how to know your computer has been attacked

19
University of Duhok Faculty Of Science Computer Department Submitted by: Dler Omer Ahmad Mamand HOW TO KNOW YOUR COMPUTER HAS BEEN ATTACKED

Upload: ahmad-mamand

Post on 13-Apr-2017

90 views

Category:

Internet


1 download

TRANSCRIPT

Page 1: How to know your computer has been attacked

University of DuhokFaculty Of Science Computer Department

Submitted by: Dler Omer Ahmad Mamand

HOW TO KNOW YOUR COMPUTER

HAS BEEN ATTACKED

Page 2: How to know your computer has been attacked

Step 1

Msconfig

Page 3: How to know your computer has been attacked

Step 2

Page 4: How to know your computer has been attacked

Step 3

Page 5: How to know your computer has been attacked

start run regedit HKEY_LOCAL_MACHINE Software Microsoft window current Version run

Regedit

Page 6: How to know your computer has been attacked
Page 7: How to know your computer has been attacked
Page 8: How to know your computer has been attacked

1. First make sure that how many users’ accounts are there in your computer

2. Find out if there are any unknown accounts with higher privileges.

3. Someone may create a user account without your knowledge and can use that account to access your system from a remote location.

User Account

Page 9: How to know your computer has been attacked

4. Go to the control panel5. open the user accounts and check if the

user is turned off and if there is any other account that you did not create.

6. Delete any unknown account except known account

User Account

Page 10: How to know your computer has been attacked

User Account

Page 11: How to know your computer has been attacked

User Account

Page 12: How to know your computer has been attacked

System.ini

Is not Hacked

Page 13: How to know your computer has been attacked

Is HackedTimer=timer.drv*** *** ***

Page 14: How to know your computer has been attacked

Net User

Page 15: How to know your computer has been attacked

Go to the the run Write cmd Write netstate –ano watch state established and pid number Go to the task manager Go to process look the pid number Right click to the pid open file location and

delete this server or vires

Netstat -ano

Page 16: How to know your computer has been attacked
Page 17: How to know your computer has been attacked

Process Red color : finish the work Process green color :is hacked and continue Process Yellow color : hacked and changed

port and server

TCP View

TCP View is application :is check computer

Page 18: How to know your computer has been attacked

TCP View

Page 19: How to know your computer has been attacked

THANK YOU ANY

QUATION?