We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Relative got scammed by 'Windows' cold call - how to ensure computer is safe?

13

Comments

  • closed
    closed Posts: 10,886 Forumite
    edited 15 January 2012 at 6:39PM
    post a hijackthis log - you are probably worrying for nothing. ask her to go into event viewer, and see if that what they suggested.

    it probably has a factory restore partition for reinstalling windows, see the manual, and backup first.
    !!
    > . !!!! ----> .
  • mandragora_2
    mandragora_2 Posts: 2,611 Forumite
    1,000 Posts Combo Breaker
    http://www.microsoft.com/en-gb/security/online-privacy/avoid-phone-scams.aspx

    I hope this link helps. Microsoft take it seriously.
    Reason for edit? Can spell, can't type!
  • Bored
    Bored Posts: 390 Forumite
    Part of the Furniture 100 Posts Name Dropper Debt-free and Proud!
    Doesn't mean that you're home safe. You need to find a good app to hunt for rootkits.

    Any recommendations? This is out of my technical expertise. :p
    2023 Mortgage-Free Wannabe #19: £11,675.68/£13,000
    Mortgage Overpayment Total: £22,397.1
  • http://public.avast.com/~gmerek/aswMBR.htm is one
    Don't bother with the update ....
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    http://public.avast.com/~gmerek/aswMBR.exe

    • Double click aswMBR.exe
    • Click no to the prompt to download Avast! virus definitions.
    • click the Scan button.
    • When the scan reports "Scan finished successfully", click Save log & save the log to your desktop.
    • Click OK when prompted. aswMBR.txt & MBR.dat will be appear on your desktop.
    • Click EXIT.
    • Copy & paste the contents of aswMBR.txt & post it here.
  • Never seen the sophos one http://www.sophos.com/en-us/products/free-tools/sophos-anti-rootkit.aspx
    TDSkiller is ok to http://support.kaspersky.com/faq/?qid=208283363
    If they run , then it is probable that the PC hasn't got one of the latest incarnations
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • waddler_8 wrote: »
    http://public.avast.com/~gmerek/aswMBR.exe

    • Double click aswMBR.exe
    • Click no to the prompt to download Avast! virus definitions.
    • click the Scan button.
    • When the scan reports "Scan finished successfully", click Save log & save the log to your desktop.
    • Click OK when prompted. aswMBR.txt & MBR.dat will be appear on your desktop.
    • Click EXIT.
    • Copy & paste the contents of aswMBR.txt & post it here.

    Thanks Waddler, my internet is a mare at the mo,
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • robmar0se
    robmar0se Posts: 1,328 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Bored wrote: »
    Any recommendations? This is out of my technical expertise. :p

    A clean Malwarebytes report is very encouraging as it usuaaly finds any stuff that is wrong; in 5 years I have had to get back to them three times on unresolved problems. Have a go with Combofix too - http://www.bleepingcomputer.com/combofix/how-to-use-combofix - if you get a clean report here you should be pretty comfortable.

    You could also try the tdss killer - although I haven't seen this rootkit loaded by these scammers - http://support.kaspersky.com/faq/?qid=208283363

    Also look at the list of programs in the add/remove programs list to see if Logmein, or teamviewer were installed - if not that is also a good sign that your Mum stopped them before they got too far.

    I have seen systems where logmein was present where harmless programs were also loaded eg Ccleaner, Auslogics Disk Defrag, and others. They are after the cash they can extort - I've seen from £113 to over £300 - and systems where internet banking etc is present, so that they can obtain the passwords etc. If your Mum doesn't do online banking then she won't be vulnerable. Keyloggers, which identify what the user is keying will almost certainly be picked up by malwarebytes/combofix.

    In summary have a go with Combofix and follow the tutorial given in the URL above.

    Good luck
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    After all these checks it really comes down to the user & the computers use. You yourself have to be confident that the machine is trustworthy if someone may have had remote access, even in the face of "clean" scans.

    If you use the computer for online banking & there is doubt in your own head each time you use it - Then I would format & reinstall.
  • Bored
    Bored Posts: 390 Forumite
    Part of the Furniture 100 Posts Name Dropper Debt-free and Proud!
    Thanks for suggestions people, will follow advice and post results on here tomorrow.
    2023 Mortgage-Free Wannabe #19: £11,675.68/£13,000
    Mortgage Overpayment Total: £22,397.1
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.5K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.7K Mortgages, Homes & Bills
  • 177.4K Life & Family
  • 258.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.