Account Hacked

#0 - Sept. 23, 2010, 5:48 p.m.
Blizzard Post
Recently I've been having some problem with my account. Since the beginning of September I have been getting locked out of my account a on fairly regular basis, so I contacted Blizz to see if they could fix the problem. After speaking with a CSR. The problem was supposed to be fixed, and I was to change my PW., I did so. This was on the 20th. On the 22nd my account was hacked, luckily a friend was online and contacted a GM and let them know someone was hacking my account. I received emails from blizz telling me what happened and they restored my characters(awesome!). That was all great, but I was curious how I got hacked. Throughout September I have run anti-virus/spyware software(Mcafee, Spybot-S&D, Malwarebytes) a number of times and they have all come back without any results. They tell me my system is clean.

I was told by the CSR that the hacker used the password reset function to access my account. As far as I know you need the current password to change your password. So I'm assuming the hacker must have discovered my password through a keylogger as between the time I changed my password on the 20th and the time of the hacking, I had only used the password twice, once to log into the game client, and once to log-in at battle.net. So I ran the anit-virus programs again to no avail... nothing came back infected... So I decided to delete my addons(just in case) and noticed that there were two addons that I did not install myself. Unfortunately I didn't write down the exact name(stupid me) and the files are long gone. But I am fairly certain one was named "Slidebar" and the other was named "!swagger". I don't know anything about either of these addons or how they got there, but I suspect one of them is probably the culprit. So I was wondering if anyone has any ideas, or pointers on how to fix this?.. I don't really want to log back in until I'm fairly certain my account won't get hacked again. Also has anyone else who has recently been hacked noticed any unsusual addons?
#5 - Sept. 23, 2010, 8:37 p.m.
Blizzard Post
I am glad to hear you were able to get the account restored, Bushman. I can indeed understand your concerns in not wanting to be compromised again and your fellow players have provided some awesome information.

I was told by the CSR that the hacker used the password reset function to access my account.
From what I can see on the account, this is not the case. The hacker did not reset the password but instead changed the password. Pahanda pointed out what is needed in order to reset the password to the account. Changing the password simply involves knowing the current password and changing it to something else. This may put your mind at ease slightly.

You may wish to scan your computer again using different programs, many of which can be found here:

Account and Computer Security, Part 4
http://us.blizzard.com/support/article/30812

Many players have also reported scanning with the game running in the background. Enter in a fake email address and a gibberish password as though you were logging in. Certain keyloggers may not activate until the game does and therefore will not be detected.

Good luck!