May 13, 2008, 10:57 PM // 22:57
|
#1
|
rattus rattus
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
|
Virus alert - PWS Lineage
I am one of three people in my far-flung family who's virus checker has detected the PWS Lineage trojan recently. It was originally designed to steal passwords from Lineage , but over the years has gradually been altered to gather logins from several other games - see here http://vil.nai.com/vil/content/v_130590.htm
Usual advice applies - make sure you have a good virus checker installed and that it's definitions are up to date. And let the bugger finish its scan - I know how annoying virus scans can be, but they're a necessary evil.
Apologies if this is the texmod false-positive again - it's a possibility, but it's better to be safe than sorry, Especially with all the recent account thefts.
The trojan was detected by AVG 8.0 - not sure where mine was, but my cousin-in-law's was in her GW folder
__________________
Si non confectus, non reficiat
Last edited by Snograt; May 14, 2008 at 12:14 AM // 00:14..
|
|
|
May 13, 2008, 11:01 PM // 23:01
|
#2
|
Wilds Pathfinder
Join Date: Dec 2005
Guild: Shyft Machine [MYTH]
Profession: E/
|
Thanks for the heads up Snograt.
|
|
|
May 13, 2008, 11:06 PM // 23:06
|
#3
|
Forge Runner
Join Date: Aug 2006
Location: Scotland
Guild: Type like an idiot, I'll treat you like an idiot
Profession: E/Me
|
The more security awareness, the better. Now I have a specific target to look for.
|
|
|
May 13, 2008, 11:09 PM // 23:09
|
#4
|
Krytan Explorer
|
Which virus scanner did you use? What files were infected?
|
|
|
May 13, 2008, 11:13 PM // 23:13
|
#5
|
Desert Nomad
Join Date: Apr 2006
Location: Scotland
Profession: W/N
|
How does infection take place.
|
|
|
May 13, 2008, 11:14 PM // 23:14
|
#6
|
Wilds Pathfinder
Join Date: Aug 2007
Location: ★☆٭Ńēŵ~ŶờЯК٭☆★
Guild: The Benecia Renovatio [RenO]
Profession: Mo/Me
|
keyloggers suck
|
|
|
May 13, 2008, 11:47 PM // 23:47
|
#7
|
Lion's Arch Merchant
Join Date: Mar 2007
Guild: The Eternal Champions
Profession: W/Mo
|
I got that virus the other week, on a brand new comp that was fully protected :/
I had to reformat just to be on the safe side.
AVG picked it up, and quarantined it. I couldn't see that it had escaped the Temp folder and done anything to the registry, but that's apparently what it would have done if undetected.
I scan twice a day now, both Virus and Spyware programs.
And no...I didn't have Textmod on the comp.
|
|
|
May 14, 2008, 12:12 AM // 00:12
|
#8
|
Lion's Arch Merchant
Join Date: Oct 2005
Location: Mexico
Guild: Go for the eyes [jizz]
Profession: W/Mo
|
Looks like the only reasonable explanation for all the "hacking" goin' around.
|
|
|
May 14, 2008, 12:35 AM // 00:35
|
#9
|
rattus rattus
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
|
Edited the OP with more info - detected by AVG 8.0 and in one instance in the GW folder.
I am unaware what specific file was involved - probably PWS-Lineage.dll, according to online databases. I think that, like Dylananimus, mine was in my Temp folder, which would be typical of this particular Trojan.
__________________
Si non confectus, non reficiat
|
|
|
May 14, 2008, 12:39 AM // 00:39
|
#10
|
Desert Nomad
Join Date: Jun 2006
Location: Look out!
Profession: E/
|
Wow, I used to play lineage, nowadays you probably couldn't give your US account away since nobody plays it anymore. Guess I'll go update my AVG.
|
|
|
May 14, 2008, 01:00 AM // 01:00
|
#11
|
Furnace Stoker
Join Date: Oct 2005
Location: Planet Earth, Sol system, Milky Way galaxy
Guild: [ban]
Profession: W/
|
I just ran a scan with AVG 7.5, and turned up a report for PWS Lineage, but I'm fairly certain it's a false positive in my case. The file was wtf(#).tmp in my local temp folder, where (#) was a number I don't remember. I use TexMod, hence my suspicion it was a false positive. None of the other files associated with PWS Lineage were found in the scan. Updating to AVG 8.0 now.
|
|
|
May 14, 2008, 03:32 AM // 03:32
|
#12
|
Popcorn Fetish
Join Date: Dec 2005
Guild: [GODS]
Profession: Mo/Me
|
Trojan Horse PSW.Linage.AGX
View your scan history in AVG 8.0
Computer Scanner->Scan History->any blue colored scheduled scan (will indicate which scans have infections.)->Infections
Location
C:\Users\Name Of User\AppData\Local\Temp\
Files It's been named
wtfD8D6.tmp
wtf1BAE.tmp
wtf2091.tmp
wtf41A1.tmp
wtf2E5.tmp
wtf674B.tmp
wtf715A.tmp
wtfA2CA.tmp
wtfDF75.tmp
Wtf9686.tmp
Wtf8A03.tmp
Wtf7A41.tmp
wtf6831.tmp
WtfEBEB.tmp
And it's only been found in the Temp folder. I ran a texmod a few ways then scanned the temp folder and Guild Wars folders and found nothing. But I'll Keep an eye on it.
|
|
|
May 14, 2008, 03:35 AM // 03:35
|
#13
|
Major-General Awesome
Join Date: Aug 2005
Location: Aussie Trolling Crew HQ - Event Organiser and IRC Tiger
Guild: Ex Talionis [Law], Trinity of the Ascended [ToA] ̖̊̋̌̍̎̊̋&#
Profession: W/
|
Has anyone detected this with an anti-virus that ISN'T AVG? I know it shows some false-positives...but this is ridiculous. Someone try with NOD32 or something decent.
|
|
|
May 14, 2008, 04:01 AM // 04:01
|
#14
|
rattus rattus
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
|
Good point.
Incidentally, my AVG found wtf# files too - forgot until Zehnchu mentioned it.
[edit] hmm, this may well be a TexMod false-positive after all
Quote:
everytime i use texmod (dl'd with the link in guildwiki), i get this trojan called wtf#.tmp
#=some random number
Is it a dangerous trojan?
|
http://www.guildwarsguru.com/forum/s...7&postcount=14
Maybe when AVG updated from 7.x to 8 it started to falsely tag TexMod again - I've had it installed for ages and AVG's never been bothered before.
__________________
Si non confectus, non reficiat
Last edited by Snograt; May 14, 2008 at 04:07 AM // 04:07..
|
|
|
May 14, 2008, 04:04 AM // 04:04
|
#15
|
Forge Runner
Join Date: Aug 2006
Location: Australia
Guild: Lost Templars [LoTe]
Profession: Me/Mo
|
i'm updating to AVG 8.0 as we speak, so if I have it, hopefully it will be picked up. Thanks for the heads up.
|
|
|
May 14, 2008, 04:13 AM // 04:13
|
#16
|
Major-General Awesome
Join Date: Aug 2005
Location: Aussie Trolling Crew HQ - Event Organiser and IRC Tiger
Guild: Ex Talionis [Law], Trinity of the Ascended [ToA] ̖̊̋̌̍̎̊̋&#
Profession: W/
|
I downloaded it, and scanned the .zip with NOD32, detected nothing. Considering the zip comes with Texmod.exe and Readme.txt, I decided just to leave it zipped, and no extract or anything, since there wasn't a reason to (already have it on the computer).
AVG fails?
Edit: Scanned my Temp files and found nothing also. <3 NOD32
Last edited by fenix; May 14, 2008 at 04:26 AM // 04:26..
|
|
|
May 14, 2008, 04:39 AM // 04:39
|
#17
|
Forge Runner
Join Date: May 2005
Guild: StP
Profession: R/
|
I only have the free Avg 7.5, can it be updated to 8.0?
|
|
|
May 14, 2008, 05:19 AM // 05:19
|
#18
|
Wilds Pathfinder
Join Date: Sep 2006
Location: Home...
Guild: Vier Reiter [Vier]
|
OK now I'm worried about textmod. My hubby DLed Textmod a month or so ago (I think from the "safe" link here but I'll check when he gets home) so I could do cartographer.
I use McAffee SecurityCenter among other scans, and after reading this and the other threads, ran the scan just on the Textmod.exe file itself. It came up with a trojan New Malware.aj to be exact. Seems to be a 2006 Heuristic trojan (wtf ?)
Crap.
|
|
|
May 14, 2008, 05:28 AM // 05:28
|
#19
|
rattus rattus
Join Date: Jan 2006
Location: London, UK GMT±0 ±1hr DST
Guild: [GURU]GW [wiki]GW2
Profession: R/
|
Don't worry yet - because of TexMod's nature of intercepting system calls, a lot of virus scanners have falsely identified it as a virus/trojan. I think that the AV companies can be reassured of a program's validity and virus definitions can be updated to ignore it.
__________________
Si non confectus, non reficiat
|
|
|
May 14, 2008, 05:34 AM // 05:34
|
#20
|
Wilds Pathfinder
Join Date: Sep 2006
Location: Home...
Guild: Vier Reiter [Vier]
|
Snog, do you mean it may not be this New Malware.aj thing at all, just that McAffee is getting mixed up by TexMod's nature and falsely IDing it as that trojan? If so you just made my night...
|
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
Similar Threads
|
Thread |
Thread Starter |
Forum |
Replies |
Last Post |
Lateralus |
Off-Topic & the Absurd |
15 |
Apr 20, 2006 06:11 PM // 18:11 |
Virus alert
|
unienaule |
Off-Topic & the Absurd |
4 |
Oct 20, 2005 05:59 AM // 05:59 |
Lineage II?
|
Ghostface |
Off-Topic & the Absurd |
33 |
Aug 13, 2005 11:05 AM // 11:05 |
All times are GMT. The time now is 07:22 PM // 19:22.
|