Key logger? World of warcraft account hacked =-X

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jamiekins, Nov 23, 2009.

  1. Jamiekins

    Jamiekins Private E-2

    My warcraft account was hacked Nov 21st. The only thing I can think of being the culprit was I was trying to watch twilight online.

    I contacted blizzard and they put my account on hold to investigate.

    I am just wondering if the key logger or whatever it was that was on my computer is still there? I do not have access to another secure computer so I changed all my passwords with the on screen keyboard in hopes of getting this lil stinker off my trail.

    Following are all logs from the programs I could run as directed by the malware removal post.
    I could not run ComboFix as it said norton was still running, although I do not have a virus/firewall installed atm. I also could not run RootRepeal as when I attempted to, it just restarted my computer after displaying a blue screened message originating from the application.

    Thank you so much for your time and effort in this manner, I am going to reinstall my AV now.
     

    Attached Files:

    Last edited: Nov 23, 2009
  2. Jamiekins

    Jamiekins Private E-2

    I just got off the phone with a Blizzard account specialist Dave who said that customers who installed addons from "wowmatrix" or "Curse.com" have been having the same troubles as me. So where did it come from has been solved as I have addons from both those places =-X
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still needing assistance or has the issue been resolved?
     
  4. Jamiekins

    Jamiekins Private E-2

    Hi Tim

    I did like 10 system restores and it seems fine to me but Blizzard emailed me to say there was still occurrences of another IP address accessing my account so something has still got to be on my computer =-(

    I will attempt to run the two scans I could not run before and if they run I will post the logs
     
  5. Jamiekins

    Jamiekins Private E-2

    I still cannot run Rootrepeal or ComboFix, following are error messages I received.

    Avast! (AV) said "Kaspersky anti-virus is running" and can cause complications.
    I don't have Kaspersky installed to my knowledge lol

    ComboFix had a pop up during start up saying "anti-virus: norton security online"
    Which I am assuming is my ISP provided all in one AV, firewall ect. I turned it off and conbofix still could not do its thing and my comp restarted.

    Rootrepeal errored with this message "Kernel_Stack_inpage_error"

    So here are the updated logs I got from the programs I could run.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So you have done a few system restores?

    You need to clean up your desktop. Create a folder on you C:\ drive to store all the jpg images.
    Let's do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now see if you can use windows to find this file:
    Code:
    C:\WINDOWS\system32\"
    0833~1        Nov 23 2009          40  "?????????????????????????????????????????????????"
    
    Tell me if you find it and the complete name of it as well as the properties of it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
    Last edited: Nov 26, 2009
  7. Jamiekins

    Jamiekins Private E-2

    Ok done

    I had an error box pop up after running the scripts in the avenger program (screen cap to follow)

    I could not find the system32 file you asked me to locate but I did find another file titled in an asian language with the same date as requested. (screen cap of properties for that file enclosed) named 㩃停潲牧浡䘠汩獥剜杯牥⁳湏楬敮倠潲整瑣潩屮潒敧獲传汮湩⁥牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩⹷潣普杩

    I also include a screen cap for ccleaner to ensure I have followed your directions to a T.
     

    Attached Files:

  8. Jamiekins

    Jamiekins Private E-2

    MGLogs
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will look at your logs tomorrow. Long day. Go back to that sys32 file and delete it.

    Eat a turkey.....:)
     
  10. Jamiekins

    Jamiekins Private E-2

    Thank you so much for your help again, If I ever win a jackpot I'm so sending you money lol
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And I could sure use it...LOL. But I won't hold my breath. ;)
     
  12. Jamiekins

    Jamiekins Private E-2

    Do I have anything on my comp? I think I do as one of the characters in wow I don't play often got some mail from the auction house for items I did not auction. =-(
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay.

    You may need to contact the owners of the WOW site.....however, lets remove a few things that I see that may be a problem.

    You still need to remove this:
    Code:
    C:\WINDOWS\system32\"
    0833~1        Nov 23 2009          40  "?????????????????????????????????????????????????"
    Then use windows explorer to find and delete:
    C:\Documents and Settings\New Owner\Local Settings\temp\A2TEMP
    C:\Documents and Settings\New Owner\Local Settings\temp\ZaYDNWZo.exe.part

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  14. Jamiekins

    Jamiekins Private E-2

    I could not find
    C:\Documents and Settings\New Owner\Local Settings\temp\A2TEMP
    C:\Documents and Settings\New Owner\Local Settings\temp\ZaYDNWZo.exe.part

    In the folder and I searched for them with search all hidden files and folders checked =-\

    I deleted a 0833~1.jpg file that said it was in desktop logs
     
  15. Jamiekins

    Jamiekins Private E-2

    here is the new log
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All the pictures that you have spread all over you desktop and on the C:\ drive should be put in a folder.
    Your logs are clean. The only thing I can suggest is that you use a different computer to change your password on WOW> and if you continue to have issues with it, contact the web site.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds