jeff matthews
Topic Starter
HI, i have ran into a serous scam that has compromised my computer and identity. Yesterday i got a call from some number stating that my computer was having serous hard drive failures and issues with my pc. They directed me to look at my log files for my windows and shown me multiple errors on my machine. I recently have had multiple issues with my computer in the past so i sent information to Microsoft. I though this call came from Microsoft, they specifically told me yesterday that this call was a return call because of me "sending information to microsoft" due to crashes, etc. Apparently it wasn't. Yesterday they claimed they were from Microsoft, but today they claimed they were from an entirely different company called "pccare". Their website is "www.24sevenpccare.com". Basically what happen was they sent me to a website through remote connection and told me to enter my credit information in the amount of 165.95 for some type of security tools that would help fix my machine. SO i gave them the information. They were very convincing to me that they were from Microsoft. My bank account blocked the transaction and i noticed that it was not in the amount of 165.95 but rather some 8756.00 dollars was the transaction that was blocked. So just today they been trying to call me back on my phone asking if i called my bank account to remove the transaction and let it go through. Naturally i called all my credit fraud agencies and got all of my cards replaced including my debit account information.
The only information i have as i was watching them take control of my pc, is they downloaded some type of file "called AA_v3.exe" They also transferred some file through their remote messaging called a "UD5 fingerprint" I have no idea what these are accept for the fact of the term UDP protocol. But the remote host name was "ammy Admin" Also i told them i was going to reboot my machine and then call my credit card company like they asked, and they would not allow me to turn off my pc, they kept moving the mouse in circles, so i finally just did a hard shut down hoping that would kill the connection, but to my surprise when i turned my pc back on, they were still remotely connected. Even now they are remotely connected and i can't use my computer for anything, i unplugged all my hard drives accept my C drive but i still have alot important data on my C drive. This person did all kinds of work and some type of scans on my pc so i have no idea what kind of activity he was trying to gain access to, most of it was used through CMD prompt. Hopefully you have a log that can detect what type scans this user was using on my machine.
Oh yes, he also tried to convince me that i needed register a full version of "antimaleware" the software that you guys originally shown me. He shown in my log files that their were 2 errors with the freeware version i am using, so he told me that using antimaleware with out having a licensed version, can cause vulnerabilities to my computer.
When i am referring to log files. I am referring to inside the control panel the "event viewer" and windows logs. This is what he was showing me as errors. one in which case pertained to antimaleware in which case i needed purchase and register the full version in order to get rid of the errors. Maybe some of these errors existed on my machine, or maybe they were just fake on a remote VPC, i don't know. But either way i think he used that as leverage to try and compromise my system.
He also tried to do some some form of "cleaning tool" that i did not recognize as a windows application. It was either cleaning up files or deleting them, and i pulled the power cord.
This user's location was located in India, Kolkata and it was the same location that chase blocked the fraudulent transaction.
That pass key application that you shown me before, i definitively want to try that out and use that for all of my user ids and passwords.
This link may help in determining the same case scenario that i went through as a scam. Their is a video at the bottom that kind of shows the phone call that this same guy experienced with this online scam.
http://www.squidoo.com/online-pc-care-scam
This kind of explains some more info regarding the scan
http://stigma31.hubpages.com/hub/Online-PC-Care-Scam
IN any case its all over google so its something that i ran into unfortantly and im now a victim of it.
Anyways this person has complete control over my pc as of this writing. Right now i am using my laptop But i need assistance in gaining acesss to my computer once again. I don't know how i am getting all these scam attempts from emails and phones, its gotten way out of hand, so that is why im completely changing all of my account information, including my emails, everything.
So please help me eradicate this remote user from my pc so i can get back to using my computer. I don't want to have to erase my HD or format hard drive just to get rid of him. He also keeps calling us on phone over and over again.
Can you determine rather or not this is fraudulent, i am sure it is though. Any user who remote connects to you should not ever remain connected to your pc even after rebooting your machine.
So please help as soon as your able to, that is all, thanks!
~Jeff~
The only information i have as i was watching them take control of my pc, is they downloaded some type of file "called AA_v3.exe" They also transferred some file through their remote messaging called a "UD5 fingerprint" I have no idea what these are accept for the fact of the term UDP protocol. But the remote host name was "ammy Admin" Also i told them i was going to reboot my machine and then call my credit card company like they asked, and they would not allow me to turn off my pc, they kept moving the mouse in circles, so i finally just did a hard shut down hoping that would kill the connection, but to my surprise when i turned my pc back on, they were still remotely connected. Even now they are remotely connected and i can't use my computer for anything, i unplugged all my hard drives accept my C drive but i still have alot important data on my C drive. This person did all kinds of work and some type of scans on my pc so i have no idea what kind of activity he was trying to gain access to, most of it was used through CMD prompt. Hopefully you have a log that can detect what type scans this user was using on my machine.
Oh yes, he also tried to convince me that i needed register a full version of "antimaleware" the software that you guys originally shown me. He shown in my log files that their were 2 errors with the freeware version i am using, so he told me that using antimaleware with out having a licensed version, can cause vulnerabilities to my computer.
When i am referring to log files. I am referring to inside the control panel the "event viewer" and windows logs. This is what he was showing me as errors. one in which case pertained to antimaleware in which case i needed purchase and register the full version in order to get rid of the errors. Maybe some of these errors existed on my machine, or maybe they were just fake on a remote VPC, i don't know. But either way i think he used that as leverage to try and compromise my system.
He also tried to do some some form of "cleaning tool" that i did not recognize as a windows application. It was either cleaning up files or deleting them, and i pulled the power cord.
This user's location was located in India, Kolkata and it was the same location that chase blocked the fraudulent transaction.
That pass key application that you shown me before, i definitively want to try that out and use that for all of my user ids and passwords.
This link may help in determining the same case scenario that i went through as a scam. Their is a video at the bottom that kind of shows the phone call that this same guy experienced with this online scam.
http://www.squidoo.com/online-pc-care-scam
This kind of explains some more info regarding the scan
http://stigma31.hubpages.com/hub/Online-PC-Care-Scam
IN any case its all over google so its something that i ran into unfortantly and im now a victim of it.
Anyways this person has complete control over my pc as of this writing. Right now i am using my laptop But i need assistance in gaining acesss to my computer once again. I don't know how i am getting all these scam attempts from emails and phones, its gotten way out of hand, so that is why im completely changing all of my account information, including my emails, everything.
So please help me eradicate this remote user from my pc so i can get back to using my computer. I don't want to have to erase my HD or format hard drive just to get rid of him. He also keeps calling us on phone over and over again.
Can you determine rather or not this is fraudulent, i am sure it is though. Any user who remote connects to you should not ever remain connected to your pc even after rebooting your machine.
So please help as soon as your able to, that is all, thanks!
~Jeff~