Windows Activation Technologies Pop-up

Page 4 of 6 FirstFirst ... 23456 LastLast

  1. Posts : 512
    Windows 7 Professional x64 SP1
    Thread Starter
       #31

    The Task Scheduler indicates it was last run 11-Sep-15 06:15:10.

    If I understand that correctly, it wasn't running when I started this thread or when I clicked the "Yes" button.

    Therefore, it must have been a fake indication of a run.

    Is that correct?
      My Computer


  2. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #32

    You would ONLY have got that popup for one reason - you were attempting to install the update.
    The update is signed, and as such, if there had been a problem with it, you would have seen a very different popup describing certificate errors.
      My Computer


  3. Posts : 512
    Windows 7 Professional x64 SP1
    Thread Starter
       #33

    I wasn't installing anything. I think that pop-up was an impostor and I was tricked into clicking yes. Once I clicked yes, all the trouble started.
      My Computer


  4. Posts : 4,776
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
       #34

    Well I kind of agree with Noel however that doesn't explain why task scheduler doesn't show that it ran when you clicked on the UAC pop up! Instead in shows 11 September which doesn't seem right.
      My Computer


  5. Posts : 512
    Windows 7 Professional x64 SP1
    Thread Starter
       #35

    Callender said:
    Well I kind of agree with Noel however that doesn't explain why task scheduler doesn't show that it ran when you clicked on the UAC pop up! Instead in shows 11 September which doesn't seem right.
    If it was an impostor, it seems right. The UAC didn't run, but a pop-up that appeared to be the UAC did run and when I clicked on "Yes," the back door was wide open for all the riff-raff.

    I thought it was very strange for that pop-up to occur. That's why I started this thread, but I didn't wait long enough to read the replies, before I got curious and clicked "Yes."

    The two were definately related.

    It's been so long since I've been hit like that that I got stupid.

    Regards
      My Computer


  6. Posts : 2
    Windows 7 N x64
       #36

    I clicked yes too


    Hey tjg79, I fell for it too even after checking the cert (expired) and researching WAT. When I saw that it did not update the file(s) it said it was going to, I immediately pull the system from the network and reimaged it. I also changed my user name and password. I still haven't solved my account lockout problem this caused though.
      My Computer


  7. Posts : 512
    Windows 7 Professional x64 SP1
    Thread Starter
       #37

    TeresaS said:
    Hey tjg79, I fell for it too even after checking the cert (expired) and researching WAT. When I saw that it did not update the file(s) it said it was going to, I immediately pull the system from the network and reimaged it. I also changed my user name and password. I still haven't solved my account lockout problem this caused though.
    I think this virus is new. It's very sophisticated, because the pop-up is high quality and looks legit.

    When ESET tech support cleaned my system, they collected what information they could about this virus. Hopefully, it will be incorporated into their virus definitions soon.

    Regards
      My Computer


  8. Posts : 2
    Windows 7 N x64
       #38

    FYI-we believe the payload came from camelcap.com/work/home/index.php. Since I re-imaged the system, that was all we could find. I also solved my account lockout issue which was fortunately only caused by my username change.

    Cheers
      My Computer


  9. Posts : 4,776
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
       #39

    TeresaS said:
    FYI-we believe the payload came from camelcap.com/work/home/index.php. Since I re-imaged the system, that was all we could find. I also solved my account lockout issue which was fortunately only caused by my username change.

    Cheers
    Well I tried to find that payload in order to try to infect my machine and study it but I get:

    Windows Activation Technologies Pop-up-404-not-found.jpg
      My Computer


  10. Posts : 21,482
    Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
       #40

    The who.is data on camelcap is interesting -
    originally registered 16/9/15 - so only 1 month old.
    Registrar is in China
    Registered owner is in the UK (!) - the post code is actually for ebuyer.com (!!) - but the address is Skelton, a couple of miles away, and appears not to exist (at least according to the Royal Mail postcode finder service).
      My Computer


 
Page 4 of 6 FirstFirst ... 23456 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 19:05.
Find Us