TEK9 Beta Website - Read more about the progress in our coder's blog or our designer's blog.
Hitta dina dina Annonser på AllaAnnonser.se

IW.net allegedly spreading a Trojan virus

Posted by Steven dfb Leunens on 2009-11-18 16:06:44
Tags: MW2, trojan, virus
Reported in this forum post on the official IW forums and our very own forums apparently hackers have found a way to go around the IW.net system and send a Trojan virus through the IW.net system to Modern Warfare 2 players. Reverse engeneering the source code for Modern Warfare 2, the hackers inserted their Trojan and used the IW.net system to spread it to players across the globe. This was brough to light after several players got notified of a breach in their security by their antivirus software. The Trojan TR/Crypt.XPACK.Gen had been sent to them using Modern Warfare 2's IW.net as the official transmitter (according to the antivirus). The Trojan itself apparently already surfaced in Call of Duty : World at War and is some sort of keylogging software hackers use to steal keycodes or potentially worse (stealing credit card information for instance).

The Trojan would exploit the port that is opened by Call of Duty when you are a listen server (when you are the host of a game) to send you the Trojan without your knowledge.

Here is a screenshot provided by Matje on the forums where his anticheat has picked up on the Trojan.



Additional information on the virus can be found here and here.

Stay tuned as we try to find out more about the Trojan and how it is exactly being spread. Due note that it is not 100% confirmed that it is actually Modern Warfare 2 (and an exploit in the game) sending you this virus.It could very well be a false positive! We have still to hear an official reaction to this news.

* update *

Another community member of ours has tracked down the location of the virus on his PC and found it to be located here: C:\Documents and Settings\yourusername\Local Settings\Temp with the file names ~B8.tmp and ~B8.vir. (windown XP)
The most important discovery however is that the files were created when the player was playing Modern Warfare 2 and he was set up as the host of the game!


Share |

82 comments

Previous
1
2
4 months ago
+1 thumbs
lol
4 months ago
+0 thumbs
lmao its getting even worse =D

gl people with mw2
4 months ago
+0 thumbs
lame.
4 months ago
+0 thumbs
;DDDD
4 months ago
-1 thumbs
as long as i can play specop mod with my bestfriend qure im happy <3




but still.. iw fo

4 months ago
+0 thumbs
<33333
4 months ago
+0 thumbs
origi or cracked? we play with cracked, but its so laggy for the one who joins... is it good for u?
4 months ago
+0 thumbs
FU TERRY BACKSTABBER!!!!!!!
4 months ago
+0 thumbs
lols
4 months ago
+1 thumbs
this moment is so amazing, i wanna make babies with it.
4 months ago
+0 thumbs
alright cox
4 months ago
+0 thumbs
:D Glad I never bought it
4 months ago
+0 thumbs
indeed ;d
4 months ago
+0 thumbs
have fun :D
4 months ago
+0 thumbs
Oh boy, I shall cherish this moment forever <3
4 months ago
+0 thumbs
SCORE!
4 months ago
+0 thumbs
i bet iw will not care about it anyway .. they don't care about pc gamers :) so fuck iw

edited 2009-11-18 16:19:59
4 months ago
+0 thumbs
so sad, iw comming with new fails every day, i like it ! :D
4 months ago
+0 thumbs
another reason to be happy i didnt go out and buy it with all the other sheep
4 months ago
+0 thumbs
I'll post you a medal.

On a serious note, you are correct, thou my bro bought the game in uni and he can't play it, WIN!
4 months ago
+0 thumbs
ah so thats what the update did yesterday, IW fucking us up twice

Now find a way to crash IW.net
4 months ago
+0 thumbs
mw2 ftw ! ;d;d;d;d;d;d
4 months ago
+1 thumbs
IW + MW2 = FARCE
4 months ago
+0 thumbs
IW.net turning emo?
4 months ago
+0 thumbs
+1
4 months ago
+0 thumbs
Whem 402 reads this:) hes gona go WATAFAK?
4 months ago
+0 thumbs
biggest fail ever :D
4 months ago
+0 thumbs
And the fail continues.
4 months ago
+0 thumbs
Its a false positive :

[Solved] TR/Crypt.XPACK.Gen Trojan- in quarantine- is computer ok?

Nicolae Moldoveanu
Avira GmbH
Date of registration: May 22nd 2006
Version: Avira Prem. Security Suite
Location: Bucharest

Yesterday, 11:45am

Hi,
The sample was re-analyzed and it is clean. The detection is already removed, just update.
Nicolae Moldoveanu
Avira GmbH
4 months ago
+0 thumbs
I have 2 files inside of my computers where the file is believed to be in, it was created this morning which I know I was hosting so tbh, still curious
4 months ago
+0 thumbs
jeeps getting better and better!
4 months ago
+0 thumbs
wicked.
4 months ago
+0 thumbs
lololz
4 months ago
+0 thumbs
lol constructive jon hah!
4 months ago
+0 thumbs
All this news about the game is just getting boring now, please write articles about something else, fml. And yes, it seems very much to be a false positive, just funny to see this community have an orgasm everytime something bad is said about the game.

The amount people talk about this game, I sometimes wonder if they hate it as much as they say or if they are just being retarded ¬_____¬
4 months ago
+0 thumbs
i've got the virus already but al my scanners don't find it :S
4 months ago
+0 thumbs
That's because it isn't a virus. It is a false positive which has already been stated in these posts.
4 months ago
+0 thumbs
iw = the matrix! noessss
4 months ago
+0 thumbs
Another community member of ours has tracked down the location of the virus on his PC and found it to be located here: C:\Documents and Settings\yourusername\Local Settings\Temp with the file names ~B8.tmp and ~B8.vir. (windown XP)

I don't have that directory and im running XP :s
I'm sure i have seen that directory before though.

Won't be going on MW2 any time soon then.
4 months ago
+0 thumbs
why? its a false positive?
4 months ago
+0 thumbs
It's so he can look cool with the rest of everyone else slating the game 24/7 lol... Fucking sheep.
4 months ago
+0 thumbs
Oh so I can look cool, ok 5 mins..
4 months ago
+0 thumbs
Hey,

Around 2-3 today, I did a scan because I was curious to see about this "trojan". So I installed the program and got all the updates from then and did the scan, heres how it turned out with file locations.



"Apologies for small image"

As you can see, the file location is correct and theres one of the two files, the 1st one, I deleted outta pure shock tbh. The second I kept just to see if it would update.

The detection there, I made about 5 mins prior to this post and it's still coming up as detected, this could be because it's still not updated "updated prior to screenshot" so really, i'm not sure what is going on, but when people are playing on family PC's, a little warning doesn't help, now go try annoy someone else.

"My bro bought the game but his Uni connection is shite so I can play the game which my bro wasted his money on"

edited 2009-11-18 19:24:45
4 months ago
+0 thumbs
Didn't realise that my bad :)

Look cool slating MW2? I have repeatedly said it's fun to play with mates and that it's shit for anything competitive. So shhhh and stop raging on the internet :)
4 months ago
+0 thumbs
@bwdcoldbolt...

(From unreals post....)

[Solved] TR/Crypt.XPACK.Gen Trojan- in quarantine- is computer ok?

Nicolae Moldoveanu
Avira GmbH
Date of registration: May 22nd 2006
Version: Avira Prem. Security Suite
Location: Bucharest

Yesterday, 11:45am

Hi,
The sample was re-analyzed and it is clean. The detection is already removed, just update.
Nicolae Moldoveanu
Avira GmbH

-----
Avira is the only program it comes up on... no other major scanners/firewalls... Its a false threat on Avira... As stated by one of their employees above?

