Go Back   Technibble Forums > General Computers > General Computer Chit-Chat

  Technibble Sponsor

Reply
 
Thread Tools Display Modes
  #1  
Old 08-11-2012, 10:15 AM
Cambridge PC Support's Avatar
Cambridge PC Support Cambridge PC Support is offline
 
Join Date: Dec 2009
Location: Cambridge UK
Posts: 2,030
Cambridge PC Support has a spectacular aura aboutCambridge PC Support has a spectacular aura about
Default Dell fake support call

Customer had a call supposedly from Dell early the other morning. The usual stuff about being heavily infected. Then he flipped the screen and told him that it would cost £xx to resolve, the customer refused.

When I got to the computer it was set to boot into Safe Mode only, so sorted that and his documents are all missing, no Documents folder at all, no Music, Pictures, nothing! I've had a good look round and found absolutely nothing. Even looked for deleted files, still nothing. No hidden partitions, no large archived files

The only other trace I can find is some LogMeIn Rescue files in appdata.

Weird one that
Reply With Quote
  #2  
Old 08-11-2012, 01:08 PM
PBComputer's Avatar
PBComputer PBComputer is online now
 
Join Date: Feb 2010
Location: Carlisle, Cumbria, UK
Posts: 1,117
PBComputer will become famous soon enough
Default

have you tried running unhide.exe? from bleepingcomputer?
__________________
Paul

Reply With Quote
  #3  
Old 08-11-2012, 07:39 PM
Cambridge PC Support's Avatar
Cambridge PC Support Cambridge PC Support is offline
 
Join Date: Dec 2009
Location: Cambridge UK
Posts: 2,030
Cambridge PC Support has a spectacular aura aboutCambridge PC Support has a spectacular aura about
Default

Nope, did an image then restore to another drive (minus security settings) and also viewed filesystem from a Unix boot Cd. Also checked for hidden partitions.
Reply With Quote
  #4  
Old 08-11-2012, 09:37 PM
Cadishead Computers's Avatar
Cadishead Computers Cadishead Computers is online now
Super Moderator
 
Join Date: Mar 2010
Location: Manchester UK
Posts: 3,630
Cadishead Computers is a jewel in the roughCadishead Computers is a jewel in the roughCadishead Computers is a jewel in the rough
Default

is anything hidden in a different profile or similar?

Just find it extremely weird how anyone could do this..
__________________
Hope this helps
Be Safe

Nige
Cadishead Computers
Reply With Quote
  #5  
Old 08-13-2012, 11:21 AM
Cambridge PC Support's Avatar
Cambridge PC Support Cambridge PC Support is offline
 
Join Date: Dec 2009
Location: Cambridge UK
Posts: 2,030
Cambridge PC Support has a spectacular aura aboutCambridge PC Support has a spectacular aura about
Default

Yep it is very weird.

I checked all over, searched for .doc file and .jpg files. Also ran an undelete tool against the partition, nothing, the only folder in his profile was AppData.

The profile was acting up so I've now created a new one and given it all back to him.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:58 PM.


Powered by vBulletin®
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Technibble.com is based out of MELBOURNE, AUSTRALIA.