• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

How much damage can fixpc99 do?

Chris_Halkides

Penultimate Amazing
Joined
Dec 8, 2009
Messages
12,980
Hi Everyone,

I have a Mac desktop machine, and I am not very computer-savvy. I was browsing for news stories, when www dot fixpc99 dot com kind of took over my browser. It would not let me close the windows when I clicked on them. When I force-quit Safari and relaunched, the windows came right back. The windows had a phone number which was 647-360-4442. I called this number, but they wanted to do a remote login to my computer. I think that this is some kind of browser hijacker.

Tech services will come by Monday, but I am left with some questions. How much damage have I done to my security and to my personal information? How do I prevent this in the future?
 
Last edited:
fixed it

SURE, I'm going to click on that link. Not.
By editing it, I unlinked it. I absolutely agree that everyone should stay away from this site. But when I search on this name, I get taken to some pseudo-blogs that say how bad it is and that I should buy some computer program to remove it. I may be getting cynical at this point, I don't trust these adverts, either.
 
Last edited:
This is being discussed at the Apple support boards. There appear to be some solutions.

It's a scam, they want money to "fix" your computer, which entails infecting it with more adware.

To re-iterate what to do to get rid of it:

1) Force-quit Safari, and re-open with Shift held down.

2) If that doesn't help, disconnect computer from network/internet while restarting Safari (and maybe everything else).

3) If that doesn't help, head over to AdwareMedic, and download and run it. You may have to use a different browser if Safari is held hostage.
 
go phish

Thank you. I will give that a try. I feel as if this might have also been a phishing scam of some sort. They also asked for my email and telephone number, so I made some stuff up.
 
Strange. I go to that link and it just redirects me to Google. Does it only do anything on Macs, or has it been taken down?
 
As far as how much damage the thing has done as long as you not have clicked on the link in it or installed anything, not much. It simply takes over your Safari, but this can be removed with very simple user actions (like launching the safe-mode of Safari, or deleting preferences and history), if you know where to look.

I couldn't find anything about what happens if you give in to them.

Here are some advice I can give to avoid bad infections:

1) Do not use an Admin account for everyday work. (Though admittedly, using one is safer on Mac OS X than it is on other popular operating systems, since even while logged in as admin, you have to provide the admin password for certain actions like copying apps into the standard Application folder.)

2) Do not type in your admin password if you do not know what triggered the password question.

3) Do not download from untrustworthy sites (this is a often given advice; the problem is that it's not necessarily easy to identify if the site you're on is untrustworthy or not. Some like Softonic or Download.com are definitely untrustworthy. Always try to make sure to go to the original company's/developer's website, or stick to Apple's app store, though some types of software is not allowed on it.)

4) Mac OS X Yosemite checks whether or not the developer is registered with Apple, and is by default set not to run apps from developers that are not. Leave it this way, and only override it if you are absolutely sure you know what you're doing (you can override it on a case-by-case basis). This check was introduced in some earlier OS version, too, but I forgot when. It's definitely there in Yosemite.

5) If you get a popup saying your computer needs to be cleaned with a phone number or a link, do not call the phone number, do not click on the link and do not let strangers remote control to your computer.
 
Last edited:
1) Do not use an Admin account for everyday work. (Though admittedly, using one is safer on Mac OS X than it is on other popular operating systems, since even while logged in as admin, you have to provide the admin password for certain actions like copying apps into the standard Application folder.)
For the part outside the brackets, this is something that MS have always advised at every stage, since at least 2002. No one takes any notice, because it means people have to do something.

For the part in the brackets, I'm assuming that by 'other popular OSes' you mean Windows. If so, this is also an option in Windows, although the default is just to prompt you to click 'yes' to agree. Many people find even this too onerous, so you can imagine how many people would disable it if it required one to type a password.
 
It's probably been taken down.

Any popup or web ad that implores you to call a number for tech support is a scam. This is doubly so for numbers that appear in a popup that seemed to come from nowhere. When you give these scammers access to your computer via remote support, they will attempt to show you how "damaged" your PC is. They then ask for several hundred dollars/pounds to "resolve" any issues, and if you refuse then they will try to delete your files and mess up your system.

YouTube is full of examples of these scammers, and the people who toy with them for hours on end. There are some reputable companies that can legitimately assist remotely, but the vast, overwhelming majority of them are scams.
 
For the part outside the brackets, this is something that MS have always advised at every stage, since at least 2002. No one takes any notice, because it means people have to do something.

For the part in the brackets, I'm assuming that by 'other popular OSes' you mean Windows. If so, this is also an option in Windows, although the default is just to prompt you to click 'yes' to agree. Many people find even this too onerous, so you can imagine how many people would disable it if it required one to type a password.

Sigh. I know.

But what do I know? I just use computers for a long time (running under Win, Mac OS X and various Linuxes), always followed that advice, and (almost*) never got any infection whatsoever, despite visiting the dirtier sites of the web (adult themed, mostly :D).

*I did get one recently on Win 8.1 with Internet Explorer as browser, while I wanted to download another browser (it was a new machine, so I had to use it). I am deeply embarrassed by it, but, as far as I can recall, it was impossible for me to see that I was not on the correct trustworthy site for the download I was trying to do. I consider myself fairly knowledgeable, so if even I cannot correctly identify trustworthy from untrustworthy downloads, I don't expect less knowledgeable people to be able to.

While I do take full blame for this malware infection, I want to point out that I consider my difficulties to identify trustworthiness were aggravated by certain design choices MS has made in Win 8.1.
 
Aye, I just found the redirect to Google to be unusual. I'd expect either a 404 or a takedown notice normally.
 
Aye, I just found the redirect to Google to be unusual. I'd expect either a 404 or a takedown notice normally.

Could it be a problem of your ISP? I sometimes run into strange search engine redirects when the ISP has problems contacting the DNS. Usually, these are only temporary problems.

For the record, I can access the link normally (but I'm on a Mac and a different country).

Assuming you mean the link to Apple support file HT203987.
 
No, I mean the original link to the malicious site. I can access Apple's site fine. I just went to it to see what it tried to do, but it redirected, whether by a 301 or whatever I couldn't tell. Could be my ISP interceding, I suppose, although they never did so when there were well known domains threatening Windows, and I would be somewhat perturbed by transparent redirects without my knowledge, even if it were to keep my (non-existent) Apple kit safe.
 
No, I mean the original link to the malicious site. I can access Apple's site fine. I just went to it to see what it tried to do, but it redirected, whether by a 301 or whatever I couldn't tell. Could be my ISP interceding, I suppose, although they never did so when there were well known domains threatening Windows, and I would be somewhat perturbed by transparent redirects without my knowledge, even if it were to keep my (non-existent) Apple kit safe.

Ahh!

Didn't try that, for obvious reasons. I would take precautions, like accessing it from a VM or so, if I were inclined to do that.

I just googled what others have written about it. From what I learned there, the damage the scripts on the webpage can do is pretty limited. They rewrite preferences of Safari, nothing more. The real damage starts when people call the number, or click on a link that's there, and in the follow-up allow remote login and/or provide their admin password, after which the bad guys can do anything they want.
 
Last edited:
What we are discussing is called Ransomware.

I have found Chrome to be pretty good at detecting dangerous sites, although there have been some false positives. No detection scheme is 100% perfect.
 
3) Do not download from untrustworthy sites (this is a often given advice; the problem is that it's not necessarily easy to identify if the site you're on is untrustworthy or not. Some like Softonic or Download.com are definitely untrustworthy. Always try to make sure to go to the original company's/developer's website, or stick to Apple's app store, though some types of software is not allowed on it.)

I always thought the Download.com (from Cnet) was one of the go-to, trusted places? I've gotten dozens of items from there, but I usually only take one of the top two in whatever's listed.
 

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom