So I just got hacked.

WoW Discussion
Post Reply
User avatar
Keverian FireCry
Way too much time!
Way too much time!
Posts: 2919
Joined: July 3, 2002, 6:41 pm
Gender: Mangina
Location: Seattle, WA

So I just got hacked.

Post by Keverian FireCry »

This last Friday I got infected with a Trojan. I immediately ran every scan I had and found one trojan, which I immediately cleaned off my computer. Did a couple full scans that detected nothing major and that was that.

Thinking all was ok, I went online and changed my passwords for email and WoW. Logged on later that night, got some classic dungeon achievements finished and logged for the rest of the weekend.

Spent the weekend at a friends house, where I had no access to a computer. Come Monday I got back home and checked my email only to see that my WoW password had been changed and my main lvl 70 character had been transferred to another server...

I go back through all the normal scans and security measures that have kept me clean for the last decade and change my passwords again. I log in WoW after many hours of freaking out to find that my main character on Suramar is now on Rivendare and was logged off, mostly naked in Shadow Labyrinth where I haven't been in at least 3 months (apparently this is a hub for hackers?).

I've gone through all the petitions and online forms dedicated to similar incidents and an in-game GM helped me through the rest.

So... I just had to know if anyone on VV has had anything like this happen to them and if anyone knows extra steps I can take to protect myself better in the future and to ensure I get my shit back.

This sucks. The end.
Bagar-
Star Farmer
Star Farmer
Posts: 434
Joined: September 20, 2007, 5:09 pm
Gender: Male

Re: So I just got hacked.

Post by Bagar- »

I go back through all the normal scans and security measures that have kept me clean for the last decade and change my passwords again. I log in WoW after many hours of freaking out to find that my main character on Suramar is now on Rivendare and was logged off, mostly naked in Shadow Labyrinth where I haven't been in at least 3 months (apparently this is a hub for hackers?).

Guildie got hacked a few months back and they spent a good 5 to 10 hours sitting in shadowlabs logging him on and off. I have no idea why. He had everything on his character and in his bags restored iirc, not sure about his bank and gold though.
Going out to play pool now with my fellow klan members. Have a nice night. - Midnyte
Bagar-
Star Farmer
Star Farmer
Posts: 434
Joined: September 20, 2007, 5:09 pm
Gender: Male

Re: So I just got hacked.

Post by Bagar- »

By the way, do you have any idea what website caused it?
Going out to play pool now with my fellow klan members. Have a nice night. - Midnyte
Fairweather Pure
Super Poster!
Super Poster!
Posts: 8509
Joined: July 3, 2002, 1:06 pm
XBL Gamertag: SillyEskimo

Re: So I just got hacked.

Post by Fairweather Pure »

Get one of those keychain thingies from Blizzard. I thik they're only 5 bucks. My friend has one and he's pretty happy with the added protection for his account.
User avatar
Kwonryu DragonFist
Super Poster!
Super Poster!
Posts: 5405
Joined: July 12, 2002, 6:48 am

Re: So I just got hacked.

Post by Kwonryu DragonFist »

Any update Kev?
User avatar
Truant
Way too much time!
Way too much time!
Posts: 4440
Joined: July 4, 2002, 12:37 am
Location: Trumania
Contact:

Re: So I just got hacked.

Post by Truant »

Most cases are keyloggers gotten from clicking links posted on the official wow forums. They all have the same domain name, and it's really obvious once you learn what it is. I'm too lazy atm to look it up, but I will later today if people are that unfamiliar with it.
Soreali
Way too much time!
Way too much time!
Posts: 1374
Joined: July 3, 2002, 3:49 pm
Gender: Male
XBL Gamertag: Dyerseve 1321
Location: Jersey

Re: So I just got hacked.

Post by Soreali »

Just make sure your virus/spyware software is updated daily.

