Solved I just got that call...

HAVOC

New member
Guru
VIP
Local time
4:25 PM
Messages
1,355
Location
Connecticut
I just got that call... (fix my computer)

My cousin called to tell me that he had a pop-up that said he has a virus and to call this number. He did and was told that it will cost $300 to fix and he can take it to Staples to get fixed (never heard of that one).

I'm going there tomorrow to fix it. Can you guys/girls give me a list of software I might need?

So far I have MSE, Malwarebytes, ComboFix, HiJackThis.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome
Google that phone number or try in some other way to determine what particular virus that might be and then pound Google for a solution--which might mention applications that are known to be able to get rid of it.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Ignatz Special; 4 speed manual gearbox; factory air conditioning; one of one
OS
Windows 7 Home Premium SP1, 64-bit
CPU
Intel Skylake i5-6600K, not overclocked
Motherboard
AsRock Z170M Extreme 4, micro ATX
Memory
8 GB HyperX DDR4-2666 (2 x 4 GB)
Graphics Card(s)
none; graphics are integrated on CPU
Sound Card
onboard: Realtek ALC1150; external: USB Behringer UF0-202
Monitor(s) Displays
Dell S2340M 23 inch IPS
Screen Resolution
1600 x 900
Hard Drives
System: Crucial MX100 series SSD, 128 GB;
Data: Samsung Spinpoint 103SJ, 1 TB;
Backup: WD Caviar Green WD30EZRX-00D8PB0, 3 TB
PSU
Rosewill SilentNight 500 watt fanless, semi-modular
Case
Antec Solo II
Cooling
Noctua NH-U12S; Noctua F12 intake, Noctua S12A exhaust
Keyboard
Microsoft 200 6JH-00001 USB
Mouse
Dell or Microsoft optical wired; USB
Antivirus
Microsoft Security Essentials and Malwarebytes Premium
Browser
Pale Moon
Other Info
All fans PWM; speeds at idle: CPU circa 500 rpm; intake circa 600 rpm; exhaust circa 600 rpm; CPU temps 27 idle and 47 C load in a warm room (27 C/81 F) when running Intel Extreme Tuning Utility stress test.
My cousin called to tell me that he had a pop-up that said he has a virus and to call this number. He did and was told that it will cost $300 to fix and he can take it to Staples to get fixed (never heard of that one).

I'm going there tomorrow to fix it. Can you guys/girls give me a list of software I might need?

So far I have MSE, Malwarebytes, ComboFix, HiJackThis.

This is obviously a scam.

Don't go to Staples ( or Bestbuy Geek squad) for any repair.

A person on this forum went there ( on her own) and they charged her over $300 for a computer that was one week old and had nothing wrong with it - just lots of bloatware.

If you think you might have a problem, it can be fixed here.

In the future, when you comp is clean, get in the habit of doing image backups and if you do get a virus, you can do a restore and be back to normal in minutes.

Search Results - Macrium Software

You can also call Staples, and I'm sure they will tell you that they did not initiate that call.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self-Built
OS
Windows 7 Professional X64
CPU
Core i7 (2nd gen) i7-2600K / 3.40GHz
Motherboard
ASUS P8Z77-V Intel 7 Series Motherboard
Memory
DDR3 2400MHz (OC) 16gb
Graphics Card(s)
Intel(R) HD Graphics 3000, -1988 Mb
Sound Card
8 ChannelsAudio Chipset Realtek ALC892
Monitor(s) Displays
LG 29UM65 Black 29"
Screen Resolution
2560 x 1080
Hard Drives
840 EVO 250 GB SSD ;2tb (2);Seagate;1tb Seagate; 750 gb Seagate; wd ext (2) 750 gb,WD 2tb X 2;WD 3TB Black
PSU
750 watt
Case
Thermaltake RX -1
Cooling
2120mm Fans Included 1Other Fan Ports 5x 200mm Fan Ports
Keyboard
Microsoft Digital Media Pro
Mouse
Microsoft Wireless 6000
Internet Speed
U-verse 18 mbps
Antivirus
MSE
Browser
Firefox, Chrome and my favorite: Pale Moon
Other Info
HdHomerun Dual Tuner.
SRS Audio Lab,
Pioneer BDR 208-DBK
PS3-What a difference in my Surround Sound Receiver!
HP 4540s - My new Toy.
Epson R280 Printer- To personalize my Dvds.
Canon MP 560 - For scanning.
I've told my cousin numerous times to make backups of everything. Does he listen? No.

I kept trying to tell him over the phone that it was fake and he's convinced he has a virus. I know he has something bad on his system but I'm not sure what. His son later tried to download Minecraft (I have no idea from where) and they got a lot of other "software" with it. He now says his computer is acting very weird. I'm going to look at it after work today.

