Hi
There is an interesting thread over in the Outpost section having to do with creating secure passwords if any one wants to take a look at that thread.
http://community.norton.com/norton/board/message?board.id=Tech_Outpost&thread.id=377
Hi
There is an interesting thread over in the Outpost section having to do with creating secure passwords if any one wants to take a look at that thread.
http://community.norton.com/norton/board/message?board.id=Tech_Outpost&thread.id=377
Thanks Phil.
I must activate it on my testbed and get used to it since there is a vast disparity between the number of entries each of us would need and hers would get lost if mixed with mine.
I finally finished scanning my desktop with Malwarebytes and this is the log from that. It found 10 items which I deleted. Could any of these be the cause of my hack?
Thanks,
Steven
Malwarebytes' Anti-Malware 1.44
Database version: 3529
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/10/2010 10:31:16 AM
mbam-log-2010-01-10 (10-31-16).txt
Scan type: Full Scan (C:\|F:\|G:\|I:\|)
Objects scanned: 592088
Time elapsed: 5 hour(s), 30 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{d28cd14c-50be-4cfa-951e-b37f25da3472} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{deceaaa2-370a-49bb-9362-68c3a58ddc62} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{42f2c9ba-614f-47c0-b3e3-ecfd34eed658} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7149e79c-dc19-4c5e-a53c-a54ddf75eee9} (Adware.MediaMotor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Hi csblue
Once it has been determined that your computer is totally clean, I would suggest removing your restore points and setting up a new one. I would also suggest that you keep an eye on your computer and see if the problem is still continuing or not. IF there is a rootkit involved, then malwarebytes can sometimes clean up the secondary infections, but not touch the rootkit. I'm not saying that you have a rootkit, I'm just saying that having a clean malwarebytes isn't always enough to know that your computer is really clean.
Since it found so many things on your computer, you may want to try a scan with the free version of SuperAntiSpyware and see if that comes out clean now. That's also an on demand scanner which will work with your Norton product. It's a different engine, so it might find some other things also.
Here is a free on demand antimalware scanner. It is safe to use on demand with your Norton product. Please don't forget to update the product before running the scan.
http://www.superantispyware.com/
You will be able to post the log here using the "add attachments" link below the orange post button.
Thanks. I am still trying to determine if any of those things that Malwarebytes found could have hacked my email. Or was it definitely something online? I need to know because if it was my online email isp or Amazon.com, I need to find out what their security measures are and what can be done about this.
Thanks,
Steven
Hi csblue
I don't know if any of those malwares that malwarebytes found could have hacked your accounts or your email accounts.. I do know that if you have a computer that has malware on it, it's not a safe environment to do online purchases and banking. I think it still needs to be determined if you do have a rootkit which could have caused all these malwares to show up now. If you do have a rootkit, then it's not safe to do any online purchases or banking till it is cleaned up.
Hi csblue,
Malware instances that are found by Malwarebytes' only in registry keys with no infected files reported can be leftover remnants of infections that have been previously removed (See this Malwarebytes Forum thread for an explanation of a detection identical to yours). So it is unlikely that anything that Malwarebytes' found was involved in your breached accounts. Did you happen to respond recently to any emails concerning the status of any of your accounts? Did you log into any account and end up at a page that didn't look right or act as you expected that it should?
Thanks for your help. I think we have determined to a pretty high degree that the hack did not come from my computer but was hacked online.
To floplot: If I have a rootkit, wouldn't Norton have found it? Do I actually need a third scan program (SuperAntiSpyware) to discover this?
To SendOfJive: Here are the steps in the order that happened. I received an email from Amazon.com stating that there may be some phishing going on and so the next time I go to their website and login to my account, I should create a new password. So I went to Amazon.com (not from a link in the email, but just surfing there on my own) and when I went to login to my account the window said to please create a new password. I did, and logged in. Later in the day I went back to Amazon to check something and when I tried to login with my new password it said it was invalid. I tried my old password and it said that was invalid also. I could not login. So, I went to my email account to see if Amazon had sent me another email and I could not login to my email at that point. I was locked out. I called Amazon customer support and explained the situation and they logged me in to my account and that was when we discovered that someone had hacked it and charged almost $600.00.
The thing is, Amazon customer support told me that, yes, they had sent me the email to change my password. But it was someone from another country, so he could have misunderstood. My ISP was closed for the day but I reached them the next day and they had me change my password to lock out the hacker (like you guys suggested). When I went to my email account, that original email from Amazon was no longer there. It had just disappeared. I checked all my folders for it: spam, trash, etc.
So now I'm trying to determine whether the hacker originally hacked Amazon.com or hacked my email ISP, so that I can check my security situation with them and ask them if I was hacked there, and also, what about my security there in the future. Unfortunately, I had the same password in both places, bad on my part, but as we've discussed here, I'm doing new passwords everywhere using Norton's Identity Safe.
csblue
Reading all the above, I'm sorry to hear of you problem.
I think I read at the start that you have NIS 2009
As I haven't seen it mentioned since, I'll just say , that when you get things sorted, it might be advisable to upgrade to NIS 2010.
