Someone gained access to two of my clients computers systems this week. On both systems some shady ebay and paypal transactions took place.

the computers have PC Anywhere installed and vnc and I changed the authentication for both programs on both systems today.

Is there a chance they used something besides these two programs to get into the system?
Any suggestion on how to prevent this?

thanks

Dani AI

Generated

Short practical follow-up for and thanks to for calling attention to thorough cleanup: a takeover can start with remote-control software, but attackers also use stolen credentials, phishing, browser-saved passwords, drive-by malware, compromised routers/DNS, or reused passwords on other sites. Fixing the endpoint is only part of restoring trust — online accounts and the network path into the PC must be treated as potentially compromised too.

Immediate steps to reduce further damage (use a known-clean device for these):

  • Change passwords for email, eBay, PayPal, bank and any other sensitive accounts; enable two-factor authentication where available.
  • Revoke active sessions and saved payment methods on PayPal/eBay and contact their fraud teams to dispute unauthorized transactions.
  • Check and secure the email account used for password recovery (attackers often use this to reset other logins).
  • Remove saved credentials in browsers and password managers, and review recent login activity.

Technical hardening to prevent repeat incidents:

  • Remove or tightly restrict any remote-control/remote-access services you don’t actively use. If remote access is required, put it behind a VPN and limit access by IP and strong auth.
  • Inspect the router: change the admin password, disable remote administration, update firmware, disable UPnP if not needed, and review port-forwarding rules and DNS settings.
  • Apply all OS and application patches, run an offline/bootable malware scan from clean rescue media, and keep daily accounts non-admin.
  • Start using a password manager and unique long passwords; keep good offline or offsite backups.

If the fraud was significant or multiple machines were hit, preserve logs/screenshots and consider a professional incident response or law-enforcement report. Rebuilding from known-clean media and then securing accounts and the network is the reliable long-term fix.

Recommended Answers

All 2 Replies

If your computer has been compromised, you should do a complete reformat and reinstallation of the operating system, the only thing that you should backup is data. The reason for this is that hackers may have installed root kits, trojans, and other programs that pretend to be your normal applications but are in fact acting as back doors for the hacker to get back in your computer. For this reason you cannot trust any application on your workstation until you've rebuilt your entire system.

Thanks for the advice. I reformatted the drives last week and haven't had any complaints.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.