Cleaning Up After Blue Screen/browser Control Scam

Discussion in 'Malware Help (A Specialist Will Reply)' started by Khatru54, Dec 24, 2015.

  1. Khatru54

    Khatru54 Private E-2

    Hello,

    I'm trying to clean up this computer after someone fell for a blue screen scam yesterday and made a payment for anti-virus service/allowed the scammer remote access to their computer. I went through the whole process and am attaching the logs. Can I be confident that the computer is clean? Should I just reinstall the OS?

    I keep getting an error message when attaching the TDSSKiller log, saying that the file is empty. TDSSKiller didn't find anything -- is that the reason for the message? Should I try to run it again?

    Thank you for your help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Not seeing any malware. You can do this:

    Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Tasks tab and locate this detection:

    [Suspicious.Path] \UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 -- C:\WINDOWS\TEMP\DeleteFolderTask.exe -> Found

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    How are things running?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds