Hacked WoW acc, time for a cleanout

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nazca, Apr 18, 2013.

  1. Nazca

    Nazca Private E-2

    As stated someone hacked my battle.net account and initiated a character transfer and faction change on my dormant level 85 rogue. I've since locked up the account, changed passwords, changed email passwords etc. But clearly there was an intrusion into my PC and a likely keylogger/malware present.

    I first ran Comodo antivirus and it found nothing. Hence I went on your website. I ran all tests to good effect. I did however encounter a very troubling (if temporary) issue when running MGtools. I turned off Comodo as instructed but immediately any actions on my part gave an error of "Windows cannot access the specified device, path, or file. You may not have the appropriate permission to access the item". And I mean ANY actions. Attempting to access MGtools, attempting to access Chrome, anything. I was basically locked out of the comp. So I rebooted, and instead of turning comodo off I left it on, deleted the MGtools C: path folder and tried again. Only this time I only turned comodo off once my wireless connection was severed. MGtools ran to completion with no errors. But I'm afraid of some sort of malware induced lockout should my antivirus/firewall fail in the future.

    I really just want to give this comp a good cleanout while it's still functioning at a good level. I've had times in the past where I used your site and getting a scan to finish on a diseased PC was a massive victory on its own. Currently there were numerous detected errors in the scans so please let me know how to proceed. As instructed I ignored/skipped over certain errors to garner good logs. Any help would be greatly appreciated. Thanks in advance for your help and to regular users of this site. It's a huge plus that there are people out there who're around to help, so thank you!

    -Nazca
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. Nazca

    Nazca Private E-2

    Secure Computer and e-mail.
    1a.) As I said above I've secured my email and WoW account.
    b.) I changed the e-mail pass from a safe location
    c.) Not applicable
    d.) I've fully updated spybot search and destroy and comodo antivirus/firewall.
    e.)1. Windows is updated
    2. & 3. Comodo Antivirus / Firewall, scanned and came up clean (see above)
    4. CC cleaner was installed and ran regularly.
    5. Realtime blocker - Comodo
    Spybot is installed, scanned and immunized came up clean. Ran SuperAntispyware to completion as well.
    Spywareblaster - installed as per your instructions.
    7-15. Miscellaneous tips and tricks. I use chrome as a default and Firefox as backup so some of it not applicable. The rest isn't news.

    f.) Above are the attached scans as recommended in this bullet point. Would love to get feedback on how to handle the detected potential threats found in multiple scans.

    Secure WoW account
    2a-d.) WoW account is already secured.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only malware in your logs are what Hitman found. You can rerun it and delete those files. What issues are you having?
     
  5. Nazca

    Nazca Private E-2

    I guess none frankly, I just want to make sure everything's okay and my laptop is actually clean.

    I deleted those few items in Hitman Pro. Also used SuperAntispyware and found 182 items. So with all that done, so long as the logs look okay I'm confident that my issues are solved. Thanks for your help man.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  7. Nazca

    Nazca Private E-2

    Thanks again man, I'm gonna go to your optimization section and continue tweaking. Thanks again.
     
  8. Nazca

    Nazca Private E-2

    P.S. if you could link me to some more optimization threads that you find most helpful for increasing performance/ maintaining the system.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Check some of the threads HERE.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds