My Father Granted Someone Remote Access To His Computer; What Should I Do

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jrasicmark, Jun 14, 2016.

  1. jrasicmark

    jrasicmark Private First Class

    My elderly father was taken in by some kind of pop-up ad that claimed he had viruses when he was online. He clicked on it and he filled out their form so they called him and before I'm aware of any of this, he had granted them remote access to his computer.
    They are a company called Rhombus located (supposedly) in Texas although they all seem to have Indian accents. They got him to agree to pay them over $800 for continued technical support. They're supposed to send FedEx to his house today to pick up his check. I've told him I think it's a rip-off. That $800 tech support supposedly includes a lifetime subscription to Malwarebytes.
    I also turned off the computer so they can't get remote access without us knowing it and I told him not to touch it until I have a chance to look at it.
    I want to disconnect the computer from the router so they can't stop me from deleting the software they installed that allows remote access. They left a shortcut for it on the desktop so it can be easily found, but I don't remember the name of the software (I'm posting from work).
    Thing is, I don't really know what else they may have done to the computer. It may have files or software that is hidden and I'm not sure how to find it.
    I also noticed that our Wifi that I use to access the internet for my own PC, laptop, and tablets is down, so I can't get online. I checked, and it says I have access to a Wifi network (which seems to be a new one that isn't the one we usually use) but I still can't get online.

    So I'd like some advice on how to clean his PC of whatever he did to it and to re-establish our Wifi and get rid of the one they installed.

    Thanks
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Sorry, about my first post - I have been up all night.
    *Do NOT pay anymore money out on that scam!
    There is nothing that we can do for you & your Dad without logs to review.

    Regretfully,
    dr.m
     
    Last edited: Jun 14, 2016
  3. jrasicmark

    jrasicmark Private First Class

    Okay, sorry for the delay in posting the logs.
    Hitman and TDSKiller didn't find anything and didn't give me any logs to upload.
    The "tech support" provided by this company supposedly includes a lifetime subscription to Malwarebytes Pro, so I used that version to run the scan; it didn't seem to find anything, though I've uploaded the log anyway. Since they provided it, I'm a little suspicious of it, so if you think I should uninstall their version and run a version of the software I downloaded from here, please let me know.
    It looks like they've installed AnyDesk as well as some kind of Tech Support shortcut on the desktop. I haven't uninstalled or deleted them yet; I figured I should wait to hear what you may see in these logs, if anything.
    Thanks.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Welcome back!

    Now re-run RogueKiller and run a scan. After it finishes the scan, select the following Registry tab and then select any of the below that exist and then click the Delete button.
    *Make sure you select the Click to Expand text ( if present ) at the bottom of the quote box to see the whole fix.
    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in the original instructions and upload the new log.

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.

    Please download ZHPcleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
      • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
      • Then press the ''Repair'' button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
    Note: Your MGlogs.zip is very much incomplete. Didn't you wait for it to finish running before you uploaded the log? You must wait for it to tell you it is finished. And you must also accept the Trend Micro HijackThis license twice to get it to produce a log.

    Try running it again observing the above note.

    Upload all requested logs to your next reply.
     
  5. jrasicmark

    jrasicmark Private First Class

    Okay, I figured maybe I'd better start with trying to correct my mistakes from last time, since those scans were to be done first.

    I think my mistake with MGTools was because the window it ran in didn't open to the full depth of the screen. So when it paused in its scan, it did it just before the instructions that said to wait, it wasn't done yet. So I didn't see that and thought it was done.

    Your comment about Trend Micro Hijack This confused me because I couldn't find that software mentioned in the "Read and Run Me First" instructions. I thought maybe you meant Hitman instead? So I thought maybe I should try to run Hitman again to be safe, and then also run Hijack This as well. I'm sorry, I've been so tired tonight, I think it was Hitman that ended up deleting some files even though the instructions said to only include a log. I don't remember having to click either of them twice to accept the licence, but they both provided a log anyway.