It's a free upgrade if you have an active suscription for 2009
Hi csblue
Unfortunately, Norton's doesn't always find the new generation of rootkits. They change so rapidly and take on so many different characteristics and stay hidden for the most part. Most of the time, it really takes an expert with the right tools and expertise to find rootkits and help the user clean up his computer. I suggested SAS not to find the rootkit if there is one, but just to make sure your computer is now clean of what was there. I don't know if you do have a rootkit. I was just saying that it is a possibility when you had so many remnants or actual malware that malwarebytes found. I was suggesting another scan with either product actually to see if they found anything more. If those scans would find more malware, then something is putting it there and that something could possibly be a rootkit.
Hi csblue,
That is indeed an interesting story. At the point where you were no longer able to log into your Amazon account, you had been compromised and the bad guys had changed your Amazon password, locking you out. The most likely scenario, since Amazon is a constant target for phishers and you did receive an email concerning your account information, is that somewhere in all that password changing drama the bad guys got your Amazon credentials, found your email address on file, logged into your email account using the same password (Bingo!) and locked you out there too, so you would not receive any confirmation messages from Amazon concerning "your" $600.00 purchase. This would have given them enough time to pull off their scheme had you not returned to the Amazon site "to check something" and stumbled upon the fraudulent transaction. You got lucky, although you would not have been responsible for the credit card charges above $50.00 (which is usually waived anyway).
You mentioned not responding to the Amazon email by clicking a link. Is this because there was no link, or because you are smart enough to know not to click on them in emails? This is an important point because Amazon does not include links in its emails concerning customer accounts. If you saw a link, then the email was a fake. This does not explain how the bad guys might have gotten your information if you did not use the link, but it would definitely flag the email as a phishing attack. You can read how to tell a legitimate Amazon email from a phony one here:
http://www.amazon.com/gp/help/customer/display.html?nodeId=15835501
Thanks guys, again.
boneidle: I have NIS 2010 and will be updating as soon as this is all settled. Thanks.
floplot: Good info. I will try the SuperAntiSpyware scan, just to see. I'll let you know the details.
SendOfJive: I am very savy of email links and attachments. I don't believe there was a link in Amazon's email, but if there was I would not have clicked on it. Your post also makes me realize that when I did finally regain access to my email, there was no confirmation email from Amazon concerning the order the hacker made. I know Amazon always sends one but I missed that until reading your post. I have reported fake Amazon emails to them in the past, but I thought this one was real. But now I wonder. If the hacker removed both this email and the confirmation email from my email account, maybe it was fake. If it was fake, then that means they probably hacked my online email first. If it wasn't fake, they probably hacked my Amazon account first. I hope to find out more tomorrow when I call them both with my new info.
csblue wrote:Thanks for your help. I think we have determined to a pretty high degree that the hack did not come from my computer but was hacked online.
To floplot: If I have a rootkit, wouldn't Norton have found it? Do I actually need a third scan program (SuperAntiSpyware) to discover this?
...
So now I'm trying to determine whether the hacker originally hacked Amazon.com or hacked my email ISP, so that I can check my security situation with them and ask them if I was hacked there, and also, what about my security there in the future. Unfortunately, I had the same password in both places, bad on my part, but as we've discussed here, I'm doing new passwords everywhere using Norton's Identity Safe.
The odds are high that:
1. Your email was hacked first. Once your email account has been breeched, all sorts of other hacking can take place easily and without your noticing. All password resets would be sent to your email account. Your email account password would be left unchanged so that you would not be aware of the breeching until the damage was done. My guess is that it was more coincidence than anything else that made you aware of something wrong in time to do something about it. Most people wouldn't have that opportunity and would suffer significant loss.
2. You are in danger until you substantially modify your email password (which I assume you have done by now). Why? Because it is the nature of thieves -- both internet and physical -- to rob you twice (or more). If your email account is still available (which it would be in the case of most people who would only assume their Amazon account had been cracked), then it can be used again as a vehicle for resetting the password on another account (or even on Amazon again). They would wait long enough that you would forget the original incident and lower your alertness level. This is the reason we recommend changing EVERY password on EVERY account you have. They may already know your VISA or Mastercard or American Express or Dillard's account number and password.
And learn from this ... which I think you already have. A little pain, in this case, may have paid off in a huge gain. Good luck.
Here's an interesting article I found the other day on some things that you might overlook after your email account has been compromised:
Thanks again for all of your help. I'll be working on all of this tomorrow. I'll let you know how it turns out.
Steven
Thanks again for all your help. The ask Leo link was very useful. Great info there. I talked to my ISP this morning and they thoroughly checked my account. Nothing seems to be amiss and there doesn't appear to be anything there that doesn't belong. They were able to change my username and password over the phone. I plugged that info into Norton Identity Safe and was able to login to my email without any keystrokes. I think Identity Safe is a very useful tool and will be used by me a lot from now on. I think I am out of the dark thanks to all of you. You are awesome. Now that my email looks secure again, I am in the process of changing and securing all of my other accounts with good encryption. I'll let you know if anything goes awry, but I think I'm okay now... quite relieved that I was as lucky as I was in nipping this in the bud!
Thanks again,
Steven 