So I just got hacked.
- Keverian FireCry
- Way too much time!
- Posts: 2919
- Joined: July 3, 2002, 6:41 pm
- Gender: Mangina
- Location: Seattle, WA
So I just got hacked.
This last Friday I got infected with a Trojan. I immediately ran every scan I had and found one trojan, which I immediately cleaned off my computer. Did a couple full scans that detected nothing major and that was that.
Thinking all was ok, I went online and changed my passwords for email and WoW. Logged on later that night, got some classic dungeon achievements finished and logged for the rest of the weekend.
Spent the weekend at a friends house, where I had no access to a computer. Come Monday I got back home and checked my email only to see that my WoW password had been changed and my main lvl 70 character had been transferred to another server...
I go back through all the normal scans and security measures that have kept me clean for the last decade and change my passwords again. I log in WoW after many hours of freaking out to find that my main character on Suramar is now on Rivendare and was logged off, mostly naked in Shadow Labyrinth where I haven't been in at least 3 months (apparently this is a hub for hackers?).
I've gone through all the petitions and online forms dedicated to similar incidents and an in-game GM helped me through the rest.
So... I just had to know if anyone on VV has had anything like this happen to them and if anyone knows extra steps I can take to protect myself better in the future and to ensure I get my shit back.
This sucks. The end.
Thinking all was ok, I went online and changed my passwords for email and WoW. Logged on later that night, got some classic dungeon achievements finished and logged for the rest of the weekend.
Spent the weekend at a friends house, where I had no access to a computer. Come Monday I got back home and checked my email only to see that my WoW password had been changed and my main lvl 70 character had been transferred to another server...
I go back through all the normal scans and security measures that have kept me clean for the last decade and change my passwords again. I log in WoW after many hours of freaking out to find that my main character on Suramar is now on Rivendare and was logged off, mostly naked in Shadow Labyrinth where I haven't been in at least 3 months (apparently this is a hub for hackers?).
I've gone through all the petitions and online forms dedicated to similar incidents and an in-game GM helped me through the rest.
So... I just had to know if anyone on VV has had anything like this happen to them and if anyone knows extra steps I can take to protect myself better in the future and to ensure I get my shit back.
This sucks. The end.
Re: So I just got hacked.
I go back through all the normal scans and security measures that have kept me clean for the last decade and change my passwords again. I log in WoW after many hours of freaking out to find that my main character on Suramar is now on Rivendare and was logged off, mostly naked in Shadow Labyrinth where I haven't been in at least 3 months (apparently this is a hub for hackers?).
Guildie got hacked a few months back and they spent a good 5 to 10 hours sitting in shadowlabs logging him on and off. I have no idea why. He had everything on his character and in his bags restored iirc, not sure about his bank and gold though.
Going out to play pool now with my fellow klan members. Have a nice night. - Midnyte
Re: So I just got hacked.
By the way, do you have any idea what website caused it?
Going out to play pool now with my fellow klan members. Have a nice night. - Midnyte
-
- Super Poster!
- Posts: 8509
- Joined: July 3, 2002, 1:06 pm
- XBL Gamertag: SillyEskimo
Re: So I just got hacked.
Get one of those keychain thingies from Blizzard. I thik they're only 5 bucks. My friend has one and he's pretty happy with the added protection for his account.
- Kwonryu DragonFist
- Super Poster!
- Posts: 5405
- Joined: July 12, 2002, 6:48 am
Re: So I just got hacked.
Any update Kev?
Re: So I just got hacked.
Most cases are keyloggers gotten from clicking links posted on the official wow forums. They all have the same domain name, and it's really obvious once you learn what it is. I'm too lazy atm to look it up, but I will later today if people are that unfamiliar with it.
-
- Way too much time!
- Posts: 1374
- Joined: July 3, 2002, 3:49 pm
- Gender: Male
- XBL Gamertag: Dyerseve 1321
- Location: Jersey
Re: So I just got hacked.
Just make sure your virus/spyware software is updated daily.
Use AVG. It's realtime protection is the best i've seen around and it'll update on its own.. keep it up to date and you shouldn't have issues.
Use AVG. It's realtime protection is the best i've seen around and it'll update on its own.. keep it up to date and you shouldn't have issues.
Timmah.
- Bubba Grizz
- Super Poster!
- Posts: 6121
- Joined: July 3, 2002, 12:52 pm
- Gender: Male
- Location: Green Bay, Wisconsin
Re: So I just got hacked.
So not posting on the official forums is a good thing then?
- miir
- Super Poster!
- Posts: 11501
- Joined: July 3, 2002, 3:06 pm
- XBL Gamertag: miir1
- Location: Toronto
- Contact:
Re: So I just got hacked.
Running Vista with IE in protected mode is pretty effective at blocking keyloggers.
I've got 99 problems and I'm not dealing with any of them - Lay-Z
Re: So I just got hacked.
No, posting is fine. Just don't click random links.Bubba Grizz wrote:So not posting on the official forums is a good thing then?
The keylogger posts are pretty obvious...they something like "Check this out!" and post a link and nothing else.
The domain is pretty obvious, i'll post it when I get home from work tonight.
- Keverian FireCry
- Way too much time!
- Posts: 2919
- Joined: July 3, 2002, 6:41 pm
- Gender: Mangina
- Location: Seattle, WA
Re: So I just got hacked.
Yeah it was a click from WoW forums. And It definitely won't happen again- I just didnt pay attention to the link itself. Sounded cool...and I clicked. That was that.
Right now I'm just waiting for Account Administration to investigate and get back to me. Hopefully they'll restore everything. I also ordered one of those key chains which sound really great.
Right now I'm just waiting for Account Administration to investigate and get back to me. Hopefully they'll restore everything. I also ordered one of those key chains which sound really great.
-
- Way too much time!
- Posts: 1673
- Joined: July 16, 2004, 11:02 am
- Location: Royal Palm Beach, FL
Re: So I just got hacked.
I TOLD YOU ID SHOOT! BUT YOU DIDNT BELIEVE ME! WHY DIDNT YOU BELIEVE ME?
Re: So I just got hacked.
cadalano wrote:theres actually a lot of forum posts on google about how people have gotten help
link
lmao. I see what you did there!
- Kwonryu DragonFist
- Super Poster!
- Posts: 5405
- Joined: July 12, 2002, 6:48 am
Re: So I just got hacked.
Good one Cadela!
Re: So I just got hacked.
fucking a.
I saw what seems like 10 of them in one day earlier this week. Now I can't find one. They get cleared out by moderators pretty quickly. It's always a 4 part domain, followed by a random thread assignment number.
like httpenis://www.wow.mmo.com/?t=15468
That's not exactly it, but it's close. The number at the end will always be different, but the rest of the address is always the same.
And again, the posts themselves don't actually have any content. They just post in threads, and say "Hey check this out" or "Wow, I can't believe these new changes" or whatever.
edit. oops, forgot to break the link, just in case that is it.
I saw what seems like 10 of them in one day earlier this week. Now I can't find one. They get cleared out by moderators pretty quickly. It's always a 4 part domain, followed by a random thread assignment number.
like httpenis://www.wow.mmo.com/?t=15468
That's not exactly it, but it's close. The number at the end will always be different, but the rest of the address is always the same.
And again, the posts themselves don't actually have any content. They just post in threads, and say "Hey check this out" or "Wow, I can't believe these new changes" or whatever.
edit. oops, forgot to break the link, just in case that is it.
- Keverian FireCry
- Way too much time!
- Posts: 2919
- Joined: July 3, 2002, 6:41 pm
- Gender: Mangina
- Location: Seattle, WA
Re: So I just got hacked.
Well, my character is back on his server, but no items were restored...actually more are missing now that he's been restored. I'm not sure if that means the hacker sold items on the original server first before moving- and then didn't finish clearing em out on the new server? Or maybe they are still working on getting items restored...or uh /shrug.
- Aardor
- Way too much time!
- Posts: 1443
- Joined: July 23, 2002, 12:32 am
- Gender: Male
- XBL Gamertag: Phoenix612
- Location: Allentown, PA
Re: So I just got hacked.
From my experiences with friends getting hacked, they are probably still working on restoring your items. I would make sure they are, since it takes forever for them to do anything, and it can be an argument to get what you want/they promised you.Keverian FireCry wrote:Well, my character is back on his server, but no items were restored...actually more are missing now that he's been restored. I'm not sure if that means the hacker sold items on the original server first before moving- and then didn't finish clearing em out on the new server? Or maybe they are still working on getting items restored...or uh /shrug.
- Keverian FireCry
- Way too much time!
- Posts: 2919
- Joined: July 3, 2002, 6:41 pm
- Gender: Mangina
- Location: Seattle, WA
Re: So I just got hacked.
well things just went from better, to completely fucked.
Just in time for WOTLK! When I try to login into my account it says my account has been closed permanently. I hope to god it just says that when they disable my account for 72 hours, otherwise I'm going to go postal.Greetings ,
* * * NOTICE OF ACCOUNT CLOSURE REVIEW * * *
Account Name:
Account Action: 72 Hour Suspension with review for Account Closure
Offense: World of Warcraft Terms of Use Violation
Details: Character(s) on this account were found to be used for intended exploitation of the World of Warcraft economy.
The actions detailed above have been deemed inappropriate for World of Warcraft by the Blizzard Entertainment In-game Support Staff. As a result, the World of Warcraft account has been given a 72 hour account suspension and will not be accessible for the duration thereof. This World of Warcraft account has also been forwarded to our Account Administration team for review of current and previous policy infractions to determine if further account actions, up to and including account closure, are necessary. Our Account Administration team will contact you with a decision once all information has been reviewed.
Thank you for respecting our position on this matter.
Any disputes or questions concerning this account review can only be addressed by Account Administration. To learn more about how Account Administration is able to assist you, please visit us at http://www.blizzard.com/support/wowaa/.
Please visit http://www.worldofwarcraft.com/termsofuse.shtml for further information and to review the World of Warcraft Terms of Use.
Regards,
Vohinton
Game Master
Blizzard Entertainment
http://www.worldofwarcraft.com
- Xouqoa
- Way too much time!
- Posts: 4103
- Joined: July 2, 2002, 5:49 pm
- Gender: Mangina
- XBL Gamertag: Xouqoa
- Location: Dallas, TX
- Contact:
Re: So I just got hacked.
Man, that sucks. I'm sorry.
"Our problems are man-made, therefore they may be solved by man. No problem of human destiny is beyond human beings." - John F Kennedy
-
- Star Farmer
- Posts: 460
- Joined: July 3, 2002, 6:27 pm
- Location: Vancouver, WA
- Contact:
Re: So I just got hacked.
About the only thing I can say is: Keep at it. You will get restored and unbanned.
Also, please install Firefox with the NoScript addon.
Also, please install Firefox with the NoScript addon.
-
- Super Poster!
- Posts: 8509
- Joined: July 3, 2002, 1:06 pm
- XBL Gamertag: SillyEskimo
Re: So I just got hacked.
I can't help, but I feel for you!
- Keverian FireCry
- Way too much time!
- Posts: 2919
- Joined: July 3, 2002, 6:41 pm
- Gender: Mangina
- Location: Seattle, WA
Re: So I just got hacked.
I do have Firefox, but I'll go find NoScript.
- Jarori Bloodletter
- Star Farmer
- Posts: 323
- Joined: July 4, 2002, 6:15 am
- Gender: Male
- Location: Vancouver, WA
- Contact:
Re: So I just got hacked.
Same sorta thing happened to my 70 priest, i kept calling Blizz every damn day and sent many e-mails and in 4 days it was all restored and good. I did have to tell them the account was "Secure" now and etc.
1800-592-5499 Is blizzards number in case anyone else needs it.
1800-592-5499 Is blizzards number in case anyone else needs it.
Eq1
Jarori Bloodletter (retired)
Emgug 85 Cleric
Fugara 85 Shaman
Jardoeni 85 Beastlord
Jarori Bloodletter (retired)
Emgug 85 Cleric
Fugara 85 Shaman
Jardoeni 85 Beastlord
- Animalor
- Super Poster!
