Re: Hacked and remote controlled computer

From: Lanwench [MVP - Exchange] (lanwench_at_heybuddy.donotsendme.unsolicitedmail.atyahoo.com)
Date: 10/11/04


Date: Mon, 11 Oct 2004 10:32:00 -0400

Micke__1 wrote:
> We used to have a Win 2k sp4 fully patched IBM laptop. Several time
> when the user were connected to our lan, the computer were remote
> controlled. Someone delete mail, choose Start-Run and wrote a message
> to the user. A bit scary. I scanned it with, antivirus software,
> adaware software, check entries in the registry. Checked processes in
> taskmanager, look for strange connections with netstat... but found
> nothing. I format and installed Win XP SP2, and it seems to have
> started again. I can tell for sure that no one from inside our
> network doing it. And even if that was the case it has to exist some
> remote control aplication, which I couldn't found. A thought would be
> that there is some kind of a root kit, but I dont know have to found
> them. I tried to boot in safe mode but there were no strange service
> that was running...

When this first happened, was the laptop protected by a perimeter firewall
on your LAN that blocks all potentially dangerous ports? Was this computer
ever used on unprotected networks? Kept patched with all critical updates,
and running good current generation antivirus software?



Relevant Pages

  • LAN Help needed
    ... its' been a long road but I finally have a LAN working at home. ... internal machine into the address bar of konqueror and I get ... I would try out the article by Marcel Gagne about remote desktop control. ...
    (alt.os.linux.suse)
  • Re: Useless UK police get their just deserts.
    ... "YOU WANT TO CONNECT A PC TO A REMOTE ... The remote control in question would be one that controls a 3-pin ... Do you simply want to switch the PC off and on at the mains by remote ... your LAN. ...
    (uk.legal)
  • Re: cannot connect to a host behind a router
    ... LAN, what IP address are ... you entering in the Computer box on the General page of Remote ... > forwarding on the router to forward incoming RDC connections to ... I configured users on the host to allow ...
    (microsoft.public.windowsxp.work_remotely)
  • RE: Re: Remote connections
    ... provides a home for an AX control that gets downloaded to the client. ... This AX control is a "stripped-down" RDP client that uses exactly the ... Subject: Remote connections ... Aside from creating a VPN tunnel and then performing a Remote Desktop ...
    (Focus-Microsoft)
  • RE: Re: Remote connections
    ... TSWEB is nothing more than an ActiveX control embedded in a web page. ... The ActiveX control still communicates via RDP. ... Subject: Remote connections ... Aside from creating a VPN tunnel and then performing a Remote Desktop ...
    (Focus-Microsoft)