I'm Either Being Hacked Or Raving Mad

Discussion in 'Malware Help (A Specialist Will Reply)' started by jurrr, Jul 31, 2008.

  1. jurrr

    jurrr Private E-2

    Summary: I get e-mail of a failed Moneybookers login that arrived while I was surely sleeping. I cannot login to MB. I change MB password. Funds still there. Gmail glitches. E-mail of failed login disappears from Gmail. I cannot login to MB again. Impossible to change password again. Malware detectors show nothing. I'm not sure what to think.

    I play online poker and use a Moneybookers online wallet to deposit and withdraw.

    Tonight I wake up at 3:30 am (neighbors woke me) and check my e-mail. An hour ago I have gotten a message from Moneybookers saying I have a failed login.

    Now, I may have had a failed login earlier during the day but an hour ago I was soundly sleeping.

    Something's up. I try to login to Moneybookers and it fails. Now, maybe I have forgotten my password, but I think not. I go through the "change password" deal and get a link to change the password at. I change the password. My money is still there.

    Suddenly my Gmail acts up a bit, not refreshing correctly and the earlier e-mail telling of the failed login disappears. Hmmm, I didn't delete it as far as I remember. And it's not in trash. I change my Gmail password wondering if it will do me any good.

    I try logging in to Moneybookers. It fails again. I try to change the password again through the "failed login" option. It fails this time as it says it sent me the link and it didn't in the end.

    I feel like more of the Moneybookers notifications from Gmail have disappeared, but since I didn't take screenshots and was pretty frantic I don't know how many. Either way the first one has definitely disappeared and it was there, I had even a draft of a reply that hadn't disappeared and when I sent it then it started a new thread so the old one's gone.

    I get my primary poker account locked. I e-mail MB as they have no phone number for such cases.

    I run AVG Free (nothing), Ad-Aware (nothing), MBAB (nothing), SAS (nothing), HijackThis (nothing wrong I can see). I check "netstat -a" and see nothing I can identify as immediately wrong. My router/firewall seems fine but I don't know where OpenWRT keeps logs.

    My gf's desktop computer's AVG Free has been reporting Trojan "downloader" infections in the strangest places that I felt must be false positives. Nothing reported at any point on my laptop where this was happening. I doubt I've used the MB account from that computer in the last few weeks, but I have certainly used the Gmail account a few days ago.

    Now, my Gmail password is a very old one and it is saved in my Firefox password store (which was probably not a good idea). That doesn't give one an easy way to guess at my Moneybookers password (which also wasn't a very complex one but still). So what could be going on?

    a) Someone has a keylogger with me and has logged both MB and Gmail (and probably other) passwords. He mistypes the MB one once and forgets to remove the e-mail from Gmail. But he changes the MB password. Then before he can steal the funds, when I change it back he decides to remove selective e-mails from Gmail (parallel sessions with me so glitches appear for me) and change the MB password again.

    This makes very little sense but is the best explanation so far.

    b ) Moneybookers software glitches and sends me a notification late. I get it late and imagine it was a hacking account. In my panic I forget the password. I change it and in my panic delete some e-mails from Gmail. In my panic I forget the MB password again. Gmail glitches for no good reason.

    c) I'm a raving lunatic with paranoia and am starting to imagine things due to minor sleep deprivation.


    Any ideas will be appreciated.
     
  2. jurrr

    jurrr Private E-2

    BTW repeat scans of my gf's computer revealed nothing just now.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you suspect that passwords are really getting stolen, the you should run the below Cleaning Procedure on ALL PCs where you have logged into your accounts from. You will need to have a separate thread for each PC.

    I also suggest that you do take the below actions:


    Cleaning Procedure

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds