Elderly Friend Fell For Fake Microsoft Phone Call

Discussion in 'Malware Help (A Specialist Will Reply)' started by CarmsComputer, Apr 12, 2016.

  1. CarmsComputer

    CarmsComputer Private E-2

    Hi, I'm trying to undo whatever this phony "Microsoft repair" person talked my 84 year old not comp savvy friend into installing on her machine, then tried to charge over $150. She told him from the start she couldn't afford this. (I wish I'd had the chance to tell her this was a scam).

    There is even a text file on her desktop claiming to be from "Windows Helpdesk" from an employee and his ID number at "COMEONTOP TECHNOLIGIES LTD" :)mad:) on her desktop if you're interested in seeing it. Thankfully, she isn't out any money, but trying to get this Supremo deleted from her machine has been a problem. I was able to delete whatever the other downloaded rescue program, apparently it was not installed, merely downloaded. When I wasn't able to get rid of Supremo, I came and ran through the Read and run me first tutorial without any difficulties, Here are the logs. Thank you
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs are not really showing any major issues. Please describe in more detail the exact issues that still remain. Is it just the fact that the below is still running?

    O23 - Service: Supremo (SupremoService) - Nanosystems S.r.l. - C:\Program Files (x86)\Supremo\SupremoService.exe
     
  3. CarmsComputer

    CarmsComputer Private E-2

    Yes, and I cannot uninstall or delete Supremo. (I'm not currently at her house)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay will need some additional data. Please run the below scan with FRST.

    Please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  5. CarmsComputer

    CarmsComputer Private E-2

    Hi, here are the two logs
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay before I create a fix that may delete something that you installed in order to maintain this PC, I need to first confirm whether or not you knowingly installed another remote control program named LogMeIn

    I see the below folder dated 4/7/2016
    C:\Users\Carman\AppData\Local\LogMeIn Rescue Applet
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I decided to post the fix anyway to help move things along. I included the LogMeIn Rescue Applet in the items to remove. If you do not want to delete this you can edit the attached fixlist.txt file and delete the below two line and then resave.

    2016-04-07 15:38 - 2016-04-07 15:38 - 00000248 _____ C:\rescue.info
    2016-04-07 15:36 - 2016-04-11 17:36 - 00000000 ____D C:\Users\Carman\AppData\Local\LogMeIn Rescue Applet

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.

    Also at this point, I want to double check the status by having you run another scan with FRST like in my last message and attach the new FRST.txt .
     

    Attached Files:

  8. CarmsComputer

    CarmsComputer Private E-2

    This was the day Carm got the phone call from the phony repair person, and that is something he told her to download. Starting now on the procedure you gave.
     
  9. CarmsComputer

    CarmsComputer Private E-2

    here are the the logs
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like that took care of Supremo and LogMeIn. Are you having any other problems?
     
    CarmsComputer likes this.
  11. CarmsComputer

    CarmsComputer Private E-2

    Nope, there weren't problems before, I just knew this wasn't something a malware scan could handle and Carm and I are truly grateful for the help. Thank you very much! She learned to hang up and not fall for this.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.

    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. CarmsComputer

    CarmsComputer Private E-2

    Okay I'll get this list done I haven't been over for a bit due to illness, was #6 purposely left blank or was something important accidentally omitted? I'll get to work on this
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it was just an instruction that you did not need to run so I removed it. Normally the blank list line would get cleaned up when posting but I guess it did not work this time. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds