I got a call from recently from someone claiming to be a Dell tech rep. He said my laptop was reporting multiple errors. Realizing immediately that this was a scam I let him continue while I started a Windows 7 Virtual Machine session. Because I had some free time I let him talk me through all the steps of how to view the "critical" errors in the event viewer, making sure to misunderstand him due to his accent. This required that he repeat himself frequently and phonetically spell out anything he wanted me to type. By the time he was ready to remote into my laptop I had the VM session up and running where I was able to waste still more of his time. Unfortunately by the time he was ready to "fix" things I had run out of time and patience. All I had time to do at that point was to point out exactly what I thought of him and his choice of vocation.

I hope that the next time they call I have the time to let them loose on a clean VM session to see what they do with it.

Dani AI

Generated

Good move by to use a throwaway VM — that is one of the safest ways to waste a scammer’s time while keeping a real system protected. The thread shows how common and persistent these callers are (, , ). Below are concise, practical steps and checks that add value beyond the anecdotes here.

If an unsolicited caller asks to “fix” a PC

  • End the call. Do not install software, give remote access, or read out authentication codes. Block the number and report the attempt to the device vendor and consumer-protection authorities appropriate to the country.
  • If a remote session was allowed or credentials were shared, treat the device as compromised: isolate it from networks immediately.

Quick containment and triage (from a clean device, where passwords can be reset)

  • Change passwords for email, banking, and any accounts accessed from the compromised machine. Enable 2‑factor authentication.
  • Alert banks/credit card companies and monitor statements.
  • Run full offline/boot-time antivirus and a reputable anti‑malware scan.

Check for persistent backdoors (on the affected machine)

  • Look for recently installed remote‑control apps (TeamViewer, AnyDesk, LogMeIn, Ammyy, Splashtop, etc.), new user accounts, unfamiliar startup entries, scheduled tasks, or services.
  • Quick commands to inspect installed programs and listening network services:
powershell -Command "Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select DisplayName,DisplayVersion,Publisher"
powershell -Command "Get-ItemProperty HKLM:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Select DisplayName,DisplayVersion,Publisher"
netstat -abn

Recovery recommendation

  • If remote-control tools or signs of tampering are found, restore from a known-good backup or perform a clean OS reinstall. Back up critical files first (scan them from a clean machine). If sensitive info or money was exposed, consider credit monitoring or a credit freeze.

Notes tied to the thread

  • ’s VM tactic is excellent when disposable and fully isolated; keep a revertible snapshot for experiments. ’s automated prank ideas are clever but do not substitute for securing accounts and systems after any possible breach.

Recommended Answers

All 17 Replies

Yeah. It would be interesting to see just how many viruses and trojans they can infect the system with. LOL. I too find these calls "entertaining" if I have the time. We have no Windows systems in our house. My wife is an iDevice user exclusively, and I am a Linux-only user. :-) I like the idea of starting up a Windows 7 VM though for this experiment. I do have a Win7 installation DVD for such purposes (software testing, etc).

I've gotten these calls too and also find them entertaining and let them walk me through the process, up to the part where they connect, of course. Then I just hang up. I'm way not confrontational enough to use any choice words.

One time I got a random spammy cold call. I had some time on my hands so I decided to entertain the call and ended up in a conversation with the guy. He ended up telling me that I made his week because he just had this crappy telemarketing job and everyone constantly hung up on him and I was the nicest person he ever spoke to on the job. He said he couldn't tell me how much he appreciated it, and thanked me, and we ended up becoming Facebook friends.

commented: You just never know! :-) +14

Rproffitt, what phone number is that?

Oh joy. I got anothe call this afternoon. I played along for a while, but this guy was smart enough to realize he was in a virtual machine. I was able to give him an earful before disconnecting. The next call will get a warning that any follow up calls will get 120 db of airhorn into the phone.

CAN YOU HEAR ME NOW!!!!!

Wow, he realized he was in a VM? I honestly didn't think these people were intelligent enough to know what they are looking at (such as seeing virtual hardware or network connections). I thought they were just reading from a script because they found a script on some black hat website that says you can gain access for following theee steps exactly. You know, like a script kiddie. Funny that we were just talking about t and a call came in a day later. How often do you get these calls? Been years for me!

They seem to come in spurts. I got one such call a few months ago, then nothing for a while.

To clear up the confusion, CAN YOU HEAR ME NOW is going to be my response to them after I blast them with 120 db of air horn. It's not (to my knowledge) the name of the scam.

You must be on some kinda list, Jim. Lol.

I've also been getting a lot of sex spam. I wonder if someone got my email address off a database somewhere ^_^

Jim, you really need to turn off or block your webcam before you start playing around! LOL!

Jim, you really need to turn off or block your webcam

My face is the only thing they could see but it ain't Grecian Formula they're trying to sell me.

I've also been getting a lot of sex spam. I wonder if someone got my email address off a database somewhere ^_^

Me too and they try to add my account to Hangouts, so I reply to add my "other" account instead, which is the email address of a previous spammer. When they insist, I reply with Siri's quotes, random tweets, youtube videos. Last time, the correspondence continued for a week before they gave up.

I've also been getting a lot of sex spam. I wonder if someone got my email address off a database somewhere ^_^

Hey here you can check it out i have been leaked 3 times O_O
https://hacked-emails.com/

EDIT: also this one too https://haveibeenpwned.com/

commented: yeah, I know about those services ;) +14
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.