Skype account compromised

Discussion in 'Malware Help (A Specialist Will Reply)' started by se9040, Jan 4, 2010.

  1. se9040

    se9040 Private E-2

    I'm generally a pretty savvy user and understand basic computer security. However, a couple weeks ago my Skype account was compromised and a spammer got in there and charged hundreds to the stored card. Needless to say I'm freaked about how this happened and want to close whatever backdoor that allowed them to do this.

    Logs attached. I am x64 and Windows 7 so combofix isn't an option, according to the read me first thread.

    TIA
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm sorry but you do not appear to be having malware problems. Your issues just may be due to security holes in the software you are running (like Skype) and also running high risk software like utorrent. Also you have Logmein/Goto Meeting running and if they are not properly password protected you leave yourself open to attack.

    The only other item I question is what is this?
    C:\Program Files (x86)\TechSmith\Jing\Jing.exe

    In additon to the above, your PC does not appear to have proper protection installed. The QwestInternetSecurity you have installed is questionable at best and appears to be broken anyway. And you also seem to be relying on the Windows Firewall which is also rather poor. Also your logs show signs of some software from Symantec but it is also broken/uninstall. Thus you basically have no protection and have left the door open for all kinds of possible attacks.
     
  3. se9040

    se9040 Private E-2

    That's good to know, I guess. I figured there would be more scans you'd have me do to ensure that it's not a rootkit or something sneaky that would get past MBAM or SAS.

    I understand you have to say that about uTorrent, it's not used for downloading anything "high risk". Just linux distros and such. This is an office computer. I am certain that LMI/GTM are not left running, meetings are always shut down when they are over.

    Jing.exe is the free, casual-user version of SnagIt (if you've heard of that software). It's for making screen shots.

    The Security Center in windows say that I am fully protected and up to date with Microsoft Security Essentials, which I read in a recent article is as good or better than AVG in terms of virus coverage. It is true that I only have the windows firewall though, which some tell me is inadequate. QwestInternetSecurity was uninstalled quite some time ago (I believe it's a rebranded version of McAfee, which I hate).

    Thanks for your help, I take it you are some kind of anti-malware god around here based on your post history. You're doing a good thing here!
     
  4. se9040

    se9040 Private E-2

    There are a couple other computers I use Skype on that could possible be where the account was compromised rather than this computer. Should I make a separate thread for those, or put their scan logs in here?

    Thanks
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still leaves your PC open to the world no matter what you are downloading or even if you are not downloading and it is just running.

    Company PCs should never be running P2P or torrent programs and I'm quite surprised that you IT dept (assuming you have one) would allow this. This tools are block by most companies because they are high security risks.


    Not according to your logs. MSE does not show as installed or running. Also that showed was broken Symantec and broken QwestInternetSecurity . And as far as how good MSE really is remains to be seen. Right now, I don't think very much of it.

    No question about it. It's rating has always been poor.

    Not completely. And neither did Symantec. Notice tha below in your hijackthis.log inside the MGlogs.zip file:


    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [NovaNet-WEB Tray Control] "C:\Program Files (x86)\Qwest Office Backup\TrayControl.exe"
    O4 - HKLM\..\Run: [isCfgWiz] "c:\Program Files (x86)\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW.exe" -G:{77CCBE0B-A541-49a9-883E-14F8337EC861} -T:Config -REBOOT
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [AuthStart] "C:\Program Files (x86)\QwestInternetSecurity\ISS\app\authstart.exe"


    Perhaps you should do the below to finish cleaning this up:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [NovaNet-WEB Tray Control] "C:\Program Files (x86)\Qwest Office Backup\TrayControl.exe"
    O4 - HKLM\..\Run: [isCfgWiz] "c:\Program Files (x86)\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW.exe" -G:{77CCBE0B-A541-49a9-883E-14F8337EC861} -T:Config -REBOOT
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [AuthStart] "C:\Program Files (x86)\QwestInternetSecurity\ISS\app\authstart.exe"

    After clicking Fix, exit HJT.
     
    Last edited: Jan 9, 2010
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Each computer requires a new thread. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds