Q: Help! I was scammed, now what?
Last evening while online I had navigated to a site that did not look right, I attempted to leave and instantly recieved a pop-up that urgently advised me to contact a 866-500-4??? because I now had a virus. I attempted to delete and leave, but it would not let me. It also had a shrill audio warning. So I called and then downloaded two items (teamviewer.com, support.me) which allowed them to be on my computer to "fix" the problem. I became very wary as no apple insignias were on their "help," yet I watched as they flew through stuff (console, terminal, and apple info that showed the age of the hardware and that my support time had ended. Being a disabled shut-in and now quite leery, I did not pay the $99 to "fix" the problem, so he gave me what he called, a temporary fix. He then went to my firewall settings.--- After shutting things down, I re-emptied the trash, checked my firewall that it was on and then went to sleep. (Turning off the computer.)
I am not a computer genius. I read a similar post and the advice was to reconfigure and reinstall the OS. How do I do this? I am very concerned I now have a Trojan horse.
Please tell me what to do.
Thank you in advance for any help.
Rene
Mac mini, OS X El Capitan (10.11.3)
Posted on Mar 30, 2016 12:40 PM
the terminal thing is a smoke and mirrors show, they show you a bunch of network processes that the computer uses every minute of every day and stop and say "look, theres the virus" and you could be looking at a printer packet from six weeks ago.
I can't say they didn't install something no one knows about but for the most part these are crooks, not computer genius either, just garden variety con artists looking to get on your computer, do their script and get money wired to them. after that they are gone so wiping your computer would erase any doubt you might have but it's a bit extreme and I don't know if you need to get that extreme
team viewer for instance is not malware, its used by IT people to do their job, legitimate work, but crooks use it too because it's very simple to set up and it doesn't arise a lot of suspicion. Here are the instructions to delete it. It's a pice of software, nothing more.
https://www.teamviewer.com/en/uninstall/
I don't know support.me. was it "logMeIn"?
that's another legit software used by crooks and it is easily removable.
http://help.logmein.com/articles/en_US/FAQ/How-do-I-uninstall-LogMeIn-for-Mac-ma nually
what you need to do now
call you bank
reset your passwords
make a new admin account and make your current admin account into a standard account afterwords. delete any startup items in your old admin account that are "log me In", "team viewer" or anything else that looks suspicious.
backup your computer with Time Machine either way.
if they didn't have you log in as root, and install a key logger they are not "experts" just “******", and trust me you would had to go through some memorable steps to have that happen.
Enabling and using the "root" user in OS X - Apple Support
and that HAS to be done by someone sitting at the computer, not over a VNC remote session.
likely there is one or two things you need to be concerned about but if cash was not wired that's the biggest one.
for further reading
https://malwaretips.com/blogs/remove-tech-support-scam-popups/
and if you want to follow up you can post an etrecheck report
and there will be no shortage of volunteers here to look at whats running on your system and what shouldn't be there in the event something is.
deep breath.
exhale.
that's it.
<Edited by Host>
Posted on Mar 30, 2016 1:44 PM