We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

My email account has been hacked!

Options
13»

Comments

  • NinkyNonk_2
    NinkyNonk_2 Posts: 116 Forumite
    torbrex - were your emails ok? I'm concerned that the hacker saw usernames and passwords for other my accounts. And even though avast and malwarebytes have found nothing, I'm scared there's a keylogger on my system.

    I always log out when I'm finished using any account.

    Maybe a site I have visited is infected and picked up my password that way?
  • torbrex
    torbrex Posts: 71,340 Forumite
    10,000 Posts Combo Breaker Rampant Recycler Hung up my suit!
    NinkyNonk wrote: »
    torbrex - were your emails ok? I'm concerned that the hacker saw usernames and passwords for other my accounts. And even though avast and malwarebytes have found nothing, I'm scared there's a keylogger on my system.

    I always log out when I'm finished using any account.

    Maybe a site I have visited is infected and picked up my password that way?
    I have had no problem since, it would seem to have been a random attack, possibly from a bot of some kind.
    None of the original recipients have been in touch to let me know of any further emails of the same nature and as a couple of my other email addresses were victims of the original hack, I would have had something to them if it had been ongoing.
  • robmar0se
    robmar0se Posts: 1,328 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    NinkyNonk wrote: »
    Some of the addresses that it was sent to were places that I had emailed once sometime last year (for example). Nearly all but not entirely, all of my friends email addys are in these 'failed to send' emails.

    Since some if not all yr contacts have received these spoof emails, it is likely that yr contacts list has been hacked.

    If you only use webmail, than yr Yahoo account was hacked, and should be sufficient to change yr passwords.

    If however you use an email client eg Outlook, Live Mail, etc., then yr PC was probably hacked. Malwarebytes not finding things is good, but not conclusive. The guys over at Bleeping Computer might assist - http://www.bleepingcomputer.com/forums/ - I use them all the time for difficult to solve situations - using combofix under their tutelage will find anything if its there.
  • NinkyNonk_2
    NinkyNonk_2 Posts: 116 Forumite
    I'm writing this from my laptop as am scared to use my desktop at moment. I'm running Combofix right now and it's found a system file has been infected. But whilst running this, my comp crashed and I have started again. It's currently on stage 48 and all of my desktop icons and bar have disappeared and I can't get onto the internet. I thought it may be aol playing up but I then got onto the web with my laptop.
    I'm really starting to panic as I had logged into paypal and ebay and a few other sites. I'm wondering how long has this thing been hiding on my comp. And how did it get through?

    My friend clicked on the link that was in the email that was from my hacked account, thinking it was from me. He said it was a blank page. He has no virus protection. What do you think could possibly happen to his comp?

    I only use web based email, no client based.
    Could it be a fault with yahoo or not myself?
  • NinkyNonk_2
    NinkyNonk_2 Posts: 116 Forumite
    edited 15 June 2012 at 10:00PM
    ComboFix 12-06-15.06 - Jones 15/06/2012 21:13:57.5.4 - x86
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.2815.1606 [GMT 1:00]
    Running from: c:\users\Jones\Desktop\ComboFix.exe
    AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -- Previous Run --
    .
    Infected copy of c:\windows\system32\userinit.exe was found and disinfected
    Restored copy from - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
    .
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-05-15 to 2012-06-15 )))))))))))))))))))))))))))))))
    .
    .
    2012-06-15 20:27 . 2012-06-15 20:27
    d
    w- c:\users\Wayne\AppData\Local\temp
    2012-06-15 20:27 . 2012-06-15 20:27
    d
    w- c:\users\Public\AppData\Local\temp
    2012-06-15 20:27 . 2012-06-15 20:27
    d
    w- c:\users\Jordan\AppData\Local\temp
    2012-06-15 20:27 . 2012-06-15 20:27
    d
    w- c:\users\Default\AppData\Local\temp
    2012-06-14 11:15 . 2012-04-28 03:17 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
    2012-06-14 11:15 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\system32\msi.dll
    2012-06-14 11:15 . 2012-05-15 01:05 2343936 ----a-w- c:\windows\system32\win32k.sys
    2012-06-14 11:15 . 2012-04-26 04:45 58880 ----a-w- c:\windows\system32\rdpwsx.dll
    2012-06-14 11:15 . 2012-04-26 04:45 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
    2012-06-14 11:15 . 2012-04-26 04:41 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
    2012-06-14 11:15 . 2012-05-01 04:44 164352 ----a-w- c:\windows\system32\profsvc.dll
    2012-06-14 11:15 . 2012-04-24 04:36 140288 ----a-w- c:\windows\system32\cryptsvc.dll
    2012-06-14 11:15 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\system32\crypt32.dll
    2012-06-14 11:15 . 2012-04-24 04:36 103936 ----a-w- c:\windows\system32\cryptnet.dll
    2012-06-06 13:01 . 2012-06-06 13:01
    d
    w- c:\users\Jordan\AppData\Local\Mozilla
    2012-05-23 17:08 . 2012-05-23 17:08
    d
    w- c:\users\Jones\AppData\Local\Power2Go
    2012-05-23 17:03 . 2012-05-23 17:03
    d
    w- c:\users\Public\CyberLink
    2012-05-23 17:03 . 2012-05-23 17:03
    d
    w- c:\users\Jones\AppData\Roaming\CyberLink
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-06-09 10:45 . 2012-04-04 10:37 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2012-06-09 10:45 . 2011-06-09 14:47 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-04-04 14:56 . 2011-01-20 20:06 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-03-31 04:39 . 2012-05-12 06:33 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2012-03-31 04:39 . 2012-05-12 06:33 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
    2012-03-30 10:23 . 2012-05-12 06:33 1291632 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2004-11-11 16:36 . 2004-11-11 16:36 1020416 ----a-w- c:\program files\PSCore3.dll
    2004-11-11 16:36 . 2004-11-11 16:36 92160 ----a-w- c:\program files\PSSourceFilter3.dll
    2004-11-11 16:36 . 2004-11-11 16:36 901120 ----a-w- c:\program files\MSRAAutoFix.dll
    2004-11-11 16:36 . 2004-11-11 16:36 77312 ----a-w- c:\program files\PSPublish.dll
    2004-11-11 16:36 . 2004-11-11 16:36 78848 ----a-w- c:\program files\CabinetDll3.dll
    2004-11-11 16:36 . 2004-11-11 16:36 76800 ----a-w- c:\program files\bandexpander.dll
    2004-11-11 16:36 . 2004-11-11 16:36 71680 ----a-w- c:\program files\PSTransitionFilter.dll
    2004-11-11 16:36 . 2004-11-11 16:36 49664 ----a-w- c:\program files\PSDMusicDMO.dll
    2004-11-11 16:36 . 2004-11-11 16:36 41984 ----a-w- c:\program files\WavDest3.dll
    2004-11-11 16:36 . 2004-11-11 16:36 102912 ----a-w- c:\program files\PhotoStory3.exe
    2004-09-17 19:00 . 2004-09-17 19:00 31440 ----a-w- c:\program files\PSLegitCheck.dll
    2011-12-21 07:42 . 2012-01-09 12:43 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{3806b089-6759-411d-b2c3-b7995a9f34d7}"= "c:\program files\Harmony_Hollow_Software\prxtbHarm.dll" [2011-05-09 176936]
    .
    [HKEY_CLASSES_ROOT\clsid\{3806b089-6759-411d-b2c3-b7995a9f34d7}]
    .
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3806b089-6759-411d-b2c3-b7995a9f34d7}]
    2011-05-09 09:49 176936 ----a-w- c:\program files\Harmony_Hollow_Software\prxtbHarm.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3806b089-6759-411d-b2c3-b7995a9f34d7}"= "c:\program files\Harmony_Hollow_Software\prxtbHarm.dll" [2011-05-09 176936]
    .
    [HKEY_CLASSES_ROOT\clsid\{3806b089-6759-411d-b2c3-b7995a9f34d7}]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2012-03-06 23:15 123536 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
    "FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
