Another Tech Support Scam Popup

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by trisha, Jun 12, 2018.

  1. trisha

    trisha Corporal

    Not sure if this is the right place to post this. My friend clicked on one of these deadly links and called the number and let them have control over his computer. As he watched them uninstall McAfee he got nervous and stopped the call and closed the remote access.
    NOW...when the computer is booted up it only shows one option for login... other user. There is no way for him to enter his login credentials.
    I have been looking at this computer and cannot go into safe mode. The boot is in a repetitive loop. Dell splash screen, then log in window then reboots again without me doing anything. It reminds me of that virus from the 90's that kept rebooting your computer. Anyway, he can't find the recovery disc I made him and there is no way I can run any scans because I can't log in. Any ideas? He bought another Windows 10 program. Should I just go ahead and install the new OS?
     
  2. trisha

    trisha Corporal

    UPDATE
    I was finally able to get to the reset pc stuff by hold down shift+f12. Who knew? Anyway, I tried to run the repair startup utility and it said it was unable to repair the startup. I am currently doing a reinstall and keeping files option. I am not sure if that was the right choice because I don't know what has been dropped on this computer.
    After I get the computer up and running I will run the Read Me and Run First stuff and then post to a new thread. If you want me to continue to post to this thread, please let me know.
     
  3. trisha

    trisha Corporal

    Here are the logs. I saw the program that was probably installed by the tech scam people it's called Advanced Identity Protector. It was uninstalled when the OS was reset.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. The reset probably is what removed any leftover malware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  5. trisha

    trisha Corporal

    Thanks for your help Tim.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. :)
     
  7. trisha

    trisha Corporal

    I have a question. When I did the Windows reset I chose the option to keep the personal files. I see two Folders. one is names windows.old and the other windows.old2. I can access these folders but how do I put them back where they belong, i.e, Users, Documents, pictures, music, etc. thanks
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The reset kept your files and documents. Various ways to restore those individual files. Drag a file to the desktop, click on move ..etc. If you are unsure, post in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds