World of Warcraft

Blizzard Entertainment
View All Posts by This User ignore-inactive
Techsupport
Blizzard Poster
  • 0. ____- New Trojans found by Launcher   20/04/2007 09:56:15 PDT
quote locked
Update 24/12/07

Hello,

We have completed our list of anti-virus programs that are capable of removing this latest batch of Trojans that have been detected. We now have support articles for all of these here:

  • Backdoor.Win32.Bifrose.aej : http://eu.blizzard.com/support/article.xml?articleId=21570
  • Trojan.DL.OnlineGames.Gen.3 : http://eu.blizzard.com/support/article.xml?articleId=21571
  • Trojan-Dropper.Win32.Agent.bcw : http://eu.blizzard.com/support/article.xml?articleId=21573
  • Trojan-PSW.Win32.Nilage.my : http://eu.blizzard.com/support/article.xml?articleId=21574
  • Trojan-PWS.Win32.Nilage.ajf : http://eu.blizzard.com/support/article.xml?articleId=21575
  • Trojan-Spy.Win32.GhostKeyLogger.e : http://eu.blizzard.com/support/article.xml?articleId=21576
  • Trojan.Win32.Agent.abf : http://eu.blizzard.com/support/article.xml?articleId=21577
  • Trojan.Win32.Agent.aik : http://eu.blizzard.com/support/article.xml?articleId=21578

    For a complete list of known trojans please check the following article.

    http://eu.blizzard.com/support/article.xml?articleId=19644

    --------------

    Hello,

    Two new Trojans have recently been identified by our Launcher:

    Trojan-dropper.win32.agent.bcw

    Backdoor.Win32.Bifrose.aej Trojan


    Trojans are a "back door" in to your machine which can allow hackers to obtain sensitive data as well as cause harm to your machine. Trojans differ from Viruses as Viruses replicate themselves and are designed to purely cause damage to the "host" machine. Each Trojan functions differently, however most are designed to obtain information through use of keyloggers or allow remote functions for the hacker to literally use your computer. Trojans pose a serious threat to all computer users and it is extremely important that they are removed immediately before information can be gathered. Some Trojans are also used to allow further infection, installing additional Trojan functions as well as Viruses.

    Follow these steps to remove the Trojan and protect yourself from future infection:

    1. Close the Blizzard Launcher. You are still allowed to log in and play, however playing the game with a Trojan installed puts your account at serious risk of being compromised as the hacker can easily obtain your World of Warcraft account name and password.

    2. Ensure that all programs are closed. If you have recently downloaded any executable (.exe) files meant for use with the game, delete them so that they are not accidentally used in the future.

    3. Use one or more of the below programs to help remove the Trojan and provide future protection against them. After installing the program, ensure that you update its "definitions". Definitions are used as a dictionary of sorts for the program to help it detect new Trojans. This is usually prompted to be done shortly after install by the program itself. If not, the process to do so should be available within the program options.

    4. Make sure you run a thorough scan of your entire system. After removing the Trojan, use the Blizzard Launcher again to start the game and see if any additional threats are detected.

    Removal Programs

    The below programs can all be used to detect and remove the Trojan found on your system.

    We are still compiling a full list of Anti-Virus programs that can be used to remove these from your computer so that we can provide an FAQ page as we do for other identified trojans, for now we have had some reports that the following programs may help to remove these:

    Trojan-dropper.win32.agent.bcw

    AntiVir
    http://www.free-av.com/
    Identifies as: SPR/Ardamax.K.Gen riskware

    F-Secure Anti-Virus Trial
    http://www.f-secure.com/
    Identifies as: Trojan-Dropper.Win32.Agent.bcw

    Kaspersky Anti-Virus Trial
    http://www.kaspersky.com/
    Identifies as: Trojan-Dropper.Win32.Agent.bcw

    VBA32
    http://www.anti-virus.by/en/
    Identifies as: Trojan-Dropper.VB.21 (probable variant)

    Backdoor.Win32.Bifrose.aej Trojan

    Kaspersky Anti-Virus Trial
    http://www.kaspersky.com/
    Identifies as: Backdoor.Win32.Bifrose.aej

    Also, Karuma has suggested this program:
    http://www.spywareremove.com/removeBackdoorBifrose.html

    Account Recovery

    If your account has already been compromised please make sure the Trojan is removed by following the steps above. After the Trojan has been successfully removed follow the steps below for help with recovery.

    If your account has been compromised and you are unable to login please attempt to recover your password by clicking here:
    https://www.wow-europe.com/login-support/

    If you are unable to recover your account password or are having difficulty with the hacker changing it again after recovery; please first make sure the Trojan is fully removed by following the steps at the top of this page as well as running a thorough system scan. If the Trojan has been removed please contact our Billing & Account department by phone:
    http://wow-europe.com/en/support/accountbilling.html

    If you have successfully recovered the account and the hacker has not been able to login but you are missing items or characters; please contact our In-Game Support department by creating an in-game petition.
  • [ Post edited by Gelmkar ]

    Forum Nav : Jump To This Forum
    Blizzard Entertainment