PDA

View Full Version : My email account was hacked into due to a hidden trojan - It can happen to you!!!!



DrGonzo
12-13-2012, 01:45 PM
So yesterday I started getting alerts on my phone that emails were going out from my old Hotmail account. I have had that email account for almost 20 years now and only use it for paying bills and paypal. I don't send emails from the account at all.

I checked the emails going out and found out that the links were html redirects to a trojan keylogger program Avast shows it's called "HTML:Redirector-AI [TRJ]". Luckily I only had like 15 contacts in my account that they sent the email out to. Most of them were bad email address I haven't used in years and the others were spoof email addresses, like spoof@paypal.com. I quickly changed the password on the account and switched all my accounts over to use my gmail account.

So I got all my accounts locked down and switched over to the new gmail account for emailing. I flushed the hotmail account of all emails and contacts and set up a forwarded to gmail just so I capture any valid emails from accounts I missed.

I started doing some checking on my home computers to see if somehow I got a trojan keylogger installed. Sure enough my gaming/video rig had a damn trojan on it. I only found it by running a boot scan. System scan did not catch it..

The main file that brought the trojan in was Wondershare PDF Editor program "pdfeditor.exe". This was a PDF editor program I downloaded probably from Cnet "Download.com" some time ago. Luckily I don't use that computer much, but recently I started working from home twice a week and use it for general browsing and checking email which is how they got the password. Neither Avast or Spybot/TeaTimer caught the trojan when it installed.

So I am in the process of finishing a full system scan "3tb" and once that is done I have to re-image the machine fresh as I don't trust the virus programs from getting everything removed/cleaned. Since I don't know when the trojan was first installed I can't re-image from back up. So fresh install of everything........

I am a computer geek, I'll admit it. I spend 90% of my day on a computer. I am very system and network savvy. So even the best of us can get hacked....:(

IPD
12-13-2012, 04:09 PM
yeah, my hotmail got hacked recently as well. not bad, considering i've never had any issues with it in the previous 15 years. only 5 people got spammed, and none of them were stupid enough to click on the link, so it's all good.

changed the PW to something even more obtuse than my own logic, and i sleep peacefully.

Roybatty
12-13-2012, 04:52 PM
Hey bros go easy on the pr0n sites =p

Sent from garage

Alan92RTTT
12-13-2012, 05:02 PM
Been there, Done that, Not fun.

I got nailed by a popup on a comic book news site. I knew it the moment it happened (saw the phone windows virus scanner) but by them its too late.

DrGonzo
12-13-2012, 05:03 PM
LOL... the only Pr0n I watch it what Doc posts in the members area!!!

Just got finished with the fresh install..... now I have to re-install all the drivers and software!! :(

GTOJOE
12-13-2012, 06:51 PM
In that case I would simply remove the HDD and connect it to another machine and run combofix, superantispyware and at-least 2 other good virus scanners over it.

ChargerX3
12-13-2012, 10:01 PM
So... with that said what is the best anti spyware and malware crap to get? Im no geek, so im just waiting...

stealthify
12-13-2012, 10:11 PM
A virus, what's that? :p :)


So... with that said what is the best anti spyware and malware crap to get? Im no geek, so im just waiting...

Personally, I'm a fan of MalwareByes and Microsoft Security Essentials.

GTOJOE
12-13-2012, 10:12 PM
As above. Use combofix for first scan then superantispyware then malware bytes then ms sec essentials.

Sent from my GT-I9300 using Tapatalk 2

ChargerX3
12-13-2012, 10:19 PM
A virus, what's that? :p :)



Personally, I'm a fan of MalwareByes and Microsoft Security Essentials.
That is exactly what i run atm. I hate how MWB expires though.

stealthify
12-13-2012, 10:21 PM
That is exactly what i run atm. I hate how MWB expires though.

The trick is to never accept the trial. ;) I believe you can keep clicking cancel/continue every time it comes up, and it won't start the timer (unless they've changed it).

green-lantern
12-13-2012, 10:59 PM
LOL... the only Pr0n I watch is what Doc posts in the members area!!!



Yeah me too

:suspect:

IPD
12-14-2012, 01:50 AM
been using kapersky for 2+ years now. much better than that POS bit-defender.

Lugnut
12-14-2012, 05:26 AM
I have a hacking happening now for the game Guild Wars 2 where they actually have my login and password for this game, but the game itself is setup by Guild Wars to where I have to approve the I.P.address login through my email before they can actually access the game .. IDK for certain when they got the password, but after some quick research I read the games server was hacked at one point, so Im assuming thats when they got it .. Basically to change the login and password I have to get on the game which at this time cannot happen as Im away on business so at the minute I'm on stuck to that end .. Nothing else of mine was hacked and although all my internet stuff has different passwords and all I went ahead and changed all my internet stuff anyways through a different computer .. This one actually .. So anyway, I watch them login from about 15 different cities in China over the last month or so .. And in the meantime I've educated myself enough to learn how I can trace it back for a bit through the login attempt info to a server, but thats as far as I have gotten/gone with it .. The point of all this is I was wondering if anyone has any words for what I can do to get more info on them or is it a waste of time even trying .. I would love to just trace it and send them a email .. And maybe a picture of my nutsack or something .. Nothing more for say since I know it is just a dead end ..

DrGonzo
12-14-2012, 08:11 AM
In that case I would simply remove the HDD and connect it to another machine and run combofix, superantispyware and at-least 2 other good virus scanners over it.

I'm not very trusting of virus scanners. They are all reactive and not proactive, Meaning they can only defend against what they know about. If a new virus/trojan gets created and distributed, No Antivirus software will be able to prevent it until they know about it and have updated their definitions to look out for it. Some Anti-virus companies have algorithms and certain things they check for, but those things are easily coded around. In my case the trojan came in on a known file from a trusted download site "CNET.com". The initial scan when I downloaded it did not catch it and no alerts went off when I installed it. I'm thinking that the Avast did not have the trojan in it's definitions when I first got it. Eventually it made it into the anti-virus definitions and my full system scan caught it.

When I get a virus/trojan I always do a full system clean. I can't take the chance that there is some residue code sitting out there that I don't know about. In my line of work I deal with too many outside systems that I can't take the chance of a security breach due to a damn trojan.



So... with that said what is the best anti spyware and malware crap to get? Im no geek, so im just waiting...

Buy a Mac!!

IPD
12-14-2012, 08:47 AM
Buy a Mac!!

roflmfao

Jimvr4
12-14-2012, 03:48 PM
I got hit by FBI Ransomware a few months ago. I had clicked on a site to watch a "video" and it immediately took over my computer, locking the screen and activating the webcam. The message said the FBI was after me for viewing illegal content and wanted me to click a link to go and pay $200 to make it go away.

Rebooting did not help so I restored the whole computer from a backup. I'm a computer geek too so I have a NAS with 3TB and I use Acronis to run daily backups of my windows and data partitions. The only trouble I had was restoring the correct partitions. It turns out W7 may use a 100MB boot partition (depending on whether it is a new or upgrade installation) and I had to regenerate this portion after accidently removing it.

AFAIK Norton and MacAfee aren't able to detect this one either. It was a good decision to minimize the windows partition since it restores alot quicker.

DrGonzo
12-14-2012, 04:22 PM
In that case I would simply remove the HDD and connect it to another machine and run combofix, superantispyware and at-least 2 other good virus scanners over it.


So... with that said what is the best anti spyware and malware crap to get? Im no geek, so im just waiting...


I got hit by FBI Ransomware a few months ago. I had clicked on a site to watch a "video" and it immediately took over my computer, locking the screen and activating the webcam. The message said the FBI was after me for viewing illegal content and wanted me to click a link to go and pay $200 to make it go away.

Rebooting did not help so I restored the whole computer from a backup. I'm a computer geek too so I have a NAS with 3TB and I use Acronis to run daily backups of my windows and data partitions. The only trouble I had was restoring the correct partitions. It turns out W7 may use a 100MB boot partition (depending on whether it is a new or upgrade installation) and I had to regenerate this portion after accidently removing it.

AFAIK Norton and MacAfee aren't able to detect this one either. It was a good decision to minimize the windows partition since it restores alot quicker.

I had the same issue with the Win7 partition also. It for some reason installed the boot partition on D:\ and the rest of the OS on C:\. MBR was on C:\ pointing to D:\. Took me an hour to figure that shit out....LOL

HilbillyHomeboy
12-14-2012, 04:32 PM
From CNet? Wow.

I use MS security essentials, spybot, and ccleaner. I used to use avast, great program.

Jeremy

Alan92RTTT
12-14-2012, 05:14 PM
AVG, Spybot, Firefox with adblock

IPD
12-14-2012, 08:20 PM
even if someone activates webcam, it's impossible to see through a piece of electrical tape.

Mikes2nd
12-16-2012, 10:28 AM
you guys call yourself computer guys and you have troubles with viruses? rofl.

one... if you ever have a problem, simply get Microsoft essentials defender offline... (its a whole boot from cd OS, updates and runs essentials, yes it kills the FBI 500$
virus and everything else I've seen).

http://windows.microsoft.com/en-US/windows/what-is-windows-defender-offline

Security essentials was getting lazy I think lately, but they are back up to speed now and with more people moving to W7/dumb people to ipads it only helps.

