Okay, it's not really exclusive, but whatever. Good hook to get you to read this, no?
I literally <i>just</i> got home from school when I got this e-mail, apparently from the GMC:<fieldset><legend>Suspicious E-Mail</legend><font size="-7" face="Courier New, Courier, mono">From - Thu May 04 15:38:49 2006X-Account-Key: account3X-UIDL: 0MKuxu-1Fbk8T3XHE-0007E6X-Mozilla-Status: 0001X-Mozilla-Status2: 00000000Return-Path: <nobody@cust4655a.ipslink.com>Delivery-Date: Thu, 04 May 2006 16:09:18 -0400Received-SPF: none (mxus0: 67.15.173.51 is neither permitted nor denied by domain of cust4655a.ipslink.com) client-ip=67.15.173.51; envelope-from=nobody@cust4655a.ipslink.com; helo=cust4655a.ipslink.com;Received: from [67.15.173.51] (helo=cust4655a.ipslink.com) by mx.perfora.net (node=mxus0) with ESMTP (Nemesis), id 0MKuxu-1Fbk8T3XHE-0007E6 for adam@thetyphooncorp.com; Thu, 04 May 2006 16:09:17 -0400Received: from nobody by cust4655a.ipslink.com with local (Exim 4.52) id 1Fbk8Q-0002VN-SV for adam@thetyphooncorp.com; Thu, 04 May 2006 15:09:14 -0500To: adam@thetyphooncorp.comSubject: Administration forums.gamemaker.nl ( From Game Maker Community )From: "Game Maker Community" <gmcommunity@gmail.com>X-Priority: 3X-Mailer: IPB PHP MailerMessage-Id: <E1Fbk8Q-0002VN-SV@cust4655a.ipslink.com>Date: Thu, 04 May 2006 15:09:14 -0500X-AntiAbuse: This header was added to track abuse, please include it with any abuse reportX-AntiAbuse: Primary Hostname - cust4655a.ipslink.comX-AntiAbuse: Original Domain - thetyphooncorp.comX-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]X-AntiAbuse: Sender Address Domain - cust4655a.ipslink.comX-Source: X-Source-Args: X-Source-Dir: Envelope-To: adam@thetyphooncorp.comX-SpamScore: 0</font><b>We offer you to take a part in our new tournament.Just register in the application below:<font color="#ff0000">[LINK REMOVED -ed]</font></b></fieldset>Either I already have viruses already, and they're just being tricky, or something is awry with the GMC. And yes, I'm intelligent enough to see that this didn't come from the GMC, although I'm supposed to think that it did. However, now that I look closely at the headers, it at least <i>looks</i> like it came through an Invision Power Board…I find it suspicious that the GMC is also down while this is happening…And by the way, do yourself a favor and <i>don't</i> go to that URL…I'm pretty sure it's spyware or a virus. I'm too cautious to check.I think that the GMC might've downloaded Trojans or whatever automatically…here's ewido's summary of what was wrong:<fieldset><legend>ewido anti-malware - Scan report</legend><font size="-7" face="Courier New, Courier, mono">+ Created on: 4:11:17 PM, 5/4/2006 + Report-Checksum: BBCFF370 + Scan result: HKLMSOFTWAREClassesCLSID{3E422F49-1566-40D3-B43D-077EF739AC32} -> Adware.Generic : Cleaned with backup HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{3E422F49-1566-40D3-B43D-077EF739AC32} -> Adware.Generic : Cleaned with backup HKUS-1-5-21-1202660629-1409082233-725345543-1003SoftwareMicrosoftWindows CurrentVersionExtSettings{3E422F49-1566-40D3-B43D-077EF739AC32} -> Adware.Generic : Cleaned with backup HKUS-1-5-21-1202660629-1409082233-725345543-1003SoftwareMicrosoftWindows CurrentVersionExtStats{3E422F49-1566-40D3-B43D-077EF739AC32} -> Adware.Generic : Cleaned with backup C:WINDOWSsystem32NaviHelper.dll -> Adware.Navi : Cleaned with backup ::Report End</font></fieldset>More details at ten…or whenever AVG gets done scanning my 180GB computer.<i>Later that night…</i>Oops…kind of forgot about this. Anyways, AVG turned up negative, so I guess it's all good now.
Yeah there's a trojan embedded in it right now. I already suffered an infection. >.<
it is.
Lets see. It's from a site called TraffDollars, has the phrase LOADAD in the filename - wtf, people.
Yeah, they're getting pretty dumb these days. They could at <i>least</i> make it something non-suspicious-sounding like "FREEHALFLIFE2_INSTALL.EXE" or something…lol.
lol
Don't post links to trojans XD
noobs viruses….
They still don't learn a good virus or trojan doesn't say it is a trojan. It covers itself.I wondered why I was getting weird JS pop ups and things trying to be downloaded. Should I run a virus scan just in case?
Yeah, you probably should. I found all that crap on my computer and I know it wasn't there before…
Heh, my anti-virus detected them right away and deleted them, so I'm fine.
And Takua, why do you keep changing the blog's title? I always think it's a different blog. xD