Have I been hacked?

General software, Operating Systems, and Programming discussion.
Everything from software questions, OSes, simple HTML to scripting languages, Perl, PHP, Python, MySQL, VB, C++ etc.
Post Reply
User avatar
Easto
SG Elite
Posts: 5856
Joined: Sat Dec 02, 2000 12:00 am
Location: So. California

Have I been hacked?

Post by Easto »

As per my last thread in this software forum I was not allowed to use Google without going through a "captcha". I guess someone may have got into my network. I changed all the passwords, reset the router etc. Everything seemed find. Today I notice that I have a notepad file on my desktop titled network security setting and it is exposing my new router password and security key. I did not create this file. I keep all my passwords in a KeyPass file and I have no idea where this file came from.
User avatar
TonyT
SG VIP
Posts: 10356
Joined: Fri Jan 28, 2000 12:00 am
Location: Fairfax, VA

Post by TonyT »

What operating system do you have?
A common exploit in XP or later is Remote Desktop.
Many OEM computers have an Administrator account setup or an user account named Owner with no password. It is possible to connect via Remote Desktop and take control of the computer. If Remote Desktop is enabled shut if off.
Or you have a trojan...

All one need do is use a network scanner like nmap or others, scan a range of IP addresses and look for the open port 3389. By default it's open in Windows. The person can then try various usernames and blank password to connect. Or brute force the username and password.

The router can also be hijacked. It has a setting for DNS servers. That's where you should enter other than isp dns.

If your browser 'remembers' form info and passwords then anyone who uses your comp can access the router and change settings.
No one has any right to force data on you
and command you to believe it or else.
If it is not true for you, it isn't true.

LRH
User avatar
Easto
SG Elite
Posts: 5856
Joined: Sat Dec 02, 2000 12:00 am
Location: So. California

Post by Easto »

Tony,

Thanks for the response. I'm running Win 7 - 64bit. Remote desktop has always been disabled. The administrator account has its own name (not admin) and a random password 11 characters in length. When I notice I was having a problem with Google not allowing me to search without using a captcha due to the fact it claimed I was sending out too many requests... I unplugged my router and reset the router password, admin access and guest access. I also had set the router to use OpenDNS.

I have run Malwarebyte's Root Kit detector and got nothing. I also do not have my computer remember anything and usually run CCleaner after each session.

I just went into the router settings and the time settings were incorrect. I'm going to go in and reset everything again tonight and see what happens. IN the meantime, what is a good Trojan hunter? I think I'm probably going to be installing a new hard drive and possible just start from scratch if these weird things keep happening.
User avatar
Easto
SG Elite
Posts: 5856
Joined: Sat Dec 02, 2000 12:00 am
Location: So. California

Post by Easto »

Call the dogs off. I'm not watching what I'm doing. One of the last screens when setting up the DLink router had a check box that is always checked "copy settings to desktop". I didn't untick it the first time and that's why that file was there. I think I'm good.
User avatar
TonyT
SG VIP
Posts: 10356
Joined: Fri Jan 28, 2000 12:00 am
Location: Fairfax, VA

Post by TonyT »

Good news!
As for malware, adwcleaner and combofix are imho the best at what they do.
No one has any right to force data on you
and command you to believe it or else.
If it is not true for you, it isn't true.

LRH
Post Reply