Jul 11, 2009, 09:56 PM // 21:56
|
#1
|
Desert Nomad
Join Date: Jul 2008
Profession: A/W
|
Trojan preventing GW from being played
Hello there is a problem my cousin is having trouble with. He recently got some type of trojan that is preventing Guild Wars to be played. It pops up a lot of weird windows and my cousin screen shot them.
First of all here is the shortcut:
http://i32.tinypic.com/2vj98ue.jpg
When you click it, this pops up:
http://i30.tinypic.com/24e9o45.jpg
When you click "Unlock my Account", this pops up:
http://i28.tinypic.com/2d8nuz9.jpg
When you click shopping cart, it goes to this link:
https://secure.ncsoft.com/cgi-bin/St...ory= 4#group4
Since my cousin is a tech guy, he knew the shortcut must be leading to some other file. Well this is where it leads to:
C:\Program Files\Guild Wars\ArenaNet Manager.exe
He tried to replace it with Gw.exe, and it comes up this error:
http://i27.tinypic.com/f1krw3.jpg
He told me he is trying a lot of antivirus programs to remove the trojan but will not detect it.
Will he have to format or is there a way to save this?
UPDATE
-------------------
It will also not let him delete Gw.exe or Gw.dat. It comes up a wacky error like cannot be deleted or something.
UPDATE #2
-------------------
It will not even let WinPatrol to delete on startup. I am working on my cousin's PC at the moment and it comes up:
CANNOT EXECUTE %DELETE% IN PSOS KERNEL
Windows cannot execute the command Del on %BOOT%
Basically it's like the file is locked into the kernel or something.
BTW this is my cousin's computer so it's not my account or my computer. Atm, I'm trying everything to remove it.
UPDATE #3
------------------
We decided to format. If his account is hacked, we will contact ANET about this.
UPDATE #4
------------------
We just formatted his computer and reinstalled XP. He installed GW on the clean computer and it works fine! To save the trouble, I transfered my Dat file to his. Also we checked his account. He did not get hacked. He changed his password as well.
Last edited by Braxton619; Jul 12, 2009 at 01:10 AM // 01:10..
|
|
|
Jul 11, 2009, 10:04 PM // 22:04
|
#2
|
Lion's Arch Merchant
Join Date: Feb 2008
Guild: Looking For TA Guild!
Profession: W/
|
Delete all the gw folder you have now and just download the client from guildwars.com
It wont have any effect on your account since that info is not stored on your computer
|
|
|
Jul 11, 2009, 10:06 PM // 22:06
|
#3
|
Desert Nomad
Join Date: Jul 2008
Profession: A/W
|
Quote:
Originally Posted by The Air Revenger
Delete all the gw folder you have now and just download the client from guildwars.com.
|
Yes he tried to do that. Whenever you try to delete ArenaNet Manager.exe it comes up something like "This file cannot be deleted."
Also if you try to del the shortcut, it comes up the same error.
|
|
|
Jul 11, 2009, 10:35 PM // 22:35
|
#4
|
Krytan Explorer
Join Date: Jun 2005
Location: Texas
Guild: We Wear Sombreros [文文文], Ugly Ducklings [ugly]
|
contact support
|
|
|
Jul 11, 2009, 10:43 PM // 22:43
|
#5
|
Lion's Arch Merchant
Join Date: Feb 2008
Guild: Looking For TA Guild!
Profession: W/
|
have you run an anti-virus/spyware scan yet? and has it picked up anything?
|
|
|
Jul 11, 2009, 10:43 PM // 22:43
|
#6
|
Site Contributor
|
Wow, that's an interesting one Leet Tankur. Haven't seen this one before. Good luck with it and if it does get resolved please let us know how you did it.
|
|
|
Jul 11, 2009, 10:45 PM // 22:45
|
#7
|
Supastar~ ★
Join Date: May 2006
Location: USA [GMT -7]
Guild: Sierraas Asian Harem [love]
Profession: Me/
|
Winpatrol = amazing. Install it, pull it up and under active tasks find the ArenaNet Manager.exe and right click "Delete on Reboot". Winpatrol is good about asking you about programs that want to run after you install them too.
Last edited by Sierraa; Jul 11, 2009 at 10:47 PM // 22:47..
|
|
|
Jul 11, 2009, 10:48 PM // 22:48
|
#8
|
Frost Gate Guardian
Join Date: Feb 2005
Profession: Mo/
|
scan the system with an up to date virus checker (which i guess has been done?). If it doesn't work, one can try other free online scanner.
