This topic is locked from further discussion.

Avatar image for Lawrencevanrijn
Lawrencevanrijn

312

Forum Posts

0

Wiki Points

0

Followers

Reviews: 97

User Lists: 0

#1 Lawrencevanrijn
Member since 2005 • 312 Posts

To the website manager!

 

gamerankings dot com is infected with PWS-lineage dot dll.

 My McAfee blocked it. do not know who to alert, mainly because there is no clear alert adress.

 

Please forward this to the apropriate parties!

 

 

Avatar image for ashe_si
ashe_si

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#2 ashe_si
Member since 2003 • 25 Posts

Using Norton Antivirus 2002 I also detected a VIRUS on Gamespot.

This is the link I got the virus at and my logfile.

http://www.gamespot.com/pc/action/jointoperations/review.html?om_act=convert&om_clk=gssummary&tag=summary;review

Date: 4/2/2007, Time: 0:08:26, user on USER
The file
C:\WINDOWSmppds.exe
is infected with the Infostealer.Gampass virus.
Unable to repair this file.


Date: 4/2/2007, Time: 0:08:26, user on USER
The file
C:\WINDOWSmppds.exe
is infected with the Infostealer.Gampass virus.
Access to the file was denied.

The file
C:\Documents and SettingsmynameLocal SettingsTemporary Internet FilesContent.IE54H2R8HMZa[1].exe
is infected with the Infostealer.Gampass virus.
Unable to repair this file.


Date: 4/2/2007, Time: 0:23:34, user on USER
The file
C:\Documents and SettingsmynameLocal SettingsTemporary Internet FilesContent.IE54H2R8HMZa[1].exe
is infected with the Infostealer.Gampass virus.
Access to the file was denied.

Avatar image for G013M
G013M

6424

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#3 G013M
Member since 2006 • 6424 Posts
I got a hit from Windows Defender as well. Not sure which one it was, but it was one of the two sites listed above.

Edit: That being said, it could have just been a beign file, but it was called Crasos.exe, in my temp directory. Athough I am leaning towards a harmful file here, as it was attempting to get itself to autorun every login.
Avatar image for Ground_Zero
Ground_Zero

3475

Forum Posts

0

Wiki Points

0

Followers

Reviews: 10

User Lists: 0

#4 Ground_Zero
Member since 2003 • 3475 Posts

yeah same here McAfee blocked it tho.

I was checking the STALKER page and Viva pinata page

Avatar image for zepman71
zepman71

4120

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#5 zepman71
Member since 2005 • 4120 Posts
My AVG picked up 2 trojan downloaders after i tried to view the images and forums on the Super Mario Galaxy page (in both cases my Internet Explorer shut down and had to restart) Would that have anything to do with the viruses?
Avatar image for ej902
EJ902

14338

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#6 EJ902
Member since 2005 • 14338 Posts

I've noticed Internet Explorer crashes when attempting to load a certain URL. It loads the gamespace just fine, stops, then starts loading this URL and freezes. The page it's loading is in Chinese and contains one link to some stats page or whatever it is.

Since I have no idea what's there it could potentially be very unsafe. I'm posting it because it might be the source of the virus problems, so don't go to the page if you're unsure. It might be completely harmless, but be careful nonetheless.

[spoiler] The URL is: http://www.82087871.com/css3.htm and in case you didn't read my warning, a reminder that it could be unsafe. It probably isn't, since the source doesn't show much that could deal with viruses, and it links to a login page for website statistics, but be careful nonetheless [/spoiler]

Since I couldn't find that URL in the page source it's probably something to do with an advert.

Also, I tried opening that page in IE and it didn't crash, so I could be wrong. 

 

EDIT: I am 99% certain it's that URL that's causing IE and other Trident-based browsers to crash, as I just added it to my URL filter (an IE add-on) and it did not crash on the pages it used to crash on.

Avatar image for iratheous
iratheous

60

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#7 iratheous
Member since 2004 • 60 Posts
http://www.gamespot.com/pc/rpg/silverfall/index.html?tag=similargames;title;2 Gives: Virus Profile: Exploit-ANIfile.c Risk Assessment - Home Users: Low - Corporate Users: Low Date Discovered: 3/28/2007 Date Added: 3/28/2007 Origin: N/A Length: varies Type: Trojan SubType: Exploit DAT Required: 4995 Virus Characteristics This detection covers ANI files that attempt to exploit a recent ANI file format handling vulnerability. AVERT has confirmed that the exploit affects at least systems running Microsoft Internet Explorer 6 & 7 on Windows XP SP2. Systems running Windows XP SP1 and Windows XP SP0 do not seem vulnerable to this exploit. These malicious ANI files may be hosted by websites, which when visited can result in silent execution of arbitrary code. One such sample silently downloaded a new downloader trojan, Downloader-BBH. Indications of Infection This exploit runs silently without showing any obvious symptoms. This exploit is simply a transport mechanism for other malicious code; whatever the attack chooses to include. Method of Infection Malicious code can be delivered via a web page or email message. Removal Instructions AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination. Additional Windows ME/XP removal considerations Aliases TROJ_ANICMOO.AX (Trend Micro)
Avatar image for iratheous
iratheous