If it starts being detected by other programs, then I'd begin to worry.
4 months ago
+0 thumbs
I might be wrong to say but,

I read all 36 post about the trojan, but that isn't hte same situation atm. That's given the fact of another file being infected with the same trojan. Also it was date @ October "first post" and the file which was infected, is in a completely different directory than mine (mine being in Temp) and his being system32

If i'm wrong, well that only means my key won't be stolen "Should I really be happy for that xD"
4 months ago
+0 thumbs
lol nice
4 months ago
+1 thumbs
MW2 is wicked :D:D:D:D::D stop hating. SP amazing, MP pub with friends is funfunfun and virus is false. no competition? ooohhh wel. still worth the money. Not a bad game.
4 months ago
+0 thumbs
This.
4 months ago
+0 thumbs
Some of the maps are crap like Estate but it's not as bad as people make out, IW.net is a fail, therefore i get crap reg/pings pretty regularly and matchmaking can be an absolute bitch sometimes.The gameplay itself is actually pretty decent.

Not wicked but it aint bad ;)
4 months ago
+0 thumbs
I agree. Tonight I've had one of the worst MW2 times since I got it. SnD is boring as fuck. I can't seem to match my sens to cod4 and QL. also I was playing with 4 friends and it matched us with a group of 5-7 americans, of which one was the host so all of us had like 1 bar. This happened a couple of times. How can they justify matching EU player with US players is pathetic :( AND that was on estate! lol

I've been raging :(

I'm sure I'll like playing again 2moz :P
4 months ago
+0 thumbs
windows 7 link to temp files :

C:\Users\Username here\AppData\Local\Temp


I think its the same for vista, cant confirm though.
4 months ago
+0 thumbs
well that's a new one
4 months ago
+0 thumbs
AV just confirmed:

@bmxliveit It is possible to get a virus while playing the game. It is close to possible to get a virus FROM the game or from the servers.
2 minutes ago from HootSuite in reply to bmxliveit

on twitter from ATVI_Amber. she first assaulted me with:

@bartjen Activision here. Where are you getting your information regarding this? It is not possible to get a virus by just playing #mw2

AV is taking zah blame
4 months ago
+0 thumbs
keep us updated
4 months ago
+0 thumbs
they are not stating anything else. they are moving it towards IW.

And if that is true well... we can wait for ages
4 months ago
+0 thumbs
Still getting the error, new file made just 5 mins ago, it's not detecting old files but making new files, wanna know wtf is going on xD
4 months ago
+0 thumbs
Still getting the error, new file made just 5 mins ago, it's not detecting old files but making new files, wanna know wtf is going on xD
4 months ago
+0 thumbs
Still getting the error, new file made just 5 mins ago, it's not detecting old files but making new files, wanna know wtf is going on xD
4 months ago
+0 thumbs
Still getting the error, new file made just 5 mins ago, it's not detecting old files but making new files, wanna know wtf is going on xD
4 months ago
+0 thumbs
ECHO
4 months ago
+0 thumbs
Play COD4

ez
4 months ago
+0 thumbs
False, NOD32 foreveeer
4 months ago
+0 thumbs
+ 1 for SS , matje on picaaa !!!
4 months ago
-1 thumbs
a little bit of cum came out when i read this. yet another reason to avoid using anything related to iw.net
4 months ago
+0 thumbs
Has anyone else noticed that only Avira is picking this up? No other antivirus, only a shitty free one? Pretty sure it's a false positive.
4 months ago
+0 thumbs
got the error 4 times today (em yesterrday^^)

wtf is going on? I updated avira and it do not stop ? :(
4 months ago
+0 thumbs
it was me
4 months ago
+0 thumbs
lol hmm.. avira use to be a good antivirus..
4 months ago
+0 thumbs
i have no alert yet
4 months ago
+0 thumbs
its nice to read this.

i hope this Trojan destroy all the hardware you have maybe in a short time we dont hear anymore about mw2
4 months ago
+0 thumbs
im stayin cod4, thats for sure lol
4 months ago
+0 thumbs
people's help me out. is this hing gonna destroy my computer or is it not. im reading all these comments of "false positive's" but i haz never heard of that so explain pl0x :)
4 months ago
+0 thumbs
A false positive occurs when innocent files are being flagged as infected but are infact harmless. This could well be a false positive, like suggested in the above comments, but we'll wait and see if more becomes known before we give the 'all clear'.
4 months ago
+0 thumbs
tnx :)
Previous
1
2
Please login or register to post comments.