Hello together and thanks in advance!
First of all I want to mention that i am an software developer / architect so we can speak on a somewhat technical level if required.
5 weeks ago when I worked on a Word document (Windows 10 Home) somebody began to write into it while I was watching. He wrote a sentence which would mean something like "Now he is f*****" in English.
This felt like some kind of remote access trojan. I am rather paranoid and just do Gaming, Photoshop and Office stuff (if MS Office is mandatory) in Windows. Important stuff is usually done in Ubuntu.
So I took the Computer from the network and tried to investigate. I have a Kaspersky Internet Security installed and checked the past network activity and there was nothing I would consider suspicious. No big data transfer amounts and no executables which would make me nervous.
Since I did not find anything I formatted my System disk and nearly everything else on the other disks except some Steam games. I changed every user account I could remember. This was a lot of work and I felt save.
Now suddenly 2 days ago while working somebody wrote into my browser search bar the same sentence while I was watching and you can imagine that I was shocked.
The last 2 days I tried to find some kind of RAT or anything which is suspicous with absolutely no success. Without knowing how this backdoor works I can never be sure that I have a clean system (yeah I know we can never know but you know what I mean).
What I tried already
- Kaspersky Scans
- Kaspersky Rescue Disk Scans for finding Bootkits
- and many more
- I checked FRST logs (as far as I understand them - e.g. for unsigned drivers)
- watched sysinternals process explorer and process monitor for ages to find something suspicious (an unknown process, something unsigned, something with no company, some packed image, checked strings for URLs etc..)
- checked sysinternals Autostarts for anything obivious
and I found absolutely nothing. This is very scary since a NAS system in the same network contains years of development work and personal documents i want to know save.
Since I run out of ideas I am writing in here. Maybe some of you guys is able to give some advice what I can do. I am also wondering whether I should call the cops in this case.
Thank in advance!
Edited by empersec, 07 June 2017 - 03:04 PM.