We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Email Hijacked problem

rizla01
rizla01 Posts: 7,260 Forumite
Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
edited 12 December 2010 at 10:50AM in Techie Stuff
Hi

My email account has been to be hijacked.

Ii is sending emails out to all in my address book.

I am running Avira, and Online Armour as well as IObit 360 Security Anti Malware (Hope that isn't a clash)

Have run Spybot and Superantispyware and they have discovered nothing.

Any suggestions please?
"Unhappiness is not knowing what we want, and killing ourselves to get it."
Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
Women and cats will do as they please, and men and dogs should relax and get used to the idea.
«13

Comments

  • davb
    davb Posts: 1,293 Forumite
    Part of the Furniture Combo Breaker
    What type of email account, is it webmail such as Hotmail, or do you have a local email client such as Outlook.
  • mr-mr_2
    mr-mr_2 Posts: 109 Forumite
    1. Need more info about your email set up.
    2. Get http://www.prevx.com/safebook.asp for your PC, it is free.
    3. Get, update and run MBAM: http://www.malwarebytes.org/mbam-download.php

    Once sure PC is clear, change your email password.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Download MALWAREBYTES (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_malwarebytes_anti_malware/
    Open malwarebytes and goto UPDATE and click 'check for updates'. After its updated goto SCANNER and click PERFORM QUICK SCAN then click SCAN
    Remove everything thats found (needs to be ticked)
    Post the COMPLETE log here AFTER youve deleted everything it finds
    If anything was found then do the exact same but run a FULL scan


    reboot

    Download HIJACK THIS (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_hijackthis/
    Click MAIN MENU then DO A SYSTEM SCAN AND SAVE A LOGFILE(Takes seconds) then post the log so we can see whats running
    (do NOT do anything else with Hijack but scan and post the FULL log)
    If you get a message that you cant write to the hosts file then Press the SHIFT key, and whilst holding it RIGHT CLICK and select RUN AS (admin)
    :idea:
  • jayme1
    jayme1 Posts: 2,154 Forumite
    Part of the Furniture Combo Breaker
    change the password of said email account, if you can do it on a known clean computer (or if you can through a phone or ipod touch)

    then do as the others have said.
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    assume you are using Windows live mail or outlook express??
    Ex forum ambassador

    Long term forum member
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Here is the Malwarebytes log

    Malwarebytes' Anti-Malware 1.50
    www.malwarebytes.org
    Database version: 5298
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702
    12/12/2010 12:52:17
    mbam-log-2010-12-12 (12-52-17).txt
    Scan type: Quick scan
    Objects scanned: 158011
    Time elapsed: 8 minute(s), 48 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    (No malicious items detected)
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 12 December 2010 at 2:02PM
    Here is the Hijack file

    For some reason I couldn't download from File-Hippo so had to use Cnet

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 14:01:55, on 12/12/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    G:\Zentimo\ZentimoService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    G:\Online Armor\OAcat.exe
    G:\Online Armor\oasrv.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Prevx\prevx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    C:\Program Files\Prevx\prevx.exe
    C:\WINDOWS\system32\igfxpers.exe
    G:\Online Armor\oaui.exe
    G:\IObit Security 360\IS360tray.exe
    G:\Zentimo\Zentimo.exe
    F:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
    G:\Online Armor\OAhlp.exe
    C:\Magnifier 1.09\Magnifier.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    D:\My Documents\HijackThis.exe
    C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\OUXA9NPW\HijackThis[1].exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://by150w.bay150.mail.live.com/default.aspx?wa=wsignin1.0
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/clipextractor/{A9E3981F-6A11-4EF1-A702-3819AB03CE4F}
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: SafeOnline BHO - {69D72956-317C-44bd-B369-8E44D4EF9801} - C:\WINDOWS\system32\PxSecure.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Roboform\roboform.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Roboform\roboform.dll
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [@OnlineArmor GUI] "G:\Online Armor\oaui.exe"
    O4 - HKLM\..\Run: [IObit Security 360] "G:\IObit Security 360\IS360tray.exe" /autostart
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] G:\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [Zentimo xStorage Manager] G:\Zentimo\Zentimo.exe /startup
    O4 - S-1-5-18 Startup: Alienware Dock.lnk = F:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe (User 'SYSTEM')
    O4 - S-1-5-18 Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Alienware Dock.lnk = F:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe (User 'Default user')
    O4 - .DEFAULT Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe (User 'Default user')
    O4 - Startup: Alienware Dock.lnk = F:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
    O4 - Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe
    O8 - Extra context menu item: Customize Menu - [URL]file://D:\Roboform\RoboFormComCustomizeIEMenu.html[/URL]
    O8 - Extra context menu item: Fill Forms - [URL]file://D:\Roboform\RoboFormComFillForms.html[/URL]
    O8 - Extra context menu item: Identities Editor - [URL]file://D:\Roboform\RoboFormComEditIdent.html[/URL]
    O8 - Extra context menu item: Locate Spot on Map by GPS - F:\IExif 2.3\IExifMap.htm
    O8 - Extra context menu item: Password Generator - [URL]file://D:\Roboform\RoboFormComPasswordGenerator.html[/URL]
    O8 - Extra context menu item: RoboForm Toolbar - [URL]file://D:\Roboform\RoboFormComShowToolbar.html[/URL]
    O8 - Extra context menu item: Save Forms - [URL]file://D:\Roboform\RoboFormComSavePass.html[/URL]
    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - F:\IExif 2.3\IExifCom.htm
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - [URL]file://D:\Roboform\RoboFormComFillForms.html[/URL]
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - [URL]file://D:\Roboform\RoboFormComFillForms.html[/URL]
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - [URL]file://D:\Roboform\RoboFormComSavePass.html[/URL]
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - [URL]file://D:\Roboform\RoboFormComSavePass.html[/URL]
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - [URL]file://D:\Roboform\RoboFormComShowToolbar.html[/URL]
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - [URL]file://D:\Roboform\RoboFormComShowToolbar.html[/URL]
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\SPYBOT~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\SPYBOT~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
    O16 - DPF: {0A43D7AC-D6C1-4622-B309-BF975F427C0E} (first direct internet banking plus digital safe) - https://internetbankingplus2.firstdirect.com/ibplus/frontdoorFD.cab
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1218797834562
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
    O20 - Winlogon Notify: !SASWinLogon - G:\SUPERAntiSpyware\SASWINLO.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
    O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - G:\Online Armor\OAcat.exe
    O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - G:\Online Armor\oasrv.exe
    O23 - Service: Zentimo Assistant (ZentimoService) - Unknown owner - G:\Zentimo\ZentimoService.exe
    --
    End of file - 7981 bytes
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    My 1st guess is your 'ZentimoService.exe' is not helping
    What is it?
    :idea:
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 12 December 2010 at 3:19PM
    Its a device that saves time and extends user abilities on active work with flash-drives, portable drives, card readers and other gadgets.

    I also notice that any links either don't work or have a distinct delay (Or need double clicking).
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • rizla01 wrote: »
    Hi

    My email account has been to be hijacked.

    Ii is sending emails out to all in my address book.

    I am running Avira, and Online Armour as well as IObit 360 Security Anti Malware (Hope that isn't a clash)

    Have run Spybot and Superantispyware and they have discovered nothing.

    Any suggestions please?

    Malware doesn't have to be on the client computer for an email login to be stolen.

    You'd typically steal the login by either

    * routing people to a fake Hotmail, Gmail login page
    * creating a 'genuine' service which requires logins, and assume a fraction of users will reuse their 'normal' password for other services, such as webmail.

    From there, it'd be a simple matter of using an app to spam a certain message using automated SMTP or POP logins.

    So.

    The solution is to change the password on the webmail account. If you use that password on any other services, change them, *especially* if you use your webmail address (e.g. xyz@hotmail.co.uk) as your login.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.3K Banking & Borrowing
  • 253.7K Reduce Debt & Boost Income
  • 454.4K Spending & Discounts
  • 245.4K Work, Benefits & Business
  • 601.2K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.