Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


wonderstuff

110 posts

Master Geek


#274575 29-Aug-2020 11:33
Send private message

Hi all,

 

 

 

It's been about 10 years since I have used MS Windows and your advice would be welcome.

 

On Thursday morning a relative reached out to me.   They had been contacted by Spark to say that there computer was compromised and "Spark" wanted to do an online session to protect their computer.   I made my relative absolutely aware that this was a scam, ignore them completely, and never trust anyone that reaches out to you.  

 

Later that evening may relative was contacted again by "Spark" and which stage why relative told them that this was a scam and not to call again.  "Spark" then indicated that they would disable the internet for them, so my relative panicked and accepted the Zohodesk session.   During this session the "Spark" person asked my relative to log in to Westpac, TradeMe and a number of other sites, so that they could assess if they were secure.

 

After 3 hours on the phone and once the session finished, my relative gave me a call and asked if they needed to run a virus check.   My advice was, get off the phone, call the bank, stop all credit cards and in progress transactions, power off the computer and courier to me.   Unfortunately in this short time my relative had many thousands of dollars transferred out of their bank account.   We will pursue that with the bank.

 

After hearing the description of what happened, I have assumed that a key logger was installed (how else would they see the passwords), risk of a crypt locker installed, and probably harvesting of email accounts.

 

I have now received the computer and working out what the best plan of attack is.   It is off network.   There is data I would like to recover from it, and the data is pretty simple so should be unlikely to have any unwanted payloads in it.  However, I am also wondering at how effective Windows Defender is?   I initiated a scan and found TrojanDownloader.Win32/Dalesic.C on it which I have removed and the Zohodesh app that I have removed.  Nothing else is highlighted by Defender.

 

Would Defender have found any key loggers or cryptolockers?   

 

Do I need to use a different tool for neutralising threats?

 

Back in the old days I would have reformatted the HD and reinstalled the OS.   Is this still the best way?  (I am not even sure how to do this with Win10 these days!)


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
freitasm
BDFL - Memuneh
79253 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2551873 29-Aug-2020 11:44
Send private message

You can use TrendMicro Housecall to start with. Then follow with MalwareBytes. Unplug or turn other computers off when doing this if you want to be sure but they should be ok if up-to-date. 

 

If this is Windows 10 you can use Reset my PC to reinstall a fresh copy of Windows - you find this in Settings.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup




Linux
11399 posts

Uber Geek

Trusted
Lifetime subscriber

  #2551874 29-Aug-2020 11:44
Send private message

Malwarebytes free home edition is very good

gb67
44 posts

Geek


  #2551890 29-Aug-2020 12:29
Send private message

System Restore to a time before the scam?

 

Then all the security scans mentioned above.

 

Change email password and check for forwards set up  in email so scammers can see password changes.




freitasm
BDFL - Memuneh
79253 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2551891 29-Aug-2020 12:30
Send private message

System restore doesn't really do much - reset is a lot better.




Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


huckster
842 posts

Ultimate Geek

ID Verified
Lifetime subscriber

  #2551896 29-Aug-2020 12:58
Send private message

So sorry to hear about this. Have managed to head one of these off at the pass before any real damage myself.

 

Another alternative - if the data is simple - use a Linux boot CD and copy off to a usb stick? Then blow the OS away completely.


wonderstuff

110 posts

Master Geek


  #2552629 30-Aug-2020 20:38
Send private message

I would like to thank you all for your advice - much appreciated.

 

Looks like Windows Defender did a reasonable job.

 

TrendMicro Household was unable to find any other infections.

 

MalwareBytes found some potential threats which I removed.

 

I finished with the Windows Reset and have spend the rest of the afternoon restoring Office and the other apps.

 

Thanks.  Now will see if my relative is able to recover the funds transferred.

 

 


Apsattv
2388 posts

Uber Geek


  #2552752 31-Aug-2020 04:00
Send private message

The last one i looked at, they thought they were clever and could hide things and  made a restore point before they started mucking with the guys pc. Which they tried to restore  once they finished.

 

 


 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
timmmay
20575 posts

Uber Geek

Trusted
Lifetime subscriber

  #2552755 31-Aug-2020 06:20
Send private message

I wouldn't boot the compromised computer at all in this case. I'd probably create a temporary computer as a malware removal workstation, even if it meant taking the main hard drive out of my normal computer, or booting a Linux USB. I'd copy the data off you want to keep, image the drive with something like Macrium just in case you missed something, then format the disk and reinstall windows. Scan the data you copied off, and copy it back onto the new windows install.


Dulouz
883 posts

Ultimate Geek


  #2552816 31-Aug-2020 07:54
Send private message

I did this yesterday. Malwarebytes followed by HitmanPro did the job for me.





Amanon

freitasm
BDFL - Memuneh
79253 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2552839 31-Aug-2020 08:44
Send private message

Apsattv:

 

The last one i looked at, they thought they were clever and could hide things and  made a restore point before they started mucking with the guys pc. Which they tried to restore  once they finished.

 

 

I wouldn't trust a restore point at all for these things.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


1101
3122 posts

Uber Geek


  #2552909 31-Aug-2020 10:48
Send private message

All his passwords need to be reset , not just bank & trademe . Also his email pass , any passwords saved in Chrome IE edge etc.
Have a look and see if anything has been sent via his email ,see if the scammer has been using his email to send scam emails to people in his contact lists (unlikely but worth checking)

 

Check the router to make sure DNS hasnt been changed .

 

 


Apsattv
2388 posts

Uber Geek


  #2553012 31-Aug-2020 11:17
Send private message

freitasm:

 

Apsattv:

 

The last one i looked at, they thought they were clever and could hide things and  made a restore point before they started mucking with the guys pc. Which they tried to restore  once they finished.

 

 

I wouldn't trust a restore point at all for these things.

 

 

 

 

I'm talking about the scammer, they made a restore point before they started messing with the guys pc.

 

Then once they were done tried to reset the pc to remove all trace of their activity.

 

The usual scam, guy was told by demanding indian to travel into town (rural guy) and get itunes vouchers etc!

 

Im amazed people STILL fall for this nonsense

 

 


hio77
12999 posts

Uber Geek

ID Verified
Trusted
Lizard Networks

  #2553024 31-Aug-2020 11:29
Send private message

malware can be a pain unpick at times, some of it is quite nasty with how it locks itself in there. best solution...

 

 

 

fdisk.





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.

 

 


elpenguino
3419 posts

Uber Geek


  #2556069 2-Sep-2020 23:46
Send private message

hio77:

 

malware can be a pain unpick at times, some of it is quite nasty with how it locks itself in there. best solution...

 

fdisk.

 

 

Amen. I'd never be able to trust that machine again until the HDD was nuked from orbit i.e. reformatted and completely wiped.





Most of the posters in this thread are just like chimpanzees on MDMA, full of feelings of bonhomie, joy, and optimism. Fred99 8/4/21


  #2556073 3-Sep-2020 00:39
Send private message

If its a spinning hd bin it and install fresh on ssd.





Ding Ding Ding Ding Ding : Ice cream man , Ice cream man


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.