Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Remote Control attack, unknown consequences

  • Please log in to reply
1 reply to this topic

#1 haplo888


  • Members
  • 25 posts
  • Local time:01:25 AM

Posted 12 November 2015 - 11:21 AM

My sister navigated to a webstie and received a message she'd been infected and needed to call 'Microsoft' for help.  Which, she did.  The person that answered had her run iexplore + some website from a command prompt, installing an unknown remote control app and the person took control of her computer.  He showed her something indicating she had been '91% infected' and that her IP address would be compromised for 'all her devices', unless they helped her.  At this point she finally called me and hearing red flags I told her to power off her laptop and hang up.


Upon getting access to the laptop I used a hirens boot cd to run mini xp and ran malwarebytes and some antivirus, which found and removed a few items.  After, from safe mode, I ran rkill, malwarebytes, adwclean, roguekiller, and trendmicro's stand alone antivirus, again a few discoveries were removed.  I then finally did a regular boot and repeated rkill, malwarebytes, adwclean, finding nothing.  I also noticed goto meeting and a citrix launcher showed as being installed around the time of the indicent, but I cannot confirm they are related. I uninstalled those and reset IE and firefox to defaults.


Where can I find some more information about this type of attack?

And what else should I look for to make sure her computer has been cleaned?


She's running Win8.1.




BC AdBot (Login to Remove)


#2 boopme


    To Insanity and Beyond

  • Global Moderator
  • 73,569 posts
  • Gender:Male
  • Location:NJ USA
  • Local time:01:25 AM

Posted 12 November 2015 - 04:45 PM

Hi haplo, this was a scam page.

we need a deeper look to get it out.
Repost this info according to steps 6,7 and 8

Please follow this Preparation Guide and post in a new topic.
Let me know if all went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users