Ex-Wife's Computer Hacked...

   / Ex-Wife's Computer Hacked... #1  

mark02tj

Platinum Member
Joined
Nov 10, 2013
Messages
964
Location
Southwest Ohio
Tractor
2005 JD 3520
I wasn't sure where else to post this but I know this forum gets a lot of traffic so here I am. :)

Long story short - I got a panicked / frantic call from the ex-wife the other night. She had "Microsoft Tech Support" on her land line and they were concerned about her computer because it was sending out viruses. I told her it was a hoax and to hang up on the guy and shut the computer off immediately!!

I'm not sure what she opened up to let them on to her system. She's a bit fuzzy on the details. I asked her about "TeamViewer" and "Ammy" but neither of those rang a bell to her. I looked around a bit on her system and found a file called "AeroAdminLog.txt" in the root directory of her C drive. It was dated and timestamped at about the same time she called me. I looked around in her "Program Files" folder and in the other folders, but nothing jumped out at me.

Here's a screenshot of what is in the AeroAdminLog.txt file:
Ex-Wife_Hack_Attempt.jpg

I know enough about this stuff to know the basics of what's in the file. But I'm hoping that some of you super-smart TBN tech guys can give me specifics. :thumbsup:

Fortunately she doesn't use this computer for much more than surfing the web but she does do her online banking on it. She's already changed her online login information (from another computer). There's no pictures to save (all on her phone), no Word docs, etc.

Her computer is an HP Pavillion "G Series" runing Win-7 Home Premium. I noticed that she has a D drive marked "Recovery" (2.24 GB free of 20.7 GB) and an E drive marked "HP_TOOLS (1.89 mb free of 3.95 GB). Do either of those drives contain what I need to wipe the drive, reformat and reinstall the OS? Or should I take it to the little shop in town that has "We'll repair your computer for $69" painted in their front window?

Any help that you can give me would be appreciated. I have the computer for a few days so I can follow up on anything that's asked.

THANKS!
 
   / Ex-Wife's Computer Hacked... #3  
I would use the CD\DVD. It's rare but wouldn't take much to modify the HP recovery partition. Reinstall but still have the same remote login. If all she does is surf the internet, download linux, it's free and easy to install.
 
   / Ex-Wife's Computer Hacked... #6  
The text file just looks like a log file. Most new computers don't come with OS & App CD's anymore. The D: Recovery drive is a partition (virtual drive) where the OS and App files reside. If the computer is running OK and you haven't gotten any auto-spam emails from her, I doubt there's an infection. Microsoft does not call users to tell them they've got a BOT. That is a function of the ISP.
 
   / Ex-Wife's Computer Hacked... #7  
With those naked IP addresses, someone could have a whole lot of fun with a revenge game than you could ever imagine. A denial of service action would be my first salvo. Next would be a drone strike.
 
   / Ex-Wife's Computer Hacked... #8  
ughs another "microsoft blah blah techsupport call" hoax!!! and scam!!!

not setting at correct pc that has my various "family ware" stuff for cleaning up family member computers right off hand.

spybot search and destroy from... what is it safernetworking.org free version. tends to pull up a lot of extra crud, that "task manager" and file explorer does not show.
--be carefull other companies / scams out there, that list there app as "spybot search and destroy" ya want from safernetworking.org

i don't remember the other program right off, it is a fairly small program. ya download latest version, and run it, and it will make some log files of all the various info on your computer. most tech forums ask for the log to be posted to a forum thread. so they can see it.

i run "avg internet security" so i can get antivirius app and a cheap firewall program. that prompts me when ever something wants to connect to internet. that prompting of the internet firewall software has saved me a couple times from a virus.
 
   / Ex-Wife's Computer Hacked... #9  
I looked it up - that IP shows to host Conficker B, AB and Sality P2P malware.
 
   / Ex-Wife's Computer Hacked... #10  
If she doesn't have anything on the computer I'd just wipe it and use the factory install. It'll take a few days to catch up on updates but at least she'd have the computer back. Don't bother trying to uninstall or fix it - far bigger pain than just wiping it.

Use Chrome, but don't use their save password/userID feature as it's entirely in clear text (bad.) Get a password vault like Norton Identity Safe or 1Password. Install AdBlocker as that's where a lot of drive-by malware comes from. Obviously some sort of AV/endpoint protection is necessary too but it's also a good time to explain to her how social engineering and phishing work. As we say in my industry, "there's no patch for stupidity."
 

Tractor & Equipment Auctions

Dump bed (A51692)
Dump bed (A51692)
2012 CHEVROLET SILVERADO SINGLE CAB TRUCK (A51406)
2012 CHEVROLET...
2014 DIAMOND C TRAILER MFG. (A50322)
2014 DIAMOND C...
2012 Dodge Ram 5500 Chipper Truck (A52377)
2012 Dodge Ram...
FORD 555B BACKHOE (A51246)
FORD 555B BACKHOE...
DUMP HOPPER (A53843)
DUMP HOPPER (A53843)
 
Top