Hello, first of all I'll start by saying this.
A few months ago my world of warcraft was hacked (still unable to get it back). I sent the person who hacked my gmail a email, which at that time didn't know that he can trace my ip. About 3 month ago I brought a new computer and which came with Norton anti-virus. I did a virus scan last month with norton and it picked up hacktool.proxy and quarintied it, I then downloaded Malware Bytes updated it and do a scan every 3 days only a trojan bho popped up and it malwarebytes killed it. I have had two blue screens of death (I heard thats what it was called. happen to me one where is today. I was playing a game, it came up crashed and restarted my computer and i did another scan with malware bytes nothing popped up.

on windows defender history, this shows

Description:
This program has potentially unwanted behavior.

Advice:
Permit this detected item only if you trust the program or the software publisher.

Resources:
regkey:
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\dump_wmimmc

file:
C:\ijji\ENGLISH\Gunz\GameGuard\dump_wmimmc.sys

Category:
Not Yet Classified

I scanned my game and nothing popped up, also in norton history..
Unauthorized access blocked (allocate virtual memory) and heaps of
An intrusion by was blocked, it started with happening twice a week, now today when i got the blue screen of death, the intrusion happened like 10 times and all of them were blocked.
Today i also got a email from WOWACCOUNTADMIN, which looked very fishy so i deleted it, it happened an hour after the blue screen of death.

Sorry if this was in the wrong section >.>.
Is there anyway I can prevent this? I don't mind reformatting my computer not too many important things. And i don't want my computer to be hacked, because my dad uses it for his power point presentations at his job.

Dani AI

Generated

Quick summary for : the file path you posted (C:\ijji\ENGLISH\Gunz\GameGuard\dump_wmimmc.sys) is a strong indicator that nProtect/GameGuard (the game anti‑cheat) is installed. GameGuard installs a kernel‑level driver and is frequently flagged as “potentially unwanted” by security products; a Norton message that “an intrusion by 60.234.2.2 was blocked” most often means your firewall/IPS stopped an external probe, not that an attacker already owned your PC. (sysnative.com)

Why you saw blue screens: GameGuard operates with kernel hooks and low‑level drivers to detect cheats, behaviour that can destabilize Windows or conflict with AV/other drivers — that commonly produces STOP errors (BSOD). The unusual driver name and the timing (game running + immediate crash) make a driver conflict far more likely than a remote takeover. Check the kernel‑mode driver first before assuming a breach. (sysnative.com)

Practical next steps (do these in order):

  1. Do not reply to the WoWAccountAdmin mail — treat it as phishing. (nsa.gov)
  2. Verify the GameGuard driver: check its digital signature with Sigcheck (Sysinternals) and, if unsure, submit the file or its hash to VirusTotal for a second opinion. (learn.microsoft.com)
  3. Run an offline/rootkit scan (Microsoft Defender Offline) and use Autoruns to inspect hidden drivers/startup entries. (learn.microsoft.com)
  4. Review Windows Security/Event Viewer for unexpected logons or new accounts (audit Event IDs) and, if you suspect account compromise, change passwords and enable two‑factor authentication on Gmail and your game accounts. (cisa.gov)

If instability or suspicious artifacts remain after those checks, back up personal files and do a clean reinstall — kernel hooks left by anti‑cheat or malware are hard to trust. As and pointed out, cleanup tools and firewalls help with general hygiene, but the targeted checks above (signtool/sigcheck, offline scan, autoruns, event logs) are the right forensic steps before reimaging. For a follow‑up, collect the driver file hash, Defender/AV logs and a short timeline and share those details for analysis. (support.microsoft.com)

Recommended Answers

All 4 Replies

Download and install ccleaner, it doesnt protect you from being hacked but will clean up some bad stuff that you may have on your computer. I normally run it 2 or 3 times a day because its really fast scaning and deleting rubbish that you may have.

Also, i really hate norton, i use free avg, and i think you should do the same. You should also avoid e-mailing back, principally if they're hackers. Keep malwarebytes, but i think you should install spybot, just for a few months and run it everytime after you finish using the internet.

I never run all at the same time, it may not do the scans properly. Get a firewall if you havent got one.

Dan08

I recommend using Zone Alert for your firewall.

This thread is 2 years old and now closed.

I recommend using Zone Alert for your firewall.

Heard of Zone Alarm, but not Zone Alert.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.