I Downloaded Remote Desktop Software From A Scammer.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rush1Done, Jan 19, 2021.

  1. Rush1Done

    Rush1Done Private E-2

    I downloaded remote Desktop software from a scammer now I have Boost and can't remove it. And
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where did you download it from and were you asked to agree to installing boost?
    If you need help, please follow the Read and Run First instructions.
     
    Rush1Done likes this.
  3. Rush1Done

    Rush1Done Private E-2

    I called a phone number on a virus warning popup they told me to click on a download link then they took over my desktop, opened and viewed the chrome passwords and ran something on the cmd line. They showed me my ip address and said my wifi was compromised. When they said that I could get their help for $1,600, I hung up quick. But now my internet connects automatically and there is a BOOST speedometer on my desk top. In safe mode start up defender found csbmini.exe among several other things. I did not know what to do with the results so I left everything alone.
     
  4. Rush1Done

    Rush1Done Private E-2

    No there was no agreement to install boost
     
    Last edited: Jan 19, 2021
  5. Rush1Done

    Rush1Done Private E-2

    No there was no agreement to install Boost
     
    Last edited: Jan 19, 2021
  6. Rush1Done

    Rush1Done Private E-2

    Sorry I may not have replied correctly. I can't find the read me first instructions!
     
  7. Eldon

    Eldon Major Geek Extraordinaire

    Rush1Done likes this.
  8. Rush1Done

    Rush1Done Private E-2

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay...dentist. Please attach the logs when you are finished.
     
    Rush1Done likes this.
  10. Rush1Done

    Rush1Done Private E-2

    The adwcleaner scan was over very quickly. I am afraid to delete or quarantine what it found. Sounds like something my HP Pavilion needs. Also as a by the way, I noticed that all my restore points are gone.
     

    Attached Files:

  11. Rush1Done

    Rush1Done Private E-2

    I Downloaded all the tools accept MG I disabled security and put an old version from 2011 in my recycle been. I moved my downloads folder to the desktop as I am not given a choice when downloading.
     
  12. Rush1Done

    Rush1Done Private E-2

    I finally obtained the logs. Here they are. I have not run MG Tools yet because after obtaining the hitman log I made the mistake of running hitman to fruition. Please advise should I continue with MGtools now or am I refused help As the hitman tutorial states this may happen?
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MBAM log is not the results but the services log.
    Under the RK log, please remove these items:
    [PUP.Anvisoft (Potentially Malicious)] (X86) HKEY_LOCAL_MACHINE\Software\Anvisoft -- N/A -> Found
    [PUP.Anvisoft (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-21-66200047-498935820-2666587744-1000\Software\Microsoft\Windows\CurrentVersion\Run|Anvi_CSB -- C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBMini.exe (missing) -> Found
    >>>>>> O87 - Firewall
    [Adw.Sendori (Malicious)] (X64) HKEY_USERS\.DEFAULT\Software\Sendori -- N/A -> Found
    [Adw.Sendori (Malicious)] (X64) HKEY_USERS\S-1-5-18\Software\Sendori -- N/A -> Found
    [PUP.Gen1 (Potentially Malicious)] (folder) PackageAware -- C:\Users\vmb\AppData\Local\PackageAware -> Found
    [PUP.Anvisoft (Potentially Malicious)] (folder) Anvisoft -- C:\Program Files (x86)\Anvisoft -> Found

    Then I suggest you remove everything found in the Hitman log.

    Reboot and rerun MBAM, RK and Hitman and attach the new logs.
     
    Rush1Done likes this.
  14. Rush1Done

    Rush1Done Private E-2

    How do I retrieve the MBAM log, your tutorial page is not loading Also, the scan result showed zero items?
    I had run MBAM before I contacted you. I uninstalled that version with 17 items quarantined. I have it in my recycle bin. I tried to restore it for the log but it won't restore.
    How do I remove items under the RK log? I guess I need to rerun it to get an active log?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes. Both RK and Hitman. When you ran MBAM, did it show any infections once it was finished?

