»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 11-07-2003, 03:42 PM   #1 (permalink)
Registered User
 
Join Date: Nov 2003
Posts: 3
ipsa is on a distinguished road
internal hacking or spying, need help

I have been told that someone has been hacking into the network that I utilize and been reading web based materials and internet sites for security leaks. (Ex-spouse employee of IT director)

I have my personal computer logged into this network that I rent from. I am not an employee of this company network. I know it is not the most secure, so I have to be suspicious. No privacy policy.

I believe I am being hacked by someone on this network, and it is most likely software based. I do not let anyone have access or install anything on this computer without my permission. I am confident that there has not been anyone accessing my cpu directly. (So are there employee spyware software out there that can be installed remotely)

Here is what I suspect. I think a Spector or like key logger may be on my system and have tried all the free-ware to get it off. (I suspect spector because I heard our IT had it) I have not had too much luck in identifying any "funny" processes in task manager. (I am a beginner at registry stuff) I am linked to the internet over a "internet gateway" that was not always there, and this gateway always seem to be sending and receiving bytes (is this OK) and in addition, when viewing my task manager networking graph it is always moving, never higher than .1%, but it looks like a constant seepage.

Also, I have access and am authorized to use all computers and servers since I provide them with consultation on accounting services, and want to know what to look fore if I do get a chance to see what computer programs are installed.

I want to know software that will detect spector pro or a procedure to locate a spector on my computer, and then after detection and removal, would a wireless connection prevent anyone from being able to get onto my web history and key logging and emails.

Thank you ahead of time

ipsa is offline   Reply With Quote
Old 11-07-2003, 04:00 PM   #2 (permalink)
Registered User
 
noprob's Avatar
 
Join Date: Oct 2003
Location: Mountains WV. USA.
Posts: 308
noprob is on a distinguished road
I'm certain you will get a better reply soon.
all I can say is I use Zonealarm(software based firewall) and I use Ad-Aware,also another program called Spybot-search&destroy.
These programs are all free for personal use and work very well for me.
also it may help assist others in this were you to state your operating system used.
Good Luck & Welcome to TechIMO!

P.S. the programs are linked on my www page
noprob is offline   Reply With Quote
Old 11-07-2003, 04:07 PM   #3 (permalink)
Registered User
 
Join Date: Oct 2001
Posts: 6,533
John Prophet is on a distinguished road
Welcome to the forum!

Not my area of expertise either.

But there are a few things Id do first.

Go to www.symantec.com and do their virus check...or www.antivirus.com

Download and install "ad aware"..its free and it checks for "spyware"

Do a google search for "Spector"
__________________
"Even a fool is thought to be wise if he is silent"
John Prophet is offline   Reply With Quote
Old 11-07-2003, 04:08 PM   #4 (permalink)
Registered User
 
Join Date: Oct 2001
Posts: 6,533
John Prophet is on a distinguished road
Wireless is LESS secure, lol. With wireless a kid riding around on his bike near your house can tell what brand of toothpaste your gerbil uses.....
__________________
"Even a fool is thought to be wise if he is silent"
John Prophet is offline   Reply With Quote
Old 11-07-2003, 04:12 PM   #5 (permalink)
Registered User
 
Join Date: Oct 2001
Posts: 6,533
John Prophet is on a distinguished road
http://securityresponse.symantec.com...c.spector.html
__________________
"Even a fool is thought to be wise if he is silent"
John Prophet is offline   Reply With Quote
Old 11-10-2003, 09:25 AM   #6 (permalink)
Registered User
 
Join Date: Nov 2003
Posts: 3
ipsa is on a distinguished road
follow up

thanks for the help and fast reply. does not look like spector is on my system, but what if something else is?

FYI i run Windows XP sp1.

anyone know where i can post my processes so that an expert may review and identify anything suspect. I can show all of the4m using sentinal.

I keep looling at my network connection and see that on a reboot and system just sitting idle i have bytes in the mega range going here and there, but if i do the same at home, there is no activity.
ipsa is offline   Reply With Quote
Old 11-10-2003, 09:39 AM   #7 (permalink)
puk
Registered User
 
Join Date: Oct 2001
Location: toronto
Posts: 481
puk is on a distinguished road
Re: follow up

Quote:
Originally posted by ipsa


anyone know where i can post my processes so that an expert may review and identify anything suspect. I can show all of the4m using sentinal.

post them right here!
take a screen shot and post it!

puk
__________________
puk
puk is offline   Reply With Quote
Old 11-10-2003, 09:39 AM   #8 (permalink)
Registered User
 
Chuckiechan's Avatar
 
Join Date: Oct 2001
Location: Sacto, Colliefornia
Posts: 787
Chuckiechan is on a distinguished road
Simply put, you are trying to remove a program. Keep it simple. Since you own the computer you don't have to be sneaky...

I would try a file search under "spectator.*" and see what turns up. See if there is an unistaller, if not, delete the .exe file, (or the whole folder). Or the .dat file (it may operate bur won't collect data).

Next I would try a registry search.:

start/run/regedit

If you find something, make a backup copy of your registry (export to _____). Read up on how to import a registry from a set of floppies or a CD. (Bootable?)

Then delete the line in the registry. Do note the line may be a red herring and it may be hidden else where under another name.

MY .02 but there are many people on this board who know much more than me!

PS: We love good detective stories!

__________________
"I pledge allegiance to school vouchers and to the values for which they stand"

Last edited by Chuckiechan; 11-10-2003 at 09:46 AM.
Chuckiechan is offline   Reply With Quote
Old 11-18-2003, 01:28 PM   #9 (permalink)
Registered User
 
Join Date: Oct 2003
Location: Mexico, D.F.
Posts: 37
Galaxy_EGS is on a distinguished road
Send a message via Skype™ to Galaxy_EGS
Here's a link you can also try:

http://www-tcsn.experts-exchange.com

Good luck
Galaxy_EGS is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 11:19 PM.