Ex-husband is hacking me under Webroot's radar. Can you all find him?

  • 27 April 2018
  • 7 replies
  • 131 views

Userlevel 1
Hi, Webroot Community,
 
 
I'm a longtime Webroot user. I'm also a devoted mom and was a loyal wife. I'm not really a computer person -- or, I didn't think I was... before. I'm a teacher by training, and also a writer. I'm a rule-follower, a quiet person, and utterly ethical. I'm not a computer geek by nature, but am becoming one by necessity.
 
My ex-husband is wealthy, powerful, and a computer geek by training. He is ALWAYS on the computer. He works on it, cheats on it, and lives on it being generally dastardly in various ways. He's well-connected, and protected. He was horrible to us, and it's all on public record. The three kids and I finally got freed of him (after six years fleeing in court and via social service agencies), but now he's stalking us again -- online. He appears to be accessing us, still, through our computers.
 
The local Sheriff called last year to warn us we were victims of postal theft and probably identity theft. My bank account about 8-9 months later proved this to be true. I don't know if it was connected to him.
 
My computer says there's no problem of any sort, and so does Webroot. BUT, I see that my es is following me under Webroot's radar somehow. 
 
How do I know? My gut, and...
 
In the last month, my email (Yahoo -- yeah, I know... ) started locating out of my ex's obscure little hometown, with weather posts and singles ads for his no-one-else-would-care hometown info. I'm not the singles-ad type. My ads used to promote parenting, sports, politics -- normal stuff -- and from MY own location.
 
When I change my passwords, Yahoo and Google address ME as the unauthorized user.
 
If it's useful to know, I also noticed sometime last fall that I was having problems with Window Update Assistant (like a virus), and then my emails and phone texts began to duplicate incoming and outgoing calls and messages, but only sporadically, at about the same time. 
 
Then, last week, I started to receive texts in my car's Uconnect through a really old phone dialer app on my crappy old cell phone. (I know it sounds like a first-world problem to have Uconnect stalking, but y'all, I won the car -- yes, seriously, grand prize in a national contest -- right after losing our family home to foreclosure because of this man and one of his women... and my own father, who's connected to him instead of me, also -- and to Scientology.) 
 
It's a good reminder to all of us that the pendulum does swing wide.
 
All crazy, I know. I'm writing a book. Be that as it may, though, please don't be distracted by the details. I need real help from the real experts in here.
 
I am running from savvy people in this situation, and trying to get smarter than they are, in a hurry. These people put us all in grave danger in recent years already. They are not the sort of people who anyone should have stalking them. 
 
I don't expect them to be in here on Webroot Community, though -- unless they are using a keylogger.
 
It is important to me that you know that no one ever knows how to help us because of their reach -- and neither of them are themselves very bright! It's absurd. They are just so well-connected, and my ex has some aptitude in computer systems. I am certain I can outsmart them at their own game eventually if I apply myself for our kids' sake. I only need to do so long enough to raise the youngest child to safety and independence. Then, I can go and DO in my ow life, independently, in the real world as I see fit -- we each can as we all see fit. The older two children are already grown and safe and utterly free now, both happy and, miraculously, very healthy. The youngest is still vulnerable for several reasons I won't go into here, but mostly they're health-related issues.
 
As long as my ex or his accomplices can follow us online, though, we are all vulnerable -- and in real danger. It's his last grip on us, and I expect that's why he's doing it: because he can, better than I can currently protect us in here. He's unstable (diagnosed Cluster 😎, unpredictable, and absolutely controlling. 
 
Can you help me? Can you teach me what I need to know about security of this sort? I might have a keylogger on my system. I have been scanning my startups and my actives. I've been deactivating stuff, (found an Adobe Invoker? and some other stuff), and warning others. I've cleaned up my computer substantially, but when I shut down something called osrss.exe tonight, I almost crashed my computer (blackout screen until I forced a shutdown); then, I figured out that it's OK when it's in my 32/ file path.... sigh... Rookie mistake, no doubt. I'm bumping around in the dark here, feeling pretty alone so far. This community site, though, seems very friendly, positive-minded, smart, and helpful -- all things I want and need around me while I become savvy about this stuff.
 
My intention is to learn as much as I can about cybersecurity and see if maybe all this happened to me and to our little family for some yet unrealized, greater good, ultimately. 
 
I'm teaching myself coding now and lately feel like the virtual version of Jennifer Lopez's character in "Enough". Y'know? One of these days, with your help, I might just be able to chase these guys right back up their evil, virtual pipeline and take them down. ... or, just live my life in peace. Either would be swell.
 
Thanks for reading, and for helping, if you can, and if you're willing.
 
- T.

7 replies

Userlevel 7
Badge +62
Hello BrazenRaven,
 
Welcome to the Webroot Community,
 
This is a heart wrentching story and thank you for sharing.
 
It's always difficult to live your life under fear, drama and stress. Which sounds like you have been going through alot for a long time.
 
Here are a few articles that I have googled which I am not sure you have done this yet or not?
http://www.thewindowsclub.com/keep-hackers-out-of-your-computer
https://www.wikihow.com/Prevent-Hacking
https://www.lifewire.com/ive-been-hacked-now-what-2487230
 
Also there are alot of great security articles written by Webroot that may or may not be of interest. There are many here that are informative, https://www.webroot.com/blog/
 
I am not a computer expert but I do know some basics. I do feel for others in this situation. It can be a nightmare. What consoles me is the fact that I am running Webroot. Nothing is 100% effective but IMO your best bet is to Contact the Webroot Support team and they can ease your mind abit by checking out your system. This is of course a few charge with your Webroot subscription. 
 
I wish I could help you out more and maybe others on this Forum will ping in and give you more advise.;)
 
Best of luck,
 
Kindest regards,
 
 
Userlevel 1
Thank you for these resources, Sherry. I'll start in on them right away today. 
 
Yes, Webroot taught me how to do the deep scan (no results so far) and is willing to help me take a more thorough approach to looking at my systems and files, and so I've started working on collecting the info to do that. It's going to require more time and being more thorough, it appears, because he seems to be riding in on something that is functioning as normal so not setting off alarm bells. (Or maybe I'm just beyond paranoid! I feel crazy sometimes because I can't believe what they can get away with before I can protect myself. Historically, my gut has usually been correct. And, of course, I do have evidence in places of the hacking. I need help understanding how to isolate the possibilities.) I'm learning a lot in a short amount of time, which is overwhelming, but at least now I feel like I can take back some of the control.
 
Weird question: I received duplicate badges in my profile even in here. Rather than just run around tempted by paranoia everywhere I go, I'm asking what is normal and what's not. If anyone sees the newbie badges in my profile and also sees duplicates of my first two, can you let me know if that is normal or not? I receive duplicates of things in lots of other places of notifications and pop-ups to restart devices I have working and disabled a duplicate for. Sometimes duplicate emails through yahoo or phone calls through Google bounce back and have evidence of a redirect (he changes the year date on email to 69, for instance) or messages from people with whom I'm communicating actively come in from someone else riding on that open communication under my known person's account. (Do you understand what I mean?) I am shutting down what I can and trying to salvage and protect what I can, also. I resent being chased off the technology that allows me to communicate with others. I have grown weary of having to fight just to protect us all the time when I'd prefer to walk away from the stress and drama. I was mostly free of these two men (my father and my ex-husband) in the real world until our virtual one took this new turn. It is likely only my ex-husband's doing, as my father does not possess the computer skill and they both only seek to control me in the ways in which they do that well. I intend to keep myself and my family in the aspects of technology that link us to others, and that I and we enjoy.   
 
If I can isolate the avenue(s) they are using in here to mess with me, then I know I can get Webroot's assistance to help me more methodically locate and eradicate the places I've left virtual doors open and us vulnerable. I'm all about resources right now, Community, so please don't hesitate to recommend them. I'll get to each of them eventually; and, hopefully I can update this post with progress as I go, so you all have the opportunity to learn what I did to sort this out, and what kind of information Webroot and I exchanged to get that done. The problem feels so massive in scope right now, but I'm sure it's got its parameters like anything else anywhere else, and that I'm in the right spot to get those clarified.
 
Obviously, I have a lot to learn, and it's daunting to know where to start, so thank you for pointing me in a starting direction, Sherry! Off to read and learn some more...
 
- T.
 
 
Userlevel 1
Update: I just found at least one of my problems. I had an extension I didn't remember adding called My Quick Converter. As soon as I removed it from the screen, my "Webroot" stopped being accessible so I could run a new scan. Seems like I've been operating on a dummy screen for who knows how long. I am not sure how to get in and figure out where it's embedded, as I don't expect it's gone entirely, so this is my new starting point. 
 
Please feel free to advise. I don't even trust any of my communications right now in any direction -- not that they're being looked at, which now seems the lesser of my problems -- but that they are being entirely hijacked. No wonder I've been so FRICKING confused! Grrr... 
 
Still, it's progress at this point. Gosh, I feel so alone. Anyone out there who knows this thing, and how to get me back into scannable territory, please advise. I may have several layers of problem here. Is it possible that was never the real Webroot running my scans this whole time? I can't get them to help me in Support until I hand over full logs of my entire computer -- but, as you can see here I'm having trust issues.
Userlevel 7
Badge +62
Hello BrazenRaven,
 
Your web-browser is being re-directed to My Quick Converter web page. This problem can be caused due to a unwanted software from the browser hijacker family. The browser hijacker infection is a type of malware which is developed to change your settings of all your typical web browsers. You may experience any of the following behaviors: your homepage, new tab or search provider is replaced to My Quick Converter, web sites load slowly, you see multiple toolbars on the Firefox, Chrome, Internet Explorer and MS Edge which you didn’t install, you get a ton of popup advertisements.
 
Please read below and see if you can uninstall My Quick Converter from your browser and uninstall from your AddRemove Programs.
 
What you are seeing and describing sounds like it may be what we on the Community refer to as a PUA. (Potentially Unwanted Application) These are very annoying at best in that they cause pop-us, redirect your browser home page, and other behavior that may slow down the computer and direct ads your way, but they are not actually doing anything bad like damaging files or stealing information. Often they are installed intentionally by you the user as browser add-ons for various tasks such as quick search tools.. but they also come with the result of added annoying pop-ups and ads. Other times they 'piggy back' with other software that you installed, or try to 'sneak' onto your system entirely.
 
WSA does detect and remove many PUA's, and more are being added, but WSA does not detect all of them. A simple browser add-on with PUA behavior that is easy to identify and easy to remove is not likely to be detected and removed by WSA. Those that are intentionally difficult to locate and remove are. Please see THIS LINK for more information regarding Webroot's stance on these annoying programs.
 
For those that are not detected by WSA, please see this KB Article. It has some easy to follow directions on locating and removing PUA's. You may also want to submit a Trouble Ticket, especially if you cannot remove it easily from the directions in the KB Article.
 
For those that ARE detected by WSA, but cannot be removed automatically, you can submit a Trouble Ticket.  Webroot Support will help you get these annoying 'crapware' off your computer at no extra charge..
 
Also if you need help getting your Webroot Logs I can explain how to do so. Which I highly suggest that you get those Logs to the Webroot Support Team so they can assist you further.
 
Hope this helps?
Userlevel 1
Yes, Sherry! This helps. Thank you so much. Really going to get to the bottom of this fast. Just needed a little comfirmation and reassurance, plus some links like this, to get going in the right direction. I very much appreciate your responses.
 
- T.
Userlevel 7
Badge +62
You are most welcome!
 
Just remember Webroot is always working in the background to protect your system. 😉
Userlevel 7
Hi SignedOut
 
Welcome to the Community Forums.
 
Have been following this thread with interest...but have not chipped in until now as you are in very good hands with Sherry. However, you mentioned earlier you have trust issues preventing you handing over full logs of your system, and whilst I can understand that I can assure you that in my experience you are very, very safe in terms of doing such a thing to the Webroot Support Team.
 
In my experience (and I have used WRSA for many, many years) they have never asked for anything that they did not need re. logs, information, etc., relating to my system, and only when they felt it was absolutely necessary. If they ask for it then they need it to do the job at hand...period!
 
So I would encourage you to commune with them and provide what they need when they need it as you could not be in better hands as to who can get to the bottom of your previously stated security concerns.
 
Hope that helps in some way?
 
Regards, Baldrick
 
 
 
 
 
 
 

Reply