Obviously anti virus programmers revise their stuff to try to avoid detection and anti virus programmers are not very good.

two: if you haven't figured it out yet, anti virus makers and "viruses' are a gimmick...

three: try host file blocker. It works pretty well also. I only use a host file, update once a month and Microsoft essentials.

Blocking Unwanted Connections with a Hosts File (http://winhelp2002.mvps.org/hosts.htm)

IPD
12-16-2012, 12:10 PM
go away, troll.

DrGonzo
12-16-2012, 12:25 PM
you guys call yourself computer guys and you have troubles with viruses? rofl.

one... if you ever have a problem, simply get Microsoft essentials defender offline... (its a whole boot from cd OS, updates and runs essentials, yes it kills the FBI 500$
virus and everything else I've seen).

What is Windows Defender Offline? (http://windows.microsoft.com/en-US/windows/what-is-windows-defender-offline)

Security essentials was getting lazy I think lately, but they are back up to speed now and with more people moving to W7/dumb people to ipads it only helps.

Obviously anti virus programmers revise their stuff to try to avoid detection and anti virus programmers are not very good.

two: if you haven't figured it out yet, anti virus makers and "viruses' are a gimmick...

three: try host file blocker. It works pretty well also. I only use a host file, update once a month and Microsoft essentials.

Blocking Unwanted Connections with a Hosts File (http://winhelp2002.mvps.org/hosts.htm)

Responses:
1: It's a boot time scan. Any anti virus has a boot time scan option which is the most thorough option cause no process can read from a file that anotehr process is already locked onto and using. Hence boot time scans are able to catch items before a process locks onto them.

2: If you truly believe this then you are a fucking idiot and should stop posting any further opinions related to computers in any further threads....

3: Host file blocking is the stupidest thing I have ever heard of for a PC. It is only viable in a server/network solution area were your nodes are responsible for only taking to specific machines and all other connections are blocked. Start adding items to your hostfile and it will be a never ending game of adding/removing items just to do simple tasks. Plus unless you are running a network packet sniffer you would not know the address/ip for half of the connections you PC is making "Referring to updates and such that happen as background processes where you do not see them running."



Windows defender comes pre-installed on all new Windows releases. It should not be run all by itself as it's definitions library is small compared to even the smallest AV maker out there. On a side note it is better at defending against main OS attacks.

Mikes2nd
12-16-2012, 10:20 PM
rofl... its no wonder you get viruses. Your clueless.

You either can't read or your clueless.. Its not hard to see why you get viruses..

I especially like the part where you think you know what a hosts file is.

this statement is HIGH-larious...


Start adding items to your hostfile and it will be a never ending game of adding/removing items just to do simple tasks.

I have never edited my hostfile nor have I ever had to play any game with it to do any tasks. Seriously I left you a link... Do you not know how to click on links and read?

I simply run the bat file to load the hosts file... Done and done.

DrGonzo
12-16-2012, 11:16 PM
As stated before:


go away, troll.

You have no clue what you're talking about and your moronic comments proves it. Keep your erroneous statements to yourself and out of my thread.

My god we have another Steve68 here...... Might as well just add him to my block list now and save myself the later headache!!

stealthII
12-16-2012, 11:46 PM
Funny that you mentioned CNET as a source, as I had a very similar experience. Except I was trying to download Irfanview and noticed the .exe didn't look correct. Going against my better judgement, I ran it but luckily, SEP blocked it. Ran it in my containment DMZ and sure enough, got some malware (can't remember what is was though). I'm in the network/security profession, so I absolutely agree that it can happen to the best of us and there's some nasty stuff out there. Any O/S or browser that's highly used or popular, is bound to be susceptible to this garbage.

So far, and I hate to say it, but for Windows, Symantec Endpoint Protection and Malwarebytes have been a very good combo for me. However, SEP is a resource HOG and I hate it for that! Nothing is perfect though. I ran Microsoft Essentials and MWB a while back when 3Si was hosting malware in their banners, and I got hit with that. Switched to SEP and went to 3Si again, and SEP stopped the install. So SEP got props for that.

Mikes2nd
12-17-2012, 10:26 AM
As stated before:



You have no clue what you're talking about and your moronic comments proves it. Keep your erroneous statements to yourself and out of my thread.

My god we have another Steve68 here...... Might as well just add him to my block list now and save myself the later headache!!

k thanks man... Sorry you can't read :)