How do I get rid of someone who has control over my remote desktop?! Its killing me – I am literally watching stuff being erased! HELP!
I’m on an Acer 7550 Aspire Laptop running Windows 7 Home Premium.
if you are in the network with other user then any one can remotely access your computer. to prevent this situation provide password to your account or remove your pc from network.
You need to close any open ports on your computer.
I had the same thing happen. After tryin all the fixes mentioned, I called my internet provider. Not only did he change my IP address but he also secured my net works in 2 ways and worked endlessly to reset the comuter and make sure it was virus free? In conclusion he had me chang all my pastwords, he mcontactd DELL explaining the problems. Custom servivn was exemplary and so far so good with the computer!
First off let me thank you for taking the time to help me with my dilemma. I purchased this Laptop from a local independent retailer a couple months ago as a second owner. It was in perfect shape and much better than the piece of junk HP dv2000 that finally died on me. (By the way DO NOT buy an HP product) not to get off track here but did you know that in 2009 HP built a whole series (The dv Series of Laptops) that where a mid range purchase $900.00 to $1200.00 new, that they where aware had faulty Nvidia graphics chips! Anyway so I bought this laptop used for $400.00 and it's a quality build. 17" screen 4Gig of Ram 2 AMD Athalon X2 Processors running at 2.1gigs and a 500GB hard drive (I thought Pretty good deal right?) So about 2-3 weeks later I notice my passwords are changing. Now Im sure like alot of people who are a little security paranoid I change my passwords often and use large strings of Alpha/Numeric and Symbolic characters. I figured I had just typed them in wrong or written them down wrong and would just change them either back to what I thought they where or created new ones. Now let me be clear, Im 43 years old and although no where near an expert I have been working on these systems for 25 years plus but in a fairly limited capacity. I own a Commercial Art and Advertising company and for most of that span I have only mostly focused on software, hardware and applications and builds related to my vocation and industry! IT and security has been limited to home networks and creative passwords! So when, shall we say, these small glitches I started having became more and more frequent I decided to do some research. I wont take much time walking you through that but lets sum it up by saying I have discovered that the prior owner still has control of my Root and remained Owner/Creator on this machine and has installed a variety of ports and fraudulent certificates as well as literally hundreds of registry modification allowing him to access this machine remotely. My only solution was to re-format and re-install. Virus scans, which I had run many times and used several would not have made a bit of difference in my case. This has been a tremendous education for me and although satisfied that I have fixed the issue with the help of people more knowledgeable than myself (Thank You, Thank you Thank you!) and not having to spend what Im sure would have amounted to hundreds of additional dollars out of my pocket I am disillusioned by the so call expertise of my local computer merchant who should have seen this and repaired it before reselling it to me. I wont be using him again! So that's the story of "The Ghost In The Machine" and how I eventually, after hours and hours (Something like 70 hours all told) of speculation, second guessing, self doubt and im sure what my wife would describe as senseless paranoia (She truely thought I was seeing Gremlins on the airplane wings!!!) my issue was resolved.
glad that you fixed your problem, formatting and reinstalling windows is surgery precision and 100% working solution:)
added security if you wish try Zemana Antilogger
Don’t Fall Victim to Keyloggers: Use These Important Anti-Keylogger Tools
Sorry but you are the one to blame. You bought a used PC of unknown origin. You figured you were going to save money because the O/S and applications were already installed. The very first thing you should have done, after bringing home a USED PC, was to change all the passwords if you wanted to continue using the installed software. If you were going to install your own software, which ultimately you had to do anyway, you should have asked the dealer to reformat the hard drive or you should have done it yourself to prevent exactly what happened.
As soon you turned on the PC, even before connecting to the Internet, you should have checked all the settings. You would have seen that Remote Access was turned and you could have turned it OFF. Then, before installing any of your files, you should have used the PC for a couple of days just to test it out. Only after you were perfectly satisfied with how the PC worked, should you have copied your files to it and started using it for your purposes. You did not take even the most rudimentary precautions and you got burned.
Unless you gave explicit instructions to the computer dealer on what he was to do with this PC, there is no way you can lay the blame on the dealer. He sold you a computer and he probably figured that you knew what you were getting and what to do with it. Remember, when it comes to second hand anything, it is Buyer Beware.
remove the internet connection :)
that's surgery precision:)
Out of curiosity, did you allow them to take control in the first place? Is this someone that you know?
6.If you are using Windows firewall, Windows will automatically configure the firewall to allow Remote Desktop Connections but if you are using a third party firewall, you should allow RDP traffic to be passed from the firewall.
To begin with, you need to disconnect from the internet - turn off any WiFi connections, and unplug any physical - Ethernet - connections. You may need access to another computer to access the below links.
Turn off Remote Connection Sharing - here is a link:
Run a FULL system Malware check with a free tool like this:
Setup a free Firewall to block your PC - this is one option, ZoneAlarm - look for the free version:
Get yourself a software VPN to block any "Man In the Middle" attacks - CyberGhost is free:
Get yourself a Password Manager, and change ALL your passwords to secure, uncrackable, ones. LastPass is the best:
Since you have obviously been hacked, past the steps above you will need someone with a knowledge of IT. You should properly configure your router, and completely wipe your hard drive by formating it with zeros using DOD level shredding, then reinstall Windows. That said, the above should knock anyone out, and the combination of LastPass, using CyberGhost or a similar VPN on any WiFI connection, and never using the same password more than once, will give you a very good jump on being secure.
First is to disconnect your laptop from the network, turn off Wifi and unplug any network cable attached. This should stop anyone from continuing to access your laptop through Remote Desktop. If you are connecting through mobile broadband, disconnect from there too.
Next, disable Remote Desktop as listed out by Jim Chambers above.
Reset all the password of the user accounts on your laptop:
1) Click Start
2) Click Control Panel
3) Click User Accounts
4) Click "Change your password" and reset your user password
5) Click "Manage another account"
6) Repeat step 4 for each account in the list
Lastly, any idea why your laptop is being connected through Remote Desktop? I'm assuming the connection is unauthorized.
Did you give out your windows login to anyone?
Or did you recently install any software?
You might want to run an antivirus scan/malware scan on your laptop.
disable or uninstall any app for remote viewing like teamviewer, vnc viewer, etc. also check your windows remote viewing settings and disable it.
First step would be to take your computer off the internet - unplug it or turn off the wifi manually, but get it off. Then proceed to uncheck the allow remote assistance to the computer.
How about unplugging the network instead of watching it happen? At least that would have been my first thought...
Use some Anti Virus Rescue (live) CD to make sure it's not some trojan giving access.
Then with network still unplugged or disconnected go into the "Add and remove Software" menu within Control Panel and delete any VNC or TeamViewer application.
Finally under "Control Panel > System and Security > System" click the advanced system configuration, select the Remote tab and select to not allow any Remote desktop connection.
That should get rid of most the remote desktop options.
The fastest way is to disconnect your modem from the computer. After that, you can use Jim's steps to disable the functionality in Windows. If the remote control is via some other sofware (LogMeIn, TeamViewer, etc) you will need to uninstall them or disable remote control functionality in them although they generally will prompt you when someone else wants to take control and in TeamViewer at least, it will provide a small box in the lower right corner that allows you to disconnect the other user.
Click Start button
Right click Computer
Select Advanced system settings
Select Remote Tab
uncheck Allow remote assistance to this computer