Took me over a day or so to figure out exactly what happened after I noticed fradulent purchases from my eBay and Paypal and text message sent remotely from my phone (via Pushbullet app), but determined from talking to eBay (and finding out the orders were made from my IP address) and then checking my browser history and finally system logs that the culprit was a Russian logging into my Remote Desktop via a proxy.
I turned off remote desktop and un-DMZed my connection. Changed some passwords etc. But now worried that with unrestricted access to my machine they installed a keylogger or something.
In light of that, seems like the smart/safe thing to do would be to reinstall Windows and whipe everything. I am very busy right now and this would be an _IMMENSE_ pain, but I will do it if it is the only intelligent solution.
Just wondering if there are ways to be at least reasonably sure that there are no backdoors on my machine. Is looking through the running Processes list good enough? If so, would such a program be running under my username, LOCAL, or could it be listed as a service or SYSTEM?
Also, since I would in theory like to be able to use RDP again in the future, does anyone have any tips for making it more secure? No idea how this hacker was able to log in via my remote desktop, but looks like he logged in several times over the last 5 days.
Thanks in advance for any help or advice
I turned off remote desktop and un-DMZed my connection. Changed some passwords etc. But now worried that with unrestricted access to my machine they installed a keylogger or something.
In light of that, seems like the smart/safe thing to do would be to reinstall Windows and whipe everything. I am very busy right now and this would be an _IMMENSE_ pain, but I will do it if it is the only intelligent solution.
Just wondering if there are ways to be at least reasonably sure that there are no backdoors on my machine. Is looking through the running Processes list good enough? If so, would such a program be running under my username, LOCAL, or could it be listed as a service or SYSTEM?
Also, since I would in theory like to be able to use RDP again in the future, does anyone have any tips for making it more secure? No idea how this hacker was able to log in via my remote desktop, but looks like he logged in several times over the last 5 days.
Thanks in advance for any help or advice