// Frontera Technical Support • View topic - Latest scam i have come across
   
 

Latest scam i have come across


Latest scam i have come across

Postby adyclemo on Fri Dec 02, 2011 1:19 am

This is a screen shot of one of the latest scams i have come across on a customers computer while at work today.

At the moment its not perticularly advanced and is easily removed, but will probably advance as time goes on just like they all do. All it appears to do is run internet explorer full screen with no navigation bars etc, divert you to a web address were they capture your details, disable task manager and windows explorer.

Image

To remove just boot to safe mode of which seems to function as normal, load up ms config and strip the startup items which stops the file from running and reboot, the file is locate in a hidden folder located at c:\users\your user name\appdata\local\temp. Just delete the file once the computer has rebooted (no need for safe mode now). You will need to enable the viewing of hidden folders. Once removed i would do a few scans with AV software to check rest of the machine and clear all internet temp files, cookies etc.

I will post up tomorrow the file names that you will be looking for as i have them scribbled on a scrap piece of paper on my clip board at work, they may differ but will at least give you an idea of what you are looking for.

Although the grammer is not excellent at first glance its beleivable to those that do not understand this stuff, with 90% of people at some point having had counterfeit software put on their computer or browsed web sites they probably shouldnt have, and at a supposide fine of £100 is probably considered not to be exstortionate and rather reasonable as pointed out by colleagues at work.
Regards Ady

Pics of the motor can be found here

Comment on the motor here
adyclemo
frontera God
frontera God
 
Posts: 720
Joined: Sun Feb 28, 2010 7:15 pm
Location: Derby
Model: 2.8 TDI 5dr
Registration Year: 1996/N
Modifications: Relocated diff breathers to engine bay.
Cycle carrier made for spare wheel carrier.
Steel wheels changed for alloys.
Full lenght roof rack.
Front tow bar.
CB.
Manual locking hubs.
Front and rear wrap round bull bars.
Suspension lift.
32" BFG's
Snorkle.
Egr delete
Region: Midlands

Skype:Skype Me.!



Re: Latest scam i have come across

Postby SPEEDBIRD 202 on Fri Dec 02, 2011 5:33 pm

I'm always dead keen in these types of scams and learn what you can do to avoid them.

So thanks for that adyclemo, and for me it was a Image :)

ATB
My Fronty thinks its a grown-up Tonka Toy [how sad is that] ?
Concorde with Frontera View Here Image
In the interests of the environment, this posting was constructed entirely from recycled electrons.
User avatar
SPEEDBIRD 202
frontera God
frontera God
 
Posts: 987
Joined: Fri Mar 21, 2008 3:42 pm
Location: Surrey [not the posh bit]
Model: 2.2 DTi 16v RS Sport 3dr
Registration Year: 1999/T
Region: South East



Re: Latest scam i have come across

Postby Big Dav on Sat Dec 03, 2011 12:22 am

On behalf of the police the media in Scotland put an alert out last weekend regarding the scam and for folk not to respond to it.
Don't know how much cash the scammers have made from it.
Kodiak Transglobe 2.0 SWB

Bricks are the knowledge you are taught,
the cement is the experience you gain that holds them together.
User avatar
Big Dav
Lord frontera
Lord frontera
 
Posts: 1594
Joined: Wed Sep 01, 2010 10:38 am
Model: 2.0i Sport 3dr
Registration Year: 1999/T
Modifications: Fitted - inclinometer, ice alert, wildlife whistle, drawbar/50mm towball;7781
Region: Scotland



Re: Latest scam i have come across

Postby furball on Sun Dec 04, 2011 3:32 am

I believe the current free malwarebytes download can get rid of this, not sure if it's been added to stinger yet though
Don't grow up, just get bigger toys
My truck... http://www.fronteraowners.co.uk/forums/viewtopic.php?f=46&t=27556
User avatar
furball
frontera God
frontera God
 
Posts: 954
Joined: Sat Feb 09, 2008 6:35 pm
Location: South Lancashire
Model: 2.2 DTI 5dr
Registration Year: 2003/03
Region: North West



Re: Latest scam i have come across

Postby fogman on Fri Dec 09, 2011 9:10 pm

just had a phone call from a mate & his pc is locked up with it, im not that good with pcs so im wondering if i can go into safe mode then choose a previous restore point then run the av to track it down ?
failing that have you got the file names please ady ?
WHY AINT I GOT AN ALL SINGING & ALL DANCING SIGNATURE LIKE BOXY & DRIFTY ?

Image
User avatar
fogman
Lord frontera
Lord frontera
 
Posts: 4269
Joined: Sun Dec 14, 2008 12:16 am
Region: East Anglia



Re: Latest scam i have come across

Postby BoxCleva on Fri Dec 09, 2011 9:19 pm

Don't use system restore Gary.

Download Malwarebytes Anti Malware (free version) , updating it with the latest definitions when prompted is critical. Run a full scan with that in safe mode. It should deal with the issue you have mate.
User avatar
BoxCleva
Lord frontera
Lord frontera
 
Posts: 7179
Joined: Thu Jun 17, 2010 6:46 pm
Location: North Wales, not to far from the Wayfarer- Between Wrexham and Oswestry
Vehicle Name: sack o sheet
Modifications: Beemer e46
Region: North West



Re: Latest scam i have come across

Postby fogman on Fri Dec 09, 2011 9:26 pm

ok understood mate :wink: im not sure if he has malware or antispyware on it so can i download in safe mode ? i think hes only got macfee av installed
WHY AINT I GOT AN ALL SINGING & ALL DANCING SIGNATURE LIKE BOXY & DRIFTY ?

Image
User avatar
fogman
Lord frontera
Lord frontera
 
Posts: 4269
Joined: Sun Dec 14, 2008 12:16 am
Region: East Anglia



Re: Latest scam i have come across

Postby BoxCleva on Fri Dec 09, 2011 10:21 pm

Yes mate , select safe mode with networking which will mean you will have net access in safe mode.
User avatar
BoxCleva
Lord frontera
Lord frontera
 
Posts: 7179
Joined: Thu Jun 17, 2010 6:46 pm
Location: North Wales, not to far from the Wayfarer- Between Wrexham and Oswestry
Vehicle Name: sack o sheet
Modifications: Beemer e46
Region: North West



Re: Latest scam i have come across

Postby fogman on Fri Dec 09, 2011 10:44 pm

ok thanks si :wink:
WHY AINT I GOT AN ALL SINGING & ALL DANCING SIGNATURE LIKE BOXY & DRIFTY ?

Image
User avatar
fogman
Lord frontera
Lord frontera
 
Posts: 4269
Joined: Sun Dec 14, 2008 12:16 am
Region: East Anglia



Re: Latest scam i have come across

Postby adyclemo on Sun Dec 11, 2011 11:08 pm

The names are changing but so far are very clear that they should not be theyre, ive seen names in the startup items anything from "my grans bloomers" to "mrs deatons giggles" to "scary fish balloons". In the hidden folders the app name goes along the lines of 0.0xxxxxxxxxxxxxx (x being random numbers)

System restore wont work as box has already said. Refer to my first post on how to get rid of it then scan with AV software and MBAM
Regards Ady

Pics of the motor can be found here

Comment on the motor here
adyclemo
frontera God
frontera God
 
Posts: 720
Joined: Sun Feb 28, 2010 7:15 pm
Location: Derby
Model: 2.8 TDI 5dr
Registration Year: 1996/N
Modifications: Relocated diff breathers to engine bay.
Cycle carrier made for spare wheel carrier.
Steel wheels changed for alloys.
Full lenght roof rack.
Front tow bar.
CB.
Manual locking hubs.
Front and rear wrap round bull bars.
Suspension lift.
32" BFG's
Snorkle.
Egr delete
Region: Midlands

Skype:Skype Me.!



Re: Latest scam i have come across

Postby fogman on Mon Dec 12, 2011 5:57 pm

right guys ive just returned from my mates, first of all i rebooted it in safe mode & ran a scan with the already installed macfee a/v programme, that found nothing, so rebooted it again this time with networking then downloaded superantispyware [which ive found to be excellent in the past ] left it scanning again expecting it to sort it out but he ran me again saying its still on there, thinking about it i left it still connected to the modem for the 2nd scan, do you think that would explain its reappearance ?
would going into the disc cleaning facility & deleting all temporary files & cookies clear it ? as im not too sure how to strip start up files as ady advised in his first post
WHY AINT I GOT AN ALL SINGING & ALL DANCING SIGNATURE LIKE BOXY & DRIFTY ?

Image
User avatar
fogman
Lord frontera
Lord frontera
 
Posts: 4269
Joined: Sun Dec 14, 2008 12:16 am
Region: East Anglia



Re: Latest scam i have come across

Postby BoxCleva on Mon Dec 12, 2011 7:08 pm

Download the tool from here > http://www.avg.com/ww-en/remove-win32zeroacces

Disable System Restore prior to running the tool. Instructions here > http://support.microsoft.com/kb/310405
User avatar
BoxCleva
Lord frontera
Lord frontera
 
Posts: 7179
Joined: Thu Jun 17, 2010 6:46 pm
Location: North Wales, not to far from the Wayfarer- Between Wrexham and Oswestry
Vehicle Name: sack o sheet
Modifications: Beemer e46
Region: North West



Re: Latest scam i have come across

Postby fogman on Mon Dec 12, 2011 7:26 pm

ok ill give that a try boxy :wink: out of interest what would happen if the system restore wasnt turned off while using the removal tool ?
WHY AINT I GOT AN ALL SINGING & ALL DANCING SIGNATURE LIKE BOXY & DRIFTY ?

Image
User avatar
fogman
Lord frontera
Lord frontera
 
Posts: 4269
Joined: Sun Dec 14, 2008 12:16 am
Region: East Anglia



Re: Latest scam i have come across

Postby BoxCleva on Mon Dec 12, 2011 7:32 pm

It struggles to access restore files in XP.
User avatar
BoxCleva
Lord frontera
Lord frontera
 
Posts: 7179
Joined: Thu Jun 17, 2010 6:46 pm
Location: North Wales, not to far from the Wayfarer- Between Wrexham and Oswestry
Vehicle Name: sack o sheet
Modifications: Beemer e46
Region: North West



Re: Latest scam i have come across

Postby fogman on Mon Dec 12, 2011 7:35 pm

hes running vista so would that make any difference ?
WHY AINT I GOT AN ALL SINGING & ALL DANCING SIGNATURE LIKE BOXY & DRIFTY ?

Image
User avatar
fogman
Lord frontera
Lord frontera
 
Posts: 4269
Joined: Sun Dec 14, 2008 12:16 am
Region: East Anglia



Re: Latest scam i have come across

Postby BoxCleva on Mon Dec 12, 2011 8:19 pm

Whoops, sorry didn't realise.

Disable it anyway. You can enable it again after the scan and a reboot. http://windows.microsoft.com/en-US/wind ... -on-or-off
User avatar
BoxCleva
Lord frontera
Lord frontera
 
Posts: 7179
Joined: Thu Jun 17, 2010 6:46 pm
Location: North Wales, not to far from the Wayfarer- Between Wrexham and Oswestry
Vehicle Name: sack o sheet
Modifications: Beemer e46
Region: North West



Re: Latest scam i have come across

Postby fogman on Wed Dec 14, 2011 6:11 pm

as i post this another mate is wiping his pc clean so i cant give any more input but thanks for the advice guys :wink:
WHY AINT I GOT AN ALL SINGING & ALL DANCING SIGNATURE LIKE BOXY & DRIFTY ?

Image
User avatar
fogman
Lord frontera
Lord frontera
 
Posts: 4269
Joined: Sun Dec 14, 2008 12:16 am
Region: East Anglia




Return to PC & Technology discussion

Who is online

Users browsing this forum: No registered users and 2 guests

 
   


cron