Jump to content

Someone is remotely trying to control my computer?

Go to solution Solved by Godlygamer23,

Get MalwareBytes and disconnect your Internet connection at the main line.

So I was on my desktop about 20 min ago. My laptop is beside me turned off (windows 10). Suddenly my laptop turned on, logged on by itself (no passcode lock on my laptop), and went to chrome. Before it could do anything serious I disconnected my wifi and started my antivirus kaspersky. Apparently, my protection was disabled and my data bases needed an update. Long story short I went through the updating process and started my virus scan. 

 

But this is not where it stops. Kaspersky keeps telling me that winnet advanced program is trying to send a udp packet(or something like that. It goes on about this port and ip). I block this connection but every few minutes it requests again with a new ip and port. My wifi is still off. 

 

What can I do? What do I do? I need to do other things but I'm afraid if I don't keep blocking this connection I'll lose my files. Help!

 

UPDATE: Can anyone tell me what winnet advanced program is?

UPDATE: Virus programs have found 9 adware and 1 trojan

UPDATE: Winnet udp packet request stopped coming

Link to comment
Share on other sites

Link to post
Share on other sites

First off I hope you have another computer because personally, as someone who doesn't know a whole lot about cyber security, I would take that battery the hell out of there

Shipping sucks

Link to comment
Share on other sites

Link to post
Share on other sites

Backup your files, run MalwareBytes, clean everything.  If the outgoing connection requests still happen, time for a system refresh.  Win8 and 10 have pretty good refresh options where everything is reset to stock.

 

@Mundlier

QUOTE ME IN A REPLY SO I CAN SEE THE NOTIFICATION!

When there is no danger of failure there is no pleasure in success.

Link to comment
Share on other sites

Link to post
Share on other sites

yea, I have my desktop

 

But I need my laptop ready for tomorrow.

Link to comment
Share on other sites

Link to post
Share on other sites

TeamViewer has a backdoor, so if you have anything like that installed, uninstall it immediately.

- CPU: Intel i7 3770 - GPU: MSI R9 390 - RAM: 16GB of DDR3 - SSD: Crucial BX100 - HDD: Seagate Barracuda 1TB -

 

Link to comment
Share on other sites

Link to post
Share on other sites

Get MalwareBytes and disconnect your Internet connection at the main line.

"It pays to keep an open mind, but not so open your brain falls out." - Carl Sagan.

"I can explain it to you, but I can't understand it for you" - Edward I. Koch

Link to comment
Share on other sites

Link to post
Share on other sites

Well, I know that Win 10 can start the computer by itself for no reason... Does the same with my PC when I put it into sleep mode... But why did your laptop go to Chrome - no idea

Link to comment
Share on other sites

Link to post
Share on other sites

Reinstall your OS and change all your online passwords. You may be able to save some of your files (pictures, documents and such) but everything else needs to go. Yes, this may seem a little extreme but you don't know how long this person was digging through your stuff. Better safe than sorry.

I've built 3 PC's, but none for myself... In fact, I'm using an iMac that my dad bought for me as my desktop. Awkward...

Please don't say "SSD drive." By doing so, you are literally saying "Solid State Drive Drive" and causing my brain cells to commit suicide. The same applies to HDD (Hard Disk Drive) and PCIe (Peripheral Component Interconnect Express).

Link to comment
Share on other sites

Link to post
Share on other sites

What do you mean by main line? @Godlygamer23

The cable that's connected to your modem - disconnect it.

"It pays to keep an open mind, but not so open your brain falls out." - Carl Sagan.

"I can explain it to you, but I can't understand it for you" - Edward I. Koch

Link to comment
Share on other sites

Link to post
Share on other sites

so kill my wifi right? @Godlygamer23

Kill the modem, but if everything is connected to your router, disconnect the Internet connection from there.

"It pays to keep an open mind, but not so open your brain falls out." - Carl Sagan.

"I can explain it to you, but I can't understand it for you" - Edward I. Koch

Link to comment
Share on other sites

Link to post
Share on other sites

So I killed the modem, and when I did that the requests stopped popping up. I waited about 10 min before starting it up again. The requests started popping up again (my internet to the computer was always disconnected). I just want my virus scans to finish up then go on to resetting my pc. Should I stay in the dark? @Godlygamer23

 

Ps. sorry if I'm sending too many messages, I'm just very worried.

Link to comment
Share on other sites

Link to post
Share on other sites

So I killed the modem, and when I did that the requests stopped popping up. I waited about 10 min before starting it up again. The requests started popping up again (my internet to the computer was always disconnected). I just want my virus scans to finish up then go on to resetting my pc. Should I stay in the dark? @Godlygamer23

On this particular PC, I would stay in the dark for a bit.

"It pays to keep an open mind, but not so open your brain falls out." - Carl Sagan.

"I can explain it to you, but I can't understand it for you" - Edward I. Koch

Link to comment
Share on other sites

Link to post
Share on other sites

So I killed the modem, and when I did that the requests stopped popping up. I waited about 10 min before starting it up again. The requests started popping up again (my internet to the computer was always disconnected). I just want my virus scans to finish up then go on to resetting my pc. Should I stay in the dark? @Godlygamer23

 

Ps. sorry if I'm sending too many messages, I'm just very worried.

What does the requested message said? 

Link to comment
Share on other sites

Link to post
Share on other sites

Like I said @JerkyMcDilerino

 

winnet advanced program from the low restricted group is trying to send you a udp packet from a remote computer .... then says something about a port and ip

Link to comment
Share on other sites

Link to post
Share on other sites

did Malwarebytes  find anything?

i5 4670k @4.2ghz / MSI Z87 G45 / EVGA GTX 960 SSC / Samsung  840 EVo SSD / WD Green 1tb HDD / Corsair H75 / Corsair Obsidian 750D / Corsair CS750M

Link to comment
Share on other sites

Link to post
Share on other sites

only adware, nothing serious yet. @Tetters

At this point I would try and uninstall Winnet, its a service that appears to come with Windows (IE addon) but the creator is a Korean company. Its also a favorite place to hide malware, so uninstall it if you can. The info I got is from the quick webtrawl I have done.

 

And dont worry about multiple questions or postings, the only stupid thing you can do is NOT ask ... so fire away

i5 4670k @4.2ghz / MSI Z87 G45 / EVGA GTX 960 SSC / Samsung  840 EVo SSD / WD Green 1tb HDD / Corsair H75 / Corsair Obsidian 750D / Corsair CS750M

Link to comment
Share on other sites

Link to post
Share on other sites

When cleaning the system, you may wish to boot into Safe Mode.

"It pays to keep an open mind, but not so open your brain falls out." - Carl Sagan.

"I can explain it to you, but I can't understand it for you" - Edward I. Koch

Link to comment
Share on other sites

Link to post
Share on other sites

UPDATE: Kaspersky detected HEUR:trojan-downloader

 

This was deleted

Link to comment
Share on other sites

Link to post
Share on other sites

UPDATE: Kaspersky detected HEUR:trojan-downloader

 

This was deleted

ok - thats good, use MAlwarebytes after all the Kaspersky cleaning too. If you have Ccleaner, run that too to clean up the registry.

i5 4670k @4.2ghz / MSI Z87 G45 / EVGA GTX 960 SSC / Samsung  840 EVo SSD / WD Green 1tb HDD / Corsair H75 / Corsair Obsidian 750D / Corsair CS750M

Link to comment
Share on other sites

Link to post
Share on other sites

UPDATE: Kaspersky detected HEUR:trojan-downloader

 

This was deleted

@Godlygamer23 @Tetters

 

So my antivirus caught this, a trojan downloader? It says downloader so does it mean that there's still a trojan? Or can I move on to the reset?

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×