Email hacked, spamming, just checking for cause.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by futurerush, Feb 29, 2012.

  1. futurerush

    futurerush Private E-2

    Hello, last Thursday while I was at work, a friend sent me a message on my phone asking if I had sent him a specific link, when I said no, he said he thinks I've been hacked. Choosing not to check my email via my phone I waited to get home and logged into my e-mail to see what happened. Had several undeliverable emails, or "we received your inquiry", and a friend replied to an e-mail asking if I had a virus. There was nothing suspicious in the sent folder. It appears my whole list of contacts, even ones entered automatically from automated e-mails were sent spam at a specific time in the afternoon. The e-mail account was created in 1997 and I can't remember anything I used to create it from that time and ended up locking the account trying to change things. Luckily there was a master account I could log into to change underling accounts, so my password and security question/answer was changed that way. I ran the run & read me after that to see if a virus had been recording my keystrokes, or something to that affect. I was suspicious of my housemates' unsecure network as well. I never liked that they wouldn't put a wep key on it. My e-mail has never been hacked before. I also considered my phone. Anyways, the logs seemed clean, but I'm no expert on reading them. Here ya go.

    Ps. I'm using win7 64 bit.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hello futurerush,

    These logs are clean.

    Let's just run a couple more scans to make sure there isn't any rootkit activity.

    [​IMG] I want you to read and follow these instructions: TDSSKiller - How to run

    [​IMG] Please download aswMBR to your desktop.
    • Double-click aswMBR.exe to run (Vista/7 right-click and select Run as Administrator)
    • Select No when asked "Would you like to download latest Avast! virus definitions?"
    • Click the [Scan] button.
    • On completion of the scan click [Save log], save it to your desktop and attach this log to your next message. (How to attach)
     
  3. futurerush

    futurerush Private E-2

    Sorry this took so long but Major Geeks emails started to go to my spam folder some time ago, and when I remembered to check, I had several crises to deal with and continued to forget to do this.

    The first time I ran aswMBR I wasn't sure if it froze or not, so I stopped it and ran it again. During the second scan I got the blue crash screen and force shut down and booted up again. I gave the third scan plenty of time to finish. I ran TDSSKiller once and first, but there were 3 txt files, I picked the big file to upload. The other two just had system information.

    Still looks clean to me.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    No problem. These logs are clean as well.

    __

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Be safe :)
     
  5. futurerush

    futurerush Private E-2

    My email spammed others again tonight when my computer was off. What more can I do?
     
  6. thisisu

    thisisu Malware Consultant

    Have you changed your e-mail's login password yet? If not, I would do this first to see if the problem stops.
     
  7. futurerush

    futurerush Private E-2

    Yes, as in my original message, I changed the password/security question as soon as I could. I changed it just a moment ago.
     
  8. thisisu

    thisisu Malware Consultant

    Ok good.

    If the problem persists, the next thing to do would be to contact your e-mail provider.
     
  9. futurerush

    futurerush Private E-2

    Thank you.
     
  10. thisisu

    thisisu Malware Consultant

    You're welcome. :)
     
  11. futurerush

    futurerush Private E-2

    By the way, any chance my smartphone was hacked?
     
  12. thisisu

    thisisu Malware Consultant

    Yes. Unfortunately smartphones are susceptible to malware too. :(
     
  13. futurerush

    futurerush Private E-2

    What can I do to check? Is there a run & read me-ish thing for that? Major Geeks app?
     
  14. thisisu

    thisisu Malware Consultant

  15. futurerush

    futurerush Private E-2

    The phone appears to be clean too. But thank you for the links. I'll run an avast complete scan of my computer one more time, then I give up.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds