Got Virus from a fake WoW Hack menu

User Tag List

Results 1 to 14 of 14
  1. #1
    jazman84's Avatar Site Donator
    Reputation
    41
    Join Date
    May 2008
    Posts
    185
    Thanks G/R
    2/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Got Virus from a fake WoW Hack

    Hey guys, posted this on offtopic too but there isn't much traffic there.

    Sorry if this is in the wrong spot, but I am getting desperate.

    So I was unfortunate enough to be one of the 1st to DL http://www.mmowned.com/forums/world-...g-tracker.html (WoW Trax NS - A World of Warcraft EVERYTHING tracker!) *DONT DL THIS. IT IS A VIRUS*

    The virus doesn't seem to do anything except slow my system down, however, if I try and stop in in task manager it starts a shutdown sequence and can only be stopped with shutdown -a command and the process reloads.

    Anyway, I tried following maclone's instructions, but every time i try to stop the processes through task manager I get the system shutdown error and it closes my PC in about a minute. I really need to get rid of this asap, I have a good virus remover in Eset smart security, but it doesnt seem to remove processes that are running, and they also run in safe mode which throws a spanner into it.

    Is there a program similar to rkill that will stop the processes? They are hidden as svchost.exe

    Please help!

    Got Virus from a fake WoW Hack
  2. #2
    Bagger's Avatar Active Member
    Reputation
    60
    Join Date
    Apr 2007
    Posts
    98
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Allready removed ?
    The internet, where men are men, women are men, and children are the FBI

  3. #3
    jazman84's Avatar Site Donator
    Reputation
    41
    Join Date
    May 2008
    Posts
    185
    Thanks G/R
    2/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    No not yet. It doesn't look like the old worm that did the shutdown. I cant really find anything on the virus to get rid of it.

  4. #4
    Crysto's Avatar Contributor
    Reputation
    283
    Join Date
    Mar 2008
    Posts
    492
    Thanks G/R
    4/55
    Trade Feedback
    2 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Thaloc View Post
    Allready removed ?
    He actually meant the thread.
    Last edited by Crysto; 01-17-2011 at 09:44 PM.

  5. #5
    Bagger's Avatar Active Member
    Reputation
    60
    Join Date
    Apr 2007
    Posts
    98
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Indeed i did :P
    The internet, where men are men, women are men, and children are the FBI

  6. #6
    MMOHelping's Avatar Sergeant
    Reputation
    21
    Join Date
    Jan 2011
    Posts
    48
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    #1;
    Virus Total doesnt mean anything.

    YOU MUST TRUST YOUR INSTINCTS. If the post seems like its fake don't download it.

    I suggest;
    Install Malware Bytes -GR8 Software (easy)
    -Spybot S&D

    -If your experianced download Hijack this and View the Logs; (Hard)
    Along with any rootkit viewing tools from Hirens Boot Cd is good.

    Also alot of simple viruses will just add a startup key; so goto

    Run > Msconfig and look for Startups that aren't something you recognize and investigate them! (Easy)

  7. #7
    maclone's Avatar / Authenticator enabled
    Reputation
    2420
    Join Date
    Nov 2007
    Posts
    8,726
    Thanks G/R
    0/1029
    Trade Feedback
    0 (0%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    I told you to go safemode if you can't kill the processes.
    And not all your svchost.exe processes are malware, in fact if you end the ones needed by Windows, Windows will shutdown by itself.
    Last edited by maclone; 01-18-2011 at 01:10 AM.
    Zomfg. And no, don't ask. - Dombo did it.

  8. #8
    MMOHelping's Avatar Sergeant
    Reputation
    21
    Join Date
    Jan 2011
    Posts
    48
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Correct;

    Good way to see, get an advanced process viewer it will tell you where the exe's are running from

    << ProTip : get Hirens Boot CD

  9. #9
    jazman84's Avatar Site Donator
    Reputation
    41
    Join Date
    May 2008
    Posts
    185
    Thanks G/R
    2/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by maclone View Post
    I told you to go safemode if you can't kill the processes.
    And not all your svchost.exe processes are malware, in fact if you end the ones needed by Windows, Windows will shutdown by itself.
    Thanks for that advice, but the processes were still running in safe mode

  10. #10
    maclone's Avatar / Authenticator enabled
    Reputation
    2420
    Join Date
    Nov 2007
    Posts
    8,726
    Thanks G/R
    0/1029
    Trade Feedback
    0 (0%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by jazman84 View Post
    Thanks for that advice, but the processes were still running in safe mode
    The real svchost.exe is a critical windows process and also runs in safemode...
    Open task manager, right click the process and check for the file location, if it isn't "C:\Windows\System32\svchost.exe" it's most likely the malware.

    You can also download that and look for an advanced process overview: http://live.sysinternals.com/procexp.exe
    Zomfg. And no, don't ask. - Dombo did it.

  11. #11
    jazman84's Avatar Site Donator
    Reputation
    41
    Join Date
    May 2008
    Posts
    185
    Thanks G/R
    2/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by maclone View Post
    The real svchost.exe is a critical windows process and also runs in safemode...
    Open task manager, right click the process and check for the file location, if it isn't "C:\Windows\System32\svchost.exe" it's most likely the malware.

    You can also download that and look for an advanced process overview: http://live.sysinternals.com/procexp.exe
    They all say they are running from system32 I currently have 5 instances of svchost running.

  12. #12
    maclone's Avatar / Authenticator enabled
    Reputation
    2420
    Join Date
    Nov 2007
    Posts
    8,726
    Thanks G/R
    0/1029
    Trade Feedback
    0 (0%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    That's normal.
    Then you got no virus and all of this discussion was unnecessary.
    That much for slowing down your system.
    Zomfg. And no, don't ask. - Dombo did it.

  13. #13
    Traxex84's Avatar Contributor Authenticator enabled
    Reputation
    257
    Join Date
    May 2010
    Posts
    816
    Thanks G/R
    1/25
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by jazman84 View Post
    They all say they are running from system32 I currently have 5 instances of svchost running.
    It is common to have multiple svchost.exe's the reason being (quote from microsoft)

    If you’ve ever taken a look at the Services section in control panel you might notice that there are a Lot of services required by Windows. If every single service ran under a single svchost.exe instance, a failure in one might bring down all of Windows… so they are separated out.

    Those services are organized into logical groups, and then a single svchost.exe instance is created for each group. For instance, one svchost.exe instance runs the 3 services related to the firewall. Another svchost.exe instance might run all the services related to the user interface, and so on.
    Last edited by Traxex84; 01-18-2011 at 10:34 PM.

  14. #14
    maclone's Avatar / Authenticator enabled
    Reputation
    2420
    Join Date
    Nov 2007
    Posts
    8,726
    Thanks G/R
    0/1029
    Trade Feedback
    0 (0%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)
    /closed
    If there's anything else, PM me.
    Zomfg. And no, don't ask. - Dombo did it.

Similar Threads

  1. Got Virus from a fake WoW Hack
    By jazman84 in forum Community Chat
    Replies: 0
    Last Post: 01-17-2011, 06:11 PM
  2. Why Pay for WOW Hacks?
    By LeGeNdZ in forum World of Warcraft Exploits
    Replies: 72
    Last Post: 04-12-2007, 04:57 AM
  3. WoW Hack Pack
    By Mexdude in forum World of Warcraft General
    Replies: 4
    Last Post: 11-28-2006, 09:53 AM
  4. WOW GUide FROM RED GUIDES.. ( WOW UNDERGROUND)
    By Elites360 in forum World of Warcraft Guides
    Replies: 12
    Last Post: 11-01-2006, 05:05 PM
All times are GMT -5. The time now is 02:21 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search