Forum
ยป
Brahs...I think I may have a remote hacker accessing my laptop..(REPS!)
02-09-2022, 10:58 AM
-
#31
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Basically one evening my laptop sign in screen changed. Windows usually has a fancy picture but this time it was just black with no fingerprint sign on option. Only Pin. Secondly, the profile photo looked a bit blurred and some admin privileges were changed. I immediately did a fresh install of windows 11 however if there was a keylogger in the system it would still have my passwords. I also noticed my online banking password was the same, however the security question had been changed. I contacted them and they said that no security questions had been changed. weird. Also, when I try to set up my fingerprint sign in on windows hello it says it is not available and the helloface folder/files is missing from the system 32 folder. I also noticed facefoduninstaller.exe inside that folder. Basically the entire face driver folder is missing from the registry. Weird. Ive run malware bytes bootkit and RKill in safe mode. Nothing. Any idea how to detect a RAT/Rootkit/Botnet ?
The final weird thing is that sometimes when I shut off my computer it may boot back up unknowingly. Or I may hear sounds of it still being on after i shut it down, Even the battery power seems much better than before. The power buttons on the side also changed, usually when its plugged in the white light will come on, however if I unplug the power the white light stays on.
The final weird thing is that sometimes when I shut off my computer it may boot back up unknowingly. Or I may hear sounds of it still being on after i shut it down, Even the battery power seems much better than before. The power buttons on the side also changed, usually when its plugged in the white light will come on, however if I unplug the power the white light stays on.
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:03 AM
-
#32
- JeepBruh
- Platinum
-
- JeepBruh
- Platinum
- Join Date: Aug 2019
- Posts: 12,136
- Subscribers: 2
- Rep Power: 146252
-
-
Might want to wipe your router as well. If they were able to get into the router firmware from your compromised PC you could be getting call backs even after a freshly installed OS. Hopefully you changed the default login on your router when you purchased?
02-09-2022, 11:04 AM
-
#33
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By JeepBruh⏩
the problem is the router im using is from the apartment its not mine! how would I be able to reset it ? Already turned it off and then onMight want to wipe your router as well. If they were able to get into the router firmware from your compromised PC you could be getting call backs even after a freshly installed OS. Hopefully you changed the default login on your router when you purchased?
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:06 AM
-
#34
- MyBaddBrah
- u wot m8
-
- MyBaddBrah
- u wot m8
- Join Date: Apr 2013
- Posts: 19,318
- Rep Power: 61930
-
-
If you do a reinstall you removed everything. It's extremely unlikely you have anything that's affected the firmware. Change your passwords and you should be good.
*Hole is Life Crew*
*Meditation Crew*
02-09-2022, 11:07 AM
-
#35
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By MyBaddBrah⏩
theres jsut weird chit going on that normally doesnt happen, like when I typed in weather it took me to a different location. Or when I am using chrome with adblocker I can still see adsIf you do a reinstall you removed everything. It's extremely unlikely you have anything that's affected the firmware. Change your passwords and you should be good.
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:08 AM
-
#36
- JeepBruh
- Platinum
-
- JeepBruh
- Platinum
- Join Date: Aug 2019
- Posts: 12,136
- Subscribers: 2
- Rep Power: 146252
-
-
Originally Posted By VegasLifter26⏩
Use ublock origin for ads and ghostery to minimize trackingtheres jsut weird chit going on that normally doesnt happen, like when I typed in weather it took me to a different location. Or when I am using chrome with adblocker I can still see ads
02-09-2022, 11:11 AM
-
#37
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By JeepBruh⏩
Is there a way to see if someone has remote access . I reset the network setting, I checked the Netstat in command prompt, I disabled windows remote desktop. But seems like there is still some background activity going on.Use ublock origin for ads and ghostery to minimize tracking
Ublock just worked btw
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:15 AM
-
#38
- JeepBruh
- Platinum
-
- JeepBruh
- Platinum
- Join Date: Aug 2019
- Posts: 12,136
- Subscribers: 2
- Rep Power: 146252
-
-
Originally Posted By VegasLifter26⏩
Antivirus. Windows defender does a decent job, but McAfee or dedicated antivirus will help pick up slightly more. They have free trials obv. Just uninstall once you no longer need and they start pressuring you to buy. Or just buy.Is there a way to see if someone has remote access . I reset the network setting, I checked the Netstat in command prompt, I disabled windows remote desktop. But seems like there is still some background activity going on.
Ublock just worked btw
Ublock just worked btw
Make sure scan in safemode as well. These are basic suggestions, but should catch vast majority of infections.
I still think you should figure out login information for router and wipe/reinstall firmware.
02-09-2022, 11:20 AM
-
#39
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By JeepBruh⏩
I think you may be right, I noticed that when my network was connected it would show two networks on the same router. For Instance - Bob'sRouter , and Bob'sRouter -5ghzAntivirus. Windows defender does a decent job, but McAfee or dedicated antivirus will help pick up slightly more. They have free trials obv. Just uninstall once you no longer need and they start pressuring you to buy. Or just buy.
Make sure scan in safemode as well. These are basic suggestions, but should catch vast majority of infections.
I still think you should figure out login information for router and wipe/reinstall firmware.
Make sure scan in safemode as well. These are basic suggestions, but should catch vast majority of infections.
I still think you should figure out login information for router and wipe/reinstall firmware.
that seemed very strange
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:21 AM
-
#40
- Critter5592
- That's the arm I fap with
-
- Critter5592
- That's the arm I fap with
- Join Date: Nov 2011
- Posts: 33,809
- Rep Power: 354322
-
-
if you did a fresh windows install, you are fine. Id change passwords though just to be extra safe.
Uncontrollable behavior with some psychopathic tendencies
02-09-2022, 11:22 AM
-
#41
- JeepBruh
- Platinum
-
- JeepBruh
- Platinum
- Join Date: Aug 2019
- Posts: 12,136
- Subscribers: 2
- Rep Power: 146252
-
-
Originally Posted By VegasLifter26⏩
The first one is your 2.4GHz signal. An older standard that is slower, but with better rangeFor Instance - Bob'sRouter , and Bob'sRouter -5ghz
that seemed very strange
that seemed very strange
02-09-2022, 11:25 AM
-
#42
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By JeepBruh⏩
Do you know if these viruses/Trojan once they get in your PC can they infect other PC's on a different network. FOr example if I logged into someone elses home network or a public wifi would those devices on there become infected?The first one is your 2.4GHz signal. An older standard that is slower, but with better range
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:26 AM
-
#43
- MyBaddBrah
- u wot m8
-
- MyBaddBrah
- u wot m8
- Join Date: Apr 2013
- Posts: 19,318
- Rep Power: 61930
-
-
Originally Posted By VegasLifter26⏩
Since you already wiped your files, the only place that could be left is firmware. Hackers usually aren't bothering with new firmware exploits for routers used by everyday people. Why would they? What do they have to gain? It's a lot of effort for little reward. As long as your router's been updated, which it likely has been, you're 99% good.Is there a way to see if someone has remote access .
Who else is on your network? Are you getting phished?
*Hole is Life Crew*
*Meditation Crew*
02-09-2022, 11:27 AM
-
#44
- JeepBruh
- Platinum
-
- JeepBruh
- Platinum
- Join Date: Aug 2019
- Posts: 12,136
- Subscribers: 2
- Rep Power: 146252
-
-
Originally Posted By VegasLifter26⏩
If you are wondering if you infected other networks then no. No one within your wifi range is going to re-infect your network.Do you know if these viruses/Trojan once they get in your PC can they infect other PC's on a different network. FOr example if I logged into someone elses home network or a public wifi would those devices on there become infected?
02-09-2022, 11:29 AM
-
#45
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By MyBaddBrah⏩
Nobody is on my network however I was using teamviewer last week with someone from fiverr. However I was in the mode conrolling his pc...would that have left me vulnerable?Since you already wiped your files, the only place that could be left is firmware. Hackers usually aren't bothering with new firmware exploits for routers used by everyday people. Why would they? What do they have to gain? As long as your router's been updated, which it likely has been, you're 99% good.
Who else is on your network? Are you getting phished?
Who else is on your network? Are you getting phished?
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:29 AM
-
#46
- JeepBruh
- Platinum
-
- JeepBruh
- Platinum
- Join Date: Aug 2019
- Posts: 12,136
- Subscribers: 2
- Rep Power: 146252
-
-
Originally Posted By MyBaddBrah⏩
A common tactic once they compromise your pc is to start trying to log into your router by brute forcing default passwords. "admin, admin" etcSince you already wiped your files, the only place that could be left is firmware. Hackers usually aren't bothering with new firmware exploits for routers used by everyday people. Why would they? What do they have to gain? As long as your router's been updated, which it likely has been, you're 99% good.
Who else is on your network? Are you getting phished?
Who else is on your network? Are you getting phished?
02-09-2022, 11:30 AM
-
#47
- SuperHercules
- Join Date: Jun 2014
- Height: 6'5"
- Posts: 32,378
- Subscribers: 6
- Rep Power: 566434
-
-
Originally Posted By VegasLifter26⏩
Maybe the landlord is the culpritthe problem is the router im using is from the apartment its not mine! how would I be able to reset it ? Already turned it off and then on
Anyways windows is garbage. You should just try Linux
See Shakebrah's sig
02-09-2022, 11:35 AM
-
#48
- MyBaddBrah
- u wot m8
-
- MyBaddBrah
- u wot m8
- Join Date: Apr 2013
- Posts: 19,318
- Rep Power: 61930
-
-
Originally Posted By JeepBruh⏩
True. But modern routers aren't vulnerable to brute force attacks via rate limiting. And chances are if he's set up his own router he knows to use a strong password on it.A common tactic once they compromise your pc is to start trying to log into your router by brute forcing default passwords. "admin, admin" etc
*Hole is Life Crew*
*Meditation Crew*
02-09-2022, 11:35 AM
-
#49
- flat6pilot
- Registered User
-
- flat6pilot
- Registered User
- Join Date: Oct 2015
- Age: 42
- Posts: 1,958
- Rep Power: 5996
-
-
It is possible for some viruses to get into the Bios and would reinfect a clean reinstall of windows.
https://docs.microsoft.com/en-us/ans...ry-resets.html
https://docs.microsoft.com/en-us/ans...ry-resets.html
02-09-2022, 11:36 AM
-
#50
- MyBaddBrah
- u wot m8
-
- MyBaddBrah
- u wot m8
- Join Date: Apr 2013
- Posts: 19,318
- Rep Power: 61930
-
-
Originally Posted By VegasLifter26⏩
You should be good with team viewer. Post some screen vids with the weird behavior.Nobody is on my network however I was using TeamViewer last week with someone from fiverr. However I was in the mode conrolling his pc...would that have left me vulnerable?
*Hole is Life Crew*
*Meditation Crew*
02-09-2022, 11:37 AM
-
#51
- olemo
- Registered User
-
- olemo
- Registered User
- Join Date: Dec 2013
- Age: 32
- Posts: 3,179
- Rep Power: 8054
-
-
You have a ROOTKIT it is malware infected code into hardware.
Run multiple anti rootkit software(malware bytes bascily any you can find)
Ive had a rootkit once in my motherboard. Was hacked by russian hackers.
They are hard to get rid of.
Bascily it boots the virus into your pc when the hardware is Run so even if you a do fresh instal you will get re-infected.
edit: download all of those.
https://www.bleepingcomputer.com/dow.../anti-rootkit/
edit: this tool will check your router do this for DNS HACK. (also check what your current DNS is.)
https://www.f-secure.com/en/home/fre...router-checker
Run multiple anti rootkit software(malware bytes bascily any you can find)
Ive had a rootkit once in my motherboard. Was hacked by russian hackers.
They are hard to get rid of.
Bascily it boots the virus into your pc when the hardware is Run so even if you a do fresh instal you will get re-infected.
edit: download all of those.
https://www.bleepingcomputer.com/dow.../anti-rootkit/
edit: this tool will check your router do this for DNS HACK. (also check what your current DNS is.)
https://www.f-secure.com/en/home/fre...router-checker
02-09-2022, 11:37 AM
-
#52
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By MyBaddBrah⏩
the password and usernames are custom. Its a 2 in 1 TMobile 5g router/modelTrue. But modern routers aren't vulnerable to brute force attacks via rate limiting. And chances are if he's set up his own router he knows to use a strong password on it.
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:40 AM
-
#53
- jreacher
- Registered User
-
- jreacher
- Registered User
- Join Date: Sep 2012
- Posts: 8,704
- Rep Power: 363348
-
-
Originally Posted By VegasLifter26⏩
This makes me think someone setup a proxy or VPN on your router.theres jsut weird chit going on that normally doesnt happen, like when I typed in weather it took me to a different location. Or when I am using chrome with adblocker I can still see ads
Can you use your phone as a hotspot and see if the behavior changes on a different network?
02-09-2022, 11:42 AM
-
#54
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Yea the other thing I forgot to mention was in the task manager the other day I saw weird processes like GoToMyPC and LogMeIn and windows shell
(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:42 AM
-
#55
- InVentive44
- Snakin down your chimney
-
- InVentive44
- Snakin down your chimney
- Join Date: Nov 2014
- Posts: 12,842
- Rep Power: 108456
-
-
Get on webcam and masturbate that will scare them away
Superight Crew
AntiVaxx Cew
COVID is a jok Crew
02-09-2022, 11:42 AM
-
#56
- olemo
- Registered User
-
- olemo
- Registered User
- Join Date: Dec 2013
- Age: 32
- Posts: 3,179
- Rep Power: 8054
-
-
Originally Posted By VegasLifter26⏩
Yep ur infected. Look my post above (srs)Yea the other thing I forgot to mention was in the task manager the other day I saw weird processes like GoToMyPC and LogMeIn and windows shell
02-09-2022, 11:44 AM
-
#57
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By jreacher⏩
the thing is my phone is messed up too..im about to post a screenshot from my phone. I get this weird image when i do a google search from my iphoneThis makes me think someone setup a proxy or VPN on your router.
Can you use your phone as a hotspot and see if the behavior changes on a different network?
Can you use your phone as a hotspot and see if the behavior changes on a different network?

(these are my opinions i am not a licensed broker by trade)
02-09-2022, 11:47 AM
-
#58
- SuperHercules
- Join Date: Jun 2014
- Height: 6'5"
- Posts: 32,378
- Subscribers: 6
- Rep Power: 566434
-
-
You should run a loop of an automated voice reading EOD's post history
Hackers will abandon their mission within 48 hours and possibly rope themselves
Hackers will abandon their mission within 48 hours and possibly rope themselves
See Shakebrah's sig
02-09-2022, 11:48 AM
-
#59
- olemo
- Registered User
-
- olemo
- Registered User
- Join Date: Dec 2013
- Age: 32
- Posts: 3,179
- Rep Power: 8054
-
-
Originally Posted By flat6pilot⏩
It is possible for some viruses to get into the Bios and would reinfect a clean reinstall of windows.
https://docs.microsoft.com/en-us/ans...ry-resets.html
https://docs.microsoft.com/en-us/ans...ry-resets.html
Originally Posted By VegasLifter26⏩
Rootkit took over your DNS. Thats why you're phone is infected too. Run the anti rootkits( all of them), run the tool i send u, Then factory mode your router.Now the download isnt starting in chrome. Usually when you download something it auto downloads but it aint working for me....strange
Windows shell is always used by hackers. it run scripts.
02-09-2022, 11:51 AM
-
#60
- VegasLifter26
- MAGA
-
- VegasLifter26
- MAGA
- Join Date: Mar 2017
- Posts: 9,040
- Rep Power: 27280
-
-
Originally Posted By olemo⏩
It does seem like the hardware was effected because the battery life increased dramatically. My phone and laptop always heat up and have chitty batteries but now they are working 2x better. Also the "fully charged" silver light on my laptop always stays on even if it isnt charging. Im skpetical that shutting down actually does thatYou have a ROOTKIT it is malware infected code into hardware.
Run multiple anti rootkit software(malware bytes bascily any you can find)
Ive had a rootkit once in my motherboard. Was hacked by russian hackers.
They are hard to get rid of.
Bascily it boots the virus into your pc when the hardware is Run so even if you a do fresh instal you will get re-infected.
edit: download all of those.
https://www.bleepingcomputer.com/dow.../anti-rootkit/
edit: this tool will check your router do this for DNS HACK. (also check what your current DNS is.)
https://www.f-secure.com/en/home/fre...router-checker
Run multiple anti rootkit software(malware bytes bascily any you can find)
Ive had a rootkit once in my motherboard. Was hacked by russian hackers.
They are hard to get rid of.
Bascily it boots the virus into your pc when the hardware is Run so even if you a do fresh instal you will get re-infected.
edit: download all of those.
https://www.bleepingcomputer.com/dow.../anti-rootkit/
edit: this tool will check your router do this for DNS HACK. (also check what your current DNS is.)
https://www.f-secure.com/en/home/fre...router-checker
the malware bytes rootkit already found 2 infections but cannot be removed because backup file is not available..fml
(these are my opinions i am not a licensed broker by trade)
Bookmarks
-
- Digg
-
- del.icio.us
-

- StumbleUpon
-
-
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts