PC cleanup following phone scam "your PC is infected"

djoudjoudjou -  
 djoudjoudjou -
Hello everyone, I just got back my mother-in-law's PC which was half-scammed by a message "your PC is infected... blah blah blah... call this number...." which she did.

After installing programs, the person took remote control and asked her for 300 euros...

Today:
- I uninstalled the 2 programs installed that day: cpu guardian and pc privacy shield
- ran malwarebytes with 710 suspicious files
- ran FRST, here are the reports
https://pjjoint.malekal.com/files.php?id=20170615_o12j9v14b13d5
https://pjjoint.malekal.com/files.php?id=FRST_20170615_l5l10q77y13
https://pjjoint.malekal.com/files.php?id=20170615_f15o13n149x11

Is there a good soul to help us out? :p

Configuration: Windows / Chrome 34.0.1847.137

3 answers

  1. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    Hello,

    To uninstall:
    Google Toolbar for Internet Explorer
    pdfforge Toolbar v4.6


    After that, there are just some cleanup software that the fake technician tried to sell to your mother-in-law.
    There are also the Wondershare programs to remove.

    Here is the correction to be made with FRST. You can refer to this instruction note with screenshots.

    Open Notepad: Windows key + R,
    In the "Run" field, type notepad and hit OK.
    Copy/Paste the following into it:

    CreateRestorePoint:
    CloseProcesses:
    2017-05-22 12:31 - 2017-06-15 15:17 - 00000000 ____D C:\Users\Bernadette\AppData\Local\PCPrivacyShield
    2017-05-22 12:27 - 2017-05-22 12:27 - 00000000 ____D C:\Users\Bernadette\AppData\Local\CPU_Guardian
    2017-05-22 12:26 - 2017-05-22 12:45 - 00000054 _____ C:\END
    (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
    HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
    HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
    C:\ProgramData\Wondershare
    C:\Program Files (x86)\Common Files\Wondershare
    2017-05-22 12:26 - 2017-05-22 12:38 - 00000000 ____D C:\Users\Bernadette\AppData\Roaming\supportdotcom
    2017-05-22 12:25 - 2017-05-27 10:00 - 00000000 ____D C:\Program Files (x86)\supportdotcom
    2017-05-22 12:25 - 2017-05-22 12:25 - 00000000 ____D C:\Users\Bernadette\AppData\Local\SPRT
    Hosts:
    EmptyTemp:
    RemoveProxy:
    Reboot:


    Once the text has been pasted into Notepad,
    File menu then "Save As",
    On the left, go to the Desktop,
    In the bottom field, for the file name put: fixlist.txt
    Click on "Save", this will create fixlist.txt on the Desktop.

    Restart FRST and click the "Fix" button
    A restart may be necessary (not mandatory)
    A text file will appear, copy/paste the content here in a new message.

    Restart the computer.

    2°)
    Reset/Repair the web browsers affected by the issues:

    --
    Please press a key to continue the disinfection...
    0
  2. djoudjoudjou
     
    Results of Farbar Recovery Scan Tool (x64) Version: 15-06-2017
    Executed by Bernadette (15-06-2017 18:54:24) Run:1
    Executed from C:\Users\Bernadette\Desktop
    Loaded profiles: Bernadette & UpdatusUser (Available profiles: Bernadette & UpdatusUser)
    Boot mode: Normal
    ==============================================

    fixlist content:
    CreateRestorePoint:
    CloseProcesses:
    2017-05-22 12:31 - 2017-06-15 15:17 - 00000000 ____D C:\Users\Bernadette\AppData\Local\PCPrivacyShield
    2017-05-22 12:27 - 2017-05-22 12:27 - 00000000 ____D C:\Users\Bernadette\AppData\Local\CPU_Guardian
    2017-05-22 12:26 - 2017-05-22 12:45 - 00000054 _____ C:\END
    (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
    HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
    HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
    C:\ProgramData\Wondershare
    C:\Program Files (x86)\Common Files\Wondershare
    2017-05-22 12:26 - 2017-05-22 12:38 - 00000000 ____D C:\Users\Bernadette\AppData\Roaming\supportdotcom
    2017-05-22 12:25 - 2017-05-27 10:00 - 00000000 ____D C:\Program Files (x86)\supportdotcom
    2017-05-22 12:25 - 2017-05-22 12:25 - 00000000 ____D C:\Users\Bernadette\AppData\Local\SPRT
    Hosts:
    EmptyTemp:
    RemoveProxy:
    Reboot:


    • The restore point was created successfully.
      Processes closed successfully.
      C:\Users\Bernadette\AppData\Local\PCPrivacyShield => moved successfully
      C:\Users\Bernadette\AppData\Local\CPU_Guardian => moved successfully
      C:\END => moved successfully
      C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe => No active processes found
      HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Wondershare Helper Compact.exe => value removed successfully
      HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\DelaypluginInstall => value removed successfully
      C:\ProgramData\Wondershare => moved successfully
      C:\Program Files (x86)\Common Files\Wondershare => moved successfully
      C:\Users\Bernadette\AppData\Roaming\supportdotcom => moved successfully
      C:\Program Files (x86)\supportdotcom => moved successfully
      C:\Users\Bernadette\AppData\Local\SPRT => moved successfully
      C:\Windows\System32\Drivers\etc\hosts => moved successfully
      Hosts restored successfully.

      ========= RemoveProxy: =========

      HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
      HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
      HKU\S-1-5-21-2137693414-1345286262-3239578380-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
      HKU\S-1-5-21-2137693414-1345286262-3239578380-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully

      ========= End of RemoveProxy: =========

      =========== EmptyTemp: ==========

      BITS transfer queue => 8388608 B
      DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 192035119 B
      Java, Flash, Steam htmlcache => 2886 B
      Windows/system/drivers => 1173352549 B
      Edge => 0 B
      Chrome => 765824731 B
      Firefox => 0 B
      Opera => 0 B

      Temp, IE cache, history, cookies, recent:
      Users => 0 B
      Default => 66228 B
      Public => 0 B
      ProgramData => 0 B
      systemprofile => 42320979 B
      systemprofile32 => 1047870 B
      LocalService => 173204 B
      NetworkService => 268278 B
      Bernadette => 2382448697 B
      UpdatusUser => 66228 B

      RecycleBin => 55846926 B
      EmptyTemp: => 4.3 GB temporary data deleted.

      ================================

      The system had to restart.

      End of Fixlog 18:58:10

    0
  3. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    I think it's correct.
    Any particular things to see?

    --
    Please press any key to continue the disinfection...
    0
    1. djoudjoudjou
       
      great!!

      thank you for your availability!
      0