Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Windows Live

March 12th, 2010, 17:21 GMT · By

Malware Responsible for New Windows Live Hotmail Hijackings

SHARE:

Adjust text size:


Windows Live Hotmail
Enlarge picture
Microsoft has warned customers of its free email service of a new wave of hijacks that is targeting Windows Live Hotmail accounts. According to the Redmond company, attackers use hacked Hotmail accounts in order to send spam to all the people in the victims’ contact list. Rob Margel, working in Windows Services and Content team in the UK, revealed that he was informed of the issue internally, but also pointed to an entry published on the Windows Live Solution Center, offering new details about the hacked Windows Live Hotmail accounts.

“Hotmail is seeing instances of accounts being ‘hijacked’ by spammers who send emails out advertising an electronics website. The spam mails usually have subjects like ‘Good shopping good mood’ and may go to your contact list in addition to a random list of emails. Indications that this is happening to you may include you being required to match the characters in the picture (to verify that you're a person and not an automated program) to send mails when you reach your limits,” Margel explained.

According to Microsoft, there are a number of symptoms that can be used to diagnose whether a specific Hotmail account was hacked. The Redmond company revealed that victims of hijackings typically saw deleted contacts and the safe sender's list removed. In addition, the settings of the account are changed with the Deletion of Junk messages set to “Immediately” and the Junk Mail Settings to “Exclusive.”

“The last symptom would prevent messages from being delivered to your Inbox,” Microsoft informed. “Some of the other account settings that might be affected by this issue are your Vacation reply and Signature.”

The software giant explains that spammers that have hacked Hotmail accounts don’t lock the legitimate owners out, but instead share the account with them. In this context, some users might find it very difficult to tell whether a third-party also has access to their account.

“Hotmail believes that this may be due to a virus on a computer that you have used to login to Hotmail at some point in the past. If you login and see in your ‘sent items’ folder mails that you haven't sent, or receive Non Delivery reports (NDRs) in your inbox, we recommend that you scan your computer for viruses and malware using a reliable Antivirus product. Once your computer has been cleaned, immediately change your current password to a ‘strong’ password,” Microsoft advised.

The company has so far failed to reveal which piece of malicious code is in fact responsible for the new hijackings of Windows Live Hotmail accounts.

TELL US WHAT YOU THINK:

31,112 hits · 33 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Windows Live Messenger Anti-Spim Victory for Microsoft

March 2010 Security Release ISO Image Available for Download

Windows Azure platform AppFabric Commercial Availability on April 9, 2010

$250 Off, Visual Studio 2010 Pre-Orders Now Live

Windows Azure platform AppFabric Billing Preview Now Live

READER COMMENTS:


Comment #1 by: patrick kitts on 26 Mar 2010, 11:44 UTC reply to this comment

I'm also a victim. However, in my case the hacker has been sending 2 different emails to all of my contacts describing 2 implausible scenarios. In both versions I am stranded in Great Britain. According to the first email, I've been the victim of a robbery in which I've lost all of my ID, credit cards and cell phone and am asking for funds to be sent. A second email,also soliciting funds, claims that the hotel I'm staying in was invaded by robbers, who stole the belongings of all the guests, disabled the phone lines to prevent outside communication, and that the hotel was threatening to have me arrested for nonpayment of my bill. My impersonator goes on to explain that an internet cafe took pity on him and allowed him to use one of their computers. The thought crosses my mind that if this really were me, I might be reluctant to pay my bill in consideration of the shoddy security this hotel provides for its guests!

Comment #1.1 by: Di on 01 Jan 2011, 01:13 GMT

Are you even in Great Brittain?


Comment #2 by: Dan on 20 May 2010, 13:05 UTC reply to this comment

I hate Microsoft! it is their responsibility to keep my email safe, but now its all screwed. Someone went into my mail and changed the password. I cant even contact support of hotmail.

I will never buy anything from Microsoft again, nor use their applications.
Go Apple!

Comment #2.1 by: shigis on 12 Jul 2010, 08:45 GMT

Dear fellow-sufferers, I have got the same problem. Somebody has hacked into my hotmail-plus-account and is sending the "I'm writing this with tears in my eyes ..." scam to all my friends and contacts. I have no access to my account. I reported the fraud to the police here in Vienna/Austria but my real problem are this hotmail- or Windows- or Microsoft-People. I have writen almost a docen e-mails and filled in forms and what not and all that happens is that I get into a kind of loop where the autogenerated answer "unfortunately we cannot help you" or "we have no solution to your problem" or "Unfortunately, we are unable to assist you" and so on.
I even phoned a Number in Gemany (they have no service-number in Austria) but all what they said is "report to the police" and "use windowslivehelp.com".
Using the search-machines I have found out that there are hundreds or probably thousands of victims to this hijacking.
Meanwhile I am so frustrated that I curse Bill Gates and all his employes.
The only solution I can think of is to withdraw the money I paid for the hotmail-plus-account ...
In another website I learned that the crooks of this scam are sitting in Nigeria. They are very save in this country. All we can do is send them some very strong juju- or voodoo-curses while they are laughing at us ...

