Should Be Clean - Logs Attached Just Need A Look

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by axlmastr, Feb 12, 2018.

  1. axlmastr

    axlmastr Private E-2

    This is one of two machines I'm tasked with checking and cleaning for an elderly couple scammed by the Techpro Busters Online support scam. They received an alert, panicked, paid $249, and allowed remote access to their machines by PC Techmart LLC.
    I am just helping them out since they are highly embarrassed.
    Logs attached for review. Should be clean.
    AdwareRemover found nothing.
    Roguekiller found items and they were deleted.
    Would like to toggle System Restore if logs show clean just to purge anything potential.
    Machines seems to work well now
    Thank you
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I hope they either canceled the payment through the bank or credit card.

    Your logs are clean. I don't see any reason to do a system restore.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  3. axlmastr

    axlmastr Private E-2

    Thank you TimW. Not sure how the credit card situation ended, but after someone else "cleaned" it from that first incident the phones calls returned. The owner allowed the scammers back into the machine to screw it up again which led to the machine landing in my hands.

    I wasn't going to do a restore. I was wanting to toggle system restore and delete any existing restore points. I went ahead and deleted previous restore points and then made a fresh one.

    The couple's desktop will be posted in a few minutes of this reply. It's pretty contaminated lol.

    Thanks again!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you need to tell the owners that if they are going to let unknown people into their system, they are on their own.
     
  5. axlmastr

    axlmastr Private E-2

    Yeah I hear you TimW. They are in their late 60's early 70's and they got a call from "Microsoft" and it was imperative that they let them take a look at their computer because the computer informed Microsoft there was a problem. I had a 73 year-old man get a call from "yahoo" one time and I had to go through his machine. These people aren't in the loop and are more trusting than one would expect for their years on the planet. I can say that recent experience with the much younger crowd they tend to trust downloading apps they have no idea carry payloads and will screw up their device. Both ends of the spectrum. I just try to help people much the same as you do.

    I posted for the desktop machine about 30 min ago. It's interesting.....
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds