Jump to content

Hi everybody, So I have a issue.. I got a email from Microsoft on the 18th stating that my password was changed and it came from my IP address, well I didn't do anything at all. I need a recommendation for a good program that can keep my IP secure, I'm a noob with these kind of things and I figured I would ask a group that knows what they are talking about. Thank you 

Link to comment
https://linustechtips.com/topic/1283721-need-help-with-intruder/
Share on other sites

Link to post
Share on other sites

3 minutes ago, Electronics Wizardy said:

I probalby guess there is something like malware on your system, id probalby check for that first.

 

Do a anti virus scan on your system, and change your password.

 

And enable 2FA, thats the big one.

I have malwarebytes, and spybot, nothing shows up. for antivirus all I have is windows defender (I know its not that great). How do you enable 2FA? I'm not familiar. Thanks for the reply.

Link to post
Share on other sites

Just now, Deekith said:

I have malwarebytes, and spybot, nothing shows up. for antivirus all I have is windows defender (I know its not that great). How do you enable 2FA? I'm not familiar. Thanks for the reply.

Was this for your Microsoft account?

 

https://support.microsoft.com/en-us/account-billing/how-to-use-two-step-verification-with-your-microsoft-account-c7910146-672f-01e9-50a0-93b4585e7eb4

Link to post
Share on other sites

19 minutes ago, Deekith said:

The weird thing was I never got a email or phone check when it was changed.

are ya sure its from microsoft, could be phishing.

 

21 minutes ago, Deekith said:

Yes I have 2 step verification turned on. Phone number and email. 

Use a app like google authentactor if you can, its better than sms or email.

 

 

Link to post
Share on other sites

5 minutes ago, Electronics Wizardy said:

are ya sure its from microsoft, could be phishing.

 

Use a app like google authentactor if you can, its better than sms or email.

 

Yeah I'm pretty sure its from Microsoft. I attached a image of the email, it says it was done on Microsoft edge also which I don't use ever. And ill definitely check out that google authenticator. 

 

microsoft email.png

Link to post
Share on other sites

5 minutes ago, Electronics Wizardy said:

Yea that looks legit.

 

Im still guessing keylogger or simmilar, but there isn't too much to look for, if you can access your account, I wouldn't worry too much.

Is there a program I can get that will secure my ip? Like a VPN or something? (not sure if that would help). I can pay for anything, I just want my PC secure and I really don't trust the recommendations online.

Link to post
Share on other sites

1 minute ago, Deekith said:

Is there a program I can get that will secure my ip? Like a VPN or something? (not sure if that would help). I can pay for anything, I just want my PC secure and I really don't trust the recommendations online.

A VPN really won't help here. All the websites are already encrypted with https for emails now.

 

Id just make sure defender is enabled in defender, and 2fa is enabled for accounts, and id change all your passwords now.

Link to post
Share on other sites

7 minutes ago, Electronics Wizardy said:

A VPN really won't help here. All the websites are already encrypted with https for emails now.

 

Id just make sure defender is enabled in defender, and 2fa is enabled for accounts, and id change all your passwords now.

Oh yea Is changed all of them fast. If its a keylogger can't they get my passwords?

Link to post
Share on other sites

6 hours ago, Deekith said:

Oh yea Is changed all of them fast. If its a keylogger can't they get my passwords?

That is correct, if there is a keylogger is installed onto your PC the individual will be able to tell what you're typing

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to post
Share on other sites

3 minutes ago, Deekith said:

How so I get rid of a possible keylogger?

It is sometimes difficult because it can be masked as a legitimate software. I once had a keylogger on my PC and I had to reinstall windows. I formatted the SSD and I my other drives ( I wasn't taking any chances virus can have been on there as well) but I had my files and documents backed up.

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to post
Share on other sites

5 hours ago, Sir Asvald said:

It is sometimes difficult because it can be masked as a legitimate software. I once had a keylogger on my PC and I had to reinstall windows. I formatted the SSD and I my other drives ( I wasn't taking any chances virus can have been on there as well) but I had my files and documents backed up.

If you backup all your files, isn't there a chance you can backup the keylogger?

Link to post
Share on other sites

18 minutes ago, Deekith said:

If you backup all your files, isn't there a chance you can backup the keylogger?

I have more than one location for backups. I 

Have system called the 3-2-1 system. 

 

 

3-2-1-backup.gif

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to post
Share on other sites

If your password was changed and it wasn't you, how did you log back in?

 

If your password was the same as it was before, I'd be tempted to chalk this down to Microsoft sending you that e-mail incorrectly, because no way anyone could change your password to what it already was (how would they know what it was?), nor would there be any reason to do so if they could.

ASUS B650E-F GAMING WIFI + R7 7800X3D + 2x Corsair Vengeance 32GB DDR5-6000 CL30-36-36-76  + ASUS RTX 4090 TUF Gaming OC

Router:  Intel N100 (pfSense) Backup: GL.iNet GL-X3000/ Spitz AX Switches: Netgear MS510TXUP, MS510TXPP, GS110EMX
WiFi6: Zyxel NWA210AX (1.7Gbit peak at 160Mhz) WiFi5: Ubiquiti NanoHD OpenWRT (~500Mbit at 80Mhz)
ISPs: Zen Full Fibre 900 (~930Mbit down, 115Mbit up) + Three 5G (~1200Mbit down, 115Mbit up, variable)
Upgrading Laptop/Desktop CNVIo WiFi 5 cards to PCIe WiFi6e/7

Link to post
Share on other sites

1 hour ago, Alex Atkin UK said:

If your password was changed and it wasn't you, how did you log back in?

 

If your password was the same as it was before, I'd be tempted to chalk this down to Microsoft sending you that e-mail incorrectly, because no way anyone could change your password to what it already was (how would they know what it was?), nor would there be any reason to do so if they could.

If you look at the image I shared earlier, Microsoft told me that my password was changed and gave me the option "If this wasn't you, your account has been compromised. Please follow these steps" which I chose "reset your password". I tried to log back in using my password and it was incorrect. Also if your read the previous comments, a keylogger can get your passwords then log in and change it to whatever they want. The odd thing about this is I have 2 step verification and there was never a notification sent to my phone or alternate email. The same thing happened to me months ago with my Ubisoft account, that time it told me the country of origin which was Egypt. I also had 2 step verification on that account and I never received a notification in my email or phone. As to why it was done on my Microsoft account? I have no idea what they can steal, if its linked to the microsoft store cant they get your payment info? same with Ubisoft, I think they were trying to get my card details (luckily I didn't have any card details on both accounts).

ubisoft.png

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×