VIRUS - BF2 Server Logo !

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • bigAPE

    #1

    VIRUS - BF2 Server Logo !

    My Panda Anti-Virus just found a Worm in a BF2 Server Logo Image

    W32/Rayl.A.worm

    It was downloaded during server browsing and was stored in the following location:

    c:\documents and settings\<profile name>\my documents\battlefield 2 \logocache\bf2.ea.co.kr\server\bf2_server.jpg


    Rayl.A exploits a vulnerability in order to download and execute other malware on the affected computer ... When the user opens the picture, which is in fact an HTM file, Rayl.A affects the computer.
    Anyone know whats going on here ?
  • SaladFork

    #2
    Re: VIRUS - BF2 Server Logo !

    I think it's time you stop using Panda,

    ~Salad

    Comment

    • imported_CheetahShrk

      #3
      Re: VIRUS - BF2 Server Logo !

      Actually it is possible to be a virus since the game doesnt check so it could be a virus like in the viruses description.

      Comment

      • Nexar

        #4
        Re: VIRUS - BF2 Server Logo !

        open it, its a christmas present

        Comment

        • RampageNL

          #5
          Re: VIRUS - BF2 Server Logo !

          I use NOD32 one of the best Virus Scanners around.

          Comment

          • imported_Sin317

            #6
            Re: VIRUS - BF2 Server Logo !

            stop using panda , seriously

            Comment

            • jpardo

              #7
              Re: VIRUS - BF2 Server Logo !

              Originally posted by SaladFork
              I think it's time you stop using Panda,

              ~Salad
              agreed, and if anyone would know...salad would...

              Comment

              • IVfluids

                #8
                Re: VIRUS - BF2 Server Logo !

                I could actually see where it could happen though, it is possible for someone to use the server that their logo is hosted on, to have a bunch of other things (from file sharing via ftp) and someone uploaded an infected file that spread through their ****.

                I think it's time you stop using Panda,

                ~Salad
                And now he is a saaaaaad pandaaaa...

                Comment

                • imported_TheONE

                  #9
                  Re: VIRUS - BF2 Server Logo !

                  It is possible...there is a new exploit out for xp that can be spread via image's...


                  Update on Windows WMF 0-day (NEW)
                  Published: 2005-12-29,
                  Last Updated: 2005-12-29 11:23:53 UTC by Chris Carboni (Version: 1)

                  From Daniel's diary entry yesterday ...

                  Update 19:07 UTC: We are moving to Infocon Yellow for a bit. There has been some debate among the handlers about this step, but considering that a lot of people are on holidays and might otherwise miss the WMF 0-day problem, we have decided to raise the alert level.

                  The folks at Websense Labs have a nice movie on how it looks like if a system gets exploited by this WMF 0-day, see http://www.websensesecuritylabs.com/.../wmf-movie.wmv . Don't go to any of the URLs visible in the movie unless you know what you are doing (or feel like spending the next hours reinstalling your PC).

                  The orignal exploit site (unionseek.com) is no longer up. But the exploit is being served from various sites all over by now, see the F-Secure Blog on http://www.f-secure.com/weblog/ for an update on the versions of the exploit found in the wild.

                  Working exploit code is widely available, and has also been published by FRSIRT and the Metasploit Framework.

                  Regarding DEP (Data Execution Protection) of XPSP2, the default settings of DEP will not prevent this exploit from working. Comments we have received in the meantime suggest that if you enable DEP to cover all programs (as documented on Microsoft Technet ), the WMF exploit attempt will result in a warning and not run on its own. Don't feel too safe though, we have also received comments stating that a fully enabled DEP did not do anything good in their case.

                  While the original exploit only refered to the Microsoft Picture and Fax Viewer, current information is that any application which automatically displays or renders WMF files is vulnerable to the problem. This includes Google Desktop, if the indexing function finds one of the exploit WMFs on the local hard drive - see the F-Secure Weblog mentioned above for details.

                  Update 23:00 UTC: The vulnerability seems to be within SHIMGVW.DLL. Unregistering this DLL (type REGSVR32 /U SHIMGVW.DLL at the command prompt or in the "Start->Run" Window, then reboot) will resolve most of the vulnerability, but will also break your Windows "Picture and Fax Viewer", as well as any ability of programs like "Paint" and "Explorer" to display thumbnails of any picture and real (benign) WMF files.

                  Update 23:19 UTC: Not that we didn't have enough "good" news already, but if you are relying on perimeter filters to block files with WMF extension from reaching your browser, you might have a surprise waiting for you. Windows XP will detect and process a WMF file based on its content ("magic bytes") and not rely on the extension alone, which means that a WMF sailing in disguise with a different extension might still be able to get you.

                  Comment

                  • Elxx
                    Member
                    • Apr 2005
                    • 941

                    #10
                    Re: VIRUS - BF2 Server Logo !

                    Thing is, you could only really get the virus or whatnot if you actually went and opened the image. AFAIK, it can't be spread via BF2.

                    Comment

                    • IVfluids

                      #11
                      Re: VIRUS - BF2 Server Logo !

                      Originally posted by Sir. Elxx
                      Thing is, you could only really get the virus or whatnot if you actually went and opened the image. AFAIK, it can't be spread via BF2.
                      Not really sure how all of this works, but wouldn't the image be getting opened when you join a BF2 server? Because the image is downloaded to your computer and stored in your MyDoc/BF2 folder, and any time you play on that server, that image file is called up to be displayed in the game?

                      Correct me if I am wrong in thinking this, seriously.

                      Comment

                      • bigAPE

                        #12
                        Re: VIRUS - BF2 Server Logo !

                        There is nothing wrong with Panda AV. We've had it running on 5 machines here for a few years now and we have two clients who use it with 20+ desktops each. It regularly catches viri that others don't.

                        My advice is bash the virus and the twat that planted it, not the tool used to locate it

                        Comment

                        • bitvomit

                          #13
                          Re: VIRUS - BF2 Server Logo !

                          Originally posted by Sir. Elxx
                          Thing is, you could only really get the virus or whatnot if you actually went and opened the image. AFAIK, it can't be spread via BF2.
                          BF2 does open the image. How do you think it is displayed in the loading screen? I'm sure BF2 uses the same image libraries that are vulnerable to exploits to open images.

                          Comment

                          • imported_TheONE

                            #14
                            Re: VIRUS - BF2 Server Logo !

                            http://www.betanews.com/article/Real...ows/1135794414

                            'Really Bad' Exploit Threatens Windows
                            By Nate Mook, BetaNews
                            December 28, 2005, 1:30 PM

                            A new exploit has been discovered in the wild that affects fully patched Windows XP SP2 systems, according to reports by security firms F-Secure and Sunbelt. The malicious code takes advantage of a vulnerability in the WMF graphics rendering engine to automatically download and install malware.

                            WMF, or Windows Metafile, is a vector based image format used by Microsoft's operating systems. SHIMGVW.DLL is loaded to render the images and contains a flaw that opens the door for a malformed WMF image to cause remote code execution and potentially allow for a full system compromise.

                            Microsoft previously fixed a vulnerability affecting WMF and EMF files in November. That problem affected Windows 2000, XP and Windows Server 2003.

                            "We have a number of sites that we have found with this exploit. Different sites download different spyware. We only had a handful of websites using this new exploit but now we are seeing many more using this to install bad stuff. These image files can be modified very easily to download any malware or virus," said Alex Eckelberry, CEO of Sunbelt Software.

                            "I hit one site with a fully patched XP system last night and it was pretty intense -- it went right through and infected my machine."

                            F-Secure's Mika Pehkonen warned that, "Right now, fully patched Windows XP SP2 machines are vulnerable, with no known patch." The company is detecting the offending WMF files as W32/PFV-Exploit.A, .B and .C.

                            "Note that you can get infected if you visit a web site that has an image file containing the exploit. Internet Explorer users might automatically get infected. Firefox users can get infected if they decide to run or download the image file," Pehkonen added.

                            Microsoft has been notified of the issue and it could opt to issue an emergency patch, apart from its standard Patch Tuesday security bulletins. "We expect Microsoft to issue a patch on this as soon as they can," says F-Secure.

                            Sunbelt's Eckelberry echoes that sentiment: "Folks, I've seen it with my own eyes and this is a really bad exploit. Be careful out there."

                            Comment

                            • |AFF|Soupyblister

                              #15
                              Re: VIRUS - BF2 Server Logo !

                              Originally posted by IVfluids
                              And now he is a saaaaaad pandaaaa...

                              LMAO, ya stop using Panda.

                              Comment

                              Working...