Solved

Clensing a computer after user allowed scammer access to their computer

Posted on 2016-11-07
6
71 Views
Last Modified: 2016-11-25
I've had quite a few of these over the past few months.  All Windows system. The user gets a persistent webpage directing them to call Microsoft or random phone call where the caller tells them their computer is doing something it shouldn't.  Some users go as far to pay the scammer, allow remote access, etc.

When they contact me I'm scanning the drive by removing it from their machine and connecting it to my technical system.  Normally nothing is found.  Diagnosing with their hard drive installed on their machine scanning with Malwarebytes, RogueKiller, check for unwanted programs in add/remove programs, ensure nothing odd in startup under Msconfig.

Any better advice on tools I can use to scan with?

In some instances I've simply saved important user files then reinstalled Windows.   Thanks in advance.
0
Comment
Question by:1namyln
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 7

Expert Comment

by:No More
ID: 41878106
Well, I would definitely check the HOST file for any IP addresses , but to be save system wipe is way to go

Usually it's just some web link with message to contact support etc, always Indian guy on other side  

Additional tools: Spybot  https://www.safer-networking.org    This is really valuable free tool with multiple functions
0
 
LVL 94

Assisted Solution

by:John Hurst
John Hurst earned 125 total points
ID: 41878111
Also, download, install and run Process Explorer from Microsoft. Look under the Explorer tree for any strange alphanumeric processes. If you find any, kill the processes, exit PE and run Malwarebytes again.

If you cannot find anything, you may wish to back up and reinstall anyway just to be on the safe side.
0
 
LVL 88

Accepted Solution

by:
rindi earned 250 total points
ID: 41878257
It is far better to do a clean re-installation of the OS. Make sure you set it up correctly with a standard account and an Admin account. Users must only use the standard account when using the PC. Change ALL the passwords, including those of email accounts, web-site logins etc. If possible also change the email address. If the user had any of his bank or credit card info etc stored on the PC, have him contact those institutions and recall the cards/change the accounts. Have him get another phone number. Have him change his internet router's password, and if he has a wireless router, also change the wireless WPA2 passphrase.

Although this probably won't be of much use, still have him tell the law enforcement authorities, along with the phone number he called. That may at least get the number blacklisted, or even give the authorities a chance to trace the crooks.
0
Don't miss ATEN at NAB Show April 24-27!

Visit ATEN at NAB Show to learn how our "Seamlessly Entertaining" solutions deliver fast, precise video streaming without delays for the broadcasting and media environment. ATEN will showcase its 16x16 Modular Matrix Switch (VM1600) and KVM Over IP Solution (KE6900 series).

 
LVL 37

Assisted Solution

by:bbao
bbao earned 125 total points
ID: 41878333
if it were me, I would redo everything that the scammer ever touched remotely, not only including all files on the computer, but also the usernames and passwords ever stored on the computer. change all of them, immediately.

however, if the user only received the scamming phone calls or even paid to the scammer but never allowed them to touch user's computer, that should be less critical. however, a security inspection should be conducted on the computer to make sure the redirected web pages were only done by JavaScript when malicious website was visited and not plug-in or ActiveX control or other executable was downloaded and installed. The user's Downloads folder and web browsers' setting can tell the information.
0
 
LVL 1

Author Comment

by:1namyln
ID: 41883274
Clean install is the sure fire way to ensure the problem is no more.  Especially with a user that doesn't have many things to reinstall.  Thanks for the help.
0
 
LVL 88

Expert Comment

by:rindi
ID: 41901326
1namyln,
Please close the Question.
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
Learn how to PXE Boot both BIOS & UEFI machines with DHCP Policies and Custom Vendor Classes
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…

697 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question