Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Hacked


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Hacked
Reply
 
Thread Tools
Old 16-06-2005, 18:31   #1
cf.addict
 
Join Date: Dec 2004
Posts: 178
AlanYork is on a distinguished roadAlanYork is on a distinguished road
Hacked

Last night I discovered a keylogger on my pc. It was called ABCkeylog. I've removed it, done a sweep and changed all the passwords on my pc. Fortunately I don't have internet banking.

Today I received a spam e mail to my hotmail address, purporting to be from myself, dated 12 June. There was an attachment which of course I did not open.

I've reported the issue to microsoft. Is this e mail address now hopelessly compromised or is changing the password sufficient, as the spam mail was dated 4 days ago.
AlanYork is offline   Reply With Quote
Old 16-06-2005, 18:33   #2
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,931
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Hacked

Do you have a firewall running? If so I would check for outbound connections or activity for the period that the keylogger was active on your system.
Actually are you sure it was active? It seems to be a freeware download too
http://www.snapfiles.com/get/abckeylog.html
__________________
Paul is offline   Reply With Quote
Old 16-06-2005, 18:40   #3
cf.addict
 
Join Date: Dec 2004
Posts: 178
AlanYork is on a distinguished roadAlanYork is on a distinguished road
Re: Hacked

I have Zone Alarms Security Suite. I've run a leak test from Gibson Security Corp and denied it access to ZASS as instructed, it come back as no leaks detected. So thats ok.

Sorry I dont know how to check for outbound activity.
AlanYork is offline   Reply With Quote
Old 16-06-2005, 18:42   #4
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,931
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Hacked

If it had been active you might have gotten a request for permission to allow an outbound connection for it. Do you have anything unusual in your firewall logs?
__________________
Paul is offline   Reply With Quote
Old 16-06-2005, 19:20   #5
cf.addict
 
Join Date: Dec 2004
Posts: 178
AlanYork is on a distinguished roadAlanYork is on a distinguished road
Re: Hacked

No there was definately nothing like that, I have a good memory for that sort of thing. A messenger contact of mine had this on his pc too. My main concern is the security of my e mail. The keylogger has definately gone now. My friend works with computers as a job and he helped me to remove, wipe and check to make sure it had gone.
AlanYork is offline   Reply With Quote
Old 16-06-2005, 19:22   #6
Cable Forum Team
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 31
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 7,899
Rob M has a pair of shiny starsRob M has a pair of shiny stars
Rob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny stars
Re: Hacked

Have you changed the password for the hotmail account? If not you should do.
__________________
Formerly known as 'Raistlin'
For Clarity: Bold = Moderating Decision/Comment :: Normal = My Opinion/Comment
Rob M is offline   Reply With Quote
Old 16-06-2005, 19:38   #7
cf.addict
 
Join Date: Dec 2004
Posts: 178
AlanYork is on a distinguished roadAlanYork is on a distinguished road
Re: Hacked

Yes I changed every password on the pc. Is that sufficient?
AlanYork is offline   Reply With Quote
Old 16-06-2005, 19:50   #8
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,931
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Hacked

Quote:
Originally Posted by AlanYork
Yes I changed every password on the pc. Is that sufficient?
Not if you feel that your hotmail account has been compromised, have you changed you password on the hotmail site itself?
__________________
Paul is offline   Reply With Quote
Old 16-06-2005, 21:02   #9
cf.addict
 
Join Date: Dec 2004
Posts: 178
AlanYork is on a distinguished roadAlanYork is on a distinguished road
Re: Hacked

Yes I changed the password of every e mail address I have. Is that enough? I informed microsoft too. I have emails I want to keep, Im just hoping they wont close my email address down.
AlanYork is offline   Reply With Quote
Old 16-06-2005, 21:18   #10
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,931
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Hacked

Quote:
Originally Posted by AlanYork
Yes I changed the password of every e mail address I have. Is that enough? I informed microsoft too. I have emails I want to keep, Im just hoping they wont close my email address down.
As long as you have removed the key logger prior to changing the emails you should be ok. I would recommend a sweep with an Anti-virus tool and at least one spyware tool to be sure that you are clean now.
__________________
Paul is offline   Reply With Quote
Old 16-06-2005, 22:34   #11
cf.addict
 
Join Date: Dec 2004
Posts: 178
AlanYork is on a distinguished roadAlanYork is on a distinguished road
Re: Hacked

Yeah, I zapped the keylogger last night, it was a dll in Windows 32. Wiped it, did various other things under guidance from someone who knows what he is talking about, ran a check using the scanner that located it in the first place, Symantec Virus Scanner and that came up clean. Changed every password on the pc, email passwords, windows passwords, forum passwords, the lot about 8 hours later, after I'd slept. Then reported it to Microsoft. Can't think that I've missed anything.

I'm pretty sure I know how I got this keylogger too. A friend of mine who I talk to on messenger warned me he got it, so it looks like its come from using MSN messenger. He had it on his pc too but removed it. I've warned all my contacts. It's all a tad worrying as though I'm no pc expert, I use a firewall, antivirus, regularly check for spyware etc and I STILL get this. Don't really see what else I can do to stay secure.

Last edited by AlanYork; 16-06-2005 at 22:36.
AlanYork is offline   Reply With Quote
Old 16-06-2005, 23:05   #12
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: Hacked

I'm pretty sure there was a warning last month about MSN malware, can't remember the details though.
Richard M is offline   Reply With Quote
Old 16-06-2005, 23:11   #13
Ghost Process Killer
 
MetaWraith's Avatar
 
Join Date: Oct 2003
Location: 2nd CPU to the right & past the cache
Posts: 1,861
MetaWraith has a bronzed appealMetaWraith has a bronzed appeal
MetaWraith has a bronzed appealMetaWraith has a bronzed appeal
Send a message via ICQ to MetaWraith Send a message via AIM to MetaWraith Send a message via MSN to MetaWraith Send a message via Yahoo to MetaWraith
Re: Hacked

Quote:
Originally Posted by Richard M
I'm pretty sure there was a warning last month about MSN malware, can't remember the details though.
http://www.usatoday.com/tech/news/20...2-hacked_x.htm
__________________
Yesterday it worked. Today it is not working. VM is like that.
Three things are certain: Death, taxes and lost data. Guess which has occurred ?
MetaWraith is offline   Reply With Quote
Old 16-06-2005, 23:12   #14
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: Hacked

No, this was MSN Messenger...
Richard M is offline   Reply With Quote
Old 17-06-2005, 14:27   #15
cf.addict
 
Join Date: Dec 2004
Posts: 178
AlanYork is on a distinguished roadAlanYork is on a distinguished road
Re: Hacked

I just got a reply back from MSN...they actually wanted me to open the spam email purporting to be from myself!!! Now OK, I may be a novice and I will say that in the short time I've had a pc I've had a few teething problems, but even I know not to open e mails and attachments if you dont know who has sent it!!!

Apparently I'm selling myself Diet pills!!??.......hmmm or a virus or a Trojan if I open the attachment I think. MSN tech suport tell me that will help trace the sender or see if it has a false header. Actually its irrelevant as I deleted it, but I was horrified at their suggestion.

Bit of a dilemma really. I like hotmail, it's easy to use but I've kinda lost faith in it a bit, there have been a few problems of late, not least of which is constantly being asked to verify my ID. If a hacker had hijacked it however, that would explain a lot, certainly that.

Now I've zapped the keylogger and changed the password I'm hoping things should be back to normal. However I do have a German e mail address (I have a flat in Berlin) provided by GMX. That's great, secure and efficient, it's just a hassle that everything is in German, which I speak, but not well.

The GMX one hasn't been hacked, I know that for definate, so, can I ask for an opinion...if it was you guys and ladies would you ditch hotmail completely and switch to GMX or would you assume hotmail is fine again now?

I'm kinda attached to hotmail, I've always used it as its so simple but you need to be able to trust it don't you. I will say that I don't use outlook, NTL mail or anything like that. I keep things simple. I just log into hotmail on the msn site, pick up mail, send mail and log off...that's it. Same with GMX. I would have to keep my hotmail address to keep MSN messenger, but my question is, stick with hotmail as the address for all my contacts or switch to GMX? I only want and need one email address to write from and be written to.
AlanYork is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 21:52.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)