- Posts: 5902
- Joined: July 8, 2002, 12:03 pm
- Gender: Male
- XBL Gamertag: Anirask
- PSN ID: Anirask
- Location: Canada
Re: So I just got hacked.
Good god that sucks. Sorry bro.
My personal #1 rule is that a system is compromised, I nuke and rebuild. At work I drop an image and at home I rebuild.
Sure it's an inconvenience but I can't trust a system that's been compromised once.
Hopefully Blizzard realises that this wasn't you and you get your account and stuff back.
My personal #1 rule is that a system is compromised, I nuke and rebuild. At work I drop an image and at home I rebuild.
Sure it's an inconvenience but I can't trust a system that's been compromised once.
Hopefully Blizzard realises that this wasn't you and you get your account and stuff back.
Re: So I just got hacked.
There's room on EQ servers if things don't work out!
Have You Hugged An Iksar Today?
--
--
- Kwonryu DragonFist
- Super Poster!
- Posts: 5405
- Joined: July 12, 2002, 6:48 am
Re: So I just got hacked.
Dawn Kev!
This has to work out!
Hope you will get resolution soon! For the Better!
This has to work out!
Hope you will get resolution soon! For the Better!
- Xanupox
- Almost 1337
- Posts: 518
- Joined: July 5, 2002, 2:15 pm
- Gender: Male
- PSN ID: TheRealScarr
- Contact:
Re: So I just got hacked.
Wow is for losers. Thank the unknown hacker who just saved your life!
I probably gave you virtual items once upon a time...
- Keverian FireCry
- Way too much time!
- Posts: 2919
- Joined: July 3, 2002, 6:41 pm
- Gender: Mangina
- Location: Seattle, WA
Re: So I just got hacked.
It turns out that it was just a complete shutdown of my account for a limited time while they finished investigating.
They ended up sending me a form that I had to fill out and scan/fax to them with a photo copy of my license. I now have my character back just in time to play WoTLK. However, apparently the reason for them shutting down my account was that after I recovered most of my items, and initially recovered my account, someone still was able to access it and start selling stuff. So I'm missing my entire warrior dps set and many craft materials and other things- like nostalgic Linkin's Sword of Mastery/Boomerang form Un'Goro...etc.
They haven't touched most of my tank gear(my main spec) aside from my T6 helm, but I have a T4 which has great block raiting, and I'm sure WoTLK will replace everything I've lost in due time.
Apparently I had THREE different trojans that were dedicated to WoW and neither McAfee, RegMechanic, AVG, or Ad-Aware picked them up. However HijackThis was able to detect them, and BitDefender was able to clean two of them. I had to manually clear my computer of the other with HijackThis's help.
Thx for all responses and helpful tips. Come log in on Suramar alliance if you want to join my lvl 70 warrior with your new DK. Cya!
They ended up sending me a form that I had to fill out and scan/fax to them with a photo copy of my license. I now have my character back just in time to play WoTLK. However, apparently the reason for them shutting down my account was that after I recovered most of my items, and initially recovered my account, someone still was able to access it and start selling stuff. So I'm missing my entire warrior dps set and many craft materials and other things- like nostalgic Linkin's Sword of Mastery/Boomerang form Un'Goro...etc.
They haven't touched most of my tank gear(my main spec) aside from my T6 helm, but I have a T4 which has great block raiting, and I'm sure WoTLK will replace everything I've lost in due time.
Apparently I had THREE different trojans that were dedicated to WoW and neither McAfee, RegMechanic, AVG, or Ad-Aware picked them up. However HijackThis was able to detect them, and BitDefender was able to clean two of them. I had to manually clear my computer of the other with HijackThis's help.
Thx for all responses and helpful tips. Come log in on Suramar alliance if you want to join my lvl 70 warrior with your new DK. Cya!
- Animalor
- Super Poster!
