Question AweSun Remote Access software from AweRay

cmangle

Distinguished
Jan 17, 2005
76
0
18,630
An elderly friend allowed the wrong "fictitious" Amazon representative to install "AWESUN" remote access software to his laptop. Luckily he realized something was wrong before the hacker scammer got full access.
I sent the email below to AweRay, creator of AWESUN and got no reply.

Is anyone familiar with this software and how to remove the code attached to ANY of my elderly friends internet desktop shortcuts?
Thank you

[email removed]
 
Last edited by a moderator:

USAFRet

Titan
Moderator
You can run all the malware removers you want, but you'd never really be sure.

As above....
Save all personal files.
Full wipe and reinstall of Windows and everything else.
From a different, known clean system, change all passwords to ANY site they use.
 
  • Like
Reactions: cmangle

cmangle

Distinguished
Jan 17, 2005
76
0
18,630
By the time I was given the "Awesun" uninstall ink, I had already started a complete wipe and win 10 reinstall.

One bite in the butt is the scammer must have partially got in, as the "User" - "Ed" - and all folders under "ED", document, pictures, desktop, etc were transferred to a USB drive but NO FILES were in any of the xferred folders.

I should have checked AFTER I initiated the USB back, up but i didn't think the scammer had gotten in far enough to block file xfer and hold them for ransom!
 

eschaef2

Distinguished
Mar 17, 2014
3
0
18,510
An elderly friend allowed the wrong "fictitious" Amazon representative to install "AWESUN" remote access software to his laptop. Luckily he realized something was wrong before the hacker scammer got full access.
I sent the email below to AweRay, creator of AWESUN and got no reply.

Is anyone familiar with this software and how to remove the code attached to ANY of my elderly friends internet desktop shortcuts?
Thank you

[email removed]

Hi everyone.

I experienced this phone call here on the other side of the pond, and as I felt it was a phishing expedition from the initial opening, I ran with it (reasonably far) to confirm. I offer the following points for your awareness, and to try and help you understand the 'aggressive/ scare' tactics the gentleman (using the term very loosely) employed upon me:

• 'talk talk talk' to indicate a recent purchase has been "blocked" on your AMZ account b/c it appears "suspicious" to the "AMZ security team" (of which he identified himself as a member)
• Person informed me it was an iPhone purchase, and they need to have it removed by me. -No amount of 'thanking him/ them for doing such a great job of intercepting/ couldn't you (pretty please) just delete the transaction? -I (Eric) told him (scammer) it is obviously on his screen since he's telling me it's on my account and "blocked" 😏...
• 'No, No, No, dear sir,' (I never gave my name, and he couldn't seem to find it on my "visible" account that was in front of him) "we need you to download the security software that will link to the AMZ security server in order for you to finish removing the transaction. Please be sure you are sitting in front of you laptop and go to the .awesun.com website and download the security software to your laptop"
• I responded with I'm not comfortable downloading something to my laptop, and he got kind of agitated and basically said I needed to do this in order for the AMZ order to be 'erased'. "There is no other way to remove this $400.00 purchase from posting to your account soon".
• I finished with "then let's let that happen, and I'll deal with AMZ fraud services upon its posting".
• Resulted in a quick "Ahhh, OK; bye"

My message to everyone who has friends, loved ones, parents or children that might become nervous/ anxious when being bullied like this: Help them understand AMZ (or any other reliable retailer) will never NEVER demand you install a remote service, a portal, a remote link (or any other type of descriptor here) on your system just to confirm this unknown transaction has been cancelled.

Please maintain yours (and their) vigilance with the never ending increase in this type of activity.

Cheers,
-Eric

[phone# removed]