Use AVG. It's realtime protection is the best i've seen around and it'll update on its own.. keep it up to date and you shouldn't have issues.
Timmah.


Image
User avatar
Bubba Grizz
Super Poster!
Super Poster!
Posts: 6121
Joined: July 3, 2002, 12:52 pm
Gender: Male
Location: Green Bay, Wisconsin

Re: So I just got hacked.

Post by Bubba Grizz »

So not posting on the official forums is a good thing then?
User avatar
miir
Super Poster!
Super Poster!
Posts: 11501
Joined: July 3, 2002, 3:06 pm
XBL Gamertag: miir1
Location: Toronto
Contact:

Re: So I just got hacked.

Post by miir »

Running Vista with IE in protected mode is pretty effective at blocking keyloggers. :)
I've got 99 problems and I'm not dealing with any of them - Lay-Z
User avatar
Truant
Way too much time!
Way too much time!
Posts: 4440
Joined: July 4, 2002, 12:37 am
Location: Trumania
Contact:

Re: So I just got hacked.

Post by Truant »

Bubba Grizz wrote:So not posting on the official forums is a good thing then?
No, posting is fine. Just don't click random links.

The keylogger posts are pretty obvious...they something like "Check this out!" and post a link and nothing else.

The domain is pretty obvious, i'll post it when I get home from work tonight.
User avatar
Keverian FireCry
Way too much time!
Way too much time!
Posts: 2919
Joined: July 3, 2002, 6:41 pm
Gender: Mangina
Location: Seattle, WA

Re: So I just got hacked.

Post by Keverian FireCry »

Yeah it was a click from WoW forums. And It definitely won't happen again- I just didnt pay attention to the link itself. Sounded cool...and I clicked. That was that.

Right now I'm just waiting for Account Administration to investigate and get back to me. Hopefully they'll restore everything. I also ordered one of those key chains which sound really great.
cadalano
Way too much time!
Way too much time!
Posts: 1673
Joined: July 16, 2004, 11:02 am
Location: Royal Palm Beach, FL

Re: So I just got hacked.

Post by cadalano »

theres actually a lot of forum posts on google about how people have gotten help

link
I TOLD YOU ID SHOOT! BUT YOU DIDNT BELIEVE ME! WHY DIDNT YOU BELIEVE ME?
User avatar
Truant
Way too much time!
Way too much time!
Posts: 4440
Joined: July 4, 2002, 12:37 am
Location: Trumania
Contact:

Re: So I just got hacked.

Post by Truant »

cadalano wrote:theres actually a lot of forum posts on google about how people have gotten help

link

lmao. I see what you did there!
User avatar
Kwonryu DragonFist
Super Poster!
Super Poster!
Posts: 5405
Joined: July 12, 2002, 6:48 am

Re: So I just got hacked.

Post by Kwonryu DragonFist »

Good one Cadela! :D
User avatar
Truant
Way too much time!
Way too much time!
Posts: 4440
Joined: July 4, 2002, 12:37 am
Location: Trumania
Contact:

Re: So I just got hacked.

Post by Truant »

fucking a.

I saw what seems like 10 of them in one day earlier this week. Now I can't find one. They get cleared out by moderators pretty quickly. It's always a 4 part domain, followed by a random thread assignment number.

like httpenis://www.wow.mmo.com/?t=15468

That's not exactly it, but it's close. The number at the end will always be different, but the rest of the address is always the same.

And again, the posts themselves don't actually have any content. They just post in threads, and say "Hey check this out" or "Wow, I can't believe these new changes" or whatever.

edit. oops, forgot to break the link, just in case that is it.
User avatar
Keverian FireCry
Way too much time!
Way too much time!
Posts: 2919
Joined: July 3, 2002, 6:41 pm
Gender: Mangina
Location: Seattle, WA

Re: So I just got hacked.

