Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Registered
 
Join Date: Jul 2002
Location: Orange County
Posts: 7,355
Garage
Have I just been hacked?

I was looking at a web page (I forget which one) and all of a sudden I get a message saying contact Windows Security as Windows Defender has stopped a hack attempt, the computer was frozen and no mouse.
I called the number and the tech gave me instructions to press the Windows key along with another and that got me a dialog box to type in www.ultraviewer.net. I did that and hit the download button and now have a file called ultraviewer_setup_p6.5_en on my drive in the download file.
What should I do?
Delete the file?
How can I find any files it may have already installed?

__________________
Scott
'78 SC mit Sportomatic - Sold
Old 09-08-2022, 12:26 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
Join Date: Jun 2009
Location: St Paul MN
Posts: 5,248
Garage
I think you just broke every rule of internet security. I would turn it off and schedule an appointment with a computer shop or find someone very knowledgeable to clean your computer up.

Good luck.
__________________
Rutager West

1977 911S Targa Chocolate Brown
Old 09-08-2022, 12:49 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
Join Date: Jun 2009
Location: St Paul MN
Posts: 5,248
Garage
Googling Ultraviewer and it is software that allows remote access to your computer. Keep that thing turned off. Use another computer to change passwords of important sites.
__________________
Rutager West

1977 911S Targa Chocolate Brown
Old 09-08-2022, 12:55 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,943
The popup box was fake. Microsoft will never ask you to call them. Never call anyone if a number pops up on your screen. Microsoft would not have asked you to install ultraviewer.

So you downloaded the file? Did you run/double-click the file? I hope that you did NOT double click the file. Ultraviewer itself might not necessarily be a bad thing. I think it's just a remote viewing/controlling app. But who knows where you downloaded it from.

Assuming your downloaded the file, but did not run the file, and aren't still talking to the guy on the phone, you're probably OK.

Do you have windows defender?
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 09-08-2022, 12:58 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,943
Quote:
Originally Posted by rwest View Post
I think you just broke every rule of internet security.
absolutely. scamming call center wet dream.



If all he did was download the ultraviewer executable, he's probably OK.

But yes, it wouldn't hurt to have someone knowledgeable check things out.

I don't know what the process would be like on a current windows platform. In days past, I'd recommend checking all running processes and looking for anything weird (which if you aren't knowledgeable might be almost everything), then a deep scan by whatever the current free Windows security software is (defender or whatever it's called), and then I might recommend checking out another software like malwarebytes or something like that.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 09-08-2022, 01:03 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
White and Nerdy
 
Tervuren's Avatar
 
Join Date: Jun 2004
Location: South of Charlotte N.C.
Posts: 14,923
Garage
It's a scam.
They will use remote viewer to "remove the virus".
Then sell you a monthly security fee.

If you got that far and tick them off, they can change your passwords, and lock you out.
Old 09-08-2022, 01:04 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Registered
 
Join Date: Jul 2002
Location: Orange County
Posts: 7,355
Garage
I think I'm OK guys.
As soon as I clicked the download button the phone line went dead to dial tone.
I'm running windows defender and that's what the window said stopped the trojan from downloading. That's the only reason I called the number.
I've run two scans now and deleted the file that downloaded. I did not click it to run it as I know an executable file when I see one.
If I did in fact loose mouse control in that situation, how should I have reacted to a non-responsive computer?
__________________
Scott
'78 SC mit Sportomatic - Sold
Old 09-08-2022, 01:19 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Get off my lawn!
 
GH85Carrera's Avatar
 
Join Date: Nov 2007
Location: Oklahoma
Posts: 84,864
Garage
Yep, you let the hacker in the front door.

Rule one is never ever click a link on any email, unless your are 100% sure it is legitimate.

You best bet is open your browser, and search for the company, and then find the contact information.

A coupe of years ago I got a call and it was supposed to be my credit card company. I asked her name, and she gave it to me. I asked If I call the number on the back of my CC will I be able to ask for her extension. She said yes. I hung up, dialed the number on my card, and spoke to her. I was satisfied she was legit. She asked if I was in Italy buying expensive scuba gear. I assured he I was at home and would never be buying scuba equipment, and my card was in my wallet. She canceled it, and sent me a new card.
__________________
Glen
49 Year member of the Porsche Club of America
1985 911 Carrera; 2017 Macan
1986 El Camino with Fuel Injected 350 Crate Engine
My Motto: I will never be too old to have a happy childhood!
Old 09-08-2022, 01:21 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
KNS KNS is offline
Registered
 
Join Date: Jan 2004
Location: Docking Bay 94
Posts: 7,015
So in Scott's situation - computer frozen and no mouse - what's the safest next step?
__________________
Kurt
Old 09-08-2022, 01:23 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Registered
 
Join Date: Jul 2002
Location: Orange County
Posts: 7,355
Garage
And it wasn't a link in an email.
I was just browsing a site, I forget which one now, and all of a sudden this thing happens.
__________________
Scott
'78 SC mit Sportomatic - Sold
Old 09-08-2022, 01:25 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
Registered
 
Join Date: Jan 2002
Location: west michigan
Posts: 26,604
Quote:
Originally Posted by KNS View Post
So in Scott's situation - computer frozen and no mouse - what's the safest next step?

I would do a hard power off and then restart.
__________________
78 SC Targa Black....gone
84 Carrera Targa White
98 Honda Prelude
22 Honda Civic SI
Old 09-08-2022, 01:30 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,943
I'd probably check some keystrokes.

alt-tab should switch to another "window" in windows. It's possible that by switching to another app, the mouse might have started working again. It may have just been disabled/locked up by the popup.
ctrl-alt-delete should allow you to bring up task manager. Then you could potentially close the offending window.

If nothing else you would at least know that your computer was still responsive.

If things seemed completely hung, then yes, hold the power button until the machine powers off (~10 secs usually), then power back on.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 09-08-2022, 01:47 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
 
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,943
This video was created to sell an anti-malware product "malwarefox" or something like that. I'm NOT RECOMMENDING that software, but the video content seems fairly legit otherwise.

__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 09-08-2022, 01:53 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,943
This looks/sounds like what you experienced.

__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 09-08-2022, 01:59 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Quote:
Originally Posted by rwest View Post
I think you just broke every rule of internet security. I would turn it off and schedule an appointment with a computer shop or find someone very knowledgeable to clean your computer up.

Good luck.
This.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 09-08-2022, 02:00 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Registered
 
Join Date: Jul 2002
Location: Orange County
Posts: 7,355
Garage
Quote:
Originally Posted by masraum View Post
This looks/sounds like what you experienced.

That's exactly what I experienced.
__________________
Scott
'78 SC mit Sportomatic - Sold
Old 09-08-2022, 02:32 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,943
Quote:
Originally Posted by Scott Douglas View Post
That's exactly what I experienced.
Based on what you've said, you are probably fine.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 09-08-2022, 02:47 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
Registered
 
A930Rocket's Avatar
 
Join Date: Oct 2003
Location: Mount Pleasant, South Carolina
Posts: 14,163
Mrs Rocket is computer/technology impaired. She recently got something that popped up on her screen. She called the number and when they were asking for financial information, she hung up. 😵*💫

When I talked to her, I said don’t try anything, turn it off, and take it to the nearest computer shop to get fixed.
Old 09-08-2022, 05:52 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
The Unsettler
 
stomachmonkey's Avatar
 
Join Date: Dec 2002
Location: Lantanna TX
Posts: 23,885
Send a message via AIM to stomachmonkey
Quote:
Originally Posted by KNS View Post
So in Scott's situation - computer frozen and no mouse - what's the safest next step?
CTRL+ALT+DELETE

Kill the browser process.
__________________
"I want my two dollars"
"Goodbye and thanks for the fish"
"Proud Member and Supporter of the YWL"
"Brandon Won"
Old 09-08-2022, 07:58 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
It'll be legen-waitforit
 
stealthn's Avatar
 
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,979
Sorry to hear, you need to clean your PC and change all passwords for sites you save the passwords to in your browser (banking, etc.), if you do.

Either take the PC to a professional, or if you are so inclined, create a couple of USB boot drives on another PC with AV programs like BitDefender/Malwarebytes, and boot the PC and switch to USB boot drive and run the programs to scan your PC. I prefer to use at least 2 AV boot drives.

Even with this, if they were skilled (doesn’t sound like it), some dll’s could have been replaced. A full re-install of windows would be another layer of protection, I know, I know…

Good luck

__________________
Bob James
06 Cayman S - Money Penny
18 Macan GTS
Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo
Old 09-09-2022, 05:49 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #20 (permalink)
Reply


 


All times are GMT -8. The time now is 08:45 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.