Infected With A Virus, Called The Number And They Removed It But They Needed Access To Computer...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by netrate, Jun 17, 2017.

  1. netrate

    netrate Private E-2

    I am fixing a computer that the person was infected with a virus, received a pop up that said "This is microsoft we will help you remove the virus". This person called the number, gave access to her laptop, paid $179.00 (or something like that) for a virus removal tool, spent three hours on the phone with the so-called-microsoft company and thought they were in the clear. I spoke to them, found out the phone number, searched the internet and found out it was a scam. It told the person to phone their credit card company, bank etc and ensure that no charges are coming through.

    So now the person is afraid to use the computer and needs it for her daily life. This is where I come in and want to fix this computer so they can use it again. I want to eliminate any chance that the supposed virus removal company has of accessing her computer remotely in case she does banking etc.

    I am going to use a USB key for all of the virus checkers etc, but I would love to know what the experts think about how I should begin? Safe mode?

    Thanks in advance
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do as much as you can in normal mode......attach the logs.
     
  3. netrate

    netrate Private E-2

    Any suggestions on what I should start with?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.... the Read and Run First Instructions.
     
  5. netrate

    netrate Private E-2

    I have an issue - I do not want to run my wifi with this laptop at my house. I was hoping to do everything via USB without using this laptop online - but the first thing stated using MB3 is that I need to download an update virus database. Can I get this in advance on my work PC and transfer it to the USB for the laptop?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.
     
  7. netrate

    netrate Private E-2

    Ok I found the link on the site for how to do it manually
     
  8. netrate

    netrate Private E-2

    Ok, I am stuck. I know I need to upload the logs to the forum, but how can I do that from the infected computer?
    1) I don't want to go online with this infected computer at my house
    2) Transferring the text file via USB could infect my home computer

    What shall I do?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The computer was subject to a scam. I doubt it is infected....the only concern is if there are still any remote programs installed. You should be safe to go online.
     
  10. netrate

    netrate Private E-2

    Here are the logs, the MGlog, I don't know if it is a newer version, but I couldn't find the log it was talking about so I grabbed the filelog.text , I hope that is it. Let me know if I am missing anything. I did not clear any files where it told me to leave them.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. What issues are you having?
     
  12. netrate

    netrate Private E-2

    I want to give it back to the person and let them know they can do banking and such on it. I was going to install easy cleaner to get rid of remote PC and run all of the virus checkers listed in the RUN FIRST section and clear everything they find.
    I was wondering what my next step would be so I can give this back to the person and they are worry free about using it for banking, unemployment submissions etc.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need you to upload the MGLogs.zip so I can look for remote programs.
     
  14. netrate

    netrate Private E-2

    I couldn't find them...where are they located? They were not in the c:/MGtools folder. That is why I uploaded filelog.txt because I only found that .
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It should be on your desktop. Did you run it to completion?
     
  16. netrate

    netrate Private E-2

    I ran it from the USB but did not see it on the desktop...I will have to look again but I really didn't think it was there.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run it from your desktop..... follow the instructions.
     
  18. netrate

    netrate Private E-2

    Here are the logs for MGtools
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This was installed on your PC in May:

    d-----w 0 2017-05-24 16:58:34 C:\ProgramData\RemotePC

    Is this something you use? IF not remove it.
     
  20. netrate

    netrate Private E-2

    So this person with the laptop should be ok after that?

    I am going to install Spybot, super antispy ware and anti-vira as well for them. I will remove the Remote PC first.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds