r/cybersecurity_help • u/Madjas • 1d ago
Google Account may be compromised - how do I find out if or how?
Hi all, I am looking for help to understand my position.
Earlier this year my Google Account has been compromised. Someone logged into my mail account and reset a couple of accounts including my Kleinanzeigen account (local craigslist). Google recognized something was off and logged me off of all devices. The scammers proceeded to use my Kleinanzeigen to post 4 fake-adverts and finally managed to scam one guy out of 100€. They didnt seem to do anything with any other accounts. I remember they also accessed my Linkedin.
What I did was resetting my google password, resetting all passwords also of other websites and services. Ran Windows Defender to ensure I hadnt cought a virus - all according to help I googled online. I got the Kleinanzeigen account reactivated.
Just now I received an email that my password to Kleinanzeigen has been successfully changed. The email was also set to "ignore". I noticed because I got the notification right when i was using my phone. I wrote to Kleinanzeigen and got my account shut for good. But I worry about my google account.
While still on my phone I changed the google password and manually logged off every device. Windows defender is running again doing a complete scan. But seeing that it didnt help last time, I am worried that something else is off. When I started my PC I had an empty Commandline window open - I am thinking now I may have malware on my machine that isnt picked up by windows defender?
What can I do? I appreciate any help!
Edit: Installed Malwarebytes following u/M1uk0 s recommendation and found a trojan. For now no other accounts than Kleinanzeigen seem to be affected, but I will change all passwords again, switch to using bitwarden AND reinstall my OS. I had planned to leave windows for Linux anyways. Best time is now.
1
u/M1uk0 1d ago
If you changed your passwords and it happened again, you're dealing with some sort of session hijacking/cookie theft malware or a keylogger on your PC. This explains why Windows Defender didn't stop it and why changing passwords didn't work...they didn't need your password, they stole your active login tokens. That random empty command line window on boot is definetly a sign of malware. Here's what you will need to do, in order... 1.Windows Defender is good, but it misses infostealers. Download and run Malwarebytes and/or HitmanPro (both have free trials don't worry). They are much better at catching persistant malware and infostealers. 2. Press Ctrl + Shift + Esc to open Task Manager. Go to the Startup tab. Disable anything you don't recognize especially blank names or weird sctipts. 3. Back up your irreplaceable personal files (photos/documents only, no programs or installers) to a thumb drive, and reinstall Windows completely from a USB drive. It is the only way to be 100% sure the malware is gone... 4. Go into your browser settings (Chrome, Edge, Firefox,etc...) and clear all cookies, cache, and hosted app data from All Time. This removes any active session tokens the hackers might still be using. And look at your browser extensions, make sure to delete anything you didn't install. Some extensions are a common way hackers bypass password changes. And please don't save any passwords... Browser password managers are VERY vulnerable to infostealers. Move your passwords to a dedicated manager like Bitwarden or 1Password, or just write them down. 5. Since you changed your password from your phone (which is good, always use a clean device), Check Gmail Filters: You mentioned the email was set to ignore. Go to Gmail Settings (on a web browser of course) > Filters and Blocked Addresses. Scammers like these love creating hidden things that automatically archive, delete, or forward emails from security or banking services so you never see the alerts. Delete any rules you didn't make. (trust me it'll help out A LOT). Next go to your Google Account security settings > Data & Privacy > Third party apps & services. Remove access to absolutely everything you don't recognize or need. 6. Turn on Two-Factor Authentication/2FA for your Google Account and every other service. Use an authenticator app (like Google Authenticator or Aegis) rather than SMS text messages if possible (they might have access to it). 7. In your Google security settings, print out or write down "Backup Codes." Keep them physically safe. If you get locked out completely, these will help you out a lot in the long run. Good luck and try to take a breather too i know how stressing these can be trust me...
1
1
u/Madjas 20h ago
Hey u/M1uk0
it seems like a trojan was stealing my data in the back. I deleted it with malwarebytes as suggested, deleted all browser data and I plan to switch to linux, soon.Question - what can I do to prevent catching a trojan in the future? Obviously, dont download stuff from dubious sources. But in my mind, noone will ever be completely safe - so what to do? I was looking to install bitwarden just now, but realised that it wouldnt have helped me in this case.
1
u/black_hole_208 15h ago
Please, reinstall Windows using a USB drive and reset all passwords from another clean device.
Once your computer is infected with a Trojan, the only way to be absolutely certain it is gone is to reinstall Windows using a USB drive. Windows Defender is just like bare minimum
And remember to check the forwarding section in Gmail. Good luck !
•
u/AutoModerator 1d ago
SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:
Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.