Question:
Are there other malware steps I should be taking?
?
2013-01-26 23:17:07 UTC
My password was apparently hacked on my Answers account. Here's what I know:

I had a returned e-mail to my account for some diet pills that I did not send. It was also sent to everyone in my Yahoo address book (fortunately there are only four email addresses there.) I got a notice from Yahoo that my account was accessed from a mobile browser in a place not normally associated with it: Iran. Yikes. Then it was accesses again via a web browser from Austria. Again, yikes!

I've changed the password, but suspect a key-logging program. I swapped files via a USB drive yesterday, and so that seems highly suspect. I downloaded and burned a Kaspersky Rescue Disk image, booted from that CD, updated its virus definitions, then ran a full scan. All clear.

Am I missing something? What else would you do in this situation?
Four answers:
anonymous
2013-01-27 04:24:39 UTC
'Notice of unusual account access' indicating foreign countries might be misleading in some ways.

Hacking source can be obfuscated by using a proxy service, so in reality, the guy next to you in a Starbucks (for instance) could have done it.

"Steve..." is partly correct: if you use(d) a hotspot, your Y! authentication cookie could have been slurped.

Counter-measure for that:



[My OC; posted 12-21-'12]

Yahoo finally got the message and moved mail to SSL (secure) servers, however, it must be manually set to do so all the time.

To take this essential step, in Yahoo Mail, cursor over the upper right 'gear'> Mail Options> General tab, near the bottom, check the box "Make your Yahoo! Mail more secure with SSL"> tick "Save" near the top.

Your browser should then be accepting the Certificate for "mail.yahoo.com", and whenever you connect to it, there will be the address pre-fix 'https'. Always look for that.



This step is absolutely critical if you ever use a computer (or any smartphone, tablet, etc.) in a mobile situation, like at a "hot spot" cafe, library, or anywhere really.

And likewise Home units should make the adjustment.

Firefox, with "HTTPS Everywhere" will ensure this connection is always made.



SPECIAL NOTE!

This will not prevent account hijacks ENTIRELY: it only works when you "log-in" to Yahoo and go right to mail, then "log-out" from Yahoo. If you migrate to other Y! services while logged in, you will be dropped to normal channels and THAT is when your 'session authentication' cookie will be slurped, allowing someone else to log-in as you!

------------

Of course, if you use a PC on the 'Net, then nothing is out of the equation, such as keyloggers; and most A-V don't find those anyway. https://www.pcworld.com/article/2017197/report-declares-antivirus-software-a-waste-of-money-for-businesses.html



Best current solution? Use Linux for all Internet facing tasks. Keep your PC safely sequestered.
Insyde
2013-01-27 07:19:52 UTC
Try Doing A Scan With Malwarebytes Antimalware (Free) And Get A Firewall Zonealarm is a Good Free Firewall Also Spybot Search And Destroy Can Immunize You From Web Threats And Stop The Registry From Being Altered
Stupid X-Rays
2013-01-27 07:22:06 UTC
Malwarebytes Free



http://www.malwarebytes.org/products/malwarebytes_free/
anonymous
2013-01-27 11:05:58 UTC
Have you been on an unsecured wireless some where. I'd reformat my pc if that happened to me.

What firewall you using?


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...