Forum Home
Press F1
 
Thread ID: 81815 2007-08-08 04:42:00 WIN32ONLINEGAMES ???? SurferJoe46 (51) Press F1
Post ID Timestamp Content User
578033 2007-08-08 04:42:00 Spybot sees this, and as usual it cannot do anything about it . . .

Funny, but I don't use online games and I wonder why this is in my SOYO now .

I know it is supposed to live in C:\\WINDOWS\SYSTEM32\EPSN . dll, but I'll be darned if I can find it .

It isn't showing in My Programs, or HJT or AVG Anti-Rootkit, or Rogue Remover or AdAware or anything else .

If I don't play games, what's the problem?

I went to WOW in their Tech Support, ran their system scanner and this popped in:

The Blizzard Launcher has detected the Trojan-PSW . Win32 . WOW . rc Trojan on your machine which may be used to steal your World of Warcraft account name and password . . . . since Google suggested I go there for help and got this list:



(Trojan-PSW . Win32 . WOW . rc Found)

Program . . . . . . . . . . . . . . . . . . . . . . . Version used . . . . . . . Identifies this Trojan as

AntiVir (Free) . . . . . . . . . . . . . . . . . 7 . 4 . 0 . 32 . . . . . . . . . . . . . . TR/Crypt . ULPM . Gen
BitDefender (Trial) . . . . . . . . . . 7 . 2 . . . . . . . . . . . . . . . . . . . . . . Trojan . PWS . OnLi neGames . TH
CAT-QuickHeal (Trial) . . . . . . . 9 . 00 . . . . . . . . . . . . . . . . . . . . (Suspicious) - DNAScan
ClamAV (Free) . . . . . . . . . . . . . . . . devel-20070416 . . . . . Trojan . Spy-6766
Ewido (Trial) . . . . . . . . . . . . . . . . . . . 4 . 0 . . . . . . . . . . . . . . . . . . . . . Trojan . WOW . rc
Fortinet . . . . . . . . . . . . . . . . . . . . . . . . . 2 . 85 . 0 . 0 . . . . . . . . . . . . . . . W3 2/WOW . RC!tr . pws
F-Prot (Trial) . . . . . . . . . . . . . . . . . . . 4 . 3 . 2 . 48 . . . . . . . . . . . . . . . W 32/PWStealer2!Generic
F-Secure (Trial) . . . . . . . . . . . . . . . 6 . 70 . 13030 . 0T . . . . . . . Trojan-PSW . Win32 . WOW . rc
Ikarus (Trial) . . . . . . . . . . . . . . . . . . . . T3 . 1 . 1 . 8 . . . . . . . . . . . . . . . Trojan-PWS . OnlineGames . TH
Kaspersky (Trial) . . . . . . . . . . . . . . 4 . 0 . 2 . 24 . . . . . . . . . . . . . . . . Troja n-PSW . Win32 . WOW . rc
NOD32v2 (Trial) . . . . . . . . . . . . . . . . 2329 . . . . . . . . . . . . . . . . . . . . Win 32/Pacex . Gen
Norman (Trial) . . . . . . . . . . . . . . . . . . 5 . 80 . 02 . . . . . . . . . . . . . . . . . W 32/Wow . BDV
Panda (Trial) . . . . . . . . . . . . . . . . . . . 9 . 0 . 0 . 4 . . . . . . . . . . . . . . . . . Suspici ous file
Sophos (Trial) . . . . . . . . . . . . . . . . . . . 4 . 18 . 0 . . . . . . . . . . . . . . . . . Mal/EncPk-I
Symantec (Trial) . . . . . . . . . . . . . . . 10 . . . . . . . . . . . . . . . . . . . . . . . Tro jan . Packed . NsAnti
Webwasher-Gateway (Trial) . 6 . 0 . 1 . . . . . . . . . . . . . . . . . . Trojan . Crypt . ULPM . G en

I went into Safe Mode, can still find it in Spybot, but again it cannot be removed for reasons unclear .

Since I don't game, have never had anything more than Spider Solitaire and Klondike which comes in XP that I've played . . what do you suppose invited it in?

I never had and don't want a World of Warcraft account name and password . . . how can it hack one I don't have in the first place?
SurferJoe46 (51)
578034 2007-08-08 05:00:00 See if trojan remover picks it up. Looks like its in its database under.

PWS.WOW

Steals account information for the online game
World of Warcraft.

Update it click on scan, then open c and scan it with trojan remover as well.
Speedy Gonzales (78)
578035 2007-08-08 05:14:00 BoClean got it...but now how do I get rid of the BoClean card on my desktop?...it's the one that you get if you right click the icon near the clock...

There's no "X" on the box to close it and I don't really want to shut BoClean down if I don't have to.
SurferJoe46 (51)
578036 2007-08-08 05:17:00 I still wonder why in the world I got it?

I don't game!
SurferJoe46 (51)
578037 2007-08-08 05:20:00 Pass, i dont game either.

You mean the window for Boclean?? Just close it, as long as the icon is still in the taskbar, it should still be running.
Speedy Gonzales (78)
578038 2007-08-08 05:32:00 I hadda reboot to close it..there's no "X" on the box and when I clicked the button to shut it off..BoClean disappeared at the same time..so a reboot SurferJoe46 (51)
578039 2007-08-08 05:58:00 Just cause you never game doesn't mean you can't get a game related virus.

It's like saying, I never take my car over glass covered roads, yet I can still get a punctured tire.
--Wolf-- (128)
578040 2007-08-08 06:50:00 Just cause you never game doesn't mean you can't get a game related virus.
It's like saying, I never take my car over glass covered roads, yet I can still get a punctured tire.
True, but it would seem as though the object of this trojan is only to steal user names and passwords.
But still, what else is it going to do while it is in there? it could easily be reverse engineered by someone else and do even more destructive stuff lol

Moral of the story: Don't play the lamest of all games. WoW;)
Bozo (8540)
578041 2007-08-08 06:53:00 And say you never found out about it, then tomorrow you start playing WoW.

Boom, there goes your account.
--Wolf-- (128)
578042 2007-08-08 07:14:00 if i lost my WoW account i would be greatfull because it would've just stoped me from destroying my life lol!
btw, WoW is not a game, it is an experience. Maybe we should start a thread all about how lame WoW is and the cons/cons (not pros/cons) of it are ;)
Bozo (8540)
1 2