Computer hacked... scammer wanted money... how to clean up

Page 1 of 2 12 LastLast

  1. Posts : 33
    Windows 10
       #1

    Computer hacked... scammer wanted money... how to clean up


    I'm trying to help a friend safely get back online. He has Windows 10 but I'm nut sure what anti-virus programs. He was hacked and called the phone number... got the usual routine, they asked for $250 to fix the computer. After he told them that he didn't have credit card and was only 14 yrs. old, they hung up. He is 88 yrs. old but clever. :-D

    Anyway, I have to pick up his computer and bring it home to work on it. Other than running anti-virus and spyware scans, what else should I look for? He doesn't have a backup to revert to. What about doing System Restore? Do the hackers plant software on the computers that shut them down? What would I be looking for exactly? I remember using a program called HiJackThis years ago. What is the new method? I welcome any tips. Thanks!
      My Computer


  2. Posts : 23,293
    Win 10 Home ♦♦♦19045.4355 (x64) [22H2]
       #2

    sillycat41 said:
    I'm trying to help a friend safely get back online. He has Windows 10 but I'm nut sure what anti-virus programs. He was hacked and called the phone number... got the usual routine, they asked for $250 to fix the computer. After he told them that he didn't have credit card and was only 14 yrs. old, they hung up. He is 88 yrs. old but clever. :-D

    Anyway, I have to pick up his computer and bring it home to work on it. Other than running anti-virus and spyware scans, what else should I look for? He doesn't have a backup to revert to. What about doing System Restore? Do the hackers plant software on the computers that shut them down? What would I be looking for exactly? I remember using a program called HiJackThis years ago. What is the new method? I welcome any tips. Thanks!


    Do a clean install of Windows. Clean Install Windows 10


    Your other option is to spend 2-3 weeks, being walked through complete removal...
    Virus, Trojan, Spyware, and Malware Removal Help Forum - BleepingComputer.com





    Which ever option you choose, make sure to install backup software afterwards. Then help the owner learn to use it.

    Macrium Software | Reflect Free Edition


    Quickie Macrium picture guide...
    Macrium Reflect and Bootable Rescue Media, pictures...


    Macrium Reflect User Guide...
    https://updates.macrium.com/reflect/...user_guide.pdf

    Macrium Notes:
    1. A full OS image backup will be approx. 1/2 the size of the total "used space" on the C:\ drive.
    2. Backing up takes about 75 seconds for every 20GB of "used space" on the C:\ drive.


    Full tutorial...
    Backup and Restore with Macrium Reflect


    Another simpler option for free backup software would be AOMEI Backupper.
    Free Backup Software for Windows 11/10/8/7 - AOMEI Backupper Standard







    The easiest, fastest option is to just do a clean install of Windows.
    Keep in mind that if there are other drives in the computer, besides the Windows drive... they may be infected too.

    But, as I mentioned above... BleepingComputer will walk you through, completely cleaning the computer.
    It will take a while. Figure two to three weeks.
    BleepingComputer are by far the best infection cleaners you will find. They've been doing this for at least 20 years that I know of.
      My Computer


  3. Posts : 43,022
    Win 10 Pro (22H2) (2nd PC is 22H2)
       #3

    Hint: whilst Macrium Reflect (free) is a great program, Aomei Backupper is simpler. I've posted a current Pro giveaway - now moved to the Backup and Restore section.
      My Computers


  4. Posts : 5,330
    Windows 11 Pro 64-bit
       #4

    Social engineering is the art of manipulating people so they give up confidential information. The kinds of data these criminals are looking for can shift, but when individuals are targeted the criminals are generally attempting to deceive you into giving them your passwords or bank information, or access your PC to covertly introduce malevolent software– that will give them access to your passwords and bank information and in addition giving them control over your PC.

    Criminals use social engineering tactics because it is much easier to fool someone into giving their password than it is for criminals to try hacking their password (unless the password is really weak).

    Malwarebytes' scanner
    If this program is already installed: Skip the installation and run only the scan!
    Download and install: Please download Malwarebytes' scanner to your desktop.

    • Double-click mb3-setup-consumer-3.x.x.xxxx and follow the prompts to install the program.
    • Click Finish.
    • On the Dashboard, click the 'Check for Updates' button.
    • After the update completes, click the 'Scan Now' button.
    • A Threat Scan will begin. Please allow it to progress through the scanning process.
    • When the scan is complete, if there have been detections, click Quarantines Selected button to allow the program to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.


    How to get logs: (Export log to save as txt)

    • After the restart once you are back at your desktop, open Malwarebytes once more.
    • Click on the Reports tab > Scan Report. (if you have done more than one scan in the past, select the most recent that shows the Date and time of the scan just performed. Press View Report button.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • Find the log on your Desktop and Attach that saved log to your next reply.


    (Copy to clipboard for pasting into forum replies or tickets)


    In this video, i will show you how to Use Process Explorer to Identify Malware Infection.

      My Computer


  5. Posts : 33
    Windows 10
    Thread Starter
       #5

    Thanks for the tips. One more question... how can I find out the name of the ransomware that infected this computer? I cannot read the small print in the video on using Process Explorer. :-(
      My Computer


  6. Posts : 5,330
    Windows 11 Pro 64-bit
       #6

    sillycat41 said:
    Thanks for the tips. One more question... how can I find out the name of the ransomware that infected this computer? I cannot read the small print in the video on using Process Explorer. :-(
    Ransomware is a form of malicious software (or malware) that, once it's infected your computer, threatens you with harm, usually by denying you access to your data. The attacker demands a ransom from the victim, promising — not always truthfully — to restore access to the data upon payment.



    Users are shown instructions for how to pay a fee to get the decryption key. The costs can range from a few hundred dollars to thousands, payable to cybercriminals in Bitcoin.


    Why do you think that ransomware infected computer?
      My Computer


  7. Posts : 33
    Windows 10
    Thread Starter
       #7

    @ Free Booter He said that a message popped up on the screen telling him to call a phone number and that they asked him for credit card info to get his computer working again. Doesn't that mean they planted some software on his computer that displayed the phone number, etc. ???
      My Computer


  8. Posts : 402
    Windows 10 Home 64-bit operating system, x64-based processor
       #8

    sillycat41 said:
    @ Free Booter He said that a message popped up on the screen telling him to call a phone number and that they asked him for credit card info to get his computer working again. Doesn't that mean they planted some software on his computer that displayed the phone number, etc. ???
    No! You can have pop ups happen like that coming from your browser and it`s not an infection! Some people are gullible enough to fall for it. Only if it`s locking you out of the computer is it a virus. If the computer is usable it`s not infected. Best tool for getting rid of any malicious software or virus is Norton Power Eraser it`s free! Download and run Norton Power Eraser - Free virus and malware removal tool for Windows
      My Computer


  9. Posts : 33
    Windows 10
    Thread Starter
       #9

    Thanks for the additional tips. I'll check Bleeping Computer and What the Tech. I don't have the computer yet.... have to pick it up this week. Wanted to research the problem so I know what to do first. I'll let you all know what I find out when I get a look at it. Thanks to all!
      My Computer


  10. Posts : 90
    Windows 10 Version 21H2 (os build 19044.2604)
       #10

    After the fact as usual, but back up drives are dirt cheap and there are lots of "rehabbed" returns on NewEgg and such (most are new returns) . I have an Odd and Even system. I use two old HDD's for odd months, and two for even mounts, then plug in the two others for even months. Yes, major over kill for a dig bat like me, but it is so easy to use nearly any program to make a synchronous non encrypted, non proprietary image.
    So far, so good. However my technological prowess has never been challenged by the bad guys.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 21:43.
Find Us




Windows 10 Forums