My Computer is being HACKED
teresa1517
Member Posts: 46 ■■□□□□□□□□
in Off-Topic
I transferred money into my bank account and within 20 minutes it was gone.
I called the fraud department and they replaced it instantly.
Less than 24 hours later it was taken again.
What can I do to make sure I am not being stalked and hacked and prevent it from happening again?
I called the fraud department and they replaced it instantly.
Less than 24 hours later it was taken again.
What can I do to make sure I am not being stalked and hacked and prevent it from happening again?
Comments
-
zxbane Member Posts: 740 ■■■■□□□□□□I would first verify that the incident isn't linked to your bank account rather than your computer.
-
j.petrov Member Posts: 282If you are on Windows I would run netstat -o in the cmd and take a look at what is connected. This will show any process IDs that are associated with each connection. You can then match the PID with the PID in task manager under services to see if you have anything that doesn't look right connected.
-
[Deleted User] Senior Member Posts: 0 ■■□□□□□□□□I would first verify that the incident isn't linked to your bank account rather than your computer.
-
iBrokeIT Member Posts: 1,318 ■■■■■■■■■□Back up, format, reinstall OS, install AV and scan backups before restoring2019: GPEN | GCFE | GXPN | GICSP | CySA+
2020: GCIP | GCIA
2021: GRID | GDSA | Pentest+
2022: GMON | GDAT
2023: GREM | GSE | GCFA
WGU BS IT-NA | SANS Grad Cert: PT&EH | SANS Grad Cert: ICS Security | SANS Grad Cert: Cyber Defense Ops | SANS Grad Cert: Incident Response -
lsud00d Member Posts: 1,571Call them and tell them to disable your online banking account.
If it occurs again...you got bigger problems.
Also...do you bank from your phone? Have you changed your password? Have you updated your security questions? Does your bank offer two-factor authentication?
It's possible you have malware with a keylogger. -
zxbane Member Posts: 740 ■■■■□□□□□□I just don't understand where the assumption that it is absolutely related to the computer comes in, rather than the bank account itself being compromised.
-
kriscamaro68 Member Posts: 1,186 ■■■■■■■□□□Close the account at the bank. Maybe move to a different bank entirely. Re-install your OS for safe measure following 'iBrokeIT' method.
-
Plantwiz Mod Posts: 5,057 ModI would be on the phone working with the bank immediately, and not so much online.
Stop using your machine that you believe is infected.
Once the bank side is secured, then look into troubleshooting your machine.
Do you have an alternate device to access online searches with while you problem solve the machine? If not, I'd consider obtaining one. What a disappointing bank if you report a fraud, they replace funds, and the problem happens again I'd likely consider a new bank (local one or a credit union)
Get fraud alerts on your credit reports and such too, just to slow down anyone trying to be 'you'.Plantwiz
_____
"Grammar and spelling aren't everything, but this is a forum, not a chat room. You have plenty of time to spell out the word "you", and look just a little bit smarter." by Phaideaux
***I'll add you can Capitalize the word 'I' to show a little respect for yourself too.
'i' before 'e' except after 'c'.... weird? -
YFZblu Member Posts: 1,462 ■■■■■■■■□□If you are on Windows I would run netstat -o in the cmd and take a look at what is connected. This will show any process IDs that are associated with each connection. You can then match the PID with the PID in task manager under services to see if you have anything that doesn't look right connected.
...unless any malware which may be on the system contains rootkit modules; at which point netstat is lying. Zeus variants are known to exhibit the behavior described in the original post. It will behave as a man-in-the-middle between the User's browser and the bank; redirecting transferred funds to the attacker's account. Additionally it will keylog / screenshot the User - so once the money has been returned, it's trivial for the attacker to login and transfer the money again.
My advice: Replace credit/debit cards, change your account numbers, and reimage any computers you own and use. I would be formatting my smartphone as well. IMO, when your livelihood is at stake, now is not the time to mess around. -
teresa1517 Member Posts: 46 ■■□□□□□□□□If you are on Windows I would run netstat -o in the cmd and take a look at what is connected. This will show any process IDs that are associated with each connection. You can then match the PID with the PID in task manager under services to see if you have anything that doesn't look right connected..
My advice: Replace credit/debit cards, change your account numbers, and reimage any computers you own and use. I would be formatting my smartphone as well. IMO, when your livelihood is at stake, now is not the time to mess around.
Also, changed password.kriscamaro68 wrote: »Close the account at the bank. Maybe move to a different bank entirely. Re-install your OS for safe measure following 'iBrokeIT' method.kMastaFlash wrote: »Check this first. If not, Post the following here: 1. Operating System platform (PC, Mac, or possibly your smartphone) 2. What exactly was going on when this occurred? 3. I would get the information/transaction that occurred on you bank statement, find out who the transaction traces back to and go from there.
I found out when it first happened at 3:00 a.m. in the morning when I went to buy gas.
As for tracing back, how would the bank be able to do that?Call them and tell them to disable your online banking account.
If it occurs again...you got bigger problems.
Also...do you bank from your phone? Have you changed your password? Have you updated your security questions? Does your bank offer two-factor authentication?
It's possible you have malware with a keylogger.
How can I find out if there is malware with a keylogger, and get rid of it? -
YFZblu Member Posts: 1,462 ■■■■■■■■□□^ You re-installed the operating system, correct? You have likely gotten rid of the malware in that case.
-
teresa1517 Member Posts: 46 ■■□□□□□□□□^ You re-installed the operating system, correct? You have likely gotten rid of the malware in that case.
The bank incident happened October 2012.
Not being able to log into my pc with my own password, was May 2013.
That is when I reinstalled the OS. -
YFZblu Member Posts: 1,462 ■■■■■■■■□□For some reason Comodo thinks signed malware is noteworthy - This isn't a new thing. Just more eyerolling news from Antivirus vendors I suppose.
-
teresa1517 Member Posts: 46 ■■□□□□□□□□Came across this today and figured I'd toss it up here.
Thanks -
kristankelsch87 Banned Posts: 5 ■□□□□□□□□□Definatlly its issue from bank side, I think you should close your account if that happens again..