- Posts: 5902
- Joined: July 8, 2002, 12:03 pm
- Gender: Male
- XBL Gamertag: Anirask
- PSN ID: Anirask
- Location: Canada
Re: So I just got hacked.
You had 3 different trojans(that you know of) and and still won't wipe that machine??Keverian FireCry wrote: Apparently I had THREE different trojans that were dedicated to WoW and neither McAfee, RegMechanic, AVG, or Ad-Aware picked them up. However HijackThis was able to detect them, and BitDefender was able to clean two of them. I had to manually clear my computer of the other with HijackThis's help.
How can you trust that there isn't some other 0-day or delivery mechanism on that system that hasn't been removed yet?
- Bubba Grizz
- Super Poster!
- Posts: 6121
- Joined: July 3, 2002, 12:52 pm
- Gender: Male
- Location: Green Bay, Wisconsin
Re: So I just got hacked.
I'm with him ^ I'd have wiped the machine first thing. I tend to set restore points on a regular basis but even then you can't really be sure. Wipe the machine. The expansion will still be there and while it is really cool it can definitly wait half a day.
-
- Way too much time!
- Posts: 1374
- Joined: July 3, 2002, 3:49 pm
- Gender: Male
- XBL Gamertag: Dyerseve 1321
- Location: Jersey
Re: So I just got hacked.
yeesh you guys are extreme...you can spend 45 minutes and clean all traces of the thing out rather than wipe the thing and start over.. ive had machines so infected they'd give me fake BSODs or hide the C: or disable cmd or task manager and still got every trace of them out.. theres a whole array of different tools you can download for free that'll clean out just about everything.
Timmah.
-
- Way too much time!
- Posts: 1673
- Joined: July 16, 2004, 11:02 am
- Location: Royal Palm Beach, FL
Re: So I just got hacked.
and if you miss anything, you get royally fucked. its naive to think with 100% confidence that you can completely clean your machine out, even if you do completely clean your machine out. if you suspect that you have been infected with a keylogger-- the risk ain't worth it. especially when the malware involved was designed by someone whose daily rice ration depends on making sure that thing hits its target despite your best efforts.
I TOLD YOU ID SHOOT! BUT YOU DIDNT BELIEVE ME! WHY DIDNT YOU BELIEVE ME?
- miir
- Super Poster!
- Posts: 11501
- Joined: July 3, 2002, 3:06 pm
- XBL Gamertag: miir1
- Location: Toronto
- Contact:
Re: So I just got hacked.
So the next time (when not if) you get hacked, it will be your own fucking fault for not wiping your PC.
I've got 99 problems and I'm not dealing with any of them - Lay-Z
- Animalor
- Super Poster!
- Posts: 5902
- Joined: July 8, 2002, 12:03 pm
- Gender: Male
- XBL Gamertag: Anirask
- PSN ID: Anirask
- Location: Canada
Re: So I just got hacked.
Or we could buy a Mac and play WoW on that. I don't believe they're prone to keyloggers...
What browser are you using Kev?
I would highly recommend using sandboxie (http://www.sandboxie.com/) with effectively places all interactions and changes to your system form browsers in a sandbox, permitting you to easily discard change to your system done by a browser.
There's also the NoScript plugin from Firefox that would be good but may drive you up the bend having to allow scripts every time you hit a different webpage.
What browser are you using Kev?
I would highly recommend using sandboxie (http://www.sandboxie.com/) with effectively places all interactions and changes to your system form browsers in a sandbox, permitting you to easily discard change to your system done by a browser.
There's also the NoScript plugin from Firefox that would be good but may drive you up the bend having to allow scripts every time you hit a different webpage.
-
- Way too much time!
- Posts: 1673
- Joined: July 16, 2004, 11:02 am
- Location: Royal Palm Beach, FL
Re: So I just got hacked.
the best protection is the login dongle thing that blizzard offers
I TOLD YOU ID SHOOT! BUT YOU DIDNT BELIEVE ME! WHY DIDNT YOU BELIEVE ME?
- miir
- Super Poster!
- Posts: 11501
- Joined: July 3, 2002, 3:06 pm
- XBL Gamertag: miir1
- Location: Toronto
- Contact:
Re: So I just got hacked.
That's how IE works in protected mode in Vista.Animalor wrote:I would highly recommend using sandboxie (http://www.sandboxie.com/) with effectively places all interactions and changes to your system form browsers in a sandbox, permitting you to easily discard change to your system done by a browser.
I've got 99 problems and I'm not dealing with any of them - Lay-Z
Re: So I just got hacked.
so a friend i play wow with miss typed worldofwarcraft.com this morning to something of "worldfwarcraft.com" and is abit worried not that they got any virus warnings or anything there just paranoid about these damn keyloggers and hackers in regards to wow. i ran the site on a totally isolated pc from my network, with all the standard antivirus/spybot/adaware/ and did a scan afterwards. nothing came up at all. to me honestly just seems like a placeholder domain for another site but i could be wrong, i was wondering if anyone confident on internet security would take a look just to confirm?
Thanks
Toalin
Thanks
Toalin
- Xouqoa
- Way too much time!
- Posts: 4103
- Joined: July 2, 2002, 5:49 pm
- Gender: Mangina
- XBL Gamertag: Xouqoa
- Location: Dallas, TX
- Contact:
Re: So I just got hacked.
QFTcadalano wrote:the best protection is the login dongle thing that blizzard offers
Best $7 you will ever spend as a WoW player.
"Our problems are man-made, therefore they may be solved by man. No problem of human destiny is beyond human beings." - John F Kennedy
-
- Way too much time!
- Posts: 1374
- Joined: July 3, 2002, 3:49 pm
- Gender: Male
- XBL Gamertag: Dyerseve 1321
- Location: Jersey
Re: So I just got hacked.
I went there and got re-directed numerous times to some random asian site.. no spyware/virus hits on any of my IS software.. ran full scans with two seperate utilities and came back clean..Toalin wrote:so a friend i play wow with miss typed worldofwarcraft.com this morning to something of "worldfwarcraft.com" and is abit worried not that they got any virus warnings or anything there just paranoid about these damn keyloggers and hackers in regards to wow. i ran the site on a totally isolated pc from my network, with all the standard antivirus/spybot/adaware/ and did a scan afterwards. nothing came up at all. to me honestly just seems like a placeholder domain for another site but i could be wrong, i was wondering if anyone confident on internet security would take a look just to confirm?
Thanks
Toalin
Most of the time those websites are bought just for advertising purposes.. People actually make a lot of money of of mis-types. Nothing to be too worried about.
Timmah.
- Janx
- Almost 1337
- Posts: 537
- Joined: July 3, 2002, 1:44 pm
- Gender: Mangina
- XBL Gamertag: Janx
- Location: Memphis
Re: So I just got hacked.
If I even suspect a trojan/keylogger on my system I reload. 2hrs of my time to be fully back up and playing vs days of bullshit with CS etc.. + peace of mind that you're SURE you got the damn thing is a no brainer to me.
-
- Star Farmer
- Posts: 460
- Joined: July 3, 2002, 6:27 pm
- Location: Vancouver, WA
- Contact:
Re: So I just got hacked.
Blizzard Authenticator = Best $6.50 I ever spent.
You only need 1 for all of your accounts so no need to buy 1 for each.
Anyways, peace of mind for $6.50? Priceless.
I understand they are sold out right now though, but keep looking... http://www.blizzard.com click on "Blizzard Store"
You only need 1 for all of your accounts so no need to buy 1 for each.
Anyways, peace of mind for $6.50? Priceless.
I understand they are sold out right now though, but keep looking... http://www.blizzard.com click on "Blizzard Store"
Khrashdin 80 Protection Paladin
Vox Immortalis - Hyjal-US
#1 World Ranked 10man Strict Achievement Guild
#3 World Ranked 10man Strict Progression Guild
http://www.guildox.com The Premier Guild Ranking Site
Vox Immortalis - Hyjal-US
#1 World Ranked 10man Strict Achievement Guild
#3 World Ranked 10man Strict Progression Guild
http://www.guildox.com The Premier Guild Ranking Site