I also added to the list, AdwCleaner, rkill and tdsskiller.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome
Several people I know got calls telling them their PC was infected & unfortunately, a couple believed it. They allowed the company to access their PC's & were charged for services & the company's "Special repair tool." That tool turned out to be JRT. The people got charged $150 for "services & the repair tool."

Superantispyware has a portable version you might want to add to the list. JRT is also another one you might want to add.

SUPERAntiSpyware - SUPERAntiSpyware Portable Scanner

Junkware Removal Tool Download
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
I've told my cousin numerous times to make backups of everything. Does he listen? No.

I kept trying to tell him over the phone that it was fake and he's convinced he has a virus. I know he has something bad on his system but I'm not sure what. His son later tried to download Minecraft (I have no idea from where) and they got a lot of other "software" with it. He now says his computer is acting very weird. I'm going to look at it after work today.

I also added to the list, AdwCleaner, rkill and tdsskiller.

Ask your cousin how they knew he had a problem.

They were the problem to begin with!

After you check it out, you will be able to fix it at this forum for Free.:D

Any time you download programs, always click "custom" and uncheck all the other garbage they want to add.

That's probably what he got with the download and can be easily removed.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self-Built
OS
Windows 7 Professional X64
CPU
Core i7 (2nd gen) i7-2600K / 3.40GHz
Motherboard
ASUS P8Z77-V Intel 7 Series Motherboard
Memory
DDR3 2400MHz (OC) 16gb
Graphics Card(s)
Intel(R) HD Graphics 3000, -1988 Mb
Sound Card
8 ChannelsAudio Chipset Realtek ALC892
Monitor(s) Displays
LG 29UM65 Black 29"
Screen Resolution
2560 x 1080
Hard Drives
840 EVO 250 GB SSD ;2tb (2);Seagate;1tb Seagate; 750 gb Seagate; wd ext (2) 750 gb,WD 2tb X 2;WD 3TB Black
PSU
750 watt
Case
Thermaltake RX -1
Cooling
2120mm Fans Included 1Other Fan Ports 5x 200mm Fan Ports
Keyboard
Microsoft Digital Media Pro
Mouse
Microsoft Wireless 6000
Internet Speed
U-verse 18 mbps
Antivirus
MSE
Browser
Firefox, Chrome and my favorite: Pale Moon
Other Info
HdHomerun Dual Tuner.
SRS Audio Lab,
Pioneer BDR 208-DBK
PS3-What a difference in my Surround Sound Receiver!
HP 4540s - My new Toy.
Epson R280 Printer- To personalize my Dvds.
Canon MP 560 - For scanning.
Just be very careful about ComboFix --- it is NOT for those who do not know EXACTLY what they are doing...
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Professional
I'm sitting at his computer now. His son downloaded Minecraft (paid, from Minecraft's site) and that's when the problems began. Malwarebytes found 2700 items, MSE found nothing (quick scan), HiJackThis found a couple things, TDSSKiller found nothing, RKill found some items. I won't run ComboFix until I ask people on this site if I ned to.

He was unable to get online. LAN settings in Internet Options keeps getting changed to a proxy server.

I'm presently updating Windows and other programs on the computer.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome
I just received a similar call, but mine came from "Windows Technical Dept".:D:D

I told him my phone was being monitored by the DEA, as I'm a big time criminal - He slammed the phone down so hard, my ears are still ringing.:roflmao:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self-Built
OS
Windows 7 Professional X64
CPU
Core i7 (2nd gen) i7-2600K / 3.40GHz
Motherboard
ASUS P8Z77-V Intel 7 Series Motherboard
Memory
DDR3 2400MHz (OC) 16gb
Graphics Card(s)
Intel(R) HD Graphics 3000, -1988 Mb
Sound Card
8 ChannelsAudio Chipset Realtek ALC892
Monitor(s) Displays
LG 29UM65 Black 29"
Screen Resolution
2560 x 1080
Hard Drives
840 EVO 250 GB SSD ;2tb (2);Seagate;1tb Seagate; 750 gb Seagate; wd ext (2) 750 gb,WD 2tb X 2;WD 3TB Black
PSU
750 watt
Case
Thermaltake RX -1
Cooling
2120mm Fans Included 1Other Fan Ports 5x 200mm Fan Ports
Keyboard
Microsoft Digital Media Pro
Mouse
Microsoft Wireless 6000
Internet Speed
U-verse 18 mbps
Antivirus
MSE
Browser
Firefox, Chrome and my favorite: Pale Moon
Other Info
HdHomerun Dual Tuner.
SRS Audio Lab,
Pioneer BDR 208-DBK
PS3-What a difference in my Surround Sound Receiver!
HP 4540s - My new Toy.
Epson R280 Printer- To personalize my Dvds.
Canon MP 560 - For scanning.
I just received a similar call, but mine came from "Windows Technical Dept".:D:D

I told him my phone was being monitored by the DEA, as I'm a big time criminal - He slammed the phone down so hard, my ears are still ringing.:roflmao:
This was an excellent answer.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Most of the infection has been cleaned, I think he had every type of malware on his computer.

How long should ESET online scanner and MSE take to do a full scan?

I'm thinking about saving the documents he needs to his WD MyBook drive and wipe the computer, I don't think I'll be 100% sure I'll get all of it.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome
Most of the infection has been cleaned, I think he had every type of malware on his computer.

How long should ESET online scanner and MSE take to do a full scan?

I'm thinking about saving the documents he needs to his WD MyBook drive and wipe the computer, I don't think I'll be 100% sure I'll get all of it.
Don't bother scanning with MSE. A full scan takes several hours and never finds anything. Use Malwarebytes instead. That is a powerful scanner.

For saving the files, you can use this Linux tool and before you put them on the OneBook, scan them here. But there is a 128MB size limit. So you will have to do it in batches.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Maiwarebytes was the first scanner I used and it found 2700 items. After that I used other programs and they all found a couple items. He called me and said ESET finished, there were two items that weren't removed so I had him write them down so I could come by later and see what they are. I think he's going to run MSE just to see if it finds anything.

Any idea on why the proxy settings in IE kept changing?

I have to add, when he called that number, a person convinced him to let them gain control of the computer.
Am I better off just starting from scratch? He'll have customer info on this computer. He owns his own business.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome
Bad news. If they got control of his system, they probably stole everything. You must start from scratch and he has to change all his passwords.

I would make an image of the partitions that contain his data and recover the data later from there. Use free Macrium and not Windows imaging. Safest would be a virtual partition for the recovery process. Use Windows 10 TP in the virtual partition. It is free. If the virtual partition gets infected you can care less. You just delete it at the end of the operation.


You have to be extremely careful with those data files. Only Virus Total can make a really deep scan.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Can I save the needed files/documents/pictures to the WD external drive and scan that with a known clean PC (my netbook) and Virus Total? I don't care if my netbook gets infected (it won't be connected to my network either). I can then wipe his computer and reinstall Windows.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome
That a stranger got inside a business computer is something to be very very concerned about. I sure hope customer records, accounts information was not stored on said computer. That business needs a no-nonsense IT person that when IT speaks, everybody in the office listens.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Antec desktop; Acer Aspire laptops
OS
Windows 7 Professional 64-bit
CPU
Desktop i5; Acers i5 & i7
Memory
desktop 16GB; 1 Acer 8GB & 1 Acer 16GB
Hard Drives
1TB split into 2 equal partitions [OS and data] usable by RJS
Internet Speed
AT&T DSL
Browser
FF, GChrome, msIE
Other Info
Windows 7 Firewall, Emsisoft AM/AV, MSE [scan-only], SpywareBlaster, Ruiware/BillP combine
That's one way of doing it. But a virtual machine would be less painful.

It is not very likely that the files are infected, but you never know what these guys do. I am more worried that they stole a lot of files and passwords. The passwords need attention asap. And if there is banking info in the system, talk to the bank(s).
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
He said there is no banking info on the computer. There are other users on the computer, wife and son. Should they change their passwords?

I'm going to ask him to gather all the discs for software he needs including Windows so I can do a reinstall. I need to make two profiles, him as the admin and his wife as a standard user.

One last thing. What is a good/free program to use that will allow me to login to his computer from my house should he need tech help?

Thank you.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Pauly Special
OS
Win7 Ultimate X64
CPU
Intel i5 3570K
Motherboard
Gigabyte Z77X-DS3H
Memory
8GB DDR3 1600
Graphics Card(s)
Onboard
Sound Card
Onboard
Screen Resolution
1280x1024
Hard Drives
Samsung 840 Evo SSD (OS)
1TB Spinner (Data)
PSU
800W Arctic
Case
Cooler Master
Cooling
3x120mm Fans
Keyboard
MS Wireless
Mouse
MS Wireless
Internet Speed
20M
I'm going to sound very un-nice here, what are and why are family members doing non-business things on a business computer? Many many business advice sources indicate: business and family nonbusiness should never ever be mixed -- especially on desktops or laptops conducting business involving clients, vendors, and so on. I'm sorry if I come across harsh, I'm concerned.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Antec desktop; Acer Aspire laptops
OS
Windows 7 Professional 64-bit
CPU
Desktop i5; Acers i5 & i7
Memory
desktop 16GB; 1 Acer 8GB & 1 Acer 16GB
Hard Drives
1TB split into 2 equal partitions [OS and data] usable by RJS
Internet Speed
AT&T DSL
Browser
FF, GChrome, msIE
Other Info
Windows 7 Firewall, Emsisoft AM/AV, MSE [scan-only], SpywareBlaster, Ruiware/BillP combine
Back
Top