Network Sites: FPSguru.com RTSguru.com UnboundGamer.com
Login:  Password:   Remember?  
Show Quick Gamelist Jump to Random Game
Games:567  Guilds:2,961
Members:1,440,974  Online:0
Guests:0  Posts:4,575,391
Recent forum postsRSS
Active threads
Cloud view
List all forums
General Forums
Developers Corner General Discussion
Popular Game Forums
Click a status to find game forum
Game Forums
Click a letter to find game forum
D-F
D&D Online DC Universe DUST 514 Dance Groove Online Dark Age of Camelot Dark Ages Dark Legends Dark Orbit Dark Solstice Dark and Light DarkEden Online DarkSpace Darkfall Darkwind: War on Wheels Dawn of Fantasy Dawntide Dead Earth Dead Frontier Deco Online Defiance Deicide Online Dekaron Desert Operations Diablo 3 Diamonin Digimon Battle Dino Storm Disciple Divergence Divine Souls Dofus Dominus Online Dragon Ball Online Dragon Empires Dragon Nest Dragon Oath Dragon Raja Dragon's Call Dragon's Prophet DragonSky DragonSoul Dragona Dragonica Dream of Mirror Online Dreamland Online Dreamlords: The Reawakening Drift City Duels Dungeon Fighter Online Dungeon Overlord Dungeon Party Dungeon Runners Dynasty Warriors Online EIN (Epicus Incognitus) EVE Online Earth Eternal Earth and Beyond Earthrise Eden Eternal Elf Online Emil Chronicle Online Empire & State Empire Craft EmpireQuest Empires of Galldon End of Nations Endless Ages Endless Online Entropia Universe EpicDuel Erebus: Travia Reborn Eternal Lands Ether Fields Ether Saga Online Eudemons Online EuroGangster EverQuest Online Adventures Evernight Everquest Everquest II Evony Exarch Exorace Face of Mankind Fairyland Online Fall of Rome Fallen Earth Fallen Sword Fallout Online Fantage Fantasy Earth Zero Fantasy Realm Online Fantasy Tales Online Fantasy Worlds: Rhynn Faunasphere Faxion Online Ferentus Ferion Fiesta Online Final Fantasy XI Final Fantasy XIV Firefall Fists of Fu Florensia Flyff Football Manager Live Football Superstars Force of Arms Forsaken World Freaky Creatures Free Realms Freesky Online Freeworld Fung Wan Online Furcadia Fury Fusion Fall
T-Z
TERA TS Online Tabula Rasa Tactica Online Tales Runner Tales of Fantasy Tales of Pirates Tales of Pirates II Talisman Online Tank Ace Tantra Online Tatsumaki: Land at War Terra Militaris Terra World Thang Online The 4th Coming The Agency The Chronicle The Chronicles of Spellborn The Legend of Ares The Matrix Online The Missing Ink The Mummy Online The Myth of Soma The Realm Online The Repopulation The Secret World The Sims Online The Strategems There Thrones of Chaos Tibia Tibia Micro Edition Toontown Online Top Speed Torchlight Transformers Universe Travia Online Travian Trials of Ascension Tribal Wars Tribes Universe Trickster Online Troy Online True Fantasy Live Online Turf Battles Twelve Sky Twelve Sky 2 Twilight War U.B. Funkeys UFO Online Ultima Online Ultima X: Odyssey Ultimate Soccer Boss Uncharted Waters Online Undercover 2: Merc Wars Underlight Universe Online Valkyrie Sky Vanguard: Saga of Heroes Vanquish Space Vector City Racers Vendetta Online Victory - Age of Racing Vindictus Vis Gladius Voyage Century W.E.L.L. Online WAR (Warhammer Online) WYD Global Wakfu War Rock War of 2012 War of Angels War of Legends War of Thrones War of the Immortals WarFlow Warhammer 40K: Dark Millennium Online Warhammer Online: Wrath of Heroes Warrior Epic WebLords Wild West Online WildStar WindSlayer 2 Wish Wizard 101 Wizards and Champions Wonder King Wonderland Online World Golf Tour World War II Online World of Darkness World of Heroes World of Kung Fu World of Pirates World of Tanks World of Warcraft World of the Living Dead WorldAlpha Wurm Online Xiah Xsyon YS Online ZU Online Zentia Zero Online Zodiac Online eRepublik

MMORPG.com Discussion Forums

The Chronicles of Spellborn

The Chronicles of Spellborn 

General Discussion  » Chronicles of Spellborn Virused with TCP Backdoor

6 posts found
  DkLadyKitara

Novice Member

Joined: 4/16/09
Posts: 18

 
5/19/09 3:14:53 AM#1

Was looking for new game, decided to give Chronicles of Spellborn a try.. BUT

Most current version of AVG 8.5 (19 May 2009) Brand new install from 3.0GB install downloaded from official site.

"C:\Spellborn\bin\client\SBGame.dll" ;"Virus found Win32/Devir"; "Infected"

http://www.viruslist.com/en/viruses/encyclopedia?virusid=20467

Virus.Win32.Devir (Kaspersky Lab) is also known as: Win32.Devir (Kaspersky Lab), W32/Insane.dr (McAfee), Trojan Horse (Symantec), Win32.Deviator.12288 (Doctor Web), W32/Devir-A (Sophos), Win32/Devir.A (RAV), TROJ_DEVIR.A (Trend Micro), W32/Devir.15128 (FRISK), Win32:Deviator (ALWIL), Win32/Devir.15128 (Grisoft), Win32.Insane.7096.dr (SOFTWIN), Univ.B (Panda), WIN32 (Eset)
Description added May 31 2001
Behavior Virus
Technical details

This is a per-process memory resident parasitic poly-morphic Win32-virus. The virus infects PE EXE files that have .EXE filename extensions. When run, the virus infects files in current directory only.

The virus also stays in the system memory as a component of the infected host program, gains access to KERNEL functions and intercepts 10 of them: file opening, copying, moving functions, etc. When a PE EXE file is accessed by these functions, the virus infects it. As a result, the virus will infect all PE EXE programs that are accessed by infected the host program, and the virus will be active until the moment the host program exits. The virus also hooks, selecting a new directory function, and infects PE EXE files in there.

--

The PE EXE infection method is a complex and is similar to the Win32.Driller virus. The block of host file code that is overwritten by the virus poly-morphic routine in some cases may be also compressed during infection.

The virus also contains a backdoor routine that opens an Internet connection, waits for its author's instructions and then follows them: sends/receives files, executes programs, reports system information, etc.

The virus contains the following "copyright" text:

Intruder v.0.1 by Deviator//HAZARD

 

Guild Mistress/Leader: Circle of Reflection.
"The Second Official CoS Guild"
http://cos.oldmmogamers.net

  Distaste

Hard Core Member

Joined: 10/03/06
Posts: 570

5/19/09 4:36:44 AM#2

False positive. It doesn't do anything to your computer except run the game.

  User Deleted
5/19/09 4:40:18 AM#3

 There was a thread about this in the TCoS board on this forum sometime ago,here is the link for you and it also tells you how to correct the problem,hope it helps and puts your mind at ease....

http://www.mmorpg.com/discussion2.cfm/thread/231130/Win32-virus-detected.html

 

  Redline65

Advanced Member

Joined: 8/08/06
Posts: 481

5/20/09 8:59:56 AM#4

AVG gave me this alert too a week or so ago and I took the steps to add the exclusion to my Spellborn folder. All was well after that, but yesterday AVG gave me another alert for the Win32/Devir virus in some other folder for a .dll file. It's a little suspicious to me that the same virus would show up somewhere else.

  Grenadier

Novice Member

Joined: 5/12/09
Posts: 91

5/20/09 11:29:26 AM#5
Originally posted by Redline65

AVG gave me this alert too a week or so ago and I took the steps to add the exclusion to my Spellborn folder. All was well after that, but yesterday AVG gave me another alert for the Win32/Devir virus in some other folder for a .dll file. It's a little suspicious to me that the same virus would show up somewhere else.

 

Let me guess, in your System Volume Information folder? That is where your computer keeps its restore points. Its probably a copy of the same files.


Its very annoying. I'll tolerate this kind of crap because I enjoy the game and don't want it to fail, but my patience with it is wearing thin. Acclaim and SiL are shooting themselves in the foot every chance they get. No cancel on the CC subscription, false positive virus warnings, a patch that was not very well received.... How many more of these do they think it takes to completely ruin the game's potential subscriber base?

  Redline65

Advanced Member

Joined: 8/08/06
Posts: 481

5/20/09 12:26:04 PM#6
Originally posted by Grenadier
Originally posted by Redline65

AVG gave me this alert too a week or so ago and I took the steps to add the exclusion to my Spellborn folder. All was well after that, but yesterday AVG gave me another alert for the Win32/Devir virus in some other folder for a .dll file. It's a little suspicious to me that the same virus would show up somewhere else.

 

Let me guess, in your System Volume Information folder? That is where your computer keeps its restore points. Its probably a copy of the same files.


Its very annoying. I'll tolerate this kind of crap because I enjoy the game and don't want it to fail, but my patience with it is wearing thin. Acclaim and SiL are shooting themselves in the foot every chance they get. No cancel on the CC subscription, false positive virus warnings, a patch that was not very well received.... How many more of these do they think it takes to completely ruin the game's potential subscriber base?

Exactly, it looked like it was a .dll file in the system restore folder. I agree with you though, stuff like this can only be bad for their business.