Grandma allowed Computer 350 Tech scammer to install junk.

byzantine

New member
Member
Local time
6:59 AM
Messages
53
Hi,

My chore is to remove the icon and the associated malware that my grandmother has allowed the scammers to download. She also gave them remote access to her computer and I want to make sure that is gone.

When I right click on the icon there is no "uninstall" option, of course.

I don't want to left click on it (execute it) because God only knows what it would do then.

The icon on the desktop is titled "Computer 350 Tech".

She is running Windows 7.

Thanks
 

My Computer My Computer

At a glance

windows 7 32 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
windows 7 32 bit
Motherboard
asus ??
Hard Drives
maxtor 75 g
Browser
firefox
Honestly, you really need to wipe the machine and reload it, you have no idea what type of malware could be installed in the background.
 

My Computer My Computer

At a glance

Windows 11
Computer type
PC/Desktop
OS
Windows 11
Hi byzantine,

My chore is to remove the icon and the associated malware that my grandmother has allowed the scammers to download. She also gave them remote access to her computer and I want to make sure that is gone.

When I right click on the icon there is no "uninstall" option, of course.

I don't want to left click on it (execute it) because God only knows what it would do then.

The icon on the desktop is titled "Computer 350 Tech".
:doh:

Well, I would definately, without a shadow of a doubt, re-install Windows. You will probably never get to the bottom of what they have done, and therefore you will leave yourself open to all sorts of risks. It is just not worth it, believe me!

RE-INSTALL.

How do you know they were scammers, what exactly happened?
How was the icon put onto the desktop, was it from a link that she received or was it by remote access?
Do you know what remote access program/software they used?
I assume that the program doesn't show in up Programs and Features?

I hope this helps!
 

My Computer My Computer

At a glance

Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux...Intel(R) Pentium(R) CPU P6200 @ 2.13GHz4.00 GBIntel(R) Graphics Media Accelerator HD
Computer type
Laptop
Computer Manufacturer/Model Number
Fujitsu LIFEBOOK
OS
Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux Mint 18.3
CPU
Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Motherboard
FUJITSU FJNBB06
Memory
4.00 GB
Graphics Card(s)
Intel(R) Graphics Media Accelerator HD
Sound Card
[1] Realtek High Definition Audio [2] Intel(R) Display Audio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
TOSHIBA MK5076GSX
Antivirus
AVG FREE
You also need to consider changing all passwords used ever on the PC - tthe remote access would have given the scammers complete access to the system and they will have stolen all passwords and account details stored on the hard disk and probably installed a keyboard scanner which will steal any passwords that were not stored on the system the next time they are used, any bank details will likely already been sold, so check with relevant financial agents, and do this quickly, most banks will protect the accounts in this situation, but only those transactions that occur after they are informed
 

My Computers My Computers

  • At a glance

    Windows 11 Pro x64 [Latest Release and Releas...Ryzen 9 5950X, 3.8 - 5.2 MHz64GB [2 x 32GB] DDR4 3200MHz4GB NVIDIA GEFORCE GTX 1650 Ti
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • At a glance

    Windows 11 Pro x64 Latest RPIntel I7 10750H 5.0GHz32GB [2x16GB] DDR4 2933 MHznVidia GTX1650Ti 4 GB GDDR6
    Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
You also need to consider changing all passwords used ever on the PC - the remote access would have given the scammers complete access to the system and they will have stolen all passwords and account details stored on the hard disk and probably installed a keyboard scanner which will steal any passwords that were not stored on the system the next time they are used, any bank details will likely already been sold, so check with relevant financial agents, and do this quickly, most banks will protect the accounts in this situation, but only those transactions that occur after they are informed
Excellent points and post Barman58 :thumbsup:.
 

My Computer My Computer

At a glance

Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux...Intel(R) Pentium(R) CPU P6200 @ 2.13GHz4.00 GBIntel(R) Graphics Media Accelerator HD
Computer type
Laptop
Computer Manufacturer/Model Number
Fujitsu LIFEBOOK
OS
Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux Mint 18.3
CPU
Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Motherboard
FUJITSU FJNBB06
Memory
4.00 GB
Graphics Card(s)
Intel(R) Graphics Media Accelerator HD
Sound Card
[1] Realtek High Definition Audio [2] Intel(R) Display Audio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
TOSHIBA MK5076GSX
Antivirus
AVG FREE
Hi byzantine,


:doh:

Well, I would definately, without a shadow of a doubt, re-install Windows. You will probably never get to the bottom of what they have done, and therefore you will leave yourself open to all sorts of risks. It is just not worth it, believe me!

RE-INSTALL.

How do you know they were scammers, what exactly happened?
How was the icon put onto the desktop, was it from a link that she received or was it by remote access?
Do you know what remote access program/software they used?
I assume that the program doesn't show in up Programs and Features?



I hope this helps!

She doesn't remember it very well. I don't know if it was a phone call, or an email, or a pop-up. They said her Gmail would no longer work due to a virus, and they would set her up with a Yahoo account for $150. She gave them her credit card number, and also gave them access to her computer (somehow).
The $150 charge has shown up on her card already, but no other ripoff yet. She was supposed to call her credit card and have it closed and a new one issued. I have to check with her on that.

Programs and features shows a Microsoft.net Framework 4.7.2 intstallation on 9/11/18. Could that be it?
 

My Computer My Computer

At a glance

windows 7 32 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
windows 7 32 bit
Motherboard
asus ??
Hard Drives
maxtor 75 g
Browser
firefox
Hi byzantine,

Programs and features shows a Microsoft.net Framework 4.7.2 intstallation on 9/11/18. Could that be it?
Definately not that, that is legit.

I hope this helps!
 

My Computer My Computer

At a glance

Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux...Intel(R) Pentium(R) CPU P6200 @ 2.13GHz4.00 GBIntel(R) Graphics Media Accelerator HD
Computer type
Laptop
Computer Manufacturer/Model Number
Fujitsu LIFEBOOK
OS
Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux Mint 18.3
CPU
Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Motherboard
FUJITSU FJNBB06
Memory
4.00 GB
Graphics Card(s)
Intel(R) Graphics Media Accelerator HD
Sound Card
[1] Realtek High Definition Audio [2] Intel(R) Display Audio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
TOSHIBA MK5076GSX
Antivirus
AVG FREE
Hi byzantine,


Definately not that, that is legit.

I hope this helps!

Yes, thanks. How can I tell if a keylogger has been installed? Will it have a name listed somewhere?
 

My Computer My Computer

At a glance

windows 7 32 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
windows 7 32 bit
Motherboard
asus ??
Hard Drives
maxtor 75 g
Browser
firefox
Hi byzantine,

She doesn't remember it very well. I don't know if it was a phone call, or an email, or a pop-up. They said her Gmail would no longer work due to a virus, and they would set her up with a Yahoo account for $150. She gave them her credit card number, and also gave them access to her computer (somehow).
The $150 charge has shown up on her card already, but no other ripoff yet. She was supposed to call her credit card and have it closed and a new one issued. I have to check with her on that.

This does indeed sound like she has been scammed.

How can I tell if a keylogger has been installed? Will it have a name listed somewhere?

If you are thinking that you are going to be able to sort this out and get rid of all the remnants of what they have done, I am afraid that you are going to be disappointed. These scammers are very clever and don't leave very many clues as to what they have done, or are about to do, if any.

The amount of time you will spend trying to rectify this will be hours and hours, and then you will never really know if you have been totally successful. Then, all of a sudden, her bank account will show zero.

The only logical and sensible solution to this is to re-install Windows 7, honestly. Also, don't forget to get her to change ALL her passwords immediately. I can't stress this enough!

I hope this helps!
 

My Computer My Computer

At a glance

Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux...Intel(R) Pentium(R) CPU P6200 @ 2.13GHz4.00 GBIntel(R) Graphics Media Accelerator HD
Computer type
Laptop
Computer Manufacturer/Model Number
Fujitsu LIFEBOOK
OS
Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux Mint 18.3
CPU
Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Motherboard
FUJITSU FJNBB06
Memory
4.00 GB
Graphics Card(s)
Intel(R) Graphics Media Accelerator HD
Sound Card
[1] Realtek High Definition Audio [2] Intel(R) Display Audio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
TOSHIBA MK5076GSX
Antivirus
AVG FREE
Make sure you have the windows license key.
 

My Computers My Computers

  • At a glance

    7 X64i5 84002x8gb 3200mhz
    Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • At a glance

    7x64g54008gb ddr4 2400
    Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
I called her bank and had them suspend the online access to her account. Told them what happened. Bank (fraud dept) thinks simply having Geeksquad or Bestbuy run a virus scan, and certifying the computer virus-free will be enough to unsuspend the online access., and my Mom can merrily use the account again, after changing passwords.

Obviously you guys think the virus scan alone will not be enough, right?

Reloading Windows 7 sounds like an enormous ordeal.

What about doing a Housecall TrendMicro virus scan?


Best buy wants $149 for a virus check. Same with Geeksquad.
 

My Computer My Computer

At a glance

windows 7 32 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
windows 7 32 bit
Motherboard
asus ??
Hard Drives
maxtor 75 g
Browser
firefox
$149 ? wow.

The best advice is to wipe and reinstall. Easy for us to say - we do it often, so we find it quite quick and easy.

If you are determined not to to do that, $149 - they are charging for their time. It is possible to have a go yourself - but that requires several different tools - there are plenty of free ones. However, that is more time and effort than reinstalling. More importantly, reinstalling is the safest way.
 

My Computers My Computers

  • At a glance

    7 X64i5 84002x8gb 3200mhz
    Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • At a glance

    7x64g54008gb ddr4 2400
    Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
I could probably supply and fit a replacement Hard Drive for that, but I may be missing something


You could go to Bleeping Computer [ BleepingComputer.com - News, Reviews, and Technical Support ]and open a case there, they are the de facto experts in that field and would do a much better job instructing you to perform the tasks required. and all they would ask for is a donation that you can afford, and that is optional.

It does mean that you would perform all the tests and remedial work under instruction but the guys over there are used to dealing with all levels of experience.

You can if you wish post a link back here which will save typing out too much again
 

My Computers My Computers

  • At a glance

    Windows 11 Pro x64 [Latest Release and Releas...Ryzen 9 5950X, 3.8 - 5.2 MHz64GB [2 x 32GB] DDR4 3200MHz4GB NVIDIA GEFORCE GTX 1650 Ti
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • At a glance

    Windows 11 Pro x64 Latest RPIntel I7 10750H 5.0GHz32GB [2x16GB] DDR4 2933 MHznVidia GTX1650Ti 4 GB GDDR6
    Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
Reloading Windows 7 sounds like an enormous ordeal.

It does sound intimidating at first, but it isn't that bad. I would NOT pay for one of these services, knowledge is power and this is a great thing to learn for your future.

I would suggest bringing it back to factory default as this is the most effective to remove all the crap;

1. Find and save all your personal files such as pictures, docs etc. that you don't want to loose. Back them up to a external source like a thumb drive. Then again, you may not have much. If you use all the defaults for saving, this will be very easy for you to do.

2. Make a list of any important software you added to this system as this will be deleted during the restoration; Have the software on hand to reinstall including activation numbers etc. or the links to it, or the compressed files. It's good to keep a list of this off the pc for times like this.

3. If you LOVE your bookmarks like I do, export them.

4. If you have anything special, files, coding, configs you spent allot of time on, save them also.

The rest is easy very easy:

Go to 'Control Panel' > 'Recovery' > Advanced Recovery Methods > 'Return Your Computer To Factory Condition'

This is extremely thorough and easy. When it's done, your system will be just the same and as fast as the day it was purchased.

-So if you had added software, you would now reinstall that
-Add back your pics, docs etc.
-import your bookmarks

That's it! It really is simple :)
---------------------------------------------------------

Additional Thought for Future Safety and Ease of Recovery

I personally have a load of software I had to reinstall, most people do not have this problem. But to eliminate the need to reinstall the software I have WHEN this occurs again, what I do is:

Once my new system is back up and I installed my software packages, if everything is cool, I then create an IMAGE file. This way, next time, and there always is, I can reinstall my IMAGE file instead of the Factory Default and my system will be like new except this time with my added software packages so I don't have to reinstall them.

Good food for thought :)

- Rainner
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 / Kali Linux multibootI7 orig 2.66gHz Quad unlocked & overclocked >...18GB Extreme DDR3
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Intel my own build
OS
Windows 7 Ultimate x64 / Kali Linux multiboot
CPU
I7 orig 2.66gHz Quad unlocked & overclocked > 3.6/4.2gHz
Memory
18GB Extreme DDR3
Monitor(s) Displays
4 x (never give sizes) :)
Screen Resolution
tight
Case
CoolerMaster Full Size
Next time clone the computer to an adequate USB external HDD so when disator strikes you can simply clone back.

If grandma is just surfing the net and printing things, then it might be worthwhile to use some flavor of Linux. Many use Linux Mint.

Screenshots - Linux Mint
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64
Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
Maybe there was not remote access at all, if you know what to look for you could tell. I agree with what others said above, but if there was no remote access then there is no need to get crazy.

If she is able, ask her if she gave them any passwords, or if they asked her to download anything? Otherwise there was no remote access. "They" cannot download anything without her doing so. Unless a remote access piece of software was installed prior and they asked her to click on it and give THEM the password. Do you know if Teamviewer is installed, look in Programs and Features.

If LogmeIn was installed it should be in the C: Drive or on Program Files or Program Files (x86) Don't get me wrong, anything is possible, but you have to allow access to get access. Sometimes our clients will think they were hacked because they got a browser hijack or something. A browser hijack is scary to someone that don't know what it is, but if she didn't download a program, install it and give them the password then it's unlikely she was hacked. A browser hijack will also demand you call a phone number and then they try to talk you into paying them, this is what they do, low level scammers praying on the elderly. Giving someone your credit card info does not allow access to your computer. Just something to think about before reformatting your pc.

Malwarebytes is very good in addition to what you using now. What AV product are you using now?

Do you have a good restore point available?

Was she storing Passwords in a Browser without being password protected? Even if she was and they were unprotected they would again had to have access to the pc.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bitAMD A8-3520M6.00GB DDR3 @ 674MHz (9-9-9-24)512MB ATI AMD Radeon HD 6620G
Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv7-6c23cl
OS
Windows 7 Home Premium 64bit
CPU
AMD A8-3520M
Motherboard
Hewlett-Packard 180B (Socket FS1)
Memory
6.00GB DDR3 @ 674MHz (9-9-9-24)
Graphics Card(s)
512MB ATI AMD Radeon HD 6620G
Sound Card
IDT High Definition Audio CODEC
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
(1600x900@60Hz)
Hard Drives
Samsung 850 EVO 250GB SSD
Mouse
Logitec M525
Internet Speed
30-75Mbps
Antivirus
Avast Free, Unfortunately
Browser
Google Chrome, Firefox, IE
Hi Nasty7,

My chore is to remove the icon and the associated malware that my grandmother has allowed the scammers to download. She also gave them remote access to her computer and I want to make sure that is gone.

When I right click on the icon there is no "uninstall" option, of course.

I don't want to left click on it (execute it) because God only knows what it would do then.

The icon on the desktop is titled "Computer 350 Tech".

We have all gone with the fact that the computer has been hacked because of the OP's comments above.

You have made some good observations and comments in your post above. I am sure that anyone else coming across this thread that has a similar problem will find them very useful.

I still think that at the end of the day, for security reasons and piece of mind, that a re-install is the best option available.
 

My Computer My Computer

At a glance

Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux...Intel(R) Pentium(R) CPU P6200 @ 2.13GHz4.00 GBIntel(R) Graphics Media Accelerator HD
Computer type
Laptop
Computer Manufacturer/Model Number
Fujitsu LIFEBOOK
OS
Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux Mint 18.3
CPU
Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Motherboard
FUJITSU FJNBB06
Memory
4.00 GB
Graphics Card(s)
Intel(R) Graphics Media Accelerator HD
Sound Card
[1] Realtek High Definition Audio [2] Intel(R) Display Audio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
TOSHIBA MK5076GSX
Antivirus
AVG FREE
We have all gone with the fact that the computer has been hacked because of the OP's comments above.
With all do respect I don't see any "facts" and people make unclear comments all the time, I'm only saying to get a little more clarity on the subject before the task of a reinstall because the op don't seem to be tech savvy.