Post by Keverian FireCry »

Well, my character is back on his server, but no items were restored...actually more are missing now that he's been restored. I'm not sure if that means the hacker sold items on the original server first before moving- and then didn't finish clearing em out on the new server? Or maybe they are still working on getting items restored...or uh /shrug.
User avatar
Aardor
Way too much time!
Way too much time!
Posts: 1443
Joined: July 23, 2002, 12:32 am
Gender: Male
XBL Gamertag: Phoenix612
Location: Allentown, PA

Re: So I just got hacked.

Post by Aardor »

Keverian FireCry wrote:Well, my character is back on his server, but no items were restored...actually more are missing now that he's been restored. I'm not sure if that means the hacker sold items on the original server first before moving- and then didn't finish clearing em out on the new server? Or maybe they are still working on getting items restored...or uh /shrug.
From my experiences with friends getting hacked, they are probably still working on restoring your items. I would make sure they are, since it takes forever for them to do anything, and it can be an argument to get what you want/they promised you.
User avatar
Keverian FireCry
Way too much time!
Way too much time!
Posts: 2919
Joined: July 3, 2002, 6:41 pm
Gender: Mangina
Location: Seattle, WA

Re: So I just got hacked.

Post by Keverian FireCry »

well things just went from better, to completely fucked.

Greetings ,

* * * NOTICE OF ACCOUNT CLOSURE REVIEW * * *

Account Name:
Account Action: 72 Hour Suspension with review for Account Closure

Offense: World of Warcraft Terms of Use Violation

Details: Character(s) on this account were found to be used for intended exploitation of the World of Warcraft economy.

The actions detailed above have been deemed inappropriate for World of Warcraft by the Blizzard Entertainment In-game Support Staff. As a result, the World of Warcraft account has been given a 72 hour account suspension and will not be accessible for the duration thereof. This World of Warcraft account has also been forwarded to our Account Administration team for review of current and previous policy infractions to determine if further account actions, up to and including account closure, are necessary. Our Account Administration team will contact you with a decision once all information has been reviewed.

Thank you for respecting our position on this matter.

Any disputes or questions concerning this account review can only be addressed by Account Administration. To learn more about how Account Administration is able to assist you, please visit us at http://www.blizzard.com/support/wowaa/.

Please visit http://www.worldofwarcraft.com/termsofuse.shtml for further information and to review the World of Warcraft Terms of Use.



Regards,
Vohinton
Game Master
Blizzard Entertainment
http://www.worldofwarcraft.com
Just in time for WOTLK! When I try to login into my account it says my account has been closed permanently. I hope to god it just says that when they disable my account for 72 hours, otherwise I'm going to go postal.
User avatar
Xouqoa
Way too much time!
Way too much time!
Posts: 4103
Joined: July 2, 2002, 5:49 pm
Gender: Mangina
XBL Gamertag: Xouqoa
Location: Dallas, TX
Contact:

Re: So I just got hacked.

Post by Xouqoa »

Man, that sucks. I'm sorry. :(
"Our problems are man-made, therefore they may be solved by man. No problem of human destiny is beyond human beings." - John F Kennedy
Diae Soulmender
Star Farmer
Star Farmer
Posts: 460
Joined: July 3, 2002, 6:27 pm
Location: Vancouver, WA
Contact:

Re: So I just got hacked.

Post by Diae Soulmender »

About the only thing I can say is: Keep at it. You will get restored and unbanned.

Also, please install Firefox with the NoScript addon.
Fairweather Pure
Super Poster!
Super Poster!
Posts: 8509
Joined: July 3, 2002, 1:06 pm
XBL Gamertag: SillyEskimo

Re: So I just got hacked.

Post by Fairweather Pure »

I can't help, but I feel for you!
User avatar
Keverian FireCry
Way too much time!
Way too much time!
Posts: 2919
Joined: July 3, 2002, 6:41 pm
Gender: Mangina
Location: Seattle, WA

Re: So I just got hacked.

Post by Keverian FireCry »

I do have Firefox, but I'll go find NoScript.
User avatar
Jarori Bloodletter
Star Farmer
Star Farmer
Posts: 323
Joined: July 4, 2002, 6:15 am
Gender: Male
Location: Vancouver, WA
Contact:

Re: So I just got hacked.

Post by Jarori Bloodletter »

Same sorta thing happened to my 70 priest, i kept calling Blizz every damn day and sent many e-mails and in 4 days it was all restored and good. I did have to tell them the account was "Secure" now and etc.

1800-592-5499 Is blizzards number in case anyone else needs it.
Eq1
Jarori Bloodletter (retired)
Emgug 85 Cleric
Fugara 85 Shaman
Jardoeni 85 Beastlord
User avatar
Animalor
Super Poster!
Super Poster!
Posts: 5902
Joined: July 8, 2002, 12:03 pm
Gender: Male
XBL Gamertag: Anirask
PSN ID: Anirask
Location: Canada

Re: So I just got hacked.

Post by Animalor »

Good god that sucks. Sorry bro.
My personal #1 rule is that a system is compromised, I nuke and rebuild. At work I drop an image and at home I rebuild.
Sure it's an inconvenience but I can't trust a system that's been compromised once.

Hopefully Blizzard realises that this wasn't you and you get your account and stuff back.
User avatar
Aslanna
Super Poster!
Super Poster!
Posts: 12382
Joined: July 3, 2002, 12:57 pm

Re: So I just got hacked.

Post by Aslanna »

There's room on EQ servers if things don't work out!
Have You Hugged An Iksar Today?

--
User avatar
Kwonryu DragonFist
Super Poster!
Super Poster!
Posts: 5405
Joined: July 12, 2002, 6:48 am

Re: So I just got hacked.

Post by Kwonryu DragonFist »

Dawn Kev!

This has to work out!

Hope you will get resolution soon! For the Better!
User avatar
Xanupox
Almost 1337
Almost 1337
Posts: 518
Joined: July 5, 2002, 2:15 pm
Gender: Male
PSN ID: TheRealScarr
Contact:

Re: So I just got hacked.

Post by Xanupox »

Wow is for losers. Thank the unknown hacker who just saved your life!
I probably gave you virtual items once upon a time...
User avatar
Keverian FireCry
Way too much time!
Way too much time!
Posts: 2919
Joined: July 3, 2002, 6:41 pm
Gender: Mangina
Location: Seattle, WA

Re: So I just got hacked.

Post by Keverian FireCry »

It turns out that it was just a complete shutdown of my account for a limited time while they finished investigating.

They ended up sending me a form that I had to fill out and scan/fax to them with a photo copy of my license. I now have my character back just in time to play WoTLK. However, apparently the reason for them shutting down my account was that after I recovered most of my items, and initially recovered my account, someone still was able to access it and start selling stuff. So I'm missing my entire warrior dps set and many craft materials and other things- like nostalgic Linkin's Sword of Mastery/Boomerang form Un'Goro...etc.

They haven't touched most of my tank gear(my main spec) aside from my T6 helm, but I have a T4 which has great block raiting, and I'm sure WoTLK will replace everything I've lost in due time.

Apparently I had THREE different trojans that were dedicated to WoW and neither McAfee, RegMechanic, AVG, or Ad-Aware picked them up. However HijackThis was able to detect them, and BitDefender was able to clean two of them. I had to manually clear my computer of the other with HijackThis's help.

Thx for all responses and helpful tips. Come log in on Suramar alliance if you want to join my lvl 70 warrior with your new DK. Cya!
User avatar
Animalor
Super Poster!
Super Poster!
Posts: 5902
Joined: July 8, 2002, 12:03 pm
Gender: Male
XBL Gamertag: Anirask
PSN ID: Anirask
Location: Canada

Re: So I just got hacked.

Post by Animalor »

Keverian FireCry wrote: Apparently I had THREE different trojans that were dedicated to WoW and neither McAfee, RegMechanic, AVG, or Ad-Aware picked them up. However HijackThis was able to detect them, and BitDefender was able to clean two of them. I had to manually clear my computer of the other with HijackThis's help.
You had 3 different trojans(that you know of) and and still won't wipe that machine??

How can you trust that there isn't some other 0-day or delivery mechanism on that system that hasn't been removed yet?
User avatar
Bubba Grizz
Super Poster!
Super Poster!
Posts: 6121
Joined: July 3, 2002, 12:52 pm
Gender: Male
Location: Green Bay, Wisconsin

Re: So I just got hacked.

Post by Bubba Grizz »

I'm with him ^ I'd have wiped the machine first thing. I tend to set restore points on a regular basis but even then you can't really be sure. Wipe the machine. The expansion will still be there and while it is really cool it can definitly wait half a day.
Soreali
Way too much time!
Way too much time!
Posts: 1374
Joined: July 3, 2002, 3:49 pm
Gender: Male
XBL Gamertag: Dyerseve 1321
Location: Jersey

Re: So I just got hacked.

Post by Soreali »

yeesh you guys are extreme...you can spend 45 minutes and clean all traces of the thing out rather than wipe the thing and start over.. ive had machines so infected they'd give me fake BSODs or hide the C: or disable cmd or task manager and still got every trace of them out.. theres a whole array of different tools you can download for free that'll clean out just about everything.
Timmah.


Image
cadalano
Way too much time!
Way too much time!
Posts: 1673
Joined: July 16, 2004, 11:02 am
Location: Royal Palm Beach, FL

Re: So I just got hacked.

Post by cadalano »

and if you miss anything, you get royally fucked. its naive to think with 100% confidence that you can completely clean your machine out, even if you do completely clean your machine out. if you suspect that you have been infected with a keylogger-- the risk ain't worth it. especially when the malware involved was designed by someone whose daily rice ration depends on making sure that thing hits its target despite your best efforts.
I TOLD YOU ID SHOOT! BUT YOU DIDNT BELIEVE ME! WHY DIDNT YOU BELIEVE ME?
User avatar
miir
Super Poster!
Super Poster!
Posts: 11501
Joined: July 3, 2002, 3:06 pm
XBL Gamertag: miir1
Location: Toronto
Contact:

Re: So I just got hacked.

Post by miir »

So the next time (when not if) you get hacked, it will be your own fucking fault for not wiping your PC.
I've got 99 problems and I'm not dealing with any of them - Lay-Z
User avatar
Animalor
Super Poster!
Super Poster!
Posts: 5902
Joined: July 8, 2002, 12:03 pm
Gender: Male
XBL Gamertag: Anirask
PSN ID: Anirask
Location: Canada

Re: So I just got hacked.

Post by Animalor »

Or we could buy a Mac and play WoW on that. I don't believe they're prone to keyloggers...

What browser are you using Kev?

I would highly recommend using sandboxie (http://www.sandboxie.com/) with effectively places all interactions and changes to your system form browsers in a sandbox, permitting you to easily discard change to your system done by a browser.

There's also the NoScript plugin from Firefox that would be good but may drive you up the bend having to allow scripts every time you hit a different webpage.
cadalano
Way too much time!
Way too much time!
Posts: 1673
Joined: July 16, 2004, 11:02 am
Location: Royal Palm Beach, FL

Re: So I just got hacked.

Post by cadalano »

the best protection is the login dongle thing that blizzard offers
I TOLD YOU ID SHOOT! BUT YOU DIDNT BELIEVE ME! WHY DIDNT YOU BELIEVE ME?
User avatar
miir
Super Poster!
Super Poster!
Posts: 11501
Joined: July 3, 2002, 3:06 pm
XBL Gamertag: miir1
Location: Toronto
Contact:

Re: So I just got hacked.

