I really screwed up and opened an email that looks like I have been hacked

Sep 19, 2015
1,157
1,487
Naples Fl
the email looked like my monthly social security statement but when I clicked the link it installed an access program, than put the email in the trash. I shut down this PC, jumped on my mackbook and went to the router and it would not let me in. shut down and rebooted, I was able to login but it asked me for my id again and it would not open the connected devices. I shut down everything called for a IT guy to help. he seemed to have removed but today I could not access the router interface so I used by phone to log in and found a bunch of connections to eagle eye networks with en-ccuZ-002e-2 camera and a bunch of other cameras from the same manufacture
I used avast pro, malware pro and eset on line scanner

any ideas on getting rid of this crap? Oh I did pull the email out of the trash just in case
 
the email looked like my monthly social security statement but when I clicked the link it installed an access program, than put the email in the trash. I shut down this PC, jumped on my mackbook and went to the router and it would not let me in. shut down and rebooted, I was able to login but it asked me for my id again and it would not open the connected devices. I shut down everything called for a IT guy to help. he seemed to have removed but today I could not access the router interface so I used by phone to log in and found a bunch of connections to eagle eye networks with en-ccuZ-002e-2 camera and a bunch of other cameras from the same manufacture
I used avast pro, malware pro and eset on line scanner

any ideas on getting rid of this crap? Oh I did pull the email out of the trash just in case

Ouch @Coldair

That really stinks

The router, I would try to do a factory reset, keep the other systems you suspect were compromised off line.

Once you do a factory reset on the router, I would update the sw on it, and restart.

MAC book, are you backing it up at all ?

Often PC and MAC vulnerabilities are different, so hoping the MAC is ok.

If you suspect the cameras, you need to isolate them. ( this is why my NVR is running on it's own network )
 
looks like the hack is still active, I went into my router to check the firewall for activity and it was making me sign in again when switching from screen to screen and it was not populating most menus. I have saved the email and I went looking out the sender and it looks like it came from a polish group of pro communists. I think I must have stepped on some toes
 
  • Wow
Reactions: mat200
Dude unplug your router from the Interwebs

Off line change your admin password
Full reset of the router

If you can get online after plugging it back in, download the latest FW and install, then reboot

If that doesnt work, it may be cheaper to buy a new router
 
  • Like
Reactions: mat200 and bp2008
looks like the hack is still active, I went into my router to check the firewall for activity and it was making me sign in again when switching from screen to screen and it was not populating most menus. I have saved the email and I went looking out the sender and it looks like it came from a polish group of pro communists. I think I must have stepped on some toes

What kind of router is it? Try accessing it from an Incognito / Private browsing window since that should (A) have no addons enabled, and (B) use an entirely fresh state with no conflicting cookies or authentication tokens or anything like that.

Email sender addresses are very easily spoofed especially if your email provider does not implement security best-practices for domain validation and stuff like that.
 
  • Like
Reactions: mat200