andfox wrote: What I am wondering is can he, or his group, hack into my computer and steal my information? I've got all kinds of personal information stored on here and don't know what my next step in protecting myself should be. Any advice?
This is a loaded question. Depending on the ability of the scammer and the security of your computer, the answer is a resounding MAYBE.
First thing I would suggest would be to "Check" your system. You can do this by going to
http://www.grc.com/default.htm . From there, scroll down to the "Hot Spots" section and then click on the "Shields UP!" link.
This will take you to a spot that you can test your system. It will probe your system and check the ports. Just follow the directions and click Proceed on that page. Ultimately it will give you some results about how secure your system is. Don't be alarmed if your system FAILS (Even if you accept a PING request, they consider that a fail). It's important to see WHY you failed. If you failed for a PING that's not bad. If you failed because port 139 is open (That will allow access to your local drive).. Then that is VERY bad.
Other things you can do is to make sure you have a password on EVERY account on your system. Make sure the password is NOT the same as the account name. (i.e. Logon: Administrator Password: Administrator) No blank passwords, and no password of PASSWORD. I know these seem obvioius but it's amazing how often it happens.
Finally (if you want), I have (currently) a tool here where I work that can do a much more IN DEPTH scan of your system. If you would like you can PM me and we can coordinate a time that I could run it on your system. Last time I ran it on my server... it took over 40 minutse to run.
I hope this helps.