Post by miir »

Animalor wrote:I would highly recommend using sandboxie (http://www.sandboxie.com/) with effectively places all interactions and changes to your system form browsers in a sandbox, permitting you to easily discard change to your system done by a browser.
That's how IE works in protected mode in Vista.
I've got 99 problems and I'm not dealing with any of them - Lay-Z
Toalin
Gets Around
Gets Around
Posts: 54
Joined: August 16, 2005, 11:00 pm

Re: So I just got hacked.

Post by Toalin »

so a friend i play wow with miss typed worldofwarcraft.com this morning to something of "worldfwarcraft.com" and is abit worried not that they got any virus warnings or anything there just paranoid about these damn keyloggers and hackers in regards to wow. i ran the site on a totally isolated pc from my network, with all the standard antivirus/spybot/adaware/ and did a scan afterwards. nothing came up at all. to me honestly just seems like a placeholder domain for another site but i could be wrong, i was wondering if anyone confident on internet security would take a look just to confirm?

Thanks

Toalin
User avatar
Xouqoa
Way too much time!
Way too much time!
Posts: 4103
Joined: July 2, 2002, 5:49 pm
Gender: Mangina
XBL Gamertag: Xouqoa
Location: Dallas, TX
Contact:

Re: So I just got hacked.

Post by Xouqoa »

cadalano wrote:the best protection is the login dongle thing that blizzard offers
QFT

Best $7 you will ever spend as a WoW player.
"Our problems are man-made, therefore they may be solved by man. No problem of human destiny is beyond human beings." - John F Kennedy
Soreali
Way too much time!
Way too much time!
Posts: 1374
Joined: July 3, 2002, 3:49 pm
Gender: Male
XBL Gamertag: Dyerseve 1321
Location: Jersey

Re: So I just got hacked.

Post by Soreali »

Toalin wrote:so a friend i play wow with miss typed worldofwarcraft.com this morning to something of "worldfwarcraft.com" and is abit worried not that they got any virus warnings or anything there just paranoid about these damn keyloggers and hackers in regards to wow. i ran the site on a totally isolated pc from my network, with all the standard antivirus/spybot/adaware/ and did a scan afterwards. nothing came up at all. to me honestly just seems like a placeholder domain for another site but i could be wrong, i was wondering if anyone confident on internet security would take a look just to confirm?

Thanks

Toalin
I went there and got re-directed numerous times to some random asian site.. no spyware/virus hits on any of my IS software.. ran full scans with two seperate utilities and came back clean..

Most of the time those websites are bought just for advertising purposes.. People actually make a lot of money of of mis-types. Nothing to be too worried about.
Timmah.


Image
User avatar
Janx
Almost 1337
Almost 1337
Posts: 537
Joined: July 3, 2002, 1:44 pm
Gender: Mangina
XBL Gamertag: Janx
Location: Memphis

Re: So I just got hacked.

Post by Janx »

If I even suspect a trojan/keylogger on my system I reload. 2hrs of my time to be fully back up and playing vs days of bullshit with CS etc.. + peace of mind that you're SURE you got the damn thing is a no brainer to me.
Diae Soulmender
Star Farmer
Star Farmer
Posts: 460
Joined: July 3, 2002, 6:27 pm
Location: Vancouver, WA
Contact:

Re: So I just got hacked.

Post by Diae Soulmender »

Blizzard Authenticator = Best $6.50 I ever spent.

You only need 1 for all of your accounts so no need to buy 1 for each.

Anyways, peace of mind for $6.50? Priceless.

I understand they are sold out right now though, but keep looking... http://www.blizzard.com click on "Blizzard Store"
Khrashdin 80 Protection Paladin
Vox Immortalis - Hyjal-US
#1 World Ranked 10man Strict Achievement Guild
#3 World Ranked 10man Strict Progression Guild
http://www.guildox.com The Premier Guild Ranking Site
Post Reply