1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Microsoft Scam

Discussion in 'General Malware And Security' started by DavidE, Jul 3, 2022.

  1. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    I did a very foolish thing this past Friday. On Facebook I clicked on a photo I wanted to see more of and suddenly I found my browser was hijacked/locked. I could do nothing. The mouse arrow wasn't even showing. In a panic, i called the number on the screen as it looked like a legitimate call from Microsoft. The guy has me upload "Ultraviewer" to fix and then has a few other steps for me to go through. We got to the part about allowing my "partner" to remotely control the computer and I told hjm no, I didn't want Microsoft or anyone else controlling my computer. This was all via a phone call. At that point he hung up.

    I've never been so stupid before but old timers like me sometimes get panic stricken when something happens out of the blue. I deleted the "Ultraviewer" download, deleted it every where else I could find it(x64 and 32), checked out to see if it was in the Task Manager, etc. I got as far with him as telling him the password that showed up and that was it, nothing further as he hung up. I'm wondering if I may still be vulnerable even after running Malewarebytes Premium and AdwCleaner. I know nothing else to do. This is a screen shot of what I initially saw.
     

    Attached Files:

  2. Tony D

    Tony D Administrator Administrator

    Joined:
    Sep 25, 2009
    Messages:
    5,105
    Location:
    SE Pennsylvania, USA
    Operating System:
    Windows XP Professional
    IJAC likes this.
  3. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    I figured he'd need that Ultraviewer to be able to access the computer even if he was given the password that showed. I deleted every instance of it I could find. This is what it all looked like. That was as far as we got. I told him in no uncertain terms I did not want him or anyone else remotely controlling this computer. At that point he hung up.

    I also stopped his ability to connect to the Ultraviewer. Afterwards i ran a scan with Malewarebytes who said all was well, no threats found.
     

    Attached Files:

  4. Tony D

    Tony D Administrator Administrator

    Joined:
    Sep 25, 2009
    Messages:
    5,105
    Location:
    SE Pennsylvania, USA
    Operating System:
    Windows XP Professional
    If you didn't give him access to your computer, you're OK. So many people allow them access. Then they're in trouble.
     
    starbuck and IJAC like this.
  5. IJAC

    IJAC Super-Moderator Super Moderators

    Joined:
    May 8, 2017
    Messages:
    894
    Location:
    Here
    Operating System:
    Linux Based
    Computer Brand or Motherboard:
    I have a Asus prime Z270A MB
    CPU:
    Intel i5 Quad core
    Memory:
    Rip Jaw 32 GB
    Hard Drive:
    Samsung Evo 500 GB SS
    Graphics Card:
    Radeon R7 260X/360
    Power Supply:
    750 Watt Corsair
    Any type of window that pops up like that is a scam. If at any time one pops up you can just close your browser or open task manger and end process. If none of that works just do a hard shut down holding the power button down and restart. Be careful out there the internet can be a dangerous place sometimes unfortunately.
     
    starbuck and DavidE like this.
  6. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    I don't think he has access as I deleted the "Ultraviewer" program he had me install.I assume he needs that to gain access as there seems no other reason to install it. I uninstalled it, deleted from program files(x32 and x64) and anywhere else it showed up. The last step he had me go through showed a password and user name and he asked me what it said and I told him. It was then I got suspicious and told him I didn't want him, Microsoft or anyone else remotely having access to this computer. That's when he hung up. This attached screenshot shows the last thing we did. there was probably other steps but we didn't get any further after that.
     

    Attached Files:

  7. IJAC

    IJAC Super-Moderator Super Moderators

    Joined:
    May 8, 2017
    Messages:
    894
    Location:
    Here
    Operating System:
    Linux Based
    Computer Brand or Motherboard:
    I have a Asus prime Z270A MB
    CPU:
    Intel i5 Quad core
    Memory:
    Rip Jaw 32 GB
    Hard Drive:
    Samsung Evo 500 GB SS
    Graphics Card:
    Radeon R7 260X/360
    Power Supply:
    750 Watt Corsair
    You are correct believe you are OK I was just giving out some information in case some one reading this didn't understand the scam. Glad you caught it before they stole money from you. I watch a lot of the scambaiters on YouTube so I am familiar with these types of scams.
     
    DavidE likes this.
  8. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    What started all this was a simple and innocent move on my behalf. I was scrolling down Facebook and ran across this picture. Curious as to what the interaction of the guy and the Shepard was I clicked on the picture. That's when it happened. The browser got hijacked/locked and I could do nothing. someone must have inserted a malicious code into it at some point.
     

    Attached Files:

  9. IJAC

    IJAC Super-Moderator Super Moderators

    Joined:
    May 8, 2017
    Messages:
    894
    Location:
    Here
    Operating System:
    Linux Based
    Computer Brand or Motherboard:
    I have a Asus prime Z270A MB
    CPU:
    Intel i5 Quad core
    Memory:
    Rip Jaw 32 GB
    Hard Drive:
    Samsung Evo 500 GB SS
    Graphics Card:
    Radeon R7 260X/360
    Power Supply:
    750 Watt Corsair
    Yep I understand that is what happens they inject malicious code and you get that pop up. Sometimes you can close the browser and sometimes you need to hold the power button down and restart it. You can try and put U Block origin in your extensions on your browser to see if that blocks them. I use that and also privacy badger and malware bytes browser guard. So far I haven't had a pop up screen like that in a long time. The browser extensions can be had for Chrome, Firefox and Edge.
     
  10. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    Bottom line is do you think I'm ok? I gave him no personal passwords, would never do that, only those numbers shown. Malwarebytes ran a scan on startup and indicated no threats. I also check Task Manager many times a day to see if t here's someone there that shouldn't be.
     
  11. IJAC

    IJAC Super-Moderator Super Moderators

    Joined:
    May 8, 2017
    Messages:
    894
    Location:
    Here
    Operating System:
    Linux Based
    Computer Brand or Motherboard:
    I have a Asus prime Z270A MB
    CPU:
    Intel i5 Quad core
    Memory:
    Rip Jaw 32 GB
    Hard Drive:
    Samsung Evo 500 GB SS
    Graphics Card:
    Radeon R7 260X/360
    Power Supply:
    750 Watt Corsair
    Yes I think since you uninstalled the remote support program he told you to get you should be fine. Since he did not get a chance to connect also is a good thing.
     
    DavidE likes this.
  12. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    The whole thing still makes me nervous. I've been on FB for quite a few years and nothing like that ever happened before. It took me by surprise. the only place I didn't check for this installer of "Ultraviewer" was the Registry. I wouldn't know where or what to look for.
     
  13. IJAC

    IJAC Super-Moderator Super Moderators

    Joined:
    May 8, 2017
    Messages:
    894
    Location:
    Here
    Operating System:
    Linux Based
    Computer Brand or Motherboard:
    I have a Asus prime Z270A MB
    CPU:
    Intel i5 Quad core
    Memory:
    Rip Jaw 32 GB
    Hard Drive:
    Samsung Evo 500 GB SS
    Graphics Card:
    Radeon R7 260X/360
    Power Supply:
    750 Watt Corsair
    I understand that is what the scammers are counting on you will be fine.
     
  14. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    One thing you can be assured of-I won't click on another photo on FB! Lessons learned.
     
  15. IJAC

    IJAC Super-Moderator Super Moderators

    Joined:
    May 8, 2017
    Messages:
    894
    Location:
    Here
    Operating System:
    Linux Based
    Computer Brand or Motherboard:
    I have a Asus prime Z270A MB
    CPU:
    Intel i5 Quad core
    Memory:
    Rip Jaw 32 GB
    Hard Drive:
    Samsung Evo 500 GB SS
    Graphics Card:
    Radeon R7 260X/360
    Power Supply:
    750 Watt Corsair
  16. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    I'm most thankful I had a place to come to with this problem. Thanks to all!! I was hoping there was still computer forums up and running. The old one I use to go to when I had XP and Vista seems to have vanished after many years.
     
  17. IJAC

    IJAC Super-Moderator Super Moderators

    Joined:
    May 8, 2017
    Messages:
    894
    Location:
    Here
    Operating System:
    Linux Based
    Computer Brand or Motherboard:
    I have a Asus prime Z270A MB
    CPU:
    Intel i5 Quad core
    Memory:
    Rip Jaw 32 GB
    Hard Drive:
    Samsung Evo 500 GB SS
    Graphics Card:
    Radeon R7 260X/360
    Power Supply:
    750 Watt Corsair
    Glad we could help and welcome to the forums.
     
    DavidE likes this.
  18. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi David,

    Sorry for the delay in response to your thread.
    I agree with Tony and IJAC, the fact that you have removed the Remote Access software, no passwords were given over and that Malwarebytes showed no threats ..... is all good news.
    We're always here if you ever need a health check on your system though.
    So many sites went to the wall when people started to use smart phones and tablets instead of computers .... they were easy to turn back to factory settings if anything untoward happened.
     
    IJAC and allheart55 (Cindy E) like this.
  19. DavidE

    DavidE Registered Members

    Joined:
    Jul 3, 2022
    Messages:
    21
    Operating System:
    Windows 10
    Hello-No problem. The only password he got was the one I mentioned earlier and that was just a set of numbers(shown in attachment). This is as far as I let it get. I'd never give out personal user names or passwords. I think I'm ok with what all I did but would feel better if someone checked things out. I have a guy to do that but he's out of town on vacation currently. He's helped before with other unrelated problems. A health check would be good.

    I only have a desktop computer. The only reason I ever bought a smart phone was to take on the spot photos and videos of my Corgi. I've never had a tablet other than an occasional Tylenol. :)
     

    Attached Files:

    IJAC likes this.
  20. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi David,

    If you want a system health check, look back at Tony D's first reply to your thread ..... he gave links that you will need.

    :jump:
     
    plodr and IJAC like this.

Share This Page