Ouch email hacked!

Author
LpMike75
Max Output Level: -59 dBFS
  • Total Posts : 1621
  • Joined: 2009/10/04 11:50:50
  • Location: CT
  • Status: offline
2012/06/16 21:43:55 (permalink)

Ouch email hacked!

My wife and I both use my laptop (non DAW).  I have Norton, Malewarebytes, Superanitspyware and Adaware installed and frequently run scans with all of them.  As of a few days ago my Ad-aware program started getting errors.  I uninstalled it through "add/remove programs" then my network went crazy.  I could no longer connect to the internet.  No idea what happened.....then...
 
I woke up this morning to find a whole mess of returned emails that I had sent out on my AOL account.  Apparently "I" sent out deals on buying sneakers and who knows what else to everyone in my address book..which includes business contacts!  Oh the horror!
 
What is even more weird is, I never have to actually enter my password, it is automatically stored in my computer(s) to avoid keyloggers, no idea how they did it.  So many passwords to change now......
 
I'm just venting, never been hacked before because I am usually very cautious and have several tools on the computer to prevent viruses.  Guess you can't beat them all, atleast they didnt erase my emails I had stored


- Mike
Sonar Platinum - M-Audio Profire 2626 , Pro Tools 11 HD Omni - PC I7 6850K - 64 G RAM - GeForce GTX 970
http://www.soundcloud.com/michael-lizotte 
Http://WWW.HomeRecordingWizard.Com
HTTP://WWW.Facebook.com/HomeRecordingWizard
Http://www.mjlmusic.com 
#1

7 Replies Related Threads

    Jonbouy
    Max Output Level: 0 dBFS
    • Total Posts : 22562
    • Joined: 2008/04/14 13:47:39
    • Location: England's Sunshine South Coast
    • Status: offline
    Re:Ouch email hacked! 2012/06/17 00:54:58 (permalink)
    Make sure you use plenty of different passwords and change them regularly.

    It's especially important if you have things like Facebook accounts linked to email accounts.

    Keep seperate accounts to use for business, social and for e-commerce.

    Good policy works better than any anti-malware or AV software.  Software solutions should only be a part of your security policy and not the policy itself.

    Been there.
    post edited by Jonbouy - 2012/06/17 00:56:13

    "We can't do anything to change the world until capitalism crumbles.
    In the meantime we should all go shopping to console ourselves" - Banksy
    #2
    LpMike75
    Max Output Level: -59 dBFS
    • Total Posts : 1621
    • Joined: 2009/10/04 11:50:50
    • Location: CT
    • Status: offline
    Re:Ouch email hacked! 2012/06/17 13:12:29 (permalink)
    Good policy works better than any anti-malware or AV software

     
    For sure


    - Mike
    Sonar Platinum - M-Audio Profire 2626 , Pro Tools 11 HD Omni - PC I7 6850K - 64 G RAM - GeForce GTX 970
    http://www.soundcloud.com/michael-lizotte 
    Http://WWW.HomeRecordingWizard.Com
    HTTP://WWW.Facebook.com/HomeRecordingWizard
    Http://www.mjlmusic.com 
    #3
    LpMike75
    Max Output Level: -59 dBFS
    • Total Posts : 1621
    • Joined: 2009/10/04 11:50:50
    • Location: CT
    • Status: offline
    Re:Ouch email hacked! 2012/06/17 13:22:52 (permalink)
    I figured it out, a good reminder for others.  I checked my email recently from another persons computer while I wasnt home.  That person is having all sorts of issues with their computer all of a sudden. 

    So, lesson learned, if it's not your computer don't be putting your passwords in it :(


    - Mike
    Sonar Platinum - M-Audio Profire 2626 , Pro Tools 11 HD Omni - PC I7 6850K - 64 G RAM - GeForce GTX 970
    http://www.soundcloud.com/michael-lizotte 
    Http://WWW.HomeRecordingWizard.Com
    HTTP://WWW.Facebook.com/HomeRecordingWizard
    Http://www.mjlmusic.com 
    #4
    Beepster
    Max Output Level: 0 dBFS
    • Total Posts : 18001
    • Joined: 2012/05/11 19:11:24
    • Status: offline
    Re:Ouch email hacked! 2012/06/17 16:25:17 (permalink)
    Yeah... that'll do it. And I'm not 100% sure on this but I think having your passwords stored on your system is actually LESS secure then typing it in every time. Something about keyloggers being more difficult to install than other spyware crap. Also I'd get something better than Norton for your AV too. If you're gonna pay for an AV you'd be better off with Kapersky. However Avast and Microsoft Security Essentials are pretty much top of the heap as far as AVs go and their free version work great. Another really good way to keep things secure is to use Ad and Script blockers with your browser. That's where most of this junk comes from. I've been running NoScript and AdBlockPlus for years and I've never found anything malicious when scanning. AAAANNND one more thing is many viruses and spyware will actually target your AV software rendering it useless. Scanning in SAFE MODE (without networking) keeps those bad programs from getting a chance to start up and mess with your scan.
    #5
    Jeff Evans
    Max Output Level: -24 dBFS
    • Total Posts : 5139
    • Joined: 2009/04/13 18:20:16
    • Location: Ballarat, Australia
    • Status: offline
    Re:Ouch email hacked! 2012/06/17 17:35:16 (permalink)
    An expert once gave some advice about this and told me to never store any passwords on your system anywhere. (especially your bank details!) It might take an extra step to input them but it is well worth it. Hackers know where the passwords are stored and can easily get into those locations and find them out.

    Also take Jonbouy's advice and change the passwords regularly. I have never had any issues with this sort of thing. My main audio computer is not on the net (it can be if I want though) and I still believe that is the best policy. But my main office computer is, and I have found Microsoft Security Essentials to be pretty reliable and effective at keeping bad things at bay. It updates itself regularly and whenever I do either a quick or deep scan I never find anything bad.

    Also don't just poke anything a client may bring into your studio into your computer either. I have been caught on that one! I take drives or USB devices into the office machine and do a scan on the device before putting it into my main machine. I have often found things on there which would have been harmful and MSE can isolate and nuke them first. I also run MSE on my main machine but it is set to be off all the time. If I feel I want a backup even after doing the office scan, I can turn it on, update the definitions quickly and use it as a backup while transferring data from the client onto my drives etc..

    Specs i5-2500K 3.5 Ghz - 8 Gb RAM - Win 7 64 bit - ATI Radeon HD6900 Series - RME PCI HDSP9632 - Steinberg Midex 8 Midi interface - Faderport 8- Studio One V4 - iMac 2.5Ghz Core i5 - Sierra 10.12.6 - Focusrite Clarett thunderbolt interface 
     
    Poor minds talk about people, average minds talk about events, great minds talk about ideas -Eleanor Roosevelt
    #6
    slartabartfast
    Max Output Level: -22.5 dBFS
    • Total Posts : 5289
    • Joined: 2005/10/30 01:38:34
    • Status: offline
    Re:Ouch email hacked! 2012/06/17 20:01:51 (permalink)
    having your passwords stored on your system is actually LESS secure then typing it in every time

     
    The problem is that "saved" passwords are often accessible from the application that saved it once you have logged on to the computer. The various programs inherit their security authorizations from the user. So if you can use your email or web browser without entering a "saved" password, a trojan that installed itself under your account can usually do the same.
     
    Most email spamming is done by use of trojans setting up netbots, that will use your home computer to actually send mail on the accounts available to it. In that case the trojan will often use your home computer address book as a source, or sometimes harvest it to send more live email addresses to the botmaster. It is not clear in the present case if that was the method used, or if the actual email account was hacked at the server. In the latter case, the mail can be sent from another computer that is logging on to your compromised email account at the email server using a stolen password. It makes a difference in deciding if your home machine is compromised, or just your email account. If only your email account password was stolen, then all you need to do is change the email account at your mail providers site. If your computer is compromised, then you need to do a serious cleaning which may involve a re-install of everything in the worst case.
     
    Another possibility is that neither your computer nor the email account has been compromised, but that your email address is being used to spoof email from an unrelated source. Someone whose home computer includes your email address in its address book may have been compromised, and your email address harvested. From there the spammer just makes it look like the email came from your address.
     
     
    Keyloggers are a more sophistocated and labor instensive method of stealing a password, that the hacker can later use from his own computer to access your password protected online account. If someone has a working keylogger on your machine, he would be foolish to use it to steal an email account password and start spamming. He would wait for your online banking or credit card information and start sending himself checks or merchandise .
     
     
    #7
    Fog
    Max Output Level: 0 dBFS
    • Total Posts : 12302
    • Joined: 2008/02/27 21:53:35
    • Location: UK
    • Status: offline
    Re:Ouch email hacked! 2012/06/21 16:24:06 (permalink)
    someone either zombie'd your pc or spoofed your email address, thats why your getting the returned mail. Or if you access via browser the could have got passwords that way.  if you can see the header of the emails , it might point to where they are originating from the IP.

    you might wanna use spybot s&d also.. scanning in safe mode might find more also.. do that offline .. you'll find stuff like trojans that can't be find with your registry loaded up.

    assume your router has a decent firewall built in as well, as an extra layer.

    http://www.filehippo.com/download_spybot_search_destroy/

    but do a scan on your pc without net connection and safe mode with your av.. and maybe mcafee stinger..  but spybot will immunize ya browsers also.  
    post edited by Fog - 2012/06/21 16:27:19
    #8
    Jump to:
    © 2024 APG vNext Commercial Version 5.1