I had a call from a customer, another fake advert on their browser claiming they had a virus and asking them to call a phone number.
The text in the scams said:
Your Computer might infected with an adware causing you to see this popup.
This may happen due to obsolete virus protections.
To fix, please call system support at 020-3805-0575 immediately. Please ensure you do not restart your computer to preovent data loss.
Possibility of Data & Identity theft, if not fixed immediately.
Your computer might contain adware
Attackers currently on malware.testing.google.test might attempt to install dangerous programs on your computer that steal or delete your information (for example. photos, passwords, messages, and credit cards).
Call 020-3805-0575 for assistance with removing adware, malware and viruses.
Mouse Move Security Error.
Your computer might be infected with adware.
Attackers currently on malware.testing.google.test might attempt to install dangerous programs on your computer that steal or delete your information (for example, photos, passwords, messages, and credit cards).
To fix, please contact customer care at 020-3805-0574 immediately.
The URLs the adverts were on are:
Both addresses now seem to be redirecting, in one case, successfully to http://127.0.0.1 (although then no page loads as the computer didn’t have a web server running) and the other to http://errors2.getsupportforyourpc.com/ADV/1/127.0.0.1 and return no fake error any more.
Both adverts listed similar telephone numbers:
02038050575 (aka 020 3805 0575 or 0203 805 0575 or +442038050575)
02038050574 (aka 020 3805 0574 or 0203 805 0574 or +442038050574)
Both numbers seem to be VoIP numbers hosted at Gamma Telecom.
At the time I called it was just putting me into a queue and then hanging up after about 30 seconds:
The website errors2.getsupportforyourpc.com is hosted on 22.214.171.124 – funnily enough errors1.getsupportforyourpc.com also points to this IP! It is hosted at weservit.nl in the Netherlands. No other popular sites appear to be hosted on this IP. It appears to have an internal hostname of “dedi-srv28.alb.nl.weservit.nl”
The domain getsupportforyourpc.com is registered with a privacy service and points to a popular DNS server with no clues as to who may be running the scam. The domain was recently registered on 2015-06-30
However, there are several other domains pointing to the same server.
serve1.righttechnicalsupport.com (slightly older, registered on 2015-06-04) check.onlinepchelpcenter.com (more recent again, 2015-06-30) and scan.gethelpforpc.com (mid-range ish 2015-06-23) all point to the same IP address!
The righttechnicalsupport.com domain is also protected with the same whois privacy service.
The other domains found, onlinepchelpcenter.com, computernowservices.com, onlinepccomputerhelp.com and gethelpforpc.com are also the same.
The computernowservices.com seems to have a lot more stuff accessible including another scam advert page:
the host tech.computernowservices.com is hosted on a different server [126.96.36.199] which seems to have a reference to the hostname dp.techcoast.com [188.8.131.52]. This gives away another domain name of “esvio.com” which in turn gives away a hostname of “test.esvio.com” [184.108.40.206] which then (long chain here) gives away another domain name of “cpvlabtracker.com” [220.127.116.11].
The test.esvio.com site is interesting. All it does is print out a URL to the screen of:
When clicked the cpvlabtracker.com domain then sends you on to a scam avert page!
tech-support-services.com [18.104.22.168] is hosted on the same server as cpvlabtracker.com
Needless to say, t.google-analytics-premium.com [22.214.171.124], isn’t an official google domain and has been registered using whois privacy.
It reverse DNSs to js-cdn.com also registered using whois privacy.
Also related seems to be cpvtracking411.com, server1.cdn-js-query.com [126.96.36.199], images.cdn-hosted.com [188.8.131.52], ajax.surveydonkeys.com.
Possibly also linked: fonts-community.com, www2-alexa.com
Update: 13th July 2015 – So I called them again, this time they answered.
Initially they asked me to go start, run and then type in “hh h” which loads HTML help.
They then talked me through clicking the icon in the top left (as if you were to close the program) but then select “Jump to URL” and type in (here is the interesting bit!) http://www.lmi1.com
Now… lmi1.com is a domain I’ve come across before! It isn’t owned by LogMeIn! It is a domain bought by someone using domain privacy which then forwards you to logmein. I previously saw it in conjunction with the WinZip tech support scam back in December 2014.
Another domain associated with their operation is http://www.techdriveinc.com
I quizzed them about if they were part of winzip or any of the previous company names or domain registrants I had found on the WinZip operation but none seemed to click with the person I spoke to.
So my best guess so far is that it’s a different support department / outsourcing operation but with a script or mandate from the same parent company as the winzip operation. I don’t see why lmi1.com would be common between the two otherwise.