A New Angle on PC Online Scams

scam tiles

A year ago, I wrote about people calling my clients and trying to sell them on support for their computers.
They would call themselves “Microsoft” or “Windows”  and sometimes were pretty convincing.

Now they’ve gotten even weirder.

This past weekend, a client called me very upset about a phone call he’d received from the usual gang calling themselves “Microsoft”. This time, they said they were moving their offices back to the U.S. and wouldn’t be able to support him anymore. So, they wanted to give him a refund (!) of $250.

What he had to do to get this refund was to give them his credit card number, then go to his bank and see how much money he’d be allowed to withdraw in one day.

They had him go to a web site  on his computer to finalize his refund. That’s when they took control of his computer and planted a few goodies (not!) on it. They told him not to turn off his computer and they would call him again the  next day.

Alright. The thing is, he’d never actually subscribed to their services in the first place and it dawned on him that things were getting a little out of control. He hung up and called me.

First, I told him to shut off his computer immediately so the scammers couldn’t continue to access it.

Second,  I told him to call his bank right away and report this. I would go over to his place next morning and check out the damage.

The next morning, there was indeed damage. Starting up his computer, we were confronted with a Windows log-in screen that would not accept his password. “They” had changed it and my client was effectively locked out of his own machine.

Luckily, I had an little utility with me that finds such passwords and we were able to change it and get into Windows. Now the fun really began.

This is what we saw when Windows finally started up:

pc doctor logmein 1 Capture

Automatically, my client’s computer was booting up and connecting to the bad guys. Eek!
It took two hours of scouring to get rid of every trace of the phony “Microsoft” mischief.

cleaning malware

In reality, the only protection against further fraud is to hang up the phone when they call. These guys are clever – you won’t be able to trace their calls. There isn’t much your bank can do except issue you a new credit card. And the police can’t touch them as they live in another country – almost always India.

Just so you know, Microsoft, the real Microsoft, will never call you.

By the way, Mac users take note: if you think this is a Windows-only threat, be warned that online scammers are now targeting you, too. So, I’ll say it again: if you get a call from anyone who wants to sell you a subscription to take care of your computer, HANG UP!.
Instead, call me or another professional you personally trust.

3 thoughts on “A New Angle on PC Online Scams

  1. Hah, aren’t these folk the very devil. At least once a week I get a little Asian voice puporting to be from Microsoft and telling me my computer requires immediate attention….I hang up very quickly. I don’t know if those weekly calls from duct cleaners are as insidious, but hanging up on them toute de suite is probably safer than speaking your mind. It’s terrifying to know these beastly little creatures can get into your computer.

    1. What’s especially insidious about these characters is that they are preying largely upon seniors. I don’t know where they get their calling lists from but they certainly are persistent in phoning my older clients (or anyone who indicates that they “don’t know much amount computers).
      It could also be that some generations of people are used to being more trusting when it comes to strangers on the phone.
      It’s cruel. And frustrating that they can’t be stopped.

      Of course, I put most telemarketers in the category of home invaders. They can’t seem to be stopped, either.

      Thanks for the comment, Marian.

  2. Thanks for posting this David. Many people are unscrupulous, prey on the vulnerable and get away with it! However, it never fails to surprise me.

Leave a Reply

Your email address will not be published. Required fields are marked *