60

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 0

#8 iratheous
Member since 2004 • 60 Posts
I read a news article about this virus the other day, it's supposed to steal lineage and WoW passwords.
Avatar image for ej902
EJ902

14338

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#9 EJ902
Member since 2005 • 14338 Posts

[spoiler] http://www.gamespot.com/pc/rpg/silverfall/index.html?tag=similargames;title;2 Gives: Virus Profile: Exploit-ANIfile.c Risk Assessment - Home Users: Low - Corporate Users: Low Date Discovered: 3/28/2007 Date Added: 3/28/2007 Origin: N/A Length: varies Type: Trojan SubType: Exploit DAT Required: 4995 Virus Characteristics This detection covers ANI files that attempt to exploit a recent ANI file format handling vulnerability. AVERT has confirmed that the exploit affects at least systems running Microsoft Internet Explorer 6 & 7 on Windows XP SP2. Systems running Windows XP SP1 and Windows XP SP0 do not seem vulnerable to this exploit. These malicious ANI files may be hosted by websites, which when visited can result in silent execution of arbitrary code. One such sample silently downloaded a new downloader trojan, Downloader-BBH. Indications of Infection This exploit runs silently without showing any obvious symptoms. This exploit is simply a transport mechanism for other malicious code; whatever the attack chooses to include. Method of Infection Malicious code can be delivered via a web page or email message. Removal Instructions AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination. Additional Windows ME/XP removal considerations Aliases TROJ_ANICMOO.AX (Trend Micro) [/spoiler] iratheous

I have a strong suspicion that the URL I posted earlier has something to do with it, since according to that report it only affects IE based browsers, which presumably you're running. If you are using IE, and you get hit with the virus warning every time you visit that gamespace, do you think you could give this a try?

1. Download and install the add-on IE7 pro or any other add-ons that have some form of URL filtering (the one I linked to is safe to use).
2. Start IE and look for the IE7 pro logo on the status bar. Click it and select "preferences".
3. In the new window, click "ad filter" from the side bar.
4. Make sure "enable ad filter" is checked, and in the text box at the bottom type "*.82087871.*" and click add (make sure it's set to URL block filter)
5. Go back to the gamespace that's affecting you and see if it happens again.

If that solves your problem, GameSpot needs to stop the domain www.82087871.com from loading stuff on GS pages. If it doesn't help, then I've just wasted my time to an extent (that method at least stops IE from crashing).

Avatar image for Dracula68
Dracula68

33109

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#10 Dracula68
Member since 2002 • 33109 Posts

To the website manager!

 

gamerankings dot com is infected with PWS-lineage dot dll.

My McAfee blocked it. do not know who to alert, mainly because there is no clear alert adress.

 

Please forward this to the apropriate parties!

 

 

Lawrencevanrijn
Um, there is a contact page on GR and I am the ONLY one on it. Anyway yeah, I have heard numerous times over the past 6 months or so that we have a virus by people I don't even know. What I mean is that all of us forum users don't ever get any virus alerts at all. I have told the appropriate people and they will look into it. Thanks!
Avatar image for zepman71
zepman71

4120

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#11 zepman71
Member since 2005 • 4120 Posts
Is it a problem with GameFaqs? And I think we should put a notice up on the website to prevent this virus spreading
Avatar image for Dracula68
Dracula68

33109

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#12 Dracula68
Member since 2002 • 33109 Posts
Is it a problem with GameFaqs? And I think we should put a notice up on the website to prevent this virus spreadingzepman71
I have no clue. I am just answering for GR. I am sure once the GS Techs see this thread they will see if there is anything on the GS or GF side of things.
Avatar image for Wolf-5
Wolf-5

1730

Forum Posts

0

Wiki Points

0

Followers

Reviews: 31

User Lists: 0

#13 Wolf-5
Member since 2005 • 1730 Posts
Bloodhound.Exploit.131 is what I got looking at STALKER pics and info
Avatar image for zepman71
zepman71

4120

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#14 zepman71
Member since 2005 • 4120 Posts

Bloodhound.Exploit.131 is what I got looking at STALKER pics and infooscar_rangel

What does it do? Is it just like a typical virus?

Avatar image for LTomlinson21
LTomlinson21

24423

Forum Posts

0

Wiki Points

0

Followers

Reviews: 14

User Lists: 0

#15 LTomlinson21
Member since 2004 • 24423 Posts

[spoiler] The URL is: http://www.82087871.com/css3.htm and in case you didn't read my warning, a reminder that it could be unsafe. It probably isn't, since the source doesn't show much that could deal with viruses, and it links to a login page for website statistics, but be careful nonetheless [/spoiler] EJ902

Everytime I open that link, it forces my AOL Browser to op-up.  Of course it doesn't work because it needs a password.

Avatar image for ej902
EJ902

14338

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#16 EJ902
Member since 2005 • 14338 Posts
[QUOTE="EJ902"]

[spoiler] The URL is: http://www.82087871.com/css3.htm and in case you didn't read my warning, a reminder that it could be unsafe. It probably isn't, since the source doesn't show much that could deal with viruses, and it links to a login page for website statistics, but be careful nonetheless [/spoiler] LTomlinson21

Everytime I open that link, it forces my AOL Browser to op-up.  Of course it doesn't work because it needs a password.

Yeah, I have no idea what it is, but blocking its domain definitely stopped the gamespaces from crashing IE on me. Interestingly, the content it now tries to load appears to have changed. In Avant browser, an IE shell, I've also blocked *.82087871.com/* (asterisks representing wildcards), so it doesn't crash, and every time I go onto a gamespace summary page it gives me the list of blocked URLs: The others are just adverts, but 82087871.com/1.jpg and 2.jpg ONLY appear on the gamespace summary page, nowhere else on the site for me.

I stand by my opinion that this site is in some way related to the virus, as it only occurs on the gamespace summary, the same pages the virus warnings are allegedly popping up, and how blocking that URL stops IE from crashing on those pages.

EDIT: And just like that it's gone. If people are still getting virus warnings on Gamespaces and there's no trace of 82087871.com attempting to load, then you'll know I was wrong.

Avatar image for VinceL
VinceL

3856

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#17 VinceL
Member since 2004 • 3856 Posts
This was caught over the weekend and cleaned up - there was a malicious attempt on GameRankings which was diffused. The other sites should also be fine now.
Avatar image for ashe_si
ashe_si

25

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#18 ashe_si
Member since 2003 • 25 Posts

When researching this, it appears the trojan is "infostealer.gampass".

Infostealer.Gampass is a generic detection for a Trojan horse that steals online game accounts, such as Lineage, Ragnarok online, Rohan, and Rexue Jianghu. Also, a few antivirus websites indicate some of the variations of this trojan can have a keylogger embedded in it. With that in mind, I would hate to have any of the passwords to my accounts/games/websites stolen.

Avatar image for zepman71
zepman71

4120

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#19 zepman71
Member since 2005 • 4120 Posts
Any updates on the situation...?
Avatar image for Wren28
Wren28

27811

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#20 Wren28
Member since 2005 • 27811 Posts
Not sure if this has anything to do with the virus or not, but every time I shut IE down, another window pops up to a pornographic site and it always seems to happen if I've visited any of the game/shared forums. I hadn't been on any other website today and I got that pop up. Is anyone else getting this?
Avatar image for ej902
EJ902

14338

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#21 EJ902
Member since 2005 • 14338 Posts
Not sure if this has anything to do with the virus or not, but every time I shut IE down, another window pops up to a pornographic site and it always seems to happen if I've visited any of the game/shared forums. I hadn't been on any other website today and I got that pop up. Is anyone else getting this?Wren28
Probably adware/spyware, scan your PC using software like AVG anti-spyware or Spybot: Search and Destroy.
Avatar image for Wren28
Wren28

27811

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#22 Wren28
Member since 2005 • 27811 Posts

[QUOTE="Wren28"]Not sure if this has anything to do with the virus or not, but every time I shut IE down, another window pops up to a pornographic site and it always seems to happen if I've visited any of the game/shared forums. I hadn't been on any other website today and I got that pop up. Is anyone else getting this?EJ902
Probably adware/spyware, scan your PC using software like AVG anti-spyware or Spybot: Search and Destroy.

Wouldn't Norton get rid of it? I have Norton SystemWorks 2007...if not, well, I'll go from there.