Someone Accessing Friend's Computer Accounts/pswrds/etc
4 min read
Changing passwords on the infected machine is useless, since the Remote Access will simply adjust to and begin using the new password information.
Your friend should use a different (known-clean) computer to change all online accounts and passwords immediately.
Your friend should carefully watch any/all financial accounts that could have been compromised, for unknown purchases.
Directly contact banks and financial institutions by phone or in person to change accounts and password access.
Do not use the infected machine to access any online accounts (even after changing passwords) until the machine is fully restored to clean status.
"If" the above is what your friend is dealing with, the only way to restore the machine to safe operation is to Completely Reformat the hard drive and Reinstall the Operating System.
Since this will destroy all data, media and files, have your friend back-up all important documents, pictures, media, and files to an external storage, like CD/DVD. After reformatting and reinstalling the machine, all saved documents, pictures, media and files should be thoroughly scanned by competent AntiVirus and AntiSpyware utilities prior to opening, displaying or running applications with any of that data.
For more information and tutorials about how infections occur and what to do to protect a machine after it gets cleaned up:
http://forums.tomcoyote.org/So_how_did_get…ace_t57817.html
http://forums.tomcoyote.org/Securing_Pc_Af…ack_t57869.html
Best Regards
All of her accounts have been changed (her usernames, website info, etc), passwords accessed, etc, even after changing all passwords. It seems obvious to me that this person (whom we know - and whom we know is stalking her) has the ability to get into her computer "externally" somehow - and if not, then they have ESP and can figure out my friend's passwords.
It all began when her freewebs website appeared to be closed down due to serious abuse. AFter contacting freewebs, they confirmed that they had NOT put that message on the site, and that it had been hacked into (the account info accessed).
All of her yahoo groups have been accessed as well – where the "hacker" writes posts and signs them as my friend…
Sure, a HJT Log "may" provide information about the type of infection being used.
Other advanced tools may also identify specific files and functions that have been infected.
But any additional online use of that machine simply "exposes" your friend to additional abuse.
Until the machine is fully cleaned up, restored, and protected by competent Security Baseline utilities, I would not recommend that it be used online for any purpose at all.
Best Regards
Right now, we're all (our group of friends who communicate regularly with this friend who's been highjacked, apparently) quite concerned that just by virtue of emailing with her, we're also subject to the same highjacking.
Whatever program it is that this highjacker has that allows such access could, theoretically, be used on anyone else, right?
Yes.
I would not "open" any email or IM sent from that infected machine, until it is completely cleaned and restored.
If you already have "opened" emails (especially with custom background stationary or with attachments) then you should promptly update and run all of your Security utilities and run one additional online scan from either:
Panda Online Scan
Kaspersky Online Scan
You and your friends should be sure that your Operating Systems are fully updated and that your Security Baseline utilities are updated and run regularly, especially after internet session activity.
Best Regards
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI