PC cleanup following phone scam "your PC is infected"
djoudjoudjou
-
djoudjoudjou -
djoudjoudjou -
Hello everyone, I just got back my mother-in-law's PC which was half-scammed by a message "your PC is infected... blah blah blah... call this number...." which she did.
After installing programs, the person took remote control and asked her for 300 euros...
Today:
- I uninstalled the 2 programs installed that day: cpu guardian and pc privacy shield
- ran malwarebytes with 710 suspicious files
- ran FRST, here are the reports
https://pjjoint.malekal.com/files.php?id=20170615_o12j9v14b13d5
https://pjjoint.malekal.com/files.php?id=FRST_20170615_l5l10q77y13
https://pjjoint.malekal.com/files.php?id=20170615_f15o13n149x11
Is there a good soul to help us out? :p
Configuration: Windows / Chrome 34.0.1847.137
After installing programs, the person took remote control and asked her for 300 euros...
Today:
- I uninstalled the 2 programs installed that day: cpu guardian and pc privacy shield
- ran malwarebytes with 710 suspicious files
- ran FRST, here are the reports
https://pjjoint.malekal.com/files.php?id=20170615_o12j9v14b13d5
https://pjjoint.malekal.com/files.php?id=FRST_20170615_l5l10q77y13
https://pjjoint.malekal.com/files.php?id=20170615_f15o13n149x11
Is there a good soul to help us out? :p
Configuration: Windows / Chrome 34.0.1847.137
3 answers
-
Hello,
To uninstall:
Google Toolbar for Internet Explorer
pdfforge Toolbar v4.6
After that, there are just some cleanup software that the fake technician tried to sell to your mother-in-law.
There are also the Wondershare programs to remove.
Here is the correction to be made with FRST. You can refer to this instruction note with screenshots.
Open Notepad: Windows key + R,
In the "Run" field, type notepad and hit OK.
Copy/Paste the following into it:
CreateRestorePoint:
CloseProcesses:
2017-05-22 12:31 - 2017-06-15 15:17 - 00000000 ____D C:\Users\Bernadette\AppData\Local\PCPrivacyShield
2017-05-22 12:27 - 2017-05-22 12:27 - 00000000 ____D C:\Users\Bernadette\AppData\Local\CPU_Guardian
2017-05-22 12:26 - 2017-05-22 12:45 - 00000054 _____ C:\END
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
C:\ProgramData\Wondershare
C:\Program Files (x86)\Common Files\Wondershare
2017-05-22 12:26 - 2017-05-22 12:38 - 00000000 ____D C:\Users\Bernadette\AppData\Roaming\supportdotcom
2017-05-22 12:25 - 2017-05-27 10:00 - 00000000 ____D C:\Program Files (x86)\supportdotcom
2017-05-22 12:25 - 2017-05-22 12:25 - 00000000 ____D C:\Users\Bernadette\AppData\Local\SPRT
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:
Once the text has been pasted into Notepad,
File menu then "Save As",
On the left, go to the Desktop,
In the bottom field, for the file name put: fixlist.txt
Click on "Save", this will create fixlist.txt on the Desktop.
Restart FRST and click the "Fix" button
A restart may be necessary (not mandatory)
A text file will appear, copy/paste the content here in a new message.
Restart the computer.
2°)
Reset/Repair the web browsers affected by the issues:- Repair Mozilla Firefox (first paragraph)
- Repair Google Chrome (only the first paragraph).
- Reset and repair Internet Explorer
--
Please press a key to continue the disinfection... -
Results of Farbar Recovery Scan Tool (x64) Version: 15-06-2017
Executed by Bernadette (15-06-2017 18:54:24) Run:1
Executed from C:\Users\Bernadette\Desktop
Loaded profiles: Bernadette & UpdatusUser (Available profiles: Bernadette & UpdatusUser)
Boot mode: Normal
==============================================
fixlist content:
CreateRestorePoint:
CloseProcesses:
2017-05-22 12:31 - 2017-06-15 15:17 - 00000000 ____D C:\Users\Bernadette\AppData\Local\PCPrivacyShield
2017-05-22 12:27 - 2017-05-22 12:27 - 00000000 ____D C:\Users\Bernadette\AppData\Local\CPU_Guardian
2017-05-22 12:26 - 2017-05-22 12:45 - 00000054 _____ C:\END
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
C:\ProgramData\Wondershare
C:\Program Files (x86)\Common Files\Wondershare
2017-05-22 12:26 - 2017-05-22 12:38 - 00000000 ____D C:\Users\Bernadette\AppData\Roaming\supportdotcom
2017-05-22 12:25 - 2017-05-27 10:00 - 00000000 ____D C:\Program Files (x86)\supportdotcom
2017-05-22 12:25 - 2017-05-22 12:25 - 00000000 ____D C:\Users\Bernadette\AppData\Local\SPRT
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:-
The restore point was created successfully.
Processes closed successfully.
C:\Users\Bernadette\AppData\Local\PCPrivacyShield => moved successfully
C:\Users\Bernadette\AppData\Local\CPU_Guardian => moved successfully
C:\END => moved successfully
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe => No active processes found
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Wondershare Helper Compact.exe => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\DelaypluginInstall => value removed successfully
C:\ProgramData\Wondershare => moved successfully
C:\Program Files (x86)\Common Files\Wondershare => moved successfully
C:\Users\Bernadette\AppData\Roaming\supportdotcom => moved successfully
C:\Program Files (x86)\supportdotcom => moved successfully
C:\Users\Bernadette\AppData\Local\SPRT => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-2137693414-1345286262-3239578380-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-2137693414-1345286262-3239578380-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
========= End of RemoveProxy: =========
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 192035119 B
Java, Flash, Steam htmlcache => 2886 B
Windows/system/drivers => 1173352549 B
Edge => 0 B
Chrome => 765824731 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 42320979 B
systemprofile32 => 1047870 B
LocalService => 173204 B
NetworkService => 268278 B
Bernadette => 2382448697 B
UpdatusUser => 66228 B
RecycleBin => 55846926 B
EmptyTemp: => 4.3 GB temporary data deleted.
================================
The system had to restart.End of Fixlog 18:58:10
-
-
I think it's correct.
Any particular things to see?
--
Please press any key to continue the disinfection...