Comment #2.2 by: Cindy on 29 Jul 2010, 00:26 GMT

Yep. Now it's not just 'sharing' your email account and sending spam about electronics. I pay for the 'Plus' account and just got hit with the hacker that changed my password, locked me out, harvested my contacts and sent emails that I was stranded, robbed and needed money etc. etc. The Windows Live Help Forum has literally hundreds of people with the same complaint. The only answer they are getting is to re-set their password, go through a validation process...the usual runaround. My computer is OVERLY protected and I've run close to 10 different scans with no results. This is a Microsoft security problem. It was too easy to compromise hundreds (or more) of accounts in a couple of days.


Comment #3 by: chongman on 23 May 2010, 13:06 UTC reply to this comment

Yep, my paid hotmail account was hacked last night,bunch of spam sent to my contacts ;(
Poor security from such a big time company. I'll NOT be renewing my hotmail account when they come asking for the 20 bucks!


Comment #4 by: Ben on 24 May 2010, 15:03 UTC reply to this comment

It's a tough call.

Blame microsoft for writing a horribly buggy OS with an even more buggy and security flawed browser?

Or the user who simply can't know this if they live on Planet Earth because of all the public reporting of these problems who INSISTS on using Internet Exploder which ALLOWS the malware on their machine which ALLOWS the hackers to get their login credentials.


I've been using MS OS w/non-MS Browsers since I could get on the internet with MS Windows.
Never a problem.

My sister, against all my advice, would always INSIST on using IE because learning a new browser was "too hard".

When she got her first virus (didn't take long) I told her my free advice wasn't enough for her. She needs to PAY someone to come fix her computer and maybe that invoice will convince her IE is not the tool to use when roaming the internet.


Comment #5 by: Joe on 11 Jun 2010, 11:57 UTC reply to this comment

I don't think this is a malware/virus situation. My wife has this problem and over the past month several of my other friends too. I've been getting these "shopping" spam emails from all of them. I've scanned my wife's computer - she has continues virus/malware protection running all the time but I ran some additional scans - and came up with nothing.

I think there way some security breach at MS on the server side that allowed someone to get to people's contact lists. Then they are simply emailing to that contact list.

You don't have to "log in" to someone's hotmail account to send email from their hotmail address......the spam's coming from my wife's email to me were actually sent from somewhere in indonesia.


Comment #6 by: lisa on 12 Jun 2010, 00:42 UTC reply to this comment

It is interesting why they haven't release what kind of malware does this... The antivirus/antispyware that I rent out from Microsoft cannot find anything wrong in my computer!

My account has been hacked, or otherwise compromised. My contacts, kept since the 90's have been deleted and lost very important emails. I am still trying to recover. As I try to add contacts Messenger says that my contact list is full (i was able to add only 5!)

I pay a monthly fee for protection and extra hotmail storage. I would have expected more support....


Comment #7 by: Karin on 21 Jun 2010, 16:14 UTC reply to this comment

This just hit my account yesterday.

I'm spending today cleaning up the mess, apologising, etc. and trying to do damage control. If Microsoft cancel my e-mail due to supposed misuse, as some others have found, I would be in real difficulty. I use my paid MSN Hotmail account (had it for over 10 years) for professional and personal use, and really depend on it.

I am currently doing an intensive full scan (quick scan found nothing) using Microsoft's own recommended app, but I don't expect to find any supposed malware on my PC drives.

I suspect that the problems are on the MSN servers, as that is the only place where my Contact List is actually stored.

Maybe someone is trying to warn us about the risks of Cloud Computing... storing everything in Cyberspace (someone else's servers basically) doesn't seem so reliable anymore.


Comment #8 by: theresa price on 29 Jun 2010, 16:34 UTC reply to this comment

Like Karin, I went to send apologies emails this a.m. once I realized what was going on. But guess what... NO CONTACTS!

The original spam msg says, "hey Just received my Apple MC226LL/A MacBook Pro core 4gb from this homepage , www.xxxxxxxxx.com It's so cheaper but genuine , I like it very much ,I paid it $740US couier charges included , They have some other products. If you want to get one. you can check it out .

In addition to my contacts being deleted, also empty now are my folders: inbox, sent items, drafts and even the deleted items folder is gone!

Does hotmail have a way to restore this lost data?


Comment #9 by: SteveUK on 13 Jul 2010, 10:33 UTC reply to this comment

And another unfortunate victim here. Mine seem to originate from Slovakia though if the X-originating-IP address is to be believed.

I've checked my machines, nothing found on them, not even on the only computer I had on at the time the emails were sent.

I've changed the password and as far as I can tell, there's been no other 'damage' to my account.


Comment #10 by: matt on 19 Jul 2010, 08:51 UTC reply to this comment

I have just had the same thing happen. Can't find any malware on my machine though. What the hell is going on?


Comment #11 by: Tony on 22 Jul 2010, 03:52 UTC reply to this comment

All my contacts!
Same thing here too and I hardly use this account so I know hotmail was hacked! Why is it not all over the media? Google was all over the news when some people from China got in there, why not MSN? Microsoft disapoints me all the time! I ordered an iPhone despite the problems and will not use Microsoft again.
My hack sent links from two countries; Guernsey and East Timor but who knows. We'll never know why from this crap Corp.


Comment #12 by: Chris on 27 Jul 2010, 09:54 UTC reply to this comment

Same thing happened to me, and I know it's not my computer because I just bought a new one 4 days ago!!

I had this problem on hotmail with the last one, but the computer was old and needed replacing anyway. So bought the new one, added my AV programme, orgainised all my settings and then logged into hotmail.... Suprise, spuprise, emails sent to my contacts about some "GREAT BARGAINS" for sale. I have updated my AV programme, changed hotmail password, using virtual keyboard to log in, fixed all the settings to what AV told me, Vulnerability Scan, full deep scan 5 times, everything on my computer needs permisson to to anything now!!! and still haing problems with hotmail!!!

Come on Micorosoft and get your finger out, stop passing the buck and start doing something other else will go to Yahoo or anywhere else. Not a computer geek, like most people so this means that you need to start giving us advice and help!!

P.s. My pasword was a combi of letters, numbers and symbols and over 20 char long. So not a 'weak password'


Comment #13 by: Kyra on 29 Jul 2010, 22:51 UTC reply to this comment

I realised that my free hotmail account had been hacked last night, a message was sent to all my contacts about a cheep IPhone they could get from a company called ele. I changed all my passwords on everything etc, but today have found I am locked out of hotmail as my account has been 'attempted incorrect password access', this is the first time I have tried to go on today! I have tried to get on with my new password and have been asked to match some letter/number characters but still can't get into hotmail!!!! I don't know what to do now.


Comment #14 by: Michelle on 08 Aug 2010, 01:53 UTC reply to this comment

This just happened to me as well. According to the IP search it originated from Argentina and I live in NJ. It is not possible that anyone has my password and is doing this to me maliciously. The hacker sent a pharmacy related email from my account to all my contacts with no subject in the subject line. Oddly enough, this also happened on my Yahoo account. I've scanned, re-scanned and downloaded an extra program to scan with that and nothing at all has shown up. It's very frustrating. I don't feel safe and don't think these companies are taking their security very seriously. I wish the media would get wind of this and blow it up because the more I research the issue the more I see I am not alone. Apparently this has also happened with Gmail users as well, which I found out right after I opened a Gmail account. On the free front what's left? I feel badly for people who have paid for these services (Hotmail, Yahoo, etc.), that would make me even more angry.

Comment #14.1 by: Cristina on 27 Aug 2010, 22:43 GMT

Hi Michelle, My fiancee has had this going on for months, too! We've tried scanning with different anti-v software, and nothing is found. They're the EXACT type of emails you're describig: no subject, and links to some phamaceutical companies. All have come from anywhere from Indonesia, South America, Russia, the last one today came from Canton, Ohio. Have you had any luck regaining control of your hotmail account? Has anyone here?


Comment #15 by: Maywilson on 10 Sep 2010, 20:08 UTC reply to this comment

My hotmail account has been hacked.
This fraudster has sent email to all my contacts asking for money. So far I have found out this friend of mine had
sent money to this Fraudster...


Comment #16 by: KLAbe81 on 03 Nov 2010, 20:42 UTC reply to this comment

I was wondering why at certain times Google asks if I want my hotmail translated from Indonesian to English despite it being MY hotmail account.
Do you think someone is circumventing my email to Indonesia?

Comment #16.1 by: GremmieJD on 01 Dec 2010, 23:24 GMT

Either that or Google knows that your native language was Indonesian some how...


Comment #17 by: Anon on 26 Nov 2010, 01:47 UTC reply to this comment

I bet there is not a "virus" but that Hotmail has been compromised.


Comment #18 by: GremmieJD on 01 Dec 2010, 23:23 UTC reply to this comment

In the last week, I personally know five people (including myself) that have had accounts hijacked. In my case, it was an account I rarely used. This is very UNLIKELY a virus issue and MORE LIKELY an issue with Microsoft's lax security. I've since cancelled my account and recommend anyone else that has had an account hijacked do the same. Good luck.


Comment #19 by: jay on 13 Dec 2010, 18:04 UTC reply to this comment

i'm not sure if my hotmail account has been hijacked into or it was a virus (i use a mac so i don't have an anti-virus software, yet). i received several postmaster delivery failure notices and saw those emails that i 'sent'. also, all my emails sent in december has been deleted from the sent folder. i mean could it be someone manually deleting them? it seems more like that than a virus to me.


Comment #20 by: Double T on 29 Dec 2010, 19:15 UTC reply to this comment

Hacked account. Changed my password, alternate e-mail and security questions. The recovery page request this infomation to reset your password, how the heck can you do that if you don't know what it is due to the hackers changing all information? Microsoft needs to publish a page where you can discuss online "in a private forum" the hacked account.. Then reset our passwords. Since we have no idea what the hackers change our information too.


Comment #21 by: Fanfaron on 25 Mar 2011, 15:45 UTC reply to this comment

This has been happening to me for over a year and HOTMAIL does not respond.


Comment #22 by: Gregory on 26 May 2011, 10:02 UTC reply to this comment

It's out of Microsoft's hand now. They screwed up big time by not keeping their email safe years ago. Now this problem is wide spread. This 'send to everyone in my contact list' problem most likely DID NOT originate from you!

Ask yourself this question,

"Do I receive emails from anyone with a Hotmail account that may have a virus on their computer?"

Problem is this has spread like wildfire. Anyone that has you in their contact list, once they log into hotmail, a virus bot grabs their contact list and guess what? You get an email stating this and that sent to EVERYONE in their contact list which includes YOU! If you open up this email sent to you, guess what? They now have your contact list WITHOUT a virus on you computer. Some hole in Microsoft’s Hotmail is wide open.

Resolution?

Send a blanket email to all your contacts on Hotmail, apologize and tell them you will be closing down your Hotmail account! I suggest you then STOP using Hotmail!
This cannot be stopped. Once ‘they’ have your email address, it’s over. You will continue to receive this bot email so they can update their records with your contact list.

Suggestion?

Don’t open any email comine from a Hotmail extension and stop using you Hotmail account.

Why?

Microsoft doesn't care!


Comment #23 by: John Greathead on 07 Sep 2011, 16:03 UTC reply to this comment

My hotmail seems to have a slightly different problem. My account seems fine, though when I email friends, they find a totally different email address in the 'to' box after clicking reply. How can this be? Also, one of my friends, involved in our group email conversation, found a spam email in his junk email, from a totally random email address, which contained part of the email conversation that we'd been having, at the bottom. Does anyone have any idea on this at all? I can see no out-of-the-ordinary emails sent from my account, and I seem to have all my contacts still. Any ideas? There's something wrong here, but nothing that fits the profile of anything listed below...


Comment #24 by: antihackers on 16 Sep 2011, 13:50 UTC reply to this comment

I'm using MAC! no virus. means it's not because of MY laptop. it's just that MICROSOFT SUCKS

Comment #24.1 by: Mo on 15 Oct 2011, 04:42 GMT

im using mac as well. and my hotmail has been hacked. it´s sending out e-mails to all my contacts. and my account got automatically blocked. And no where to be found an answer


Comment #25 by: samting on 11 Nov 2011, 02:05 UTC reply to this comment

Got me, seems to be a couple of different messages. Changed password etc. I have a new appreciation for the max 25 posts per day rule, and now I know all the email addresses that should get removed from my contacts list.


Comment #26 by: Dai on 07 Dec 2011, 21:14 UTC reply to this comment

Hotmail should provide support rather than DUMP you on their community group to search for information.
Hotmail should protect their members and support them !!


Comment #27 by: jdg on 02 Feb 2012, 19:44 UTC reply to this comment

I noticed today, 2/2/2012 in my hotmail email account that there are two contacts which I did not put there. They only surface when I hit the To: button to pull up the email address of one of my contacts. They are not listed in the actual contacts' list itself. Can you help me to delete these two entries? Thank you for any help which you can provide in this matter? I have had a free email for many years without any major problems until I noticed this today. Thank you.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM