ModernWarfail2 – The biggest FAIL in PC FPS gaming history
18Nov/096

Reports of Trojan Interjection using IWNet

The InfinityWard.com forums are receiving warnings from users that they are experiencing issues where they are having trojans interjected into their machine when joining certain IWNet games.

Users have been quick to point the figure that a clan has possibly hacked the game DLL files are injecting the trojans using a combination of those files and open ports on the guest clients end.

This issue is currently receiving mixed reports, we recommend strongly that you use antivirus (like AVG).
If you don't have an antivirus yet, you can download one legally for free at http://free.avg.com/ or at http://www.free-av.com/

MapModNews.com has reported that they believe this to be a false positive, http://www.mapmodnews.com/article.php/MW2-AVIRA-Crypt.XPACK.Gen-Trojan.

Update by KingOfTehInternets:
A ModernWarfail2.com reader sent me a screenshot of his Antivirus program (Avira) which picked up the Trojan:

trojan

Screenshot by JPzzz (sent via email)

More information regarding this Trojan spreading trough IWnet can be found here:
http://www.infinityward.com/forum/viewtopic.php?f=24&t=181730
http://www.infinityward.com/forum/viewtopic.php?f=24&t=181646
http://forums.steampowered.com/forums/showthread.php?t=1031092

Update by SlightlyGreen: I have people telling me it is a false positive so it might be. Because only Avira is detecting this, surprisingly.
http://www.mapmodnews.com/article.php/MW2-AVIRA-Crypt.XPACK.Gen-Trojan
http://www.infinityward.com/forum/viewtopic.php?f=24&t=182082

  • Hope avast can defend this kind of trojan.
  • thanks for the screenshot.

    look like the Trojan really not from the loader.

    btw i use avira too but not got this trojan detected when play MW2. weird.
    i only notice the random lag....... :p
  • DocMock
    This is getting worse and worse - and still IW doesn't see its horrible fail and keeps dull...
  • sorry, i mean not "infecting" to iw4sp.exe but "injecting" external .dll to iw4sp.exe :p
  • (sorry my bad english)

    hmm just wondering, maybe this not from IWnet but from local file?

    Crypt.XPACK.Gen-Trojan.
    is the same detection in the TeknoGod's SP Co-Op Fix.

    the loader/launcher is injecting .dll to the iw4sp.exe
    the loader executeable itself is packed.

    if there a screenshot of the virus detection, we can see the details of the detection like the filename , etc etc
    if the file is the loader, then its not IWnet but the antivirus just detecting the loader as "Crypt.XPACK.Gen-Trojan".
    because the loader itself is really packed and infecting external file to iw4sp.exe (a .dll file)
blog comments powered by Disqus