Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Database & SysAdmin
  3. System Admin
  4. tracking intruder

tracking intruder

Scheduled Pinned Locked Moved System Admin
question
5 Posts 4 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M Offline
    M Offline
    Martin Blanc
    wrote on last edited by
    #1

    When I came back from my holidays, I found someone used my computer (Windows NT) and besides others, installed there 'something'. There were remains of InstallShield (_delis43.ini, Zdata51.dll, _ins5176._mp) in a TEMP directory. My question is how can I find out what activities were performed on my computer. Will you give me a hint where and how I should look for them. Regards, Martin

    D R M 3 Replies Last reply
    0
    • M Martin Blanc

      When I came back from my holidays, I found someone used my computer (Windows NT) and besides others, installed there 'something'. There were remains of InstallShield (_delis43.ini, Zdata51.dll, _ins5176._mp) in a TEMP directory. My question is how can I find out what activities were performed on my computer. Will you give me a hint where and how I should look for them. Regards, Martin

      D Offline
      D Offline
      Daniel Turini
      wrote on last edited by
      #2

      look at the browser's history and list all files accessed/modified on a specific date range. If you have XP/Me you can look at System Restore's snapshots too. Q261186 - Computer Randomly Plays Classical Music

      1 Reply Last reply
      0
      • M Martin Blanc

        When I came back from my holidays, I found someone used my computer (Windows NT) and besides others, installed there 'something'. There were remains of InstallShield (_delis43.ini, Zdata51.dll, _ins5176._mp) in a TEMP directory. My question is how can I find out what activities were performed on my computer. Will you give me a hint where and how I should look for them. Regards, Martin

        R Offline
        R Offline
        Roger Wright
        wrote on last edited by
        #3

        Do a search for *.log on your system. Most installers leave an audit trail behind them. I've been playing with this myself today, and discovered quite a few attempts to hack into my system. None succeeded, and all returned 550 and 404 errors, but I'm planning to send each and every one of my admirers a personalized copy of BackOrifice as soon as I can get around to it.:-D "Another day done; all targets met; all systems fully operational; all customers satisfied; all staff keen and well motivated; all pigs fed and ready to fly." - Jennie Agard, McGuckin Hardware Systems Manager

        1 Reply Last reply
        0
        • M Martin Blanc

          When I came back from my holidays, I found someone used my computer (Windows NT) and besides others, installed there 'something'. There were remains of InstallShield (_delis43.ini, Zdata51.dll, _ins5176._mp) in a TEMP directory. My question is how can I find out what activities were performed on my computer. Will you give me a hint where and how I should look for them. Regards, Martin

          M Offline
          M Offline
          Megan Forbes
          wrote on last edited by
          #4

          Download Zonealarm from Zone Alarm[^] if you think this intrusion was via the internet. It's a brilliant software firewall, and what's more, it's free. :-D


          I've always heard that there was an idea behind Win ME... I still can't figure out what that was... anyboy know??? I;ve herad the idea was that it was supposed to be n operating system but I doubt this. - Brian Delahunty

          R 1 Reply Last reply
          0
          • M Megan Forbes

            Download Zonealarm from Zone Alarm[^] if you think this intrusion was via the internet. It's a brilliant software firewall, and what's more, it's free. :-D


            I've always heard that there was an idea behind Win ME... I still can't figure out what that was... anyboy know??? I;ve herad the idea was that it was supposed to be n operating system but I doubt this. - Brian Delahunty

            R Offline
            R Offline
            Roger Wright
            wrote on last edited by
            #5

            Buy the Pro version, Megan - it's cheap, and so much nicer! "Another day done; all targets met; all systems fully operational; all customers satisfied; all staff keen and well motivated; all pigs fed and ready to fly." - Jennie Agard, McGuckin Hardware Systems Manager

            1 Reply Last reply
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups