ConnectWise scam domains list

@ScammerRevolts, what’s your take on this one that a chode tried getting me on today…

https://join.gotoresolve.com/456273683

That one is not connect wise control.

Updated with https://mcare.help/
and http://123secure.org/

mcare.help iframes https://xibition.top/guest.aspx, the main page of which is simply a template lifted from Tooplate

I found this. I think it is connect wize
Support (vhelp.info)

1 Like

Added the above along with https://ghelps.us/ & [https://control.ctrl10.pw]

1 Like

Here is a new one.
kcare.cc

2 Likes

Added yours @FredFlintstone along with this one an SSA tried on me today…

https://rmpk.info

1 Like

Added https://9117.org to the list.

Added https://mkpks.info.

Yeah these scams are awful.

Can someone give instructions on how to remove it from my pc? thanks

I use Revo Uninstaller for all program uninstalls as it will scan all the leftover files related to programs, including registry keys, unwanted files, and folders.

If doing it manually…

Manually Remove ConnectWise Control (ScreenConnect) From Windows

Get the unique thumbprint for the ScreenConnect instance installed on the PC

  1. Open Program and Features, Control Panel > All Control Panel Items > Programs and Features
  2. Search for “ScreenConnect Client” in the list of software installed.
  3. You should see something similar to “ScreenConnect Client (xxxxxxxxxxxxxxxx)”, where “xxxxxxxxxxxxxxxx” represents the unique thumbprint. Note this thumbprint down somewhere as you will need it for the rest of the steps.

Delete all traces of ScreenConnect Client (xxxxxxxxxxxxxxxx) from C:\

  1. Open File explorer
  2. Search, find and delete any folders named “ScreenConnect Client (xxxxxxxxxxxxxxxx)” in the following directories:

C:\Program Files
C:\Program Files (x86)
C:\ProgramData
3. Do a search through the c:\ for “ScreenConnect Client (xxxxxxxxxxxxxxxx)” to confirm all traces have been removed.
Delete all traces of ScreenConnect Client (xxxxxxxxxxxxxxxx) from Registry Editor

  1. Open “RegEdit” with Admin privileges
  2. Do a “CTRL+F” to bring up search bar
  3. Search the registry for any traces of the ScreenConnect instance “ScreenConnect Client (xxxxxxxxxxxxxxxx)” & “xxxxxxxxxxxxxxxx”, where “xxxxxxxxxxxxxxxx” represents the unique thumbprint.
  4. Delete these entries from the registry
    Delete the ScreenConnect service from Windows Services
  5. Open an elevated command prompt
  6. Run the following command (where “xxxxxxxxxxxxxxxx” represents the unique thumbprint):

sc delete “ScreenConnect Client (xxxxxxxxxxxxxxxx)”
3. Open Services and confirm the ScreenConnect service has been deleted. This may take a few minutes for the command to process after running it

Hi. I made a simple TamperMonkey script to alert you when you are on a ConnectWise scam website.
Just install the js script into tampermonkey, done!
here is the source: GitHub - biden2020prez/ConnectWise-Scam-Blocker: Identify and block ConnectWise Scams

If anyone here wants edit access to the repo, in order to update the list of sites when needed (I’ll try but can’t promise), just PM me here or email me: [email protected]

Screenshots:

1 Like

Here is the second screenshot because I am a new user :slight_smile:

I have been looking a bit more into this today with the 10 scammers I called. To turn off connectwise, run these two commands:

taskkill /f /im ScreenConnect.WindowsClient.exe
taskkill /f /im ScreenConnect.ClientService.exe

This will kill the program.and go to c:\Users\username\appdata\local and delete the folder called “apps”, so it doesnt start when you turn on your PC.

jassist.us

I was baiting some scammers yesterday and had ZoneAlarm on the VM. I was surprised it detected Connectwise as malware. It let it install first and only after fifteen minutes was it detected. I’m guessing the method that stopped it was behavioral based. The ZA browser extension doesn’t seem to let it download at all now. It’s not displaying that it’s flagged for some reason, but it is keeping the download in limbo, like it’s paused indefinitely.

1 Like

Ok I added this domain, also nice to see this software is finally getting flagged :+1:

1 Like

Added https://os123.org

os123.org iframes sup2.supos123.org/guest.aspx

Added to the list @KinCryos.

Also added https://qcare.cc

added - https://shelp.info/