    "After downloading and changing the name ( if it will not run ), you will be asked if it is personal PC or work PC. Once it opens, click on the Scanner.

    The Scanner card shows the time for the next scheduled scan, if you are using the Premium or Trial versions ( don't worry, if you don't upgrade to pro version, it will automatically change to the free version ). Any version of Malwarebytes shows a blue Scan button in this card. Click it to initiate a Threat Scan on your device. You can instead click anywhere else on this card to expand the Scanner menu. The expanded menu shows the following tabs:

    Scanner: Click this tab to view details on your last scan, configure advanced scan options, and initiate a scan.
    Scan Scheduler: Click this tab to view your scheduled scan and when they will initiate. Click the Schedule scan button and follow the on screen instructions to add a new scheduled scan and configure the start times and frequency. Only Malwarebytes Premium and Trial users can schedule scans.
    Reports: Click this tab to view a list of previous scans and the times when they executed. Hover your cursor over the Scan Report entry to see options to view more details, download a text file version, or delete.

    Please copy the text report and attach it to your next post."
     
    Rush1Done likes this.
  16. Rush1Done

    Rush1Done Private E-2

    1. I left RK minimized in the taskbar with scan results and then I ran Hitman. Was this correct?

    2. I think there is a new HitmanPro icon on my desktop it is detailed as (HitmanPro 3.8 True Cloud computing Anti-Malware) Is this a malware shortcut?

    3. FYI The Hitman version I ran was (...x64...SurfRight B. V.)

    4. Icons on my desktop seemed to be changing their appearance particularly u Torrent and shortcuts to folders seem to be being added on their own. Is this malware behavior?
     

    Attached Files:

  17. Rush1Done

    Rush1Done Private E-2

    Seems or post have crossed. I did not see #15 when I posted #16.
    Here is the Malwarebytes story:
    Last Saturday I ran malwarebytes in safe mode and quarantined 17 items.
    I then uninstalled and deleted MBAM.
    I Found a MBAM folder in programs and renamed it "Salwarebytes" .
    "Salwarebytes" is now in microsoft security essentials and cannot be moved.
    There is an MBAM folder is in the recycle bin and cannot be restored.
    Today I downloaded a fresh copy of MBAM and ran that just now 4U.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean...although I am not sure about Advanced Identity Protector. What issues are you still having, if any?
     
    Rush1Done likes this.
  19. Rush1Done

    Rush1Done Private E-2

    1. What would make my "u torrent" desktop icon change from the old "green CIRCLE" type logo to a new "square menu" type thing? I haven't clicked on the icon for five years. This computer was in put in mothballs (containing no problems) 5 years ago. The old logo is gone in folders with torrent files too. I just saw it when backing up files to an external drive a day ago.

    2. There is a msert(1).exe icon on my desktop which worries me. I Have a USB stick that I have been moving between the infected computer and a newer clean computer, the msert(1)..exe has suddenly shown up on the USB stick!

    3. Advanced Identity Protector worries me too. There are 5 search results for it all in AdwCleaner Quarantine! They say created 1/16/2021 the day this scam attack happened!

    4. I tried to browse the web with chrome on the infected computer. Major Geeks was the first page I clicked on in favorites. The page did not load well just some blue text and pop ups for cloud and edge. I closed chrome and opened edge that worked better. I went back to chrome a few times and each time MajorGeeks loaded better finally I was able to download AVG Free from your site after first getting a SQL error.

    5. Perhaps I did a little too much. I was just checking for problems on the infected computer. The AVG browser behaved differently than it did on my other clean pc. When it opened it imported all the bookmarks over from chrome. I would have preferred to get the bookmarks manually one at a time by visiting other websites. Perhaps I can delete the AVG bookmarks and then start over.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rush1Done likes this.
  21. Rush1Done

    Rush1Done Private E-2

    I will comply with your instructions.
    Seems that all my out dated programs have lost their icons.

    1. There is a program in my sys config startup tab called VDownloader.exe/silent manufacturer Unknown location location .... windows currentversion\run,
    Is this a bad actor?

    2. Would it behoove me to send you an MGtools log? I finally downloaded it.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is a YouTube downloader.
    As to your desktop icons, if you right click them and choose properties you can change the icon.
    If you want to attach the MGLogs.zip I will look at it.
     
    Rush1Done likes this.
  23. Rush1Done

    Rush1Done Private E-2

    Please help/.
    While MGtools was running, it stopped. I have a message window titled ProcDll Logger ProcDll Logger has stopped working --- Check online for a solution and close... OR Close program.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
    Rush1Done likes this.
  25. Rush1Done

    Rush1Done Private E-2

    I think I am OK it finished here is the resuts
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any issue...although you may wish to remove all your temp files. any other issues should probably be addressed in the software forum.
     
    Rush1Done likes this.
  27. Rush1Done

    Rush1Done Private E-2

    I tried to run mgtools from the cmd at GetRunKey there is an error msg Unsupported 16 bit Application program or feature cannot start do to 64 bit incompatibility
    Thanks For looking at MGlogs.
    One more thing:
    I remember something now Because I just found copy of AdwCleaner on my c drive it has 72 folders in its Quarantine folder.
    What I did was after this scam attack, I installed and ran AdwCleaner in SAFE MODE.
    Now I do not know what to do with Adwcleaner folder under OS (C: ) with 72 quarantined items!
    Can I delete it? There is know AdwCleaner under add remove programs
     
    Last edited: Jan 21, 2021
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.
     
    Rush1Done likes this.
  29. Rush1Done

    Rush1Done Private E-2

    Just two last issues:
    You may refer me t0 software if you wish.
    ISSUE 1. Its the msert thing.
    A search for msert shows three files: (created shortly after the scam)msert
    a. "properties infected computer m sert.exe" (there is a space in the word msert)
    b. "msert (1).exe"
    c. "MGlogs.zip" (strange as it seems this is displayed under msert search)
    Can I Drag all this stuff to the recycle bin?

    ISSUE 2. Is there a way to delete this unavailable folder from the desktop?
    I opened a USB stick on my other clean computer and took a sniping tool image of a file from the infected computer.
    I saved the image to a new folder on the desktop.
    Now that folder can't be opened! or deleted! "error msg says location unavailable".
    I removed the USB stick and wiped it by deleting.
    Still have unreachable folder on desktop.
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.
    Are you using an Admin account?
     
    Rush1Done likes this.
  31. Rush1Done

    Rush1Done Private E-2

    How do I tell if I am using an admin account?

    I have no password on this computer. !!!!!!!!!!!!!!!!!!!

    Just now I deleted that folder it was just called new folder the label changed to msert.
    At first it would not shred with AVG shredder but I simply emptied the recycle bin and it was deleted.

    Now windows 8.1 search shows I still have two msert files on the computer.

    I searched the web for msert and it says it's malware. I now have two computers with msert.
     
    Last edited: Jan 21, 2021
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I already told you what it is. Post #20: Microsoft Safety Scanner.
    These are not malware issues. Please direct future issues to software. :)
     
    Rush1Done likes this.
  33. Rush1Done

    Rush1Done Private E-2

    Yes EVERTHING seems to be OK now on both computers ALL files were deleted.

    Funny though how a search in the AVG browser shows results for msert malware seems some people just want you to download their software to remove it.

    Thanks so much it is better work with MajorGeeks than follow youtube tutorials ect.

    I wish I could show my appreciation. Back in the day MajorGeeks accepted Donations if I am not mistaken?.

    For your amusement you may want to see my only old thread under the member name Rush2Done.
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem...you are most welcome.
     
    Rush1Done likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds