Results 1 to 8 of 8

Thread: Remote desktop onto compromised machine?

  1. #1
    Registered+
    Join Date
    Jan 2020
    Posts
    46
    Thanks
    1
    Thanked
    3 times in 1 post
    • Caimbeul2000's system
      • Motherboard:
      • Gigabyte Z170X-Ultra Gaming
      • CPU:
      • i7 6700K
      • Memory:
      • 32GB DDR4 3000
      • Graphics card(s):
      • GTX 1070Ti
      • Operating System:
      • Win10 Pro

    Remote desktop onto compromised machine?

    Hi,

    A bit of a pickle - a young person with special needs that my wife and i used to care for has been called by some scammers claiming to be from her ISP and that her router had thousands of errors and that they needed her to do some things on-line with her computer so they could fix them (i know...). She did do a lot of what they have said including confirming memorable info!
    Anyway she did call me not long after the call with them and mentioned it and her machine was doing things she thought was a bit wierd. After only a few seconds of her explaining i told her to do a hard power off to terminate whatever was going on. Now aside from dealing with this situation outside, i have no idea what has gone on with their laptop. They live around 200 miles away so popping over to get it isnt an immediate solution. Would it be safe for me to remote onto her machine using chrome remote desktop to try and ascertain what might have been done, run scans etc?

    Thanks

  2. #2
    mush-mushroom b0redom's Avatar
    Join Date
    Oct 2005
    Location
    Middlesex
    Posts
    3,494
    Thanks
    195
    Thanked
    383 times in 292 posts
    • b0redom's system
      • Motherboard:
      • Some iMac thingy
      • CPU:
      • 3.4Ghz Quad Core i7
      • Memory:
      • 24GB
      • Storage:
      • 3TB Fusion Drive
      • Graphics card(s):
      • nViidia GTX 680MX
      • PSU:
      • Some iMac thingy
      • Case:
      • Late 2012 pointlessly thin iMac enclosure
      • Operating System:
      • OSX 10.8 / Win 7 Pro
      • Monitor(s):
      • Dell 2713H
      • Internet:
      • Be+

    Re: Remote desktop onto compromised machine?

    Not really. As soon as she connects the laptop to the Internet so you can connect, I suspect whoeve the scammers were will also have access.

  3. #3
    Super Moderator Jonj1611's Avatar
    Join Date
    Jun 2008
    Posts
    5,722
    Thanks
    1,763
    Thanked
    996 times in 763 posts

    Re: Remote desktop onto compromised machine?

    If she can follow your instructions maybe post her a bootable usb of linux or something that you can connect to via teamviewer or whatever and clean the windows partition from there. Its a bit long winded but probably safest route apart from actually being there
    Jon

  4. #4
    Goron goron Kumagoro's Avatar
    Join Date
    Mar 2004
    Posts
    3,147
    Thanks
    37
    Thanked
    170 times in 139 posts

    Re: Remote desktop onto compromised machine?

    Keep it off the network and video chat. Then you can tell them what to do easier.

    First things first look at uninstall software and click on order by date and see if there is anything obvious remote wise and then uninstall it. These scammers don't tend to use sophisticated hidden programs to gain access. If you find stuff and remove it I reckon it is okay to then put it back on the network and for you to remote in and give it a proper once over.

  5. #5
    Senior Member
    Join Date
    Feb 2008
    Posts
    925
    Thanks
    4
    Thanked
    161 times in 148 posts
    • smargh's system
      • Motherboard:
      • Gigabyte GA-EP45-UD3P
      • CPU:
      • Xeon E5450 with 775-to-771 Mod
      • Memory:
      • 16GB Crucial
      • Storage:
      • Intel X25-M G2 80GB/Adaptec 3405 4x 2TB Ultrastar RAID1 / 1x 6TB Hitachi He6 / Dying 2TB Samsung
      • Graphics card(s):
      • GTX 750 Ti
      • PSU:
      • Seasonic X-560
      • Case:
      • Lian-Li PC-A71
      • Operating System:
      • Windows 7 Ultimate 64bit
      • Monitor(s):
      • BenQ G2400WD
      • Internet:
      • Really Crap ADSL2 <3Mbit

    Re: Remote desktop onto compromised machine?

    Turn off the router, turn on the laptop, then... I'm not sure, it depends. Maybe the easiest option for guiding them through it would be to do a system restore to a date before the incident?

  6. #6
    Editable... jimbouk's Avatar
    Join Date
    Aug 2005
    Location
    Bristol
    Posts
    3,071
    Thanks
    321
    Thanked
    278 times in 226 posts
    • jimbouk's system
      • Motherboard:
      • Asrock B450M-HDV R4.0
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4 3200 MHz C16
      • Storage:
      • Sabrent Rocket Q 1TB NVMe PCIe M.2 2280
      • Graphics card(s):
      • Sapphire Pulse RX 580 8GB
      • PSU:
      • Seasonic Core Gold GC-650
      • Case:
      • Lian-Li PC-V1100 ATX
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC CU34G2/BK 34" Widescreen
      • Internet:
      • EE FTC

    Re: Remote desktop onto compromised machine?

    Not sure what they do with these machines once they have access? Assume all personal info has been lifted already and they just continue to sniff for more passwords, bank details, etc. Can't imagine it gets put on a botnet or anything like that, and if the hard-drives been encrypted then that's that.

    Think one of the last two might be worth a punt - hopefully something obvious that can just be uninstalled.

    Was a news article recently about a scammer who dialled the Australian Cyber Crimes unit (I think) which had some details about what was done, see if I can find it.

  7. #7
    Editable... jimbouk's Avatar
    Join Date
    Aug 2005
    Location
    Bristol
    Posts
    3,071
    Thanks
    321
    Thanked
    278 times in 226 posts
    • jimbouk's system
      • Motherboard:
      • Asrock B450M-HDV R4.0
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4 3200 MHz C16
      • Storage:
      • Sabrent Rocket Q 1TB NVMe PCIe M.2 2280
      • Graphics card(s):
      • Sapphire Pulse RX 580 8GB
      • PSU:
      • Seasonic Core Gold GC-650
      • Case:
      • Lian-Li PC-V1100 ATX
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC CU34G2/BK 34" Widescreen
      • Internet:
      • EE FTC

    Re: Remote desktop onto compromised machine?


  8. #8
    Senior Member AGTDenton's Avatar
    Join Date
    Jun 2009
    Location
    Bracknell
    Posts
    2,708
    Thanks
    992
    Thanked
    833 times in 546 posts
    • AGTDenton's system
      • Motherboard:
      • MSI MEG X570S ACE MAX
      • CPU:
      • AMD 5950x
      • Memory:
      • 32GB Corsair something or the other
      • Storage:
      • 1x 512GB nvme, 1x 2TB nvme, 2x 8TB HDD
      • Graphics card(s):
      • ASUS 3080 Ti TuF
      • PSU:
      • Corsair RM850x
      • Case:
      • Fractal Design Torrent White
      • Operating System:
      • 11 Pro x64
      • Internet:
      • Fibre

    Re: Remote desktop onto compromised machine?

    Quote Originally Posted by jimbouk View Post
    Not sure what they do with these machines once they have access? Assume all personal info has been lifted already and they just continue to sniff for more passwords, bank details, etc. Can't imagine it gets put on a botnet or anything like that, and if the hard-drives been encrypted then that's that.

    Think one of the last two might be worth a punt - hopefully something obvious that can just be uninstalled.

    Was a news article recently about a scammer who dialled the Australian Cyber Crimes unit (I think) which had some details about what was done, see if I can find it.
    Just to add to this, a youtuber goes after these scammers and has managed to infiltrate a number of them
    https://www.youtube.com/channel/UCBN...AprVcZZ3ic84vw

    He really goes into detail and gives a lengthy insight as to what the scammers are doing. Worth a watch of a few episodes for the education & awareness side of it. He has great tricks up his sleeve and has managed on several occasions to get into the scammers PC.



    Kumagoro hits the nail on the head.
    You will have to get them to use a phone or tablet, something with a camera separate from the plagued PC in order for you to see their screen and direct them to uninstalling nasties & scanning the PC. They may have to download tools onto another machine, transfer to USB in order to run a scan.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •