• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Remote Assistance Virus

Skylinerecording

Weaksauce
Joined
Oct 15, 2007
Messages
116
Has anyone seen this new problem going around where people are getting pop ups on there machines asking to allow person x to have access to the machine. Kinda like what you would see when using go to assist but the difference is you didn't start a support session with anyone and you don't know who the person who is trying to get access. Last week we had 2 machines come into our store with this issue the first person allowed someone from Toronto on to their machine also gave them their phone number and when they finally thought maybe this is a bad idea and ended the session the person kept calling them on the phone to be let back on. The next person had the same issue but the person identified themselves as being from Microsoft. Now today I get a call from a Dr.'s office saying every 60 secs a window pops up to allow person x access to the machine. Has anyone else seen this or knows where this is coming from.
 
There was a scam goin around a few years ago where guys from India claiming to be a tech company would cold call people telling user's their PC was infected and to let them remote into it to "fix" it. They would then get on the system and do generally useless (but harmless) things like deleting logs in the Event Viewer, then they would tell the user the system is fixed and for such and such $$ they could get a lifetime tech support service with the company. Maybe something similar is happening?
 
I remember that but the weird thing about the doc office they got no phone call it just started. I did go over and looked at the computer and see no evidence of the requests and they were coming every 60 secs. Also after I had them scan with malware bytes which found nothing the requests stopped. It's a very strange problem.
 
There was a scam goin around a few years ago where guys from India claiming to be a tech company would cold call people telling user's their PC was infected and to let them remote into it to "fix" it. They would then get on the system and do generally useless (but harmless) things like deleting logs in the Event Viewer, then they would tell the user the system is fixed and for such and such $$ they could get a lifetime tech support service with the company. Maybe something similar is happening?

This scam is still quite active. I've had 3 residential clients in the past 6 months hit with this. One of my SMB clients also got called by them, when my client told the Indian caller they were a business and not a home, the caller got all aggressive and hung up the phone.

Has anyone seen this new problem going around where people are getting pop ups on there machines asking to allow person x to have access to the machine. Kinda like what you would see when using go to assist but the difference is you didn't start a support session with anyone and you don't know who the person who is trying to get access. Last week we had 2 machines come into our store with this issue the first person allowed someone from Toronto on to their machine also gave them their phone number and when they finally thought maybe this is a bad idea and ended the session the person kept calling them on the phone to be let back on. The next person had the same issue but the person identified themselves as being from Microsoft. Now today I get a call from a Dr.'s office saying every 60 secs a window pops up to allow person x access to the machine. Has anyone else seen this or knows where this is coming from.
Sounds like above. The caller/scammer aggressively persuades the unknowing user to go to a site and download a remote support tool of some kind. The user probably left that out, because they felt like an idiot and wanted to push the blame over to the caller/scammer.
 
I have figured out where it's coming from. Go to Assist was installed on the machine so there software computer could get on the machine and work on their software. Well when I got in the registry and look at the user folder for go to assist in the expertname entry you see the exact name that kept popping up every 60 secs. Now what I don't know is how something could have got in and messed with go to assist like that unless something happened to the software companies go to assist account. Has anyone seen a change like that happen to go to assist?
 
Back
Top