Otherwise It's probably not really a virus, but a malicious program, which you probably just need to delete.
Check this for deleting the file(s):
http://technet.microsoft.com/en-us/s.../bb897556.aspx
use this to check out your processes/sytem in general:
http://technet.microsoft.com/en-us/s.../bb896653.aspx
I recommend it over the standard Task Manager.
While you are/he's at it, might as well use autoruns, to make sure there's nothing running at startup that will re-create the file/problem.
http://technet.microsoft.com/en-us/s.../bb963902.aspx
Lastly, I assume you/he knows that one should never type any valid numbers into that input. If you did, you'll need to contact arenanet immediately to ensure your account isn't hijacked.
It's possibly a keylogger, but I'd say it's unlikely because it can't get your game password if you can't run the game :P (and even if you could (or if it was for some other logging), the person would be suspicious). Regardless, you want to check process explorer to ensure nothing out of the ordinary is loaded into the system.
Last edited by Xapti; Jul 11, 2009 at 10:55 PM // 22:55..
|
|
|
Jul 11, 2009, 11:05 PM // 23:05
|
#10
|
Desert Nomad
Join Date: Jul 2008
Profession: A/W
|
Quote:
Originally Posted by Alexander Burn Victim
Winpatrol = amazing. Install it, pull it up and under active tasks find the ArenaNet Manager.exe and right click "Delete on Reboot". Winpatrol is good about asking you about programs that want to run after you install them too.
|
At the moment, I am working on my cousin's PC to resolve this problem. I tried to delete on reboot and it came up a fatal error. Something like this:
CANNOT EXECUTE %DELETE% IN PSOS KERNEL
Windows cannot execute the command Del on %BOOT%
Only problem he does not have back up and he does not want to format.
|
|
|
Jul 11, 2009, 11:10 PM // 23:10
|
#11
|
Jungle Guide
|
If it has disabled deletion at kernel level then you may have more problems than just a keylogger.
You may just have to bite the bullet.
Try giving us a hijackthis log.
|
|
|
Jul 11, 2009, 11:13 PM // 23:13
|
#12
|
Lion's Arch Merchant
Join Date: Feb 2008
Guild: Looking For TA Guild!
Profession: W/
|
its not a key looger since its not asking for your password, it wants you to buy another copy of guild wars and enter the key, the key will be sent to the person who started this trojan and they can use it for themselfs and you sill wont be able to access your account probably.
|
|
|
Jul 11, 2009, 11:15 PM // 23:15
|
#13
|
Jungle Guide
|
Yes, entering the key, and sending that to someone else is the very definition of a keylogger...
|
|
|
Jul 11, 2009, 11:17 PM // 23:17
|
#14
|
Desert Nomad
Join Date: Jul 2008
Profession: A/W
|
Ok I tried to uninstall Guild Wars, and it's not letting me. It's coming up like "System files are missing. You cannot uninstall this product."
Wow, I know it's fake but I wonder how these error messages keep popping up when executing an action. I asked my cousin if he downloaded anything recently and he said no. I don't know if he did or what.
Basically it seems it has taken control of the kernel and not letting any files thats related to GW be deleted.
|
|
|
Jul 11, 2009, 11:35 PM // 23:35
|
#15
|
Lion's Arch Merchant
Join Date: Feb 2008
Guild: Looking For TA Guild!
Profession: W/
|
Quote:
Originally Posted by Kumu Honua
Yes, entering the key, and sending that to someone else is the very definition of a keylogger...
|
a keylogger is hidden and records key strokes so when you type your log-in info its secretly records them.
This is different becuase its not trying to steal your password its trying to get you to buy gw for them.
When did this happen? Can you just restore to a previous date to when Gw wasnt like this?
|
|
|
Jul 11, 2009, 11:38 PM // 23:38
|
#16
|
Technician's Corner Moderator
Join Date: Jan 2006
Location: The TARDIS
Guild: http://www.lunarsoft.net/ http://forums.lunarsoft.net/
|
Please download my Anti-Malware Toolkit and get the package that matches your Operating System. Then follow the directions in the PC Cleanup guide. After that, please post a HijackThis log.
From the sounds of it he just had a rootkit.
|
|
|
Jul 12, 2009, 01:09 AM // 01:09
|
#17
|
Desert Nomad
Join Date: Jul 2008
Profession: A/W
|
UPDATE:
We just formated his computer and reinstalled XP. He installed GW on the clean computer and it works fine! To save the trouble, I transfered my Dat file to his. Also we checked his account. He did not get hacked. He changed his password as well.
|
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 01:23 AM // 01:23.
|