I don't disagree with the safety of a reinstall, but I see this all the time, and unless the wording of the op is incorrect it's hard to say what happened.

my grandmother has allowed the scammers to download.
This suggests someone was able to download something BEFORE having access to the pc, that's not possible as we all know.

The program in question can be checked to see what the install date was, it may have been there for years. Right Click File Location, and see when it was installed. I don't see that program online either, which is weird in itself, most likely renamed icon.

So it may be worth while to talk with grandmother after she has calmed down and see exactly what happened before a reinstall. The only reason I say this is because this can be a daunting task for the uninitiated.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bitAMD A8-3520M6.00GB DDR3 @ 674MHz (9-9-9-24)512MB ATI AMD Radeon HD 6620G
Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv7-6c23cl
OS
Windows 7 Home Premium 64bit
CPU
AMD A8-3520M
Motherboard
Hewlett-Packard 180B (Socket FS1)
Memory
6.00GB DDR3 @ 674MHz (9-9-9-24)
Graphics Card(s)
512MB ATI AMD Radeon HD 6620G
Sound Card
IDT High Definition Audio CODEC
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
(1600x900@60Hz)
Hard Drives
Samsung 850 EVO 250GB SSD
Mouse
Logitec M525
Internet Speed
30-75Mbps
Antivirus
Avast Free, Unfortunately
Browser
Google Chrome, Firefox, IE
Hi Nasty7,

This suggests someone was able to download something BEFORE having access to the pc, that's not possible as we all know.

It could have been a popup [or something similar] that said the machine was infected, and in order to get rid of the infection she should click a link, and then telephone the number supplied for techical help/support. We really don't know what the sequence of events were to be honest!

The program in question can be checked to see what the install date was, it may have been there for years. Right Click File Location, and see when it was installed. I don't see that program online either, which is weird in itself, most likely renamed icon.

That is a very good point!
 

My Computer My Computer

At a glance

Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux...Intel(R) Pentium(R) CPU P6200 @ 2.13GHz4.00 GBIntel(R) Graphics Media Accelerator HD
Computer type
Laptop
Computer Manufacturer/Model Number
Fujitsu LIFEBOOK
OS
Win 7 HP SP1 64-bit Vista HB SP2 32-bit Linux Mint 18.3
CPU
Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Motherboard
FUJITSU FJNBB06
Memory
4.00 GB
Graphics Card(s)
Intel(R) Graphics Media Accelerator HD
Sound Card
[1] Realtek High Definition Audio [2] Intel(R) Display Audio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
TOSHIBA MK5076GSX
Antivirus
AVG FREE
If you are a really savvy technician, then you might be able to clean the computer. Basically, you restart the computer in Safe Mode, and you then disable all start-up items and services that you aren't absolutely sure about.

Even doing that, you may not catch everything. Therefore, only a clean install will do it. That means that you do a custom Windows 7 install; and you delete all partitions on the hard drive, then create one new partition, and install Windows on that new partition.

Everything will be forever gone once you do this, and you will have a clean copy of Windows. But that is the only way to make sure that the computer is free from whatever the scammer put on it.

Make sure you have all activation codes for Windows and for whatever software you want to install prior to doing this, because you won't be able to get these codes once you do the clean install.
 

My Computer My Computer

At a glance

Linux Mint 18.2 xfce 64-bit (VMWare host) / W...Haswell4 GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Linux Mint 18.2 xfce 64-bit (VMWare host) / Windows 8.1 Pro 32-bit (VMWare guest)
CPU
Haswell
Memory
4 GB
Monitor(s) Displays
Acer 23"
Screen Resolution
1920 x 1080
Hard Drives
Two hard drives, 1TB each: One for Linux, one for my data.
Keyboard
IBM Model M
Antivirus
Sophos (Linux), Trend Micro (Windows)
Browser
Firefox, Opera
Other Info
I use Samba to share my data drive with the other computers at my house and with my guest session in VMWare Workstation Player.
Back
Top