Tech Help Friend's computer hacked

Gosh Josh

Active Member
Joined
Oct 1, 2013
Messages
400
Hello everyone,

Someone close to me fell for a pop-up advertisement that their computer was at risk. They went as far as installing a program to allow the person control over their computer and spoke to the person over the phone before contacting one of my other friends who told me. Of course I'm convinced it's a scam, and the person is trying to undo the damages, if any. Can anyone please help?

P.S. Please only reply with HELP. I am not looking for CRITICISM as to why this happened.
 
Depending on the hacking/spyware used, you may have only two options:

1) Isolate the hard drive and reformat it completely. After reformat, run several different virus scans to check the integrity to ensure no lingering code remained that could continue to give the hacker access.

2) Scrap the hard drive, install a brand new one.

The tricky part is if there are any important documents on that hard drive. Then it becomes tricky, where the only recourse that person will likely have is to take it to a PC store to get them to help isolate the important files, transfer them to a USB stick, and then wipe the hard drive.
 
Booting up in Safe Mode and run scans with both Superantispyware and Malwarebytes. These are both free and quite effective.

If your friend is willing to pay money, then have them purchase a good AntiVirus. (http://www.pcmag.com/article2/0,2817,2372364,00.asp)

However, as SnipeEye mentioned, you might have to reformat the drive/buy a new one.
 
Depending on the company that they likely called and allowed to remotely access their computer, there are a few options.

If the company enabled Syskey and it's asking for a password before the standard Windows login screen, then you can either reinstall Windows, or depending on the OS, there are commercially available programs to forcefully disable the syskey. (I recommend having a professional or extremely knowledgeable friend do this.)

If they didn't enable anything like that, treat it like any other infection. Malwarebytes, Windows Defender Offline, antivirus scan, Autoruns and ADWCleaner if necessary. Also, make certain to uninstall the remote access software they likely installed.
 
Gosh Josh, if you haven't figured this problem out, let me know. I am pretty good with helping with things like this. And there is no need to replace hard drive because of a virus. I help a bunch of my friends get virus's, trojan's etc off they're pc's all the time. But I will say honestly if it is very infected, a reformat and fresh install is always best because pc's never seem to be "right" after infected that bad and I can help you with that too. If you need any help feel free to contact me @ http://www.edge-gamers.com/forums/member.php?u=71933. I work day's, so I am only able to help at night
 
And there is no need to replace hard drive because of a virus

Indeed. In the 30 years I've been working with PCs, I've never had to scrap a drive because of infections. There are Master Boot Record (MBR) viruses out there that can be tricky to remove, but there are tools specifically designed for them too. Those being the Offline scanners. Here at the shop, we use the one Microsoft themselves put out, the Offline Windows Defender. You burn it to a disc or install it to a blank flash drive and boot to it, letting it do a fully scan. Of the 2 computers in the last 7 years I've been working here that actually had MBR viruses, both were fixed with it.

My recommendations -

1. Download the appropriate Windows Defender. Create the bootable media, boot the computer with it and run the Full scan. Remove anything it detects.

2. Download MalwareByte's Anti-Malware. Install and run a Custom scan, check the boxes for "Rootkits" and "C:" (and any other non-removable media drives). Remove anything it finds.

3. Download AdwCleaner. Run it, Scan with it, remove all found.

4. Make sure there is a decent antivirus installed. Even many of the free ones work well. I personally use Microsoft Security Essentials. I've also used Panda Cloud Antivirus & Avast! Pick one, install it. Perform a Full scan.

5. Windows Updates. Make sure Windows is fully updated. New security holes are found and patched all the time.

6. Make sure Java and Adobe Flash are updated.

7. Remove all unnecessary add-ons / toolbars from their browser(s).

8. Once the computer is clean and updated, create a new Restore Point.

9. (Optional but recommended) Run CryptoPrevent. This will lock down certain things, such as Syskey, which scammers and some viruses will enable, locking your computer down. In addition, this will prevent current variations of the CryptoLocker / CryptoWall viruses from being run on the system. If you've never run into these RansomWares, count yourself lucky.

10. User education. Advise them to NEVER call a number on a pop-up. NEVER take cold calls from "Windows" and to beware what they click. Have them read "How did I get Infected". Grinder hasn't updated it in about 4 years, but it's still relevant. Many people will assume they only get infected if they go to "bad" sites, like porn etc... they're wrong... the reputable porn sites are rather diligent in keeping their sites virus-free. Many of our customers at the shop have been infected going to bible-related sites, via e-mail (the various USP / FedEx tracking spam) and other innocuous sites.
(peer-to-peer downloads are always "At your own risk." which is where an updated a/v and MBAM come in.)
 
Last edited:
To hopefully add to the already really good information being given. When you do get a decent Antivirus installed and updated with the latest definitions, it may help if you unplug the computer from the internet while performing the scan. Good Luck!
 
Its a tough boat the level of infection displayed here could mean FORMAT and i wont lie it probably is from what you described. The thing is there are test and stuff out there that could possibly reverse / undo this with out doing so but would take at least 8 or 9 programs and several days of testing. If you are willing to do that instead of formatting you can find me in TS ps2 area or pm me on forums and we can arrange working on this.




The pros of doing a non format is as follows

1 You can keep the pc as is and any important data is not lost.
2 You dont have to reinstall every game ect.

The cons are as follows and why alot recommend formatting

1 If you clean but miss something you could be at square 1 again wasting a lot of your time.

2 Even if you clean there is a high chance that if improperly done a keylogger or some hidden program is still in the PC meaning credit card data / passwords ect could be stolen.

3 Stores often "clean" but if there not reputable could end up costing you alot to clean something that was simple or m iss something that was extremely hard making you have to go back



PS he should CHANGE ALL PASSWORDS and moniter the credit cards incase they managed to put a keylogger in his pc.
 

Latest posts

Back
Top