It looks like you're using an Ad Blocker.
Please white-list or disable AboveTopSecret.com in your ad-blocking tool.
Some features of ATS will be disabled while you continue to use an ad-blocker.
originally posted by: GailNot
So it started when I woke up and my Windows 8.1 was in Tablet mode. I don't have a tablet. I didn't even know there was a tablet mode.
So I had to google and find out about it to get my Windows back to the way it should be.
I went to Windows 10, and about 6 months later the same thing happens.
This time I knew what was the problem. But I didn't know why it happened two times.
I did more google searches about things.
Then I learned someone could be using my computer.
I found out someone was accessing my Yahoo account then, quite by accident. I was up in the middle of the night, around 3 am. And saw 5 charges of $1999 each to Sony Playstation for a game about Forza, or something like that.
I thought that the person ordering entered the wrong email address. Until I woke the next morning and found all of the emails about the Playstation deleted. They were no longer there. I knew right away something was wrong. And look at account history and found that two devices connected from Taiwan.
I deleted my Yahoo account and created a gmail account.
A couple of days ago I read that all of the Yahoo accounts had been comprised, and had been sold on the deep/dark web.
I learned that people will install vpns (virtual private networks) on your computer when they hack you. And to find out about it to look at your Firewall. I opened my Windows Firewall and had 3 or 4 vpns active that I had never seen or heard of before. And even something in all chinese or something like it.
I reinstalled Windows 10 fresh. And did the update. And downloaded TCPview. That shows all traffic going to and from my computer, I think.
Anyway i got the knew Windows 10 update, which was a fresh windows install, and also was watching TCPView.
This morning I awoke to an IP adress, I will not post here. But it belonged to Bill Blackwater. And when he saw, or they saw I saw them my internet disconnected.
originally posted by: Moresby
It sounds like you may be getting a bit paranoid. Generally, hackers don't target individuals. Impose some sensible security measures on your computer. And get on with your life.
IP Address [***.***.**.**] is listed in the CBL. It shows signs of being infected with a spam sending trojan, malicious link or some other form of botnet.
It was last detected at 2016-08-11 15:00 GMT (+/- 30 minutes), approximately 11 days, 2 hours, 29 minutes ago.
This IP is infected (or NATting for a computer that is infected) with the misc spambot. In other words, it's participating in a botnet.
If you simply remove the listing without ensuring that the infection is removed (or the NAT secured), it will probably relist again.
How to resolve future problems and prevent relisting Norton Power Eraser is a free tool and doesn't require installation. It just needs to be downloaded and run. One of our team has tested the tool with Zeus, Ice-X, Citadel, ZeroAccess and Cutwail. It was able to detect and clean up the system in each case. It probably works with many other infections.