{"id":259,"date":"2017-09-06T16:00:25","date_gmt":"2017-09-06T20:00:25","guid":{"rendered":"http:\/\/www.heliotropicsystems.com\/blog\/?p=259"},"modified":"2017-09-07T16:05:54","modified_gmt":"2017-09-07T20:05:54","slug":"another-aol-bit-of-idiocy","status":"publish","type":"post","link":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/another-aol-bit-of-idiocy\/","title":{"rendered":"Another AOL Bit of Idiocy"},"content":{"rendered":"<p>A client called in on my support phone earlier this afternoon and told me that she had a \u201cMicrosoft System Security Alert\u201d screen that was talking to her and that she couldn\u2019t do anything with her computer.<\/p>\n<p>I launched a remote session, and by using the Windows Task Manager I quickly ended the Internet Explorer applications that were running. It was a fast and easy fix for a really stupid problem.<\/p>\n<p>I was extremely grateful that this particular home user called me, instead of the 800 number that was on the bogus alert screen (shown below). But my relief was short lived.<\/p>\n<p><a href=\"http:\/\/www.heliotropicsystems.com\/blog\/index.php\/another-aol-bit-of-idiocy\/aol_scampage\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-260 size-medium\" src=\"http:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/aol_scampage-300x211.png\" alt=\"\" width=\"300\" height=\"211\" srcset=\"https:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/aol_scampage-300x211.png 300w, https:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/aol_scampage-150x106.png 150w, https:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/aol_scampage-768x540.png 768w, https:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/aol_scampage.png 1008w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>A few minutes later she was back on the phone saying the fraudulent alert was on her computer again. I killed it and ran a scan with Malwarebytes, which turned up nothing.<\/p>\n<p>I reassured her that everything was fine.<\/p>\n<p>When she called a third time, I had to ask what it was she was doing \u2013 so she showed me. She launched Internet Explorer and it opened on AOL\u2019s home page. She told me she wanted to go to Amazon to check on a book. And she did so using the AOL Search bar and typing in Amazon.<\/p>\n<p>On the resulting page AOL search results list (shown below), she clicked on the first link that was displayed. I finally understood exactly what was going on.<\/p>\n<p><a href=\"http:\/\/www.heliotropicsystems.com\/blog\/index.php\/another-aol-bit-of-idiocy\/aol_search_results\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-261 size-medium\" src=\"http:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/AOL_search_results-300x203.png\" alt=\"\" width=\"300\" height=\"203\" srcset=\"https:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/AOL_search_results-300x203.png 300w, https:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/AOL_search_results-150x102.png 150w, https:\/\/www.heliotropicsystems.com\/blog\/wp-content\/uploads\/AOL_search_results.png 721w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>You see, that is a sponsored advertisement, meaning some organization paid AOL money to highlight their \u201cproduct\u201d based on a search. Underneath that is, in fact, Amazon\u2019s legitimate web site listing.<\/p>\n<p>I used this as an instructional moment by turning on Internet Explorer\u2019s Status bar. I moved the mouse over the Amazon site link to show that https:\/\/www.amazon.com appeared in the Status bar. I then moved the mouse over the ad, and the following bunch of gibberish appeared:<\/p>\n<pre>https:\/\/174036060.r.bat.bing.com\/?ld=d3iEIp8CztNDVVjNTYoqXRUjVUCUzK_5V032YvPMriEHbBBDFcwsFXQFK3s2qR9MgRW_xhZ9J5SlsoSk6f38u2TnHoDCUsZUB1JUNHwTr9OuZjeHpOBGhVUOyzHQ20xE-ECR9lob4HeScYrxeY00wTrgAAZ5Wu2BEbi0Pb9RjRzi-woEAc&amp;u=http%3a%2f%2fgoo.gl%2fyD6Nby%3furl%3dhttps%253A%252F%252Fwww.amazon.com%252Fbooks-used-books-textbooks%252Fb%252Fref%253Dnav_shopall_bo_t3%253Fie%253DUTF8%2526node%253D283155<\/pre>\n<p>I calmly pointed out that if my client knew which web site she wanted to go to, she could simply type it in the address bar of the browser and go there \u2013 no searching necessary. She\u2019s glad to have learned that.<\/p>\n<p>What I can\u2019t figure out is how in the heck AOL permitted this ad to be displayed in the first place. By having it up there, they are actively enabling those sleazebag \u201csupport agents\u201d to run rough-shod over the typical older AOL user, who does not have a Managed Services Provider to answer her support phone calls.<\/p>\n<p>It took 15 minutes to get through to an AOL Support rep. I\u2019m hoping \u2013 after demonstrating exactly what we found \u2013 that AOL will take this ad down and pursue the bad actors in some way. Of course, that probably won\u2019t happen\u2026<\/p>\n<p>Beware!<\/p>\n<p><strong>Update 09\/07\/2017:<\/strong> AOL has removed this ad from the search results list. Probably the fastest action they have ever taken&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A client called in on my support phone earlier this afternoon and told me that she had a \u201cMicrosoft System Security Alert\u201d screen that was talking to her and that she couldn\u2019t do anything with her computer. I launched a remote session, and by using the Windows Task Manager I quickly ended the Internet Explorer <span class=\"ellipsis\">&hellip;<\/span> <span class=\"more-link-wrap\"><a href=\"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/another-aol-bit-of-idiocy\/\" class=\"more-link\"><span>Read More &rarr;<\/span><\/a><\/span><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[44,3,40],"tags":[],"class_list":["post-259","post","type-post","status-publish","format-standard","hentry","category-aol","category-home-users","category-security"],"_links":{"self":[{"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/posts\/259","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=259"}],"version-history":[{"count":6,"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/posts\/259\/revisions"}],"predecessor-version":[{"id":267,"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/posts\/259\/revisions\/267"}],"wp:attachment":[{"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=259"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=259"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.heliotropicsystems.com\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=259"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}