Pc Taken Over Remotely

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by brunobru, Feb 11, 2017.

  1. brunobru

    brunobru Private E-2

    Hello,
    I've been battling this for weeks and have disabled all remote services (and more), blocked ports and protocols, did system restore back to before the hack, purchased new hardware (router/modem), and before I did all that, event viewer showed the pc had been accessed remotely. The pc settings keep changing back after I change them, and block the internet so it's ruined the owners IP home Phone service which sucks because they are elderly. I disabled the Wifi and for about 10 minutes after all the changes and new setup it worked great until the offender got back in again. This person did have access to the pc and local network for a couple months, then moved and took control. The pc has no internet because they block it but I need to know how to disable the MMC because it is running in task manager and I believe that's how they are controlling it now. Though I can't find MMC snap-in even installed. It's a Windows 7 home pc and when it did have internet when this all started, it blocked me from downloading malware tools and links. Wifi is disabled (by me) but I think this pc is now on the offenders network by a different wifi or port because it won't let me make a new ethernet connection or network. Only allows the same network even after I uninstalled the Ethernet adaptor and did system restore. Most of their activity is hidden until I run across it as I'm searching, so little by little I was knocking them out but they always found a way back in and I believe it is because this pc is on their network or a hidden wifi. Also, when I opened IE a message popped up and said it could not access the internet because Remote Access Connection Manager is disabled (and I wasn't going to re-enable it) as the pc is behind a cable modem/router. Hope that's ok? When I'm working on it to do what I can, black window (Command prompt window) flashes frequently like scripts are running or taking snapshots of what I'm doing.

    I took the required scans on flash drive but I forgot the AdwareCleaner program so that one is missing. I forgot it because it's in a different area than the other four programs. And I have to go back and forth with USB flash drive so I'm sorry I don't have that one at this point.

    I really need to regain control of the pc and network if possible in order to restore the phone service.

    Thank you so much for any help!!!
    Julie
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not having a malware problem. If someone has gained access to your computer, I suggest you call the police and make a complaint.

    Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  3. brunobru

    brunobru Private E-2

    Hi thanks for responding.

    So are the logs clean?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, your logs are clean.
     
  5. brunobru

    brunobru Private E-2

    Thank you so much!
    Question... if they retire the pc and get a new one, is it safe to say it also will be remotely controlled?

    They are asking me and I don't know the answer.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, if he has hacked your router. I suggest you change your admin password on the router.
     
  7. brunobru

    brunobru Private E-2

    The router admin login and password were changed from default as soon as it was installed. I don't think it matters though since the PC is now on his network and in his homegroup that won't let it leave.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still suggest you change it.
     
  9. brunobru

    brunobru Private E-2

    Will do, thanks. I will go there in a couple days. The pc is kept unplugged when I'm not there to work on it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds