D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Telephone call re my computer

 

On Tue, Jan 31, 2012 at 7:22 PM, Mark Evans wrote:
> Did they give you a number to call them back on?

They did. One that has been used by scammers for a long time - longer
than the site they were using has been registered, so they obviously
change 'companies'.

> Did you give them a completely random number, one which should pass a
> basic validation check or one reserved for drama purposes?

I don't have one of the latter kind, but I did use an existing card
and modified that a bit: I left the first four digits unchanged, and
swapped most of the others. I didn't have time to read up on the
checksums used in credit cards and I didn't expect it to go through
but it did; when I have a moment I'm going to see if the number I gave
them could be valid. Pretty certain it can't be though.

> I suspect that these people are "script kiddies", probably actually
> following a script. They probably wouldn't even notice a VMware/Virtual
> Box tray icon.

The person doing the actual 'work' was someone else than who was
talking to me. The former obviously knew his way around Windows
computers, but probably not too much. However, I don't think it's that
trivial for someone to detect that the machine is running inside a
virtual machine - there's definitely no tray icon saying that.

The oddest thing was that I was told that after the conversation
ended, they would clean up the machine. (After all, that's what I
'paid' for.) I was told not to do anything to the computer and that it
would take about one and a half hours. And it did! (Albeit with
long-ish breaks.) They did all sorts of vaguely plausible stuff:
downloaded and ran lots of free (but genuine) scanning tools
(including one that showed that the machine was very unprotected; they
then closed that window), the guy even tried to activate my Windows
version.

Martijn.

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq