Could this be malware?


Recommended Posts

What does what browser you used to create a website account have to do with the site being compromised?  Use whatever browser you want that makes you happy..  You could of been using any browser, Doesn't matter how you got there or how you put the info into the sites db... Once the db has been compromised, if not properly secured by the site owner.. Then your info would be available to the people who gained access to the DB..

 

What the email said, and what is actually true are normally light years apart ;)

 

Post up this email - so we can see what it says... My guess its a cookie cutter spam/scam email that form filled in the info they got from whatever site was compromised.  That had your info in it - any of the 30 of them it seems.  Or it could of been from one that is not yet "known" to have been compromised.

This is the email in it's entirety:

 

Hey, I know your password is: (edited out)

Your computer was infected with my malware, RAT (Remote Administration Tool), your browser wasn't updated / patched, in such case it's enough to just visit some website where my iframe is placed to get automatically infected, if you want to find out more - Google: "Drive-by exploit".

My malware gave me full access and control over your computer, meaning, I got access to all your accounts (see password above) and I can see everything on your screen, turn on your camera or microphone and you won't even notice about it.

I collected all your private data and I RECORDED YOU (through your webcam) SATISFYING YOURSELF!

After that I removed my malware to not leave any traces.

I can send the video to all your contacts, post it on social network, publish it on the whole web, including the darknet, where the sick people are, I can publish all I found on your computer everywhere!

Only you can prevent me from doing this and only I can help you out in this situation.

Transfer exactly 1400$ with the current bitcoin (BTC) price to my bitcoin address.

It's a very good offer, compared to all that horrible ###### that will happen if I publish everything.

You can easily buy bitcoin here: www.paxful.com , www.coingate.com , www.coinbase.com , or check for bitcoin ATM near you, or Google for other exchanger.
You can send the bitcoin directly to my address, or create your own wallet first here: www.login.blockchain.com/en/#/signup/ , then receive and send to mine.

My bitcoin address is: 14qd4cN3HZ2ErMddV6QmWvE7mVUcGSBh1X

Copy and paste my address, it's (cAsE-sEnSEtiVE)

I give you 2 days time to transfer the bitcoin.

As I got access to this email account, I will know if this email has already been read.
If you get this email multiple times, it's to make sure that you read it, my mailer script is configured like this and after payment you can ignore it.
After receiving the payment, I will remove everything and you can life your live in peace like before.

Next time update your browser before browsing the web.

Mail-Client-ID: 4483923502

1 hour ago, adrynalyne said:

Ditto. 

I also can't see them.

1 hour ago, devnulllore said:

Ok I checked the  https://haveibeenpwned.com/  site and it says I have been compromised by over 30 sites and they want me to buy a password program. What can I do now? Should I notify my service provider?

Most people are getting flagged up there with something.

 

Off topic i use Lastpass.

Edited by SnoopZ
1 hour ago, devnulllore said:

This is the email in it's entirety:

 

Hey, I know your password is: (edited out)

Your computer was infected with my malware, RAT (Remote Administration Tool), your browser wasn't updated / patched, in such case it's enough to just visit some website where my iframe is placed to get automatically infected, if you want to find out more - Google: "Drive-by exploit".

My malware gave me full access and control over your computer, meaning, I got access to all your accounts (see password above) and I can see everything on your screen, turn on your camera or microphone and you won't even notice about it.

I collected all your private data and I RECORDED YOU (through your webcam) SATISFYING YOURSELF!

After that I removed my malware to not leave any traces.

I can send the video to all your contacts, post it on social network, publish it on the whole web, including the darknet, where the sick people are, I can publish all I found on your computer everywhere!

Only you can prevent me from doing this and only I can help you out in this situation.

Transfer exactly 1400$ with the current bitcoin (BTC) price to my bitcoin address.

It's a very good offer, compared to all that horrible ###### that will happen if I publish everything.

You can easily buy bitcoin here: www.paxful.com , www.coingate.com , www.coinbase.com , or check for bitcoin ATM near you, or Google for other exchanger.
You can send the bitcoin directly to my address, or create your own wallet first here: www.login.blockchain.com/en/#/signup/ , then receive and send to mine.

My bitcoin address is: 14qd4cN3HZ2ErMddV6QmWvE7mVUcGSBh1X

Copy and paste my address, it's (cAsE-sEnSEtiVE)

I give you 2 days time to transfer the bitcoin.

As I got access to this email account, I will know if this email has already been read.
If you get this email multiple times, it's to make sure that you read it, my mailer script is configured like this and after payment you can ignore it.
After receiving the payment, I will remove everything and you can life your live in peace like before.

Next time update your browser before browsing the web.

Mail-Client-ID: 4483923502

The email is bull...they got your password from one of the data breaches (beyond your control) ... not from the method they wrote in the email. 

 

Just change your passwords to sites that have been compromised ... and don't use passwords that have been compromised (such as the one you "edited out" ... why are still using that one?)  

3 hours ago, devnulllore said:

Ok well now I am just concerned about the browser I use. I use the latest version of chrome. How safe is Chrome in these circumstances? 

They didn't hack you; they almost certainly got the email and password from one of the hacked websites that you had signed up with.

 

As for your main issue (I haven't read all the comments): Take an HDD or SSD, backup anything important that is on it, now disconnect all the other ones, start a fresh windows installation (do not use a backup image), at the partition selection prompt delete all the partitions and then create new ones and install windows.

 

After the installation is done, do not attach any other internal or external drives, USB flash drives, etc. Once you boot into windows, download all the required drivers from scratch and install them. Update windows if you want to. Do not install any third-party software yet.

 

Now use your computer a bit, browse websites with edge. If it looks good download steam and install a game or two and see if it stutters.

 

If it does, then either one of the latest windows updates or drivers are causing an issue or your hardware is going bad; might even be a mainboard issue as one of the posters mentioned.

 

If it doesn't stutter, then gradually download and install the software that you usually use. Check your PC for stutters regularly. You need to find what triggers the stutter so don't install all the software in one go. (Make sure to download them; do not use any setup files that you already have on your drives.)

 

If after installing everything it still doesn't stutter, connect the other drives and check again. Tell us how it goes.

 

P.S. I know; it's a bit of a pain to spend so much time doing all that but sometimes you need to go with small steps and check as many variables as you can.

Edited by eddman

Dude those words are exact from the article I linked too about this sort of nonsense

"I collected all your private data and I RECORDED YOU (through your webcam) SATISFYING YOURSELF"

 

It's spam/scam garbage - deleted it an move on..

https://malwaretips.com/resources/i-infected-you-with-my-private-malware-rat-fake-blackmail-scam.277/

 

If your email was on 30 different sites that have been compromised - then yes I would adopt better password policies..

"Use different passwords for each site"

If you can do that on your own - great, if not look to password tools, many of which are free.. I am currently just using the lastpass free option.

Which will make it easier for you to use different passwords for each site, and complex ones.

 

edit:  I am a bit surprised your email host didn't block that as spam anyway.

Hi, I went back and changed as many passwords as I could ever remember but there is news. I have a buddy of mine I used to work with at RCN with who is a security expert. He came over and used a some sort of Linux boot disk to log into my PC. He said there were 2 instances of a RAT, some sort of Remote Access Trojan and he had to reinstall windows again to be safe. I told him my nephew uses my computer once or twice a week and he admitted he browses some porn sites, some he knows get blocked occasionally, but he circumvents the blockage and goes there anyway. Well If this is real or not I will find out soon enough. I will just be vigilant about the sites he goes to from now on. He also suggest I use an encrypted password manager like Lastpass does anyone use that? Is it good and safe? I trust my buddy but I also trust you all implicitly. Thanks again for all the help but just a side note. The windows lag is still there but I since the reinstall I am no longer crashing every 5 minutes. One thing my buddy notice is when the lag happens Windows Explorer pegs my CPU usage, and memory usage maxes out so it could not have been the Trojan that was causing the lag. I think I am going to have to open my PC and do a complete overhaul ie.. reseating all my cards, checking cables and overall cleaning out the system. I will report back after I do this.

8 minutes ago, devnulllore said:

Hi, I went back and changed as many passwords as I could ever remember but there is news. I have a buddy of mine I used to work with at RCN with who is a security expert. He came over and used a some sort of Linux boot disk to log into my PC. He said there were 2 instances of a RAT, some sort of Remote Access Trojan and he had to reinstall windows again to be safe. I told him my nephew uses my computer once or twice a week and he admitted he browses some porn sites, some he knows get blocked occasionally, but he circumvents the blockage and goes there anyway. Well If this is real or not I will find out soon enough. I will just be vigilant about the sites he goes to from now on. He also suggest I use an encrypted password manager like Lastpass does anyone use that? Is it good and safe? I trust my buddy but I also trust you all implicitly. Thanks again for all the help but just a side note. The windows lag is still there but I since the reinstall I am no longer crashing every 5 minutes. One thing my buddy notice is when the lag happens Windows Explorer pegs my CPU usage, and memory usage maxes out so it could not have been the Trojan that was causing the lag. I think I am going to have to open my PC and do a complete overhaul ie.. reseating all my cards, checking cables and overall cleaning out the system. I will report back after I do this.

Lastpass is awesome a few people in this thread have said they use this a few posts back,give it a try and also setup 2fa on your mobile phone with it.

Just now, BudMan said:

Well its very odd - because your email stated that he removed his RAT ;)

 

Right but my buddy says they always leave traces but can only be picked up through a boot environment other than Windows. I am not familiar with Linux too much.

I would still test the ram just to be on the safe side, I would also download a Linux distro or a Windows 10 PE and run it off a flash drive to see if you experience any of the freezes. This way you can rule out your entire windows 10 install instantly.

So esat stops you from running smartdefrag... but didn't help you with your rat infection ;)

 

Exclude it from your detection if you want it... But there is really zero use for that software... The built in defrag is more then sufficient... Maybe if you would stop installing every piece of software under the sun on your so called "clean" installs you could actually figure out what is causing your problem ;)

1 hour ago, warwagon said:

I would still test the ram just to be on the safe side, I would also download a Linux distro or a Windows 10 PE and run it off a flash drive to see if you experience any of the freezes. This way you can rule out your entire windows 10 install instantly.

Okie will do. Thanks

It would help more to break down the explorer.exe process and find out if it is the same process/dll causing your issue or if it is constantly changing.  Explorer.exe can call 1,000,000 other processes.  Task manager only reports on the main process.  You need to drill down further with resource monitor or process explorer.

 

Your computer is basically your patient, and you are the doctor.  Your patient told you it hurt in it's stomach....you need other tools to be able to dig into its stomach to see what the actual issue is.  You obviously can't remove the patients abdomen to stop your patient from hurting, you would kill them if you did.  What are you going to use to investigate further, or are you going to keep stuffing it with medication in hopes that the pain goes away or continuing to misdiagnose it?  Or chasing the maybes or could-be's from other doctors who have never seen this exact issue before but know that something like this has happened but their patient was just about dead vs your patient that isn't dead, is still breathing and functioning normally...

3 minutes ago, sc302 said:

It would help more to break down the explorer.exe process and find out if it is the same process/dll causing your issue or if it is constantly changing.  Explorer.exe can call 1,000,000 other processes.  Task manager only reports on the main process.  You need to drill down further with resource monitor or process explorer.

Good point. He may all want to take a look at shellview .. I created a thread about it back in the windows 8 days, because there was a shell hook Nvidia was using which was causing a freeze on every right click. I use d this program to disable it.

 

 

41 minutes ago, warwagon said:

Good point. He may all want to take a look at shellview .. I created a thread about it back in the windows 8 days, because there was a shell hook Nvidia was using which was causing a freeze on every right click. I use d this program to disable it.

 

 

yes, but that is still a shot in the dark.  The issue is, you don't know what is causing explorer.exe to spike.  Using this and randomly disabling crap is a crap shoot.  I am asking to drill down and see what is actually causing explorer.exe to spike and then if we need to find the utility to disable or uninstall the program or find some other way to inoculate it to permanently fix the issue utilizing tools that can do that....one of which is built into windows but doesn't go into as much detail as the other software by sysinternals.

 

Bottom line, no one here knows what is going on and everyone is shooting at the hip in hopes that issue is fixed.  Very few have offered any real troubleshooting steps or ideas, but many have offered guesses which is taking more time to accomplish vs finding root cause.  I even entertained the thought of reinstall, more so to help a struggling individual than thinking that it would actually solve anything. 

I finally found something although I am not sure it is much. After using Procmon I found the the process 'DasHost.Exe' was the process that was spiking. Does anyone know about this? Google states it controls communication between wired and wireless devices.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Beats Studio Pro wireless over-ear ANC headphones drop to their lowest price yet by Fiza Ali Amazon is currently offering the Beats Studio Pro headphones at their all-time low price. The Studio Pro use 40mm active drivers which are designed to improve clarity and reduce distortion compared to previous models, with up to an 80% improvement over the Beats Studio3 Wireless. A built-in digital processor adjusts frequency response to keep the sound balanced rather than overly boosted in any one area. They also include Active Noise Cancelling that adapts to your surroundings to reduce background noise along with a Transparency mode that lets outside sound in when you need awareness of what’s going on around you. Furthermore, the headphones support personalised Spatial Audio with dynamic head tracking as well as Dolby Atmos playback on supported content. Moreover, built-in voice-targeting microphones improve call quality. You can also switch between three sound profiles including Beats Signature for balanced music playback, Entertainment for films and gaming, and Conversation for clearer voice in calls and podcasts. Physically, they are designed to be worn for long periods without feeling heavy or awkward. The ear cushions use UltraPlush engineered leather while metal sliders allow you to adjust the fit. On the connectivity side, the Studio Pro use Class 1 Bluetooth for a stable, long-range wireless connection. There is also a 3.5mm input if you want to plug in directly, including use with in-flight entertainment systems. Controls are located on the headphones and include a "b" button for music and call control, a volume rocker, and a multifunction button used for switching listening modes, EQ settings, power, and pairing. In addition, the headphones offer integration with both Apple and Android devices. On Apple devices, they support one-touch pairing with iCloud-linked devices, hands-free Siri access, Find My tracking based on last connected location, and automatic software updates. On Android devices, they support Google Fast Pair, Audio Switch between compatible devices, and Google Find My Device tracking, with additional features available through the Beats app. When it comes to the battery performance, it is rated at up to 40 hours of listening time with ANC turned off, and up to 24 hours with ANC or Transparency mode enabled. A 10-minute Fast Fuel charge should provide up to 4 hours of playback. Finally, the headphones use a rechargeable lithium-ion battery and charge via USB-C. Beats Studio Pro Wireless Over-Ear ANC Headphones: $149.95 (Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • "lets you pause updates by choosing an end date, for up to 35 days" Wasn't it "indefinitely"?
    • Those extra reboots are related to the UEFI Secure Boot certificate update thing.
    • Hands on with the ProtoArc EM25: Affordable ergonomic mouse that focuses on the right things by Taras Buria ProtoArc is known for making all sorts of office products with a big focus on ergonomics and comfort. Its latest product, the EM25, promises a comfortable-to-use, affordable, and customizable mouse. We took one for a spin; here are our impressions. The ProtoArc EM25 is a $49.99 mouse, but right now, during Prime Day 2026, you can get it for just $37.99. Right off the bat, you can see that the EM25 is inspired by Logitech's MX Master lineup and the legendary MX Master 3/3S. Its shape and proportions are very similar, so for a person with large hands (right-handed person, mind you), the EM25 is very comfortable to use. The mouse fills the palm, and the thumb rests on a small extension, giving your wrist a small tilt to reduce strain. The mouse is made of black plastic without any coating, eliminating long-term wear concerns. However, I can see the main buttons and other areas you touch the most getting polished over time. Despite its size and bulk, the mouse is not too heavy. It weighs about 100 grams, which is significantly less than the MX Master 3S and its successor. It is no lightweight gaming mouse by any means, but it is not excessively heavy like the MX Master 4. The EM25 has a built-in storage for its USB dongle. It is a cleverly made magnetic flap that you open by simply pressing on it. Next to the flap, you will find the on/off switch, the 1,000 Hz sensor, and a DPI button (up to 8,000 DPI). I find the DPI button location a bit odd, and I would prefer it somewhere below the main scroll wheel. Still, given that I never change DPI on my mice, I will let it pass. What is more important is that, unlike MX Master 3/3S/4, the device switch button is located below the left-click button, which allows you to switch devices without lifting and flipping the mouse. For a multi-device setup, this is a perfect solution: the button does not require too much effort to use, it does not get in your way, but it is also easily reachable with your thumb. The main scroll wheel has two modes: ratcheted and free-flow. You can only change between them with a bright orange button (I like this little touch of color), which is sprung and requires some effort to press. The wheel is dead-silent in free-flow mode, but ratched is quite loud and stiff, perhaps even too much to my liking. I can hardly call it deal-breaking, but it will certainly take some time to get used to. The side scroll wheel, it is notched, silent, and pleasant to use. Next to it, you can find a piece of glossed plastic with connection indicators: Dongle, Bluetooth 1, Bluetooth 2, and the low battery indicator. By the way, the built-in battery is rechargeable via a USB Type-C cable, which is included. It is sleeved and has an orange velcro strap to keep it tidy. After using the EM25 for a few weeks, I can say that its main buttons are my absolute favorite. They have very pronounced clicks, which feel great with just the right amount of force required to register a press. I would say they feel like something in between regular mouse clicks and silent ones. You can hear and feel the springy switch, but it is not sharp or loud to the point of annoying you. As for back/forward and device switch buttons, they are very clicky and quite noisy. Unfortunately, there are no extra buttons that you can map to specific things like in the MX Master lineup. Besides great primary clicks, another thing I like about the EM25 is its 1,000 Hz sensor. In the world, where Logitech still uses 125 Hz sensors in $100+ mice, seeing a much faster sensor in a mouse that costs three times less is very refreshing. Also, all the settings and customization you make are stored on-device, and you do not need to install any software. Just open the web-based app and change all that you need. Speaking of customization, you can remap what buttons do, adjust the DPI, and the sensor speed. Sadly, gestures are not supported, but you can still map pretty much anything to each button, including shortcuts, media buttons, and more. I also recommend using software like XMouseControl, as it will let you remap the side scroll wheel. At the end of the day, the ProtoArc EM25 is a great mouse. Clearly inspired by the MX Master lineup, it takes the best of it and complements it with a much more wallet-friendly price tag, significantly better sensor, on-device memory, a built-in storage for the dongle, and more (it fixes everything that I complained about the MX Master 4 recently). And for only $37.99 during Prime Day, the EM25 is an easy recommendation. Buy ProtoArc EM25 mouse - $37.99 | 24% off with Prime As an Amazon Associate, we earn from qualifying purchases.
    • Pretty nice tool, thanks
  • Recent Achievements

    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      460
    2. 2
      +Edouard
      161
    3. 3
      PsYcHoKiLLa
      110
    4. 4
      Michael Scrip
      81
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!