Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Rickles

2933 posts

Uber Geek

Trusted

#208241 2-Feb-2017 15:39
Send private message

A colleague recently got the following showing up on his browser.  It froze the screen and had to use Task Manager to close the browser (Edge), and then also clear caches to restore the browser to usefulness.

 

He also tried Chrome, but same result .... appeared when going to Project Free TV web site, which before this was perfectly fine.

 

Anyone shed light on what is happening please?

 

I don't think he was game to ring the telephone number.

 

 

 


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
timmmay
20576 posts

Uber Geek

Trusted
Lifetime subscriber

  #1714531 2-Feb-2017 15:40
Send private message

Just ring the number. Looks pretty custom.




xpd

xpd
Geek @ Coastguard NZ
13765 posts

Uber Geek

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #1714532 2-Feb-2017 15:41
Send private message

Has some malware Id say. Check the Internet Options in control panel for any proxy settings.

 

Download MalwareBytes on a clean PC and put on a USB stick and copy to the PC with issues and run it.

 

 





       Gavin / xpd / FastRaccoon / Geek of Coastguard New Zealand

 

                      LinkTree

 

 

 


gzt

gzt
17106 posts

Uber Geek

Lifetime subscriber

  #1714534 2-Feb-2017 15:46
Send private message

No idea. Could be an attempt to steal domain user authentication passwords.



Rickles

2933 posts

Uber Geek

Trusted

  #1714535 2-Feb-2017 15:54
Send private message

We ran Malware Bytes, then SpyBot, then a full AV scan ... nothing untoward there at all undecided

 

 


Hammerer
2476 posts

Uber Geek

Lifetime subscriber

  #1714537 2-Feb-2017 15:59
Send private message

 If it is malware then it is much better than the usual message. For example, the phone number looks like one from a block used for corporates and it is in a New Zealand number.

 

Calling the number will tend to confirm what it really is.


Rickles

2933 posts

Uber Geek

Trusted

  #1714538 2-Feb-2017 16:07
Send private message

A brief search with Mr Google indicates that many nefarious  scammers are using Amazon's "cloudfront" service to redirect local calls to elsewhere ... anyone in Wellington willing to try the number? innocent

 

What makes me concerned is that when using Chrome, we got a message along the screen bottom with something like "hard disk will delete in 5 minutes" ... a count-down timer was also shown but didn't move.

 

Freaky!!

 

 


Peppery
919 posts

Ultimate Geek

Trusted

  #1714540 2-Feb-2017 16:13
Send private message

Pretty standard "scare" ads. Seen plenty of them that force themselves full screen to get you to call them. Cloudfront is part of Amazon's AWS services so nothing off there. I would just close and go on with your life!


 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
ubergeeknz
3344 posts

Uber Geek

Trusted
Vocus

  #1714541 2-Feb-2017 16:15
Send private message

Check the router and PC DNS settings.


yitz
2074 posts

Uber Geek


  #1714542 2-Feb-2017 16:21
Send private message

As above it's just one of those nefarious popup ad networks all too common on those sorts of sites.

 

As long as you haven't accidentally typed in your internet banking user and password you should be fine. Just close the window.


michaelmurfy
meow
13241 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1714620 2-Feb-2017 18:25
Send private message

I scambaited them...

 

Fired up a very broken version of Windows 7 Professional that had been totally nuked by a previous scambait and allowed the guy to connect to it. The first thing he did was ran syskey and bought up event viewer and started saying I was infected, ran a fake virus scan etc - just your standard tech support scam from India.

 

He then quoted me $490 to fix and that is when I dropped the bombshell on this guy and asked why he was scamming people. He did the standard "I am not a scammer I am helping people" and that is when I said this VM has been running for less than 3 hours and it is already destroyed by you scammers. He then swore at me in hindi and ended the call. I called back again and got standard "your mother...." type things.





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


gzt

gzt
17106 posts

Uber Geek

Lifetime subscriber

  #1714622 2-Feb-2017 18:31
Send private message

michaelmurfy:

I scambaited them...


Fired up a very broken version of Windows 7 Professional that had been totally nuked by a previous scambait and allowed the guy to connect to it. The first thing he did was ran syskey and bought up event viewer and started saying I was infected, ran a fake virus scan etc - just your standard tech support scam from India.


He then quoted me $490 to fix and that is when I dropped the bombshell on this guy and asked why he was scamming people. He did the standard "I am not a scammer I am helping people" and that is when I said this VM has been running for less than 3 hours and it is already destroyed by you scammers. He then swore at me in hindi and ended the call. I called back again and got standard "your mother...." type things.


Did you input local credentials into that box and the scammer used them?

michaelmurfy
meow
13241 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1714624 2-Feb-2017 18:38
Send private message

gzt:
Did you input local credentials into that box and the scammer used them?

 

Nah just acted like I saw the message. I know what this Javascript crap is - it is a template that these companies buy and put their numbers on it. He connected me via the Citrix Quick-support application.

 

Just tried calling them back off a private number and it appears they've now blocked private numbers which is good since this prevents quite a few people from contacting them. Have reported them too. I did have a screen recording but it appears my computer decided to muck up the audio so just trashed it as people know what kind of scam they're running anyway.





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


Rickles

2933 posts

Uber Geek

Trusted

  #1714642 2-Feb-2017 19:51
Send private message

Thanks people ... amazing how some nasties hook themselves onto old or dud websites.


andrew027
1286 posts

Uber Geek


  #1714689 2-Feb-2017 20:34
Send private message

Any dialogue box that pops up on my screen with grammar as poor that example gets closed and ignored.


Rickles

2933 posts

Uber Geek

Trusted

  #1714703 2-Feb-2017 21:13
Send private message

I think what scared the user was the inability to close the browser ... I had to talk him though Task Manager to achieve that.

 

 


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.