Re: Problems with an Outside Threat who is accessing my computer I

From: Matt Gibson (mattg_at_blueedgetech.ca)
Date: 02/17/05


Date: Thu, 17 Feb 2005 10:06:18 -0800

Sidney,

Until you start listening to our advice, and stop speaking nonsense (IP
addresses have nothing to do with Zip codes) I think you'll find few people
willing to help you.

Matt Gibson - GSEC

"Sidney" <Sidney@discussions.microsoft.com> wrote in message
news:87EAA5BB-0A73-4E9B-A0F5-CAE6A328354E@microsoft.com...
> Hello Again:
>
> Do you know of a good tracking software to find the IP address of this
> outside threat? Because the firewall is not providing an accurate reading
> of
> his IP address, because he is using a different zip code for his IP
> address,
> so that he can remain uncatchable.
>
> Thank You,
>
>
> "Sidney" wrote:
>
>> Hello,
>>
>> Thank You Everyone for your Feedback and Information,
>>
>> Yesterday, 02/15/05, the hard drive was replaced on this computer system,
>> because of the programs being compromised, I was receiving blue screen
>> and
>> black screen error messages.
>>
>> I had to enable Internet access in order to install my mcafee security
>> center programs and I had disabled the guest account and I change my
>> passwords frequently and still this outside threat is on this computer
>> system.
>>
>> I am not able to enable the internet connection firewall and I cannot
>> install the windows xp service pack 2, because files are deleted by this
>> outside threat.
>>
>> He is disabling my mcafee personal firewall plus services, accessing my
>> disabled user account, keylogging my passwords, stopping my scheduled
>> tasks
>> and scheduled scans from running.
>>
>> My plans are to gather enough evidence against this outside threat to
>> prosecute him in a court of law for hacking, tracking, compromsing my
>> computer system and compromising my email accounts.
>>
>> I appreciate you all taking the time to provide information that I found
>> very helpful and useful.
>>
>> Thank You,
>>
>>
>>
>> "George Ellis" wrote:
>>
>> > Please do all the rest of the advise given. Until you provide detail
>> > of how
>> > you determined you were hacked, no one can help you. Adding password
>> > protection software to a hacked machine is a pointless exercise. So
>> > far,
>> > all I have seen is possible software issues and not a clear cut
>> > methdology
>> > for finding and preventing an attack.
>> >
>> > "Sidney" <Sidney@discussions.microsoft.com> wrote in message
>> > news:78E20CCF-8274-47DB-824F-F7A6068ED904@microsoft.com...
>> > > eHello,
>> > >
>> > > Actually what I am seeking is additonal information on how to remove
>> > > an
>> > > outside threat from my computer system and to prevent him from
>> > > re-entering
>> > my
>> > > computer system.
>> > >
>> > > Do you know of any password protection softwares?
>> > >
>> > >
>> > > "George Ellis" wrote:
>> > >
>> > > > "Sidney"/Anita, no one can help you. The only thing you have told
>> > > > us is
>> > > > that you have your own special audits that you have used to
>> > > > determine
>> > that
>> > > > you have been hacked and you shout it with ALL CAPS keywords like
>> > > > you
>> > are
>> > > > trying to get some search engine to find your post. If someone
>> > > > asks you
>> > for
>> > > > more details, you shout back the same things.
>> > > >
>> > > > Therefore, I call Turing test on this one. Failed, this is a
>> > > > computer.
>> > > >
>> > > > "Sidney" <Sidney@discussions.microsoft.com> wrote in message
>> > > > news:F14B459A-3FDF-428F-A0DD-01805D0FA1B1@microsoft.com...
>> > > > > Hello,
>> > > > > I know that I keep repeating, what is happening to my computer
>> > > > > system,
>> > > > > because this is very upsetting, frustrating and I have performed
>> > numerous
>> > > > > TROUBLESHOOTING steps and NOTHING has STOPPED this Outside threat
>> > > > > from
>> > > > > accessing this computer system, ILEGALLY.
>> > > > >
>> > > > > I accessed this Microsoft Newgroups to see, if there was anything
>> > > > > else
>> > I
>> > > > > should try to Remove this Intrusion from my computer system.
>> > > > >
>> > > > >
>> > > > >
>> > > > > "vegas MCE05" wrote:
>> > > > >
>> > > > > > you keep repeating:
>> > > > > >
>> > > > > > "this Outside Threat is DISABLING my Mcafee Personal Firewall
>> > > > > > Plus
>> > > > Services,
>> > > > > > and is KEYLOGGING my PASSWORDS, ACCESSING my DISABLED USER'S
>> > ACCOUNTS,
>> > > > and is
>> > > > > > MODIFYING, REMOVING, RECREATING the Programs on this Dell
>> > > > > > computer
>> > > > system."
>> > > > > >
>> > > > > > I'm waiting for you to drop the link to the anti-spyware
>> > > > > > software
>> > you're
>> > > > > > selling.
>> > > > > >
>> > > > > > "Sidney" wrote:
>> > > > > >
>> > > > > > > Hello,
>> > > > > > >
>> > > > > > > All that I have stated is Very True and is Happening on my
>> > > > > > > Dell
>> > > > Computer
>> > > > > > > System, because this Outside Threat is DISABLING my Mcafee
>> > Personal
>> > > > Firewall
>> > > > > > > Plus Services, and is KEYLOGGING my PASSWORDS, ACCESSING my
>> > DISABLED
>> > > > USER'S
>> > > > > > > ACCOUNTS, and is MODIFYING, REMOVING, RECREATING the Programs
>> > > > > > > on
>> > this
>> > > > Dell
>> > > > > > > computer system.
>> > > > > > >
>> > > > > > > Everyday computer systems are Breached, computer security
>> > > > > > > systems
>> > > > FIREWALLS
>> > > > > > > are DISABLED and passwords are KEYLOGGED, because you have
>> > SEASONED,
>> > > > hackers,
>> > > > > > > trackers, outside threats, outside attacks in the Internet
>> > community.
>> > > > > > >
>> > > > > > >
>> > > > > > >
>> > > > > > > "Looker" wrote:
>> > > > > > >
>> > > > > > > > I think we all just got taller on one side (had our leg
>> > > > > > > > pulled)
>> > > > Unless the
>> > > > > > > > hacker is INSIDE the house.
>> > > > > > > > "Joe Rookie" <nospam@dontemailme.com> wrote in message
>> > > > > > > > news:eBErDkrEFHA.2828@TK2MSFTNGP09.phx.gbl...
>> > > > > > > > > If all of this is true, then you need to contact your
>> > > > > > > > > local
>> > law
>> > > > > > > > > enforcement
>> > > > > > > > > ... Or, hire someone who can setup a secure system from
>> > > > > > > > > the
>> > start
>> > > > ....
>> > > > > > > > >
>> > > > > > > > > "Sidney" <Sidney@discussions.microsoft.com> wrote in
>> > > > > > > > > message
>> > > > > > > > > news:AD377052-7A46-4633-B41E-916E7480CC3D@microsoft.com...
>> > > > > > > > >> Hello,
>> > > > > > > > >> Thank You for Responding and your Time and Information,
>> > > > > > > > >>
>> > > > > > > > >> This outside threat Prevents this dell computer system
>> > > > > > > > >> from
>> > > > receiving
>> > > > > > > > >> critical updates, because this outside threat has
>> > > > STOPPED/DISABLED the
>> > > > > > > > > mcafee
>> > > > > > > > >> personal firewall plus services from running and
>> > > > > > > > >> Accessing my
>> >
>> > > > DISABLED
>> > > > > > > > > User's
>> > > > > > > > >> accounts to gain ILLEGAL access to this dell computer
>> > > > > > > > >> system.
>> > > > > > > > >>
>> > > > > > > > >> This outidie threat is KEYLOGGING my Passwords and I
>> > > > > > > > >> change
>> > my
>> > > > passwords
>> > > > > > > > > in
>> > > > > > > > >> my user's accounts a number of times a day and he is
>> > > > > > > > >> stopping
>> > > > scheduled
>> > > > > > > > > scans
>> > > > > > > > >> from running and he has MODIFIED, REMOVED, RECREATED the
>> > programs
>> > > > on this
>> > > > > > > > >> dell computer system, so the spyware removal scans and
>> > > > > > > > >> the
>> > > > antivirus
>> > > > > > > > >> scans
>> > > > > > > > >> are not picking him up.
>> > > > > > > > >>
>> > > > > > > > >> I have performed system restores, system config,
>> > > > > > > > >> restalling
>> > and
>> > > > > > > > > reformatting
>> > > > > > > > >> the hard drive and the hard drive will be replaced 3
>> > > > > > > > >> times
>> > in
>> > > > less than
>> > > > > > > > >> 8
>> > > > > > > > >> months, because this outside threat is causing HAVOC on
>> > > > > > > > >> this
>> > dell
>> > > > > > > > >> computer
>> > > > > > > > >> system and NONE of the Programs are working properly.
>> > > > > > > > >>
>> > > > > > > > >> I have tried my best to protect this dell computer
>> > > > > > > > >> system,
>> > but
>> > > > this
>> > > > > > > > > outside
>> > > > > > > > >> threat is DISABLING my mcafee personal firewall plus
>> > services,
>> > > > KEYLOGGING
>> > > > > > > > > my
>> > > > > > > > >> PASSWORDS and I cannot install windows xp service pack
>> > > > > > > > >> 2,
>> > because
>> > > > some of
>> > > > > > > > > the
>> > > > > > > > >> files are always MISSING and I cannot enable the
>> > > > > > > > >> Internet
>> > > > firewall
>> > > > > > > > >> connection, because he has blocked this service.
>> > > > > > > > >>
>> > > > > > > > >> I am not a novice when it comes to computer securtiy
>> > protection,
>> > > > but this
>> > > > > > > > >> outside threat is seasoned, he knows how to breach a
>> > > > > > > > >> computer
>> > > > security
>> > > > > > > > > system.
>> > > > > > > > >>
>> > > > > > > > >> Thank You for your Time,
>> > > > > > > > >> Anita
>> > > > > > > > >>
>> > > > > > > > >>
>> > > > > > > > >>
>> > > > > > > > >> "Roger Abell" wrote:
>> > > > > > > > >>
>> > > > > > > > >> > To echo what Matt has said, and add one little by very
>> > > > > > > > >> > important part . . .
>> > > > > > > > >> > When you install, do not have the machine connected to
>> > > > > > > > >> > the network. You must first enable the firewall,
>> > > > > > > > >> > install
>> > > > > > > > >> > as much service as you have a copy (like the most
>> > > > > > > > >> > recent
>> > > > > > > > >> > service pack), and anything retained on a second drive
>> > > > > > > > >> > or partition needs to be thoroughly scanned for virus
>> > > > > > > > >> > and other malware.
>> > > > > > > > >> > As soon as you are ready, with firewall enabled
>> > > > > > > > >> > without
>> > > > > > > > >> > exceptions allowed, the first thing to do when
>> > > > > > > > >> > connecting
>> > > > > > > > >> > the network is to visit Windows Update and let it do
>> > > > > > > > >> > its
>> > > > > > > > >> > thing until it sees no more critical patches.
>> > > > > > > > >> >
>> > > > > > > > >> >
>> > > > > > > > >> > --
>> > > > > > > > >> > Roger Abell
>> > > > > > > > >> > Microsoft MVP (Windows Security)
>> > > > > > > > >> > MCSE (W2k3,W2k,Nt4) MCDBA
>> > > > > > > > >> > "Sidney" <Sidney@discussions.microsoft.com> wrote in
>> > message
>> > > > > > > > >> > news:9490515A-DC16-4163-B101-3B183F31ED79@microsoft.com...
>> > > > > > > > >> > > Hello,
>> > > > > > > > >> > > I am having very serious problem with an outside
>> > > > > > > > >> > > threat
>> > who
>> > > > is
>> > > > > > > > > accessing
>> > > > > > > > >> > my
>> > > > > > > > >> > > computer system Illegally, by accessing my DISABLED
>> > user's
>> > > > accounts
>> > > > > > > > > and
>> > > > > > > > >> > > DISABLING my mcafee personal firewall plus to gain
>> > Illegal
>> > > > access to
>> > > > > > > > > this
>> > > > > > > > >> > > computer and who is keylogging my passwords,
>> > > > > > > > >> > > removing,
>> > > > modifying,
>> > > > > > > > >> > recreating
>> > > > > > > > >> > > the programs on this dell computer system, stopping
>> > scheduled
>> > > > scans
>> > > > > > > > > from
>> > > > > > > > >> > > running and who is also compromsing my emails
>> > > > > > > > >> > > accounts,
>> > > > deleting
>> > > > > > > > > emails
>> > > > > > > > >> > from
>> > > > > > > > >> > > tech support agents who are sending troubleshooting
>> > > > > > > > >> > > steps
>> > to
>> > > > remove
>> > > > > > > > > this
>> > > > > > > > >> > > outside threat from my computer system.
>> > > > > > > > >> > >
>> > > > > > > > >> > > The hard drive will be replaced on this dell
>> > > > > > > > >> > > computer
>> > system
>> > > > 3 times
>> > > > > > > > > and I
>> > > > > > > > >> > > have only had this computer for less than one year
>> > > > > > > > >> > > and I
>> > > > performed
>> > > > > > > > > system
>> > > > > > > > >> > > restores, reinstalling the windows operating system,
>> > system
>> > > > configs
>> > > > > > > > > and
>> > > > > > > > >> > > various other troubleshooting steps and still I
>> > > > > > > > >> > > Cannot
>> > remove
>> > > > this
>> > > > > > > > > outside
>> > > > > > > > >> > > threat from this dell computer system.
>> > > > > > > > >> > >
>> > > > > > > > >> > > Do you have any suggestions, on how to remove this
>> > outside
>> > > > threat,
>> > > > > > > > > from
>> > > > > > > > >> > this
>> > > > > > > > >> > > dell computer system?
>> > > > > > > > >> > >
>> > > > > > > > >> > > Thank You,
>> > > > > > > > >> > > Anita
>> > > > > > > > >> >
>> > > > > > > > >> >
>> > > > > > > > >> >
>> > > > > > > > >
>> > > > > > > > >
>> > > > > > > >
>> > > > > > > >
>> > > > > > > >
>> > > >
>> > > >
>> > > >
>> >
>> >
>> >



Relevant Pages

  • Re: New attacks on the financial PIN processing
    ... part of the issue was that the x9a10 financial standards working group ... the financial infrastructure for all retail transactions (that met all ... skimming/harvesting the account number was sufficient ... Banks face growing threat of identity theft from insiders ...
    (sci.crypt)
  • Re: Problems with an Outside Threat who is accessing my computer I
    ... > passwords frequently and still this outside threat is on this computer system. ... > I am not able to enable the internet connection firewall and I cannot ... > disabled user account, keylogging my passwords, stopping my scheduled tasks ...
    (microsoft.public.security)
  • Re: Asshole Sean Ruttledge
    ... He is using google video now because he is loosing one account after an ... Oooooooooh lummy a sinister "THREAT" from the Michael Kors gimp bwoy ... Others here and elsewhere might not see eye to eye with me beaner; ...
    (soc.culture.greek)
  • Re: Problems with an Outside Threat who is accessing my computer I
    ... DISABLING my mcafee personal firewall plus services to gain ILLEGAL access to ... this dell computer system. ... I have used the proper security measure, but this outside threat is a ... by accessing my DISABLED user's accounts and ...
    (microsoft.public.security)
  • Re: Account Lockout Policies
    ... Account lockout is a poor substitute for good passwords -- and is one of the most expensive security features you can use. ... Let's think about this by considering the threat. ... Account lockouts have one more -- very bad -- problem: they *create* opportunities for bad guys to conduct denial-of-service attacks against accounts or entire domains! ...
    (microsoft.public.security)