This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I find strange activity from my own laptop?

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I find strange activity both on my facebook and email. My facebook password was hijacked and i managed to recover it. I checked and downloaded my facebook data and i found unkown IP adress which was using my account while it was hijacked.  It even showed me the exact time it was accessed. Anyway i recovered it and changed the password. The funny things is that now i keep seeing strange activities, but this time no different IP shows up exept mine? I even check the exact time i was logged in or out and it seems i was logged through my own ip and device at a time i was not home (or i may be mistaken but almost 90% sure i am not) Also i never managed to figure out how someone cracked my facebook password. Just a few hours earlier today, i was watching a movie online and went to grab something to eat, and when i came by My computer folder was opened up and the movie minimized? I dont use wifi, i directly use cable. I have good antivirus and also i use malwarebytes regularely. I've never had any viruses and i am always carefull what linkes i open and so on ( i am not the type of guy you can fool easily). I think my laptop is accessed remotely. A few months ago a person i no longer trust was  left alone with my laptop, i started to fear if he installed something (he had a few hours time)I checked my login history on facebook and i saw a few loggins from my laptop and ip in times when i belive i was sleeping (again i may be mistaken) But i know that programs like TeamViewer terminate any connection once you restart/shut down your computer? Is it possible that he was able to remotely control my laptop even months after he had physicall access? I ask specifically about remote control because i always check the ip's i am logged in from and there was never any different ip than mine (except the one time my password was somehow changed) and since i dont use router the only chance would be if he remotely controls my laptop. How possible is that, and if it is, is it also possible the person to wake up my laptop while the lid is closed and access it without me noticing anything at all? He has no physical access for many months now.I am freaking out right now.. 

Don't know if we can really find a point of entry, but, if it were my machine I would totally disable remote access from windows and Team Viewer when not is use.

Also, when not in use shut down the computer or disable it by removing the ethernet cable connection, that way no access or activity can continue.

To configure remote access, follow these steps:
1. In Control Panel, click System And Security, and then click System.
2. On the System page, click Remote Settings in the left pane. This opens the System Properties dialog box to the Remote tab.
3. To disable Remote Desktop, select Dont Allow Connections To This Computer, and then click OK.Skip the remaining steps.
4. To enable Remote Desktop, you have two options. You can:

Select Allow Connections From Computers Running Any Version Of Remote Desktop to allow connections from any version of Windows.
Select Allow Connections Only From Computers Running Remote Desktop With Network Level Authentication to allow connections only from Windows 7 or later computers (and computers with secure network authentication).

Team Viewer
https://www.teamviewer.com/en/help/422-how-can-i-restrict-access-for-teamviewer-connections-to-my-computer

~~~~~~~~~~~~~~~

Please back up your registry!



Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.
  • Please download the installer for Registry Backup from here or here and save to your desktop.
  • Right-click on tweaking.com_registry_backup_setup.exe and select Run as Administrator >> Follow the prompts for a default installation
  • Ensure the option Open "Tweaking.com - Registry Backup" When Install Completes is selected >> Next > >> Finish
  • Once the GUI(graphical user interface) has appeared/loaded:-
[external image: TCRB-1.jpg]
  • Click on Backup Now >> once the process is complete the below will be displayed in the GUI:-
[external image: TBRB-2.jpg]
  • Close Tweaking.com - Registry Backup
Note: There will now be a folder at the root of the Hard-Drive named C:\RegBackup, do not delete this as it is the actual backup just created.

A tutorial for Registry Backup explaining the various features be viewed HERE


``````````````````````````````````````````````````````

Instruction for producing the Farbar Recovery Scan Tool (FRST) and aswMBR logs

Farbar Log

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note:
You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

(A simple way to check your system: Start –> Computer (right click) –> Properties
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Please make sure All Users is checked
  • Do not check
    *List BCD
    *Drivers MD5
    *Shortcut txt
Or your logs will be too long to post.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please don't run the Farbar Recovery Scan Tool (FRST.txt) from your "Downloads" folder or from "Temporary Internet Files"
  • Please copy and paste log into your topic.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please attach that along with the FRST.txt into your reply.
aswMBR Log

Important! Please do NOT perform any fix options offered in aswMBR, we just need to see the report.

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
  • If a prompt stating: The computer supports "Virtualization Technology" appears select Yes
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your reply with the Farbar (FRST) log.

Juliet thanks for the help. Unfortunately, i freaked out today and used reset to factory settings, which brought my 8.1 windows back to windows 8. I believe my remote access was not allowed (i think i remember checking it out a few times). I never had Team Viewer installed, unless someone installed it in secret. I am very behind with these things and i have no idea how remote access work, all i ever heard was TeamViewer but friends have told me that even if installed the program terminates any remote connection once you restart, also it should be visable when someone is accessing your machine. Also, what i have heard is when the lid is closed (on Dell laptops), there is no way someone can boot the machine since the lid itself protects from that, but i am not sure how accurate this is). I will probably reinstall windows itself to be sure, but again is it possible for such remote assistance program/softoware to remain active months after the person i fear had access, without any visiable sign? Again, i am talking mostly about remote access because i am keeping track on any IP that was logged to my accounts and if someone simply stole my password and logged in from elsewhere i would have known in an instant.

Thanks again for the support :) 

A fresh wipe and reinstall is a very good choice. Anything unwanted would be erased.

One thing I do to victims computers with a hint of corruption through IP or DNS connections, I have our tools clean it by refreshing.


What you might think of in the future is to
Flush
ipconfig /flushdns
http://www.eightforums.com/tutorials/30136-dns-resolver-cache-flush-reset-windows.html

~~~~
netsh winsock reset all

Run CMD "Command Prompt" as admininstrator.
In the command line type: netsh winsock reset
Press Enter then restart your PC
 

but again is it possible for such remote assistance program/softoware to remain active months after the person i fear had access, without any visiable sign

 
If it had not been disabled and left running I could see that but,  you would had found it listed in task manager as running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI