{"id":725,"date":"2022-03-16T13:12:52","date_gmt":"2022-03-16T12:12:52","guid":{"rendered":"https:\/\/www.susii.nrw\/what-happened\/false-support-calls\/"},"modified":"2022-04-22T10:35:41","modified_gmt":"2022-04-22T08:35:41","slug":"false-support-calls","status":"publish","type":"page","link":"https:\/\/www.susii.nrw\/en\/first-aid\/false-support-calls\/","title":{"rendered":"False support calls"},"content":{"rendered":"\n<p class=\"has-text-align-center su-page-intro has-black-color has-text-color\">Criminals regularly pose as support staff from a bank, an Internet access provider or an IT company such as Microsoft. During the call, you will be asked to install a software or update. This usually contains malware that tries to obtain your online banking data.<\/p>\n\n\n\n<div class=\"wp-block-pb-accordion-item c-accordion__item js-accordion-item no-js su-accordion su-icon-signal-wifi-off su-box-shadow\" data-initially-open=\"false\" data-click-to-close=\"true\" data-auto-close=\"true\" data-scroll=\"false\" data-scroll-offset=\"0\"><h2 id=\"at-7250\" class=\"c-accordion__title js-accordion-controller\" role=\"button\">Disconnect your computer from the Internet, network or router as soon as you suspect that malware has been installed.<\/h2><div id=\"ac-7250\" class=\"c-accordion__content\">\n<p>If your computer behaves strangely after installing software as a result of such a call or your anti-virus software sounds an alarm, then you have probably caught some malware.&nbsp;<\/p>\n\n\n\n<p>Immediately disconnect your computer from the Internet and your network and router. This can prevent the malware from spreading to other devices or your computer from being used for other criminal purposes, e.g. as part of a&nbsp;<a href=\"https:\/\/wiki.botfrei.de\/Botnetze\" target=\"_blank\" rel=\"noreferrer noopener\">Botnet<\/a>.&nbsp;<\/p>\n\n\n\n<p>Initially, do not make any independent attempt to remove the malware. Should the fraud attempt have been successful, it thus enables the police to secure evidence and initiate investigations.&nbsp;<\/p>\n\n\n\n<p>You should also avoid re-starting or rebooting the infected device. Many banking Trojans use a computer reboot to remove their traces.&nbsp;<\/p>\n\n\n\n<p>Instead, put your computer into standby.<\/p>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-pb-accordion-item c-accordion__item js-accordion-item no-js su-accordion su-icon-account-balance su-box-shadow\" data-initially-open=\"false\" data-click-to-close=\"true\" data-auto-close=\"true\" data-scroll=\"false\" data-scroll-offset=\"0\"><h2 id=\"at-7251\" class=\"c-accordion__title js-accordion-controller\" role=\"button\">Contact your bank<\/h2><div id=\"ac-7251\" class=\"c-accordion__content\">\n<p>Especially in case of spying related to bank data, you should contact your bank immediately. This will help you determine any damage already incurred or take steps to block your account.&nbsp;<\/p>\n\n\n\n<p>The nationwide emergency number to block a card or account is:&nbsp;<strong>116 116<\/strong>. The blocking emergency number can also be reached from abroad.&nbsp;<\/p>\n\n\n\n<p><strong><a href=\"http:\/\/www.sperr-notruf.de\/\" target=\"_blank\" rel=\"noreferrer noopener\">Website of the emergency blocking service<\/a><\/strong><\/p>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-pb-accordion-item c-accordion__item js-accordion-item no-js su-accordion su-icon-record-voice-over su-box-shadow\" data-initially-open=\"false\" data-click-to-close=\"true\" data-auto-close=\"true\" data-scroll=\"false\" data-scroll-offset=\"0\"><h2 id=\"at-7252\" class=\"c-accordion__title js-accordion-controller\" role=\"button\">In case of financial damage: File a report with the police<\/h2><div id=\"ac-7252\" class=\"c-accordion__content\">\n<p>If you have suffered financial damage in the event of such a call, you should report it to the police immediately.&nbsp;<\/p>\n\n\n\n<p>Use a secure secondary device for&nbsp;<a href=\"https:\/\/service.polizei.nrw.de\/anzeige\" target=\"_blank\" rel=\"noreferrer noopener\">criminal reporting online<\/a>&nbsp;to the police.&nbsp;<\/p>\n\n\n\n<p><em>If it is not possible to use a separate device, you should go personally to the nearest police station to make your report. Take the infected device with you to the police station to secure evidence.<\/em><\/p>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-pb-accordion-item c-accordion__item js-accordion-item no-js su-accordion su-icon-assignment su-box-shadow\" data-initially-open=\"false\" data-click-to-close=\"true\" data-auto-close=\"true\" data-scroll=\"false\" data-scroll-offset=\"0\"><h2 id=\"at-7253\" class=\"c-accordion__title js-accordion-controller\" role=\"button\">If there is no damage: Instructions for removing the malware<\/h2><div id=\"ac-7253\" class=\"c-accordion__content\">\n<p>If you have not suffered any financial damage, you can try to remove the malware yourself. However, there is no guarantee that all malware can be removed.&nbsp;<\/p>\n\n\n\n<p>In case of an infection with a banking Trojan, we generally recommend importing the last system backup.&nbsp;<\/p>\n\n\n\n<p>If you do not have a backup, we recommend a complete reinstallation if you still intend to perform sensitive actions such as online banking with the device.&nbsp;<\/p>\n\n\n\n<p>After reinstalling or importing the backup, you should scan your computer again intensively with an anti-virus program. You can find an overview with different AV products&nbsp;<a href=\"https:\/\/www.botfrei.de\/de\/werkzeuge\/virenscanner.html\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.&nbsp;<\/p>\n\n\n\n<p>Help and support in the removal of malware or the reinstallation after a malware infection can be found in the&nbsp;<a href=\"https:\/\/blog.botfrei.de\/forums\/\" target=\"_blank\" rel=\"noreferrer noopener\">Botfrei forum<\/a>.<\/p>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-pb-accordion-item c-accordion__item js-accordion-item no-js su-accordion su-icon-link su-box-shadow\" data-initially-open=\"false\" data-click-to-close=\"true\" data-auto-close=\"true\" data-scroll=\"false\" data-scroll-offset=\"0\"><h2 id=\"at-7254\" class=\"c-accordion__title js-accordion-controller\" role=\"button\">Related links<\/h2><div id=\"ac-7254\" class=\"c-accordion__content\">\n<p>Botfrei.de:&nbsp;<a href=\"https:\/\/blog.botfrei.de\/2015\/04\/falsche-service-mitarbeiter-rufen-wieder-an\/\" target=\"_blank\" rel=\"noreferrer noopener\">Fraudulent service staff call again!<\/a><br>ING DiBa:&nbsp;<a href=\"https:\/\/www.ing-diba.de\/ueber-uns\/wissenswert\/falscher-kundenberater\/\" target=\"_blank\" rel=\"noreferrer noopener\">Fraudulent account manager<\/a><br>Consumer Center:&nbsp;<a href=\"https:\/\/www.verbraucherzentrale.de\/betrug-per-telefon\" target=\"_blank\" rel=\"noreferrer noopener\">Fake Microsoft calls<\/a><br>T-Online.de:&nbsp;<a href=\"http:\/\/www.t-online.de\/computer\/sicherheit\/id_78535444\/vz-warnt-vor-telefonbetrug-anrufer-geben-sich-als-bank-mitarbeiter-aus.html\" target=\"_blank\" rel=\"noreferrer noopener\">Fraudsters pose as bank employees&nbsp;<\/a><br>HNA.de:&nbsp;<a href=\"http:\/\/www.hna.de\/kassel\/achtung-110-anrufen-falsche-polizisten-apparat-5213714.html\" target=\"_blank\" rel=\"noreferrer noopener\">Beware of 110 calls: Fake police officers on the line<\/a><\/p>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Criminals regularly pose as support staff from a bank, an Internet access provider or an IT company such as Microsoft. During the call, you will be asked to install a software or update. This usually contains malware that tries to obtain your online banking data.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":704,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"_links":{"self":[{"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/pages\/725"}],"collection":[{"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/comments?post=725"}],"version-history":[{"count":1,"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/pages\/725\/revisions"}],"predecessor-version":[{"id":790,"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/pages\/725\/revisions\/790"}],"up":[{"embeddable":true,"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/pages\/704"}],"wp:attachment":[{"href":"https:\/\/www.susii.nrw\/en\/wp-json\/wp\/v2\/media?parent=725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}