Compromised PC - Advice please!

Kaone

New member
Local time
12:48 PM
Messages
10
A friend (yes - honestly!) has allowed a scammer to have access to his win7 PC for 20 minutes and money has subsequently been taken from his Paypal account.

I've advised him to disconnect his PC from the internet until it's "clean" but I'd appreciate some advice on what is needed.

Would a complete re-install of Win7 be necessary?

Thanks
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Acer
OS
Windows 7 Home 64 bit
The first thing I would advise your friend is change all passwords of everything.
Use a known clean computer to do the password replacement.
Then your friend should notify all financial association of the passwords being stolen.
Then check all accounts for any strange things of any kind.

Then I would do a Clean Install. It would take forever to figure out what the intruder did to the computer and what little goodies they left behind.

Please read these tutorials by Brink and Gregrocker.

http://www.sevenforums.com/tutorials/52129-disk-clean-clean-all-diskpart-command.html


http://www.sevenforums.com/tutorials/1649-clean-install-windows-7-a.html


http://www.sevenforums.com/tutorials/219487-clean-reinstall-factory-oem-windows-7-a.html
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Thanks, Layback Bear. I've read the articles but there are a couple of things (at least) that I'm uncertain about:
1. The pc has just one disk, but a full clean can't be done over the OS. How do I get round this?
2. To reload win7 all I have are the three recovery discs (DVDs) created when the pc was first set-up. Can these be used to reinstall Win7?

Thanks
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Acer
OS
Windows 7 Home 64 bit
The pc is a Dell Inspiron 660. According to Dell's website the pc can be reset to factory settings via the F8 button at start-up. Would this be sufficient to restore the pc to a safe state?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Acer
OS
Windows 7 Home 64 bit
Setting to factory settings should bring your computer back to the way it was when it was bought. If that is okay with the owner I would try it. The intruder probably never went into that partition where your factory setting are.
When done I would still scan the computer with many security scans.

Did you read the tutorials I posted?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
He should also phone the police and let them know he's been scammed right in front of his face and tell them who it was.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
W7 Pro x64 SP1 | W10 Pro IP x64 | W8.1 Pro x64 VM | Linux Mint VM
CPU
i7-4790k @ 4GHz (4.4GHz Boost)
Motherboard
ASUS Sabertooth Z87 (BIOS Rev 2004)
Memory
16GB DDR3 Kingston HyperX Fury @ 1600MHz CL 9-9-9-27
Graphics Card(s)
EVGA GTX 980 Classified
Sound Card
Realtek Onboard
Monitor(s) Displays
Samsung S27D390
Screen Resolution
1920 x 1080
Hard Drives
240GB Intel 520 Series SSD |
Samsung 850 EVO 120GB SSD |
2TB WD Caviar Black |
2TB WD Caviar Black |
2TB WD Caviar Green
PSU
Corsair HX850-80 Gold Modular
Case
Cooler Master Silencio 650
Cooling
Corsair H80i w/2 x Corsair SP120 | 2 x 120mm Noctua NF-S12B
Keyboard
Microsoft Sidewinder X4
Mouse
Gigabyte M6900 optical
Internet Speed
152mb
Antivirus
F-Secure
Browser
Firefox 38.0
Other Info
Backup Rig: Win 7 Pro 64-bit | AMD A10-5800k | ASUS F2A85-V Pro | 8GB Samsung DDR3 @1600MHz | 120GB Toshiba SDD | 2TB Seagate HDD | Cooler Master Silencio 550
Yes, I read the tutorials - please see my second post.

It sounds as though the reset to factory settings option isn't 100% safe? It would be awful if my friend lost any further money.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Acer
OS
Windows 7 Home 64 bit
Hi Boozad, Yes he has spoken to the police and passed them all the details. Lloyds bank and Paypal have also been informed.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Acer
OS
Windows 7 Home 64 bit
At least he should get his money back as long as he can provide proof to Paypal.

You can create a bootable USB stick using an ISO image of Windows 7 instead of using any disks you have. These will include Service Pack 2 and will save some update time once installed. You'd have to download the relevant ISO from here then mount that to a USB stick following Part 2 of this tutorial :ar: http://www.sevenforums.com/tutorials/31541-windows-7-usb-dvd-download-tool.html

Then move onto the links Layback Bear posted.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
W7 Pro x64 SP1 | W10 Pro IP x64 | W8.1 Pro x64 VM | Linux Mint VM
CPU
i7-4790k @ 4GHz (4.4GHz Boost)
Motherboard
ASUS Sabertooth Z87 (BIOS Rev 2004)
Memory
16GB DDR3 Kingston HyperX Fury @ 1600MHz CL 9-9-9-27
Graphics Card(s)
EVGA GTX 980 Classified
Sound Card
Realtek Onboard
Monitor(s) Displays
Samsung S27D390
Screen Resolution
1920 x 1080
Hard Drives
240GB Intel 520 Series SSD |
Samsung 850 EVO 120GB SSD |
2TB WD Caviar Black |
2TB WD Caviar Black |
2TB WD Caviar Green
PSU
Corsair HX850-80 Gold Modular
Case
Cooler Master Silencio 650
Cooling
Corsair H80i w/2 x Corsair SP120 | 2 x 120mm Noctua NF-S12B
Keyboard
Microsoft Sidewinder X4
Mouse
Gigabyte M6900 optical
Internet Speed
152mb
Antivirus
F-Secure
Browser
Firefox 38.0
Other Info
Backup Rig: Win 7 Pro 64-bit | AMD A10-5800k | ASUS F2A85-V Pro | 8GB Samsung DDR3 @1600MHz | 120GB Toshiba SDD | 2TB Seagate HDD | Cooler Master Silencio 550
Paypal have made encouraging noises, but as he gave the scammer his password I'm not sure that they'll want to pay out. We'll see.

Thanks for the info regarding the bootable USB stick. I've had a quick look but it seems rather complicated.

Can the USB stick be created on my pc and then used to boot his?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Acer
OS
Windows 7 Home 64 bit
Can the USB stick be created on my pc and then used to boot his?

Yes it can mate. Once you've downloaded the correct ISO and the USB tool it's really straightforward, especially following those tutorials.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
W7 Pro x64 SP1 | W10 Pro IP x64 | W8.1 Pro x64 VM | Linux Mint VM
CPU
i7-4790k @ 4GHz (4.4GHz Boost)
Motherboard
ASUS Sabertooth Z87 (BIOS Rev 2004)
Memory
16GB DDR3 Kingston HyperX Fury @ 1600MHz CL 9-9-9-27
Graphics Card(s)
EVGA GTX 980 Classified
Sound Card
Realtek Onboard
Monitor(s) Displays
Samsung S27D390
Screen Resolution
1920 x 1080
Hard Drives
240GB Intel 520 Series SSD |
Samsung 850 EVO 120GB SSD |
2TB WD Caviar Black |
2TB WD Caviar Black |
2TB WD Caviar Green
PSU
Corsair HX850-80 Gold Modular
Case
Cooler Master Silencio 650
Cooling
Corsair H80i w/2 x Corsair SP120 | 2 x 120mm Noctua NF-S12B
Keyboard
Microsoft Sidewinder X4
Mouse
Gigabyte M6900 optical
Internet Speed
152mb
Antivirus
F-Secure
Browser
Firefox 38.0
Other Info
Backup Rig: Win 7 Pro 64-bit | AMD A10-5800k | ASUS F2A85-V Pro | 8GB Samsung DDR3 @1600MHz | 120GB Toshiba SDD | 2TB Seagate HDD | Cooler Master Silencio 550
The tutorials in my Post #2 are the best methods.
Because you and the members here don't know what the intruder did in your friends system.
I don't know how us telling you and then you tell your friend will work in completing these task.
Who is going to complete this repair? You or your friend?

 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Hi Layback Bear,

Sorry if there was some confusion. My friend knows nothing about computers so I have volunteered to do it for him. I also set it up for him when he first got it. I've moved it from his house to mine as I suspect it could be a lengthy process. After a career in IT I've now been retired for nearly 20 years so my technical knowledge of today's pcs is sketchy, however I can appreciate the risks posed when a professional hacker has had access. Your. and others, advice is greatly appreciated. Thank you.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Acer
OS
Windows 7 Home 64 bit
Back
Top