    "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2011-06-17 412432]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-20 7625248]
    "Freecorder FLV Service"="c:\program files\Freecorder\FLVSrvc.exe" [2010-06-26 167936]
    "HostManager"="c:\program files\Common Files\AOL\1269802939\ee\AOLSoftware.exe" [2008-06-24 41824]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
    "avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-03-06 4241512]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
    "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
    .
    c:\users\Jones\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    StarOffice 9.lnk - c:\program files\Sun\StarOffice 9\program\quickstart.exe [2008-9-12 113152]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean.exe
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2012-04-04 05:53 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2011-10-24 14:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSClearCloudTrayApp]
    2010-08-18 09:37 537936 ----a-w- c:\program files\ClearCloud\ClearCloud DNS\SBCC_Utility_Tray.exe
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 136176]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-09 257224]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 136176]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-21 1343400]
    R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    S1 aswSnx;aswSnx; [x]
    S1 aswSP;aswSP; [x]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
    S2 aswFsBlk;aswFsBlk; [x]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-03-06 57688]
    S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - AVGIDSDriver
    *Deregistered* - AVGIDSEH
    *Deregistered* - AVGIDSFilter
    *Deregistered* - AVGIDSShim
    *Deregistered* - Avgrkx86
    *Deregistered* - Avgtdix
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-06-15 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 10:45]
    .
    2012-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 09:45]
    .
    2012-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 09:45]
    .
    .
    Supplementary Scan
    .
    uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
    IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    Trusted Zone: valuedopinions.co.uk\www
    TCP: DhcpNameServer = 192.168.1.1
    FF - ProfilePath - c:\users\Jones\AppData\Roaming\Mozilla\Firefox\Profiles\5qndzzfz.default\
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
    MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
    .
    .
    .
    LOCKED REGISTRY KEYS
    .
    [HKEY_USERS\S-1-5-21-2391137309-2146828521-3579586563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.Email.1"
    .
    [HKEY_USERS\S-1-5-21-2391137309-2146828521-3579586563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.VCard.1"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    DLLs Loaded Under Running Processes
    .
    - - - - - - - > 'Explorer.exe'(2292)
    c:\users\Jones\AppData\Local\FLVService\lib\FLVSrvLib.dll
    .
    Other Running Processes
    .
    c:\windows\system32\nvvsvc.exe
    c:\windows\system32\nvvsvc.exe
    c:\program files\Sandboxie\SbieSvc.exe
    c:\program files\Alwil Software\Avast5\AvastSvc.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    c:\windows\system32\taskhost.exe
    c:\windows\system32\WUDFHost.exe
    c:\windows\system32\conhost.exe
    c:\windows\System32\rundll32.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\program files\Sun\StarOffice 9\program\soffice.exe
    c:\program files\Sun\StarOffice 9\program\soffice.bin
    c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
    c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
    c:\program files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe
    c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
    c:\windows\system32\sppsvc.exe
    .
    **************************************************************************
    .
    Completion time: 2012-06-15 21:45:59 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-06-15 20:45
    ComboFix2.txt 2011-01-22 11:49
    ComboFix3.txt 2011-01-22 11:34
    .
    Pre-Run: 210,467,188,736 bytes free
    Post-Run: 211,231,195,136 bytes free
    .
    - - End Of File - - 2897A892D13897A803FF85652FC9CB3A
  • NinkyNonk_2
    NinkyNonk_2 Posts: 116 Forumite
    Could someone take a look at this combofix for me please? It says previous run because my comp crashed in the middle of the 1st go.
  • NinkyNonk_2
    NinkyNonk_2 Posts: 116 Forumite
    I reported the hack to yahoo who have replied today. They say my account is fully working and secure. I still don't trust the account.

    I'm constantly checking my bank account and paypal to make sure everything is still there. :(
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 598.9K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.