edit] hmm, this may well be a TexMod false-positive after all
Quote:
everytime i use texmod (dl'd with the link in guildwiki), i get this trojan called wtf#.tmp
#=some random number

Is it a dangerous trojan?
http://www.guildwarsguru.com/forum/s...7&postcount=14

Maybe when AVG updated from 7.x to 8 it started to falsely tag TexMod again - I've had it installed for ages and AVG's never been bothered before.
__________________
Si non confectus, non reficiat

Last edited by Snograt; May 14, 2008 at 04:07 AM // 04:07..
Snograt is offline   Reply With Quote
Old May 14, 2008, 04:04 AM // 04:04   #15
Forge Runner
 
pamelf's Avatar
 
Join Date: Aug 2006
Location: Australia
Guild: Lost Templars [LoTe]
Profession: Me/Mo
Default

i'm updating to AVG 8.0 as we speak, so if I have it, hopefully it will be picked up. Thanks for the heads up.
pamelf is offline   Reply With Quote
Old May 14, 2008, 04:13 AM // 04:13   #16
Major-General Awesome
 
fenix's Avatar
 
Join Date: Aug 2005
Location: Aussie Trolling Crew HQ - Event Organiser and IRC Tiger
Guild: Ex Talionis [Law], Trinity of the Ascended [ToA] ̖̊̋̌̍̎̊̋&#
Profession: W/
Default

I downloaded it, and scanned the .zip with NOD32, detected nothing. Considering the zip comes with Texmod.exe and Readme.txt, I decided just to leave it zipped, and no extract or anything, since there wasn't a reason to (already have it on the computer).

AVG fails?


Edit: Scanned my Temp files and found nothing also. <3 NOD32

Last edited by fenix; May 14, 2008 at 04:26 AM // 04:26..
fenix is offline   Reply With Quote
Old May 14, 2008, 04:39 AM // 04:39   #17
Forge Runner
 
Lykan's Avatar
 
Join Date: May 2005
Guild: StP
Profession: R/
Default

I only have the free Avg 7.5, can it be updated to 8.0?
Lykan is offline   Reply With Quote
Old May 14, 2008, 05:19 AM // 05:19   #18
Wilds Pathfinder
 
Shakti's Avatar
 
Join Date: Sep 2006
Location: Home...
Guild: Vier Reiter [Vier]
Default

OK now I'm worried about textmod. My hubby DLed Textmod a month or so ago (I think from the "safe" link here but I'll check when he gets home) so I could do cartographer.

I use McAffee SecurityCenter among other scans, and after reading this and the other threads, ran the scan just on the Textmod.exe file itself. It came up with a trojan New Malware.aj to be exact. Seems to be a 2006 Heuristic trojan (wtf ?)

Crap.
Shakti is offline   Reply With Quote
Old May 14, 2008, 05:28 AM // 05:28   #19
rattus rattus
 
Snograt's Avatar
 
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
Default

Don't worry yet - because of TexMod's nature of intercepting system calls, a lot of virus scanners have falsely identified it as a virus/trojan. I think that the AV companies can be reassured of a program's validity and virus definitions can be updated to ignore it.
__________________
Si non confectus, non reficiat
Snograt is offline   Reply With Quote
Old May 14, 2008, 05:34 AM // 05:34   #20
Wilds Pathfinder
 
Shakti's Avatar
 
Join Date: Sep 2006
Location: Home...
Guild: Vier Reiter [Vier]
Default

Snog, do you mean it may not be this New Malware.aj thing at all, just that McAffee is getting mixed up by TexMod's nature and falsely IDing it as that trojan? If so you just made my night...
Shakti is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Lateralus Off-Topic & the Absurd 15 Apr 20, 2006 06:11 PM // 18:11
Virus alert unienaule Off-Topic & the Absurd 4 Oct 20, 2005 05:59 AM // 05:59
Lineage II? Ghostface Off-Topic & the Absurd 33 Aug 13, 2005 11:05 AM // 11:05


All times are GMT. The time now is 07:22 PM // 19:22.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("