Couple of new scams that we've been dealing with at work, and I have even gotten this at home.
Phone rings and ask to speak to me by name.
"This is Windows Tech support calling to let you know someone is attempting to install unauthorized files on your computer.'
First thing, I'm the guy who Tech Support calls when they can't fix it so WTF is this guy doing calling me?! :geek
Second, and important thing to remember, Tech Support NEVER calls you preemptively. You have to initiate that support call.
So I wanted to hear the sales pitch so I played along.
Long story short he took me to the Windows Events viewer and the Windows Administrative Events under Custom View. Now what this is it's a filter on all the event logs that are related to Administrative task that fail or generate a warning. EVERY computer has failed events and warnings, EVERY One has these. This Jackwagon told me these were the files that someone was trying to send to me. I knew better.
Still playing along, he wanted me to send those files to him. This is where the hook comes in. He directed me to a website with this weird address. I told him I was there and he ask me what I saw...I asked him what would he expect me to see? He said a pop up asking to install a utlitiy to upload the files to their servers.
I said, "You mean like a file someone would put on my computer to take control and hack other people's computers?" Then I asked how many people fall for this crap to which he started playing innocent. Said he's from "Windows Security". I said "Windows is not a company name, who do you work for?" Don't really matter what he said it would be a lie. At this point I hung up on him.
The SUMABITCH had the nerve to call me back and asked if I ran the file, that's whey I went redneck on him.
The second Scam we're dealing with is you get an email from ADT or some security group who threatens to disable your account if the bill is not brought up to date, the bill would be attached in a PDF file, but oddly enough the PDF file is in a ZIP file and it's an exe file when unzipped. We even have this stuff blocked on our AV scanner but I don't know how many people have disabled their AV to run the file because they are worried about the account being suspended. I had one I dealt with, asked him if he pays the bills, "No". Do you have ADT? "No". Did you read the email from our IT group warning about this scam? "No".
So folks, do your IT guy a favor, Run Chrome or Firefox with
AdBlockPlus, don't open no attachments for shipping stuff, they send you numbers, not files. Don't open invoices (especially if you're not the one paying the bill) or run any file that some weird speaking guy phone tells you to run. And when in Doubt, Reboot....
