Yes It Is A Scam - Don't Call That Number!

Recently we've had several people come to us having been hit by a nasty piece of Adware.  This particular pop-up is insidious as it's a two part pop-up, see the attached screenshot.  First you have the large underlying pop-up with the information that says "Call XXX-XXX-XXXX immediately."

nytimes_bad NEW NEW

Also take notice of the "24/7 Unmatched Service and Support".  With a quick glance you might mistake for the image for a Windows logo, but upon further inspection they don't match.

Not_Windows Not Windows Logo        Windows Proper Windows Logo

Next take a look at the smaller pop-up on top of the large one; this one serves two purposes, first is to reiterate you must call them NOW and second is to amp up the fear, "Possibly Privacy Breach and Computer Error Detected Due to Suspicious Activity Found On Your Computer.".

But in all of the fear that your computer may now be breached most people over look a very important piece of information found in this example in the upper left, but could be found in any number of locations depending on what service the Adware is being served through.

Adware

"Ads by Click2Save"  Wait!?!  What?!?  This pop-up is nothing more than a paid for advertisement???  Exactly, it's nothing more than a scam to get you call that number and have one of two scenarios play out.  Either they are going to try and gain access to your personal information in order to steal it or they are going to try and sell you fake software or services that you don't actually need, at a cost to you of hundreds of dollars.

(See our article on the similar tech support phone scam at Tech Support Scams - Don't Be A Victim.)

So you find yourself with this pop-up on your screen, you've realized it's fake, you're not going to be calling these thieves, but how do you get the pop-up to go away?  As if the ad itself isn't bad enough, this is one of those Ads that is bound and determined to stay with you.  Clicking on the "X" seems to take most people into an irritating loop where the two windows continually to appear, one on top of the other.  With testing we have been able to successfully close the Ad by simultaneously clicking the "X" and pressing "Esc".  If that doesn't work try going to your task manager and forcing the browser to shut down, End Task, that way.  If that still doesn't work you may be left with the only option of shutting down your computer.

Once you've successfully closed the Ad you've likely avoided any danger, but you can always take it to a local computer company, like Top Speed Computer Service, to make sure no damage has been done.  Pass along to your friends and family to make sure they are not victimized by this scam either!

What to do if you've been scammed?

First if you’ve found this article and are still on the line with them hang up now and cut off their remote access.  If you’re unsure how to cut their remote access, the sure fire way is to restart your computer.

If you've already had this happen, called them, given them access to your computer, paid them money or not, there are several places you should report them to.   File complaints with the FTC, Fraud.Org the National Consumers League, your local Attorney General, and if you’ve been defrauded of money your local law enforcement as well.  Fraud.Org is an especially good one to file with as they work to share information with many jurisdictions.  Local law enforcement is harder as they really only deal locally and scams like this work on a global scale not a local one.

You will also want to have your computer checked out by a local technical company in case anything malicious was installed on your computer during the so called technical support.

It is always advisable to do business with a local computer company, you never know what you're going to find on the other end of that Internet / phone connection!

Read more...

There's No Such Thing As Free Wifi

There's no such thing as a free lunch is as true today as when it was first written in the 1930s, as well as it's likely origin in the once common practice of saloons in America offering a "free" lunch to any patron who purchased at least one drink.

Today, you can take that adage and attach it to a number of scenarios in technology.  There's no such thing as free email. There's no such thing as free software. And the one we're talking about now - There's no such thing as free wifi.

We'll skip the obvious part about how you paid for the hotel room with "free" or complimentary wifi, or the Starbucks you purchased to sit and enjoy as you use their "free" wifi, or the "free" wifi now available when you walk through any number of retail stores like Target. Instead we're going to talk about something many people consider much more insidious - Adware injected into webpages on "free" wifi networks.

In 2012 Justin Watt was staying at a Courtyard Marriott in New York. Justin happens to be a web developer and as such is a bit more savvy about what he's seeing on the screen than your average web surfer. When Justin went to use the "free" wifi to access his blog he noticed a colored bar at the top of his page that shouldn't be there. His curiosity was peaked and he viewed the source code for part of the site and, "Sure enough I saw some unfamiliar CSS (including the prefix rxg) and JavaScript that had been injected after the <head> tag." Justin goes on to say in his blog, "And I found some unfamiliar JavaScript after the <body> tag."

Justin was immediately concerned his site had been hacked and began digging through his core files. Everywhere he checked his site was intact and unharmed. After much testing and eliminating possibilities Justin determined, "somewhere between the Internet and my computer, someone is injecting JavaScript into EVERY SINGLE PAGE I LOAD."

Justin did not see this as the final answer rather the next place to look. Using a utility that unpacks packed Java he was able to determine that the primary purpose of this JavaScript injection was ad injection / ad takeover, in other words forcing unwanted ads upon the unsuspecting "free" wifi user.

The next question, at least for anyone techy inclined, was had the hotel's wifi been hacked or was their something more malicious at work?  Could the hotel's ISP be involved?  Had the hotel itself brought in this technology to influence guests? Justin was also concerned about who could be notified, who would care about this invasion?

Computer companies spend a great deal of time removing Adware from computers and as a result users spend a great deal of money paying to have Adware, Malware, Viruses and Ransomware removed from their computers. But this is the cost of being online; the Internet is crawling with things we don't want on our computer and we'd like to believe that when using "free" wifi the company providing it has our best interests at heart and has put security in place to keep our systems safe.  Sadly that's not always the case.

Back to that odd prefix tag "rxg", this is how Justin was able to get to the bottom of the injected JavaScript with the help of one of his blog readers.  It turned out that "rxg" was short for Revenue eXtraction Gateway, made by a Nevada company RG Nets.

From RG Nets site, "...the rXg is the perfect platform for clear communication, authoritative control and complete cognizance over your RGN end-user population."  If that doesn't make you weary of ever using "free" wifi again I don't know what will.  RG Nets site goes on to say, "...profitable IP RGNs extract revenue from the end-user community through a combination of direct and indirect mechanisms."

demo video is available on RG Nets site. A portion of the video transcript, "As you can see the pervasive nature of the advertising banner on all webpages guarantees banner advertising impressions. The RGNets rXg HTML payload rewriting feature is a tremendously powerful tool, with a broad spectrum of applications for Internet marketing programs."  YIKES!

For anyone traveling through Atlanta's International Airport they are listed as an RG Net rXg success story, so be wary of what you see on our screen with that "free" wifi.  A local Nevada success story is the Peppermill Hotel & Casino where the rXg is "...used to advertise resort amenities, restaurants, gaming specials and events." At the Peppermill the rXg is also used to charge for different levels of access including, casino patron, convention attendee or exhibitor, and overnight guess access.

While the Marriott came out shortly after Justin posted his blog and said, "...this functionality has now been disabled." this article does not appear to have harmed RG Nets, although it appears to purchase an rXg you must now contact them directly through a contact page on their website.

Screenshots from an RG Nets online brochure.

RGNets1RGNets2                     RGNets3

Read more...
Subscribe to this RSS feed

Contact us

Phone: (775) 852-1811

Toll Free: (866) 511-1331

Fax: (775) 852-1844

Email: info@tsis.net

Physical Address:

800 South Meadows Parkway

Suite 600

Reno, NV 89521

Log in or Sign up