    I think I also misunderstood the Rogue Killer instructions, because I exported a report after the first scan, and then after I rebooted and ran it again, it generated another report; the second one has the letter "b" at the end of the file name. So I'm uploading both. Rogue Killer also gave me 2 error messages on both runs having something to do with a missing drive. I didn't know what they meant, so I took a screenshot that I am uploading. I clicked "continue" all 4 times it popped up and it kept plugging away.

    I think I got most of the other logs without any problems except for ZHPCleaner. Another odd error message popped up asking me if I had installed a server and I really wasn't sure and didn't know how to check that. I know we have a high speed internet connection with our cable, and it includes a Wifi connection, but I wasn't sure if it might have been one of those. I took a screenshot of the error message along with an open window showing our internet network connections which I will upload as well. But then I clicked "Yes" in the error message as if I had installed the server at least until I can find out for sure if it really is legitimate.
     

    Attached Files:

  6. jrasicmark

    jrasicmark Private First Class

    Here's more of my logs and errors since I've already gone above the 5 per message limit. roguekilererrormessage.jpg
    zhpcleanerservermsg.jpg
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) There are no errors of major importance noted... you'll find another reply by morning dealing with what was found by Adwcleaner and what I find in the MGlogs.zip --> which on it's own downloads/installs and run HJT, whose log is also included in the zip.

    *Check that! ZHPcleaner is questioning a web setup/ connection to an unknown source that's setup on your Dad's pc. Do you recognize it???? Is that normal or something that was set by that "Remote setup" by the company called Rhombus? Frankly speaking, you had better know the answer to that!

    Peep in again by morning and I'll have another fix posted.

    How is the pc running, by the way?
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your Dad's machine is showing very little available RAM memory, as well as the security risk of running an outdated and unsupported operation system.
    Please uninstall if still present using Add/Remove Programs:
    QuickTime

    Using Windows Explorer, delete these files listed below:
    C:\Documents and Settings\Administrator\Application Data\APCUBDIR
    C:\Documents and Settings\All Users\Application Data\{81C0D032-4AF4-4CDD-9CBD-895523FE947A}
    C:\Documents and Settings\Administrator\Desktop\AnyDesk (1).exe
    C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
    C:\Documents and Settings\Administrator\My Documents\Downloads\MGtools (1).exe

    I don't see anything else to do How's the pc running?
     
  9. jrasicmark

    jrasicmark Private First Class

    I called our cable/internet provider and they told me that server is not one of theirs, so I ran ZHP again and told it so and it found a browser hijacker. I'll post the log, though that's all it seemed to find this time. I'll have to see if our Wifi is working now that I deleted the fake internet connection; if not, I'll have to call their support to hook us up again. Oh, and I almost forgot; both yesterday and today, when I ran ZHP, I got a message during the scan that ZHPCleaner.exe was corrupt and that I should run system check. I was so tired yesterday, I forgot to mention it. I'm hoping it's just a false flag that happens as a result of the scan?

    I also deleted everything you mentioned above except for the 3rd one from the top between brackets. I couldn't find that one even when I did a search, and I do have hidden files and folders activated.

    The PC seems to be running okay, considering how old it is. I actually think it's running faster than it was, though. I know XP is old, unsupported and vulnerable, but my folks don't want to spend money to upgrade, and they're already challenged trying to work with this outdated system without having to upgrade to something even more advanced.

    He actually even ordered a "Wow!" PC made for seniors, which is supposedly easier to understand, but they can't remember how to turn it on so they never use it. I did some checking, and it looks as if the "Wow!" actually has Linux running it all under the hood, so I think it might be somewhat less likely to attract the attention of hackers. If only they would use it :)

    Here's the ZHPCleaner log. I added a 3 to the end of the filename because I thought I had saved 2 previous logs for it in the same location yesterday, but it was only the one.

    Thanks again for all your help!
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool: We've made a great deal of progress.

    Some of the tools that I had you use over-lap a bit, and I did that for redundancy of removal.

    The only thing that is needed now is to give you our standard "Final Cleanup steps" which follows:

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds