Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security

Reply
 
LinkBack Thread Tools
Old 3 Weeks Ago   #1 (permalink)
Intel Overclocker
 
fball922's Avatar
 
intel ati

Join Date: May 2005
Posts: 390

Rep: 11 fball922 Unknown
Unique Rep: 11
Trader Rating: 3
Default To Catch a Hacker

Ok, here is the story.

My girlfriend broke up with her ex about a year ago. Things have been going fine between them (read: no contact) since then. Recently, she decided to clean up her facebook by deleting people from her friends that she is no longer in contact with, and he was included in that.

Shortly after that, she was getting randomly appearing "incorrect username or password" messages every so often. I didn't get to see them personally, but I think she took a picture of it that I will try to get up here. Anyway, they stopped appearing. It seems this was an error from NOD32.

Sometime after that there were some strange things happening to her laptop. First, her homepages in Google Chrome were changed (one of them was facebook...). She then later noticed that her Google Chrome icon was renamed from "Google Chrome" to "dr. jas", which happen to be her ex's initials.

I believe he was somehow viewing her desktop remotely. At first I thought maybe he had simply gained file-access, but she said not only had the shortcut name been changed by icons had been moved around the desktop. There was no way local access had been obtained by him or anyone else at that time as she locks her bedroom door (and he lives far, far away).

Her laptop runs Vista Home Premium. As such, it does not have Remote Desktop built in. I disabled Remote Assistance, in case there was some vulnerability there he was exploiting. I checked her Windows Firewall for any strange exceptions, and ran a virus scan to make sure there was no virus doing these things (which none were found by NOD32).

So, I guess I am asking if there is some known vulnerability that may be allowing here ex-boyfriend to get into her computer. More particularly, is there a way to find out if someone is in fact doing this to her? He may have her IP address... since they broke up, I know Time Warner (both of our ISP) has not changed my WAN IP address, so it is entirely possible her's has not either. I have looked for ways to log logins in the Event Viewer, but most solutions require the Group Policy editor, which Home Premium does not have.

Any thoughts or suggestions are very much welcome and greatly appreciated!!
__________________
Spelling mistakes in my post? I am probably typing on my iPod... Please forgive me!

Columbus, OH, area pc repair!

System: HOOOSIER!!!!
CPU
Q6600 @3.25ghz
Motherboard
Gigabyte GA-P35-DS3R
Memory
4x2GB G.Skill
Graphics Card
HD 4890 soon... X1300 for now
Hard Drive
400GB OS, 80x2 RAID-0 Apps, 640GB Storage
Sound Card
Audigy Something... Old
Power Supply
430w Thermaltake
Case
Antec 300
CPU cooling
Scythe Ninja w/ 120mm fan
GPU cooling
Stock
OS
Windows 7 Pro x64
Monitor
23" Samsung
fball922 is offline   Reply With Quote
Old 3 Weeks Ago   #2 (permalink)
Caseless
 
SilverPotato's Avatar
 
amd ati

Join Date: Feb 2009
Location: Atlanta, GA
Posts: 1,372
Blog Entries: 1

Rep: 90 SilverPotato is acknowledged by some
Unique Rep: 83
Folding Team Rank: 1328
Trader Rating: 9
Default

Here's what you should do... Set the laptop down in front of you and your girlfriend and watch it for a while... If anything happens indicating the ex's involvement give him a call... or better yet pay him a visit.

Then install XP/7 on it after a good DBANing ^.^
__________________
There is no spoon.

System: Fresh Air
CPU
AMD X2 7750 BE @ 3.2GHz
Motherboard
Gigabyte MA790X-UD4P
Memory
4GB OCZ Blade LV 1066
Graphics Card
XFX 4890
Hard Drive
Hitachi 1TB + VRaptor 74GB
Sound Card
ASUS Xonar DX
Power Supply
Corsair HX620
Case
HSPC Tech Station
CPU cooling
Xiggy
GPU cooling
Scythe Musashi
OS
Windows 7 Home Premium x64
Monitor
21.5" Asus WideScreen
SilverPotato is offline I fold for Overclock.net Overclocked Account SilverPotato's Gallery   Reply With Quote
Old 3 Weeks Ago   #3 (permalink)
First Time Build
 
dudenell's Avatar
 
intel nvidia

Join Date: Oct 2009
Location: Syracuse, NY
Posts: 268

Rep: 19 dudenell Unknown
Unique Rep: 18
Trader Rating: 0
Default

install avast and use their rootkit tool

System: First Build
CPU
i7-950 @ 4.14Ghz with 1.34375
Motherboard
EVGA Classified E760
Memory
Kingston HyperX 6gb (3 x 2GB)
Graphics Card
EVGA 295 017-P3-1296-AR 704 / 1536 / 1207
Hard Drive
Western Digital 750 GB HD 7200 SATA
Power Supply
Seventeam ST-850ZAF 850W ATX
Case
Antec 902
CPU cooling
Megahalems with 2 San Ace fans
GPU cooling
stock
OS
Windows 7 Ultimate 64 Bit
Monitor
Acer H233Hbmid Black 23
dudenell is offline   Reply With Quote
Old 3 Weeks Ago   #4 (permalink)
Intel Overclocker
 
fball922's Avatar
 
intel ati

Join Date: May 2005
Posts: 390

Rep: 11 fball922 Unknown
Unique Rep: 11
Trader Rating: 3
Default

Quote:
Originally Posted by SilverPotato View Post
Here's what you should do... Set the laptop down in front of you and your girlfriend and watch it for a while... If anything happens indicating the ex's involvement give him a call... or better yet pay him a visit.

Then install XP/7 on it after a good DBANing ^.^
Haha absolutely. I am currently toying around with writing a simple program that will log every login and alert me if any of them are remote (while capturing the IP address as well).

I will look at installing Avast on there. Thanks!
__________________
Spelling mistakes in my post? I am probably typing on my iPod... Please forgive me!

Columbus, OH, area pc repair!

System: HOOOSIER!!!!
CPU
Q6600 @3.25ghz
Motherboard
Gigabyte GA-P35-DS3R
Memory
4x2GB G.Skill
Graphics Card
HD 4890 soon... X1300 for now
Hard Drive
400GB OS, 80x2 RAID-0 Apps, 640GB Storage
Sound Card
Audigy Something... Old
Power Supply
430w Thermaltake
Case
Antec 300
CPU cooling
Scythe Ninja w/ 120mm fan
GPU cooling
Stock
OS
Windows 7 Pro x64
Monitor
23" Samsung
fball922 is offline   Reply With Quote
Old 3 Weeks Ago   #5 (permalink)
nVidia Enthusiast
 
Greensystemsgo's Avatar
 
intel nvidia

Join Date: Apr 2006
Location: Phoenix, ARIZONA!!!!!!
Posts: 971

Rep: 75 Greensystemsgo is acknowledged by some
Unique Rep: 66
Trader Rating: 0
Default

ya safest bet at this point - reformat.
__________________
MY FOR SALE THREAD

System: My Machine
CPU
Q6600 G0 @3.1ghz 1.25v
Motherboard
EVGA 680i SLI
Memory
4gb Gskill @ stock clocks
Graphics Card
Geforce 8800gts - 640mb/320bit
Hard Drive
seagate 160gb, hitachi 1tb
Sound Card
on board HD
Power Supply
CORSAIR 750w
Case
Antec900 - custom wire mgmt
CPU cooling
Rosewill
GPU cooling
Stock
OS
win7 rtm x64
Monitor
19" LCD hd 720
Greensystemsgo is offline   Reply With Quote
Old 3 Weeks Ago   #6 (permalink)
Overclocker in Training
 
king_play334's Avatar
 
intel nvidia

Join Date: May 2009
Location: Brampton, ON, Canada
Posts: 561

Rep: 46 king_play334 is acknowledged by some
Unique Rep: 36
Trader Rating: 0
Default

reformat the HDD, don't keep any files, change all passwords. Hes probably using a R.A.T (remote admin tool) to gain access to the computer. Its like remote assistance in windows. Im not going to say what softwares can be used to infect people with R.A.T but its pretty easy. about 30% of all R.A.T's are FUD so that's why NOD32 isn't picking anything up.
__________________

Savings for Custom Case & Liquid cooling Project: $100.

System: The beast.
CPU
Intel Q6600 Core 2 Quad at 3.0GHz
Motherboard
XFX 780i FTW
Memory
8GB OCZ SLI-Ready
Graphics Card
BFG Nvidia Geforce GTX 280 OC SLI
Hard Drive
500GB WD Caviar, 1TB SG Barracuda, 1TB External
Sound Card
onboard 7.1
Power Supply
1000Watt OCZ Pro-X-Stream
Case
Antec 1200 full tower gaming case
CPU cooling
Thermaltake Ruby Orb
GPU cooling
Stock Cooling
OS
Windows 7 Ultimate X64
Monitor
LG 23" Widescreen LCD Monitor 1080p
king_play334 is offline   Reply With Quote
Old 3 Weeks Ago   #7 (permalink)
LTC
Audiophile
 
intel nvidia

Join Date: Jul 2007
Posts: 303

Rep: 5 LTC Unknown
Unique Rep: 5
Trader Rating: 0
Default

Call the police, this is highly illegal, and should be taken care of, right away!
__________________
System: Quicky
CPU
Core 2 Duo E6600 @ 3GHz
Motherboard
ASUS P5N-E SLI
Memory
Corsair XMS2 2x1GB
Graphics Card
Inno3D 8800GTS 320MB
Hard Drive
2x500GB Samsung spinpoint
Sound Card
Creative X-Fi Extreme Music
Power Supply
Corsair 520W
Case
Lian-li PC-v1000 Plus II
CPU cooling
Scythe Infinity
OS
Dualboot WinXP 32bit/WinVista 64bit
Monitor
Samsung 226BW
LTC is online now   Reply With Quote
Old 3 Weeks Ago   #8 (permalink)
4.0 GHz
 
r31ncarnat3d's Avatar
 
intel nvidia

Join Date: May 2009
Location: Merced, CA
Posts: 660

Rep: 67 r31ncarnat3d is acknowledged by some
Unique Rep: 55
Folding Team Rank: 962
Trader Rating: 4
Default

Quote:
Originally Posted by Greensystemsgo View Post
ya safest bet at this point - reformat.
If you're going to reformat, possibly change your IP Address as well if you have the capability of doing so?

Man, this seriously gives me the creeps. Best of luck to you and your girlfriend.
__________________
System: Eurynome
CPU
e8500 C0 4.0 GHz | 1.28V
Motherboard
Gigabyte GA-EP45-UD3LR
Memory
G.Skill 2x2GB DDR2 800
Graphics Card
EVGA GTX 260 216SP 55nm
Hard Drive
2x Seagate 160GB, 1x Seagate 320GB
Sound Card
Creative X-Fi Titanium Fatal1ty
Power Supply
Corsair CMPSU-550VX
Case
Cooler Master Storm Scout
CPU cooling
Xigmatek Dark Knight w/ Stock Xigmatek Fan
GPU cooling
Stock Cooler
OS
Windows 7 Ultimate x64
Monitor
Asus VK246H 24"
r31ncarnat3d is offline I fold for Overclock.net r31ncarnat3d's Gallery   Reply With Quote
Old 3 Weeks Ago   #9 (permalink)
4.0 GHz
 
Ladiesman101's Avatar
 
intel nvidia

Join Date: Apr 2009
Location: Irish Pub
Posts: 1,516

Rep: 107 Ladiesman101 is acknowledged by manyLadiesman101 is acknowledged by many
Unique Rep: 97
Trader Rating: 0
Default

well
fet a firewall in the router and computer

make sure
"remote computer" is off
__________________
E8400@ 3.962 stockvolts W Noctua
http://www.overclock.net/gallery/dat...creenshot5.jpg

Quote:
Originally Posted by Cyberbot View Post
Yes, do so! I can't wait to see you troll EVGA!
EVGA: EVGA customer support
You: Hey, I dropped my helmet on my EVGA GTX 280.
EVGA: You did what?
You: I dropped my helmet on my GTX 280 when I had sugar momma over.

System: Ladiesman's Girlfriend
CPU
e8400 @4.0 @stockvolts
Motherboard
Foxconn Black Ops
Memory
2x2GB Gskill DDR3
Graphics Card
Gigabyte GTX 260/216 @ 665
Hard Drive
200GB+500GB
Sound Card
Sonar Audio 7.1
Power Supply
OCZ ModXstream 700 Modular
Case
Coolermaster 690
CPU cooling
Noctua-UH12P
GPU cooling
stock
OS
XP32bit,Vista64bit
Monitor
HP w2007
Ladiesman101 is offline   Reply With Quote
Old 3 Weeks Ago   #10 (permalink)
ATI Enthusiast
 
ArmenianLegend's Avatar
 
intel ati

Join Date: Jun 2006
Location: Toronto
Posts: 1,155

Rep: 48 ArmenianLegend is acknowledged by some
Unique Rep: 41
Trader Rating: 0
Default

its an easy fix, reformat your comp, and change all passwords to every email/fb etc.

problem solved just make sure ur gf doesn't open any attachments
__________________
System: Guardian
CPU
i920 D0 4.4Ghz HT on
Motherboard
Asus Rampage II Gene
Memory
OCZ Reaper 12GB 1866Mhz 8-7-7-20
Graphics Card
2xATI HD5970 2GB QuadFire
Hard Drive
OCZ Vertex 32GB(OS)+OCZ 60GB(games)+1TB 7200.12
Sound Card
SupremeFX X-Fi
Power Supply
1Kw
Case
TT Armor
CPU cooling
Swiftech Apogee XT / Swiftech MCP655 / 120.3 PA
GPU cooling
Stock
OS
Windows 7 Ultimate 64
Monitor
24" + 28" + 24" EyeFiniTy 5760x1200 res
ArmenianLegend is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 09:28 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.15561 seconds with 8 queries