|
|
此文章由 kakei14 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kakei14 所有!转贴必须注明作者、出处和本声明,并保持内容完整
接到电话说是我家的internet有问题。
以前类似这样的电话接过很多次,但我都是1分钟挂掉,今天闲着了。。。想多聊几句。
各种前戏问候寒暄就跳过去了,直接上技术部分。
骗术1
他会一字不差的告诉你的computer ID,然后验证:
Windows+R 弹出Run box,输入cmd,在命令窗口运行
assoc
然后会告诉你看最后一行ZFSendToTarget里的ID就是你的computer unique ID,和他先前告诉你的一字不差。
.ZFSendToTarget=CLSID\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}
骗术2,运行msconfig
在service里问你是不是很多service 都被stopped了?
骗术3,运行 eventvwr
然后你会看到成千上万条critical events/erros
骗术4,运行 netstat,告诉你的网络有非法链接
然后我说电脑是公司的,我要拿去给IT部门看,话音刚落他就挂了我的电话。。
查了一下,终极骗术是要你连接他指定的网站地址,从而取得对你的电脑的远程控制。
这个骗术应该有至少5年了,网上有不少:
Indeed, what he read back to me was "888DCA60-FC0A-11CF-8F0F-00C04FD7D062" which matched what was listed in my command prompt window. He continued to insist that the number was my computer's unique ID even after I told him I have been a computer technician since 1998 so knew that "ZFSendToTarget=CLSID\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}" has to do with the file association for ZIP (compressed) files and that the "888DCA60-FC0A-11CF-8F0F-00C04FD7D062" number is definitely not unique to any particular Windows system; in fact it is universal since WinXP.
ZFSendToTarget has been used by scammers for more than six years
Next, they then wanted me to input 'netstart teamview.com', which would ultimately have given them remote access to my PC. I terminated the call at that point.
|
评分
-
查看全部评分
|