Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Warning about this link


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Warning about this link
Reply
 
Thread Tools
Old 09-05-2005, 01:29   #1
cf.mega poster
 
AndrewJ's Avatar
 
Join Date: Nov 2004
Posts: 7,736
AndrewJ has a nice shiny star
AndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny star
Warning about this link

I need to put a urgent warning out to everyone.

Earlier tonight my gf was using her laptop on her msn list and this link was sent by her friends with lmao is this you? Like most people in msn you click the link expecting joke this is no joke and no spamming matter.

http://pictures.templates4friends.com/pictures.php?email=xxxxxx@hotmail.com

Was the link and I am serious now do not click it, it opens loads of msn windows spams its self stupid, and then it disabled my sygate personal firewall and my avast! home system, i had to reenable via services in control panel, also my network which runs via ethernet is down so my new pc is offline right now.

I have no idea how to stop this other then formatting both systems I have scanned scanned and even more scanned this HD and found nothing.

All I know is some program runs this called project1 and its making a mockery of this laptop right now.

Edit: Link modified (Paul).

Last edited by AndrewJ; 09-05-2005 at 01:58.
AndrewJ is offline   Reply With Quote
Old 09-05-2005, 01:46   #2
Cable Forum Team
 
Graham M's Avatar
 
Join Date: Jul 2003
Location: Poole, Dorset
Age: 23
Services: Sky+ V-Box VM 10MBit
Posts: 9,597
Graham M has a nice shiny starGraham M has a nice shiny starGraham M has a nice shiny starGraham M has a nice shiny star
Graham M has a nice shiny starGraham M has a nice shiny star
Send a message via ICQ to Graham M
Re: Warning about this link

Might be an idea to edit the link so noone clicks it, IE remove the http://
__________________
Used to be Zeph - I'm still me though
Peter: Oh my god, Brian, there's a message in my Alphabits. It says, 'Oooooo.'
Brian: Peter, those are Cheerios.
www.elitehealthdistribution.co.uk - www.loonyasylum.net
Graham M is offline   Reply With Quote
Old 09-05-2005, 01:58   #3
cf.mega poster
 
AndrewJ's Avatar
 
Join Date: Nov 2004
Posts: 7,736
AndrewJ has a nice shiny star
AndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny star
Re: Warning about this link

True, right I have narrowed it to this c:\Windows\System32\System.exe aka Helz Little Angel according to a spyware scan ( found out gf never kept her spybot upto date didnt see a point in it)

Removed on next reboot am seeing how it works.
AndrewJ is offline   Reply With Quote
Old 09-05-2005, 02:00   #4
Busy Admin
 
Paul M's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 45
Services: VM Phone : Sky+ Multiroom : VM Cable (20 Mbps)
Posts: 14,432
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Paul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny starPaul M has a nice shiny star
Send a message via ICQ to Paul M
Re: Warning about this link

Posting a clickable link was not a very bright move - edited.
__________________
DigiGuide Click here for a real, interactive, tv guide.
Paul M is offline   Reply With Quote
Old 09-05-2005, 02:18   #5
cf.mega poster
 
AndrewJ's Avatar
 
Join Date: Nov 2004
Posts: 7,736
AndrewJ has a nice shiny star
AndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny star
Re: Warning about this link

Finally fixed the little sod and the posting of the link was unintechable although stupid and I do apologise.

Basically it is some clever little virus.

It disabled the following services as well as mess up my msn on my gfs computer.

Windows Firewall/IC Sharing
Sygate
Avast

All the above services was gone and it caused havoc until spybot runs on next boot and removed.

C:\windows\system32\system.exe listed on spybot as Helz little angel.

thats all i know right now I am off to bed.
AndrewJ is offline   Reply With Quote
Old 10-05-2005, 10:56   #6
Inactive
 
Join Date: May 2005
Posts: 5
marco0840 is an unknown quantity at this point
Re: Warning about this link

Quote:
Originally Posted by AndrewJames
I need to put a urgent warning out to everyone.

Earlier tonight my gf was using her laptop on her msn list and this link was sent by her friends with lmao is this you? Like most people in msn you click the link expecting joke this is no joke and no spamming matter.

http://pictures.templates4friends.co...xx@hotmail.com

Was the link and I am serious now do not click it, it opens loads of msn windows spams its self stupid, and then it disabled my sygate personal firewall and my avast! home system, i had to reenable via services in control panel, also my network which runs via ethernet is down so my new pc is offline right now.

I have no idea how to stop this other then formatting both systems I have scanned scanned and even more scanned this HD and found nothing.

All I know is some program runs this called project1 and its making a mockery of this laptop right now.

Edit: Link modified (Paul).
Dear people,
My name is Marco Hesselink, owner of www.templates4friends.com, and I have no idea how a virus can go around with above mentioned link.
I have no physical hosting, and a redirect only to an other website, also templates.
I really do hope anybody can explain to me, if I can do something to resolve this problem, or that somebody else is just missusing my domainname.
Marco Hesselink
Germany
marco0840 is offline   Reply With Quote
Old 10-05-2005, 11:36   #7
Gametag: Random Hom3r
 
Hom3r's Avatar
 
Join Date: Mar 2004
Location: A secret Moonbase (shh don't tell anybody)
Age: 39
Services: VIP Package. VM Phone, 1 V+,1 PACE & 1 Samsug STB, NTL:250 20Mb connection
Posts: 4,651
Hom3r has a bronzed appealHom3r has a bronzed appeal
Hom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appealHom3r has a bronzed appeal
Re: Warning about this link

to the forum

It is possible that someone is using your site to send spam. You need to check the security to see if there are ant holes or open ports.
__________________
A member of the 5 GOLD pip club

A Guide to Computer Ports - PDF
Hom3r is offline   Reply With Quote
Old 10-05-2005, 11:47   #8
cf.mega poster
 
AndrewJ's Avatar
 
Join Date: Nov 2004
Posts: 7,736
AndrewJ has a nice shiny star
AndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny starAndrewJ has a nice shiny star
Re: Warning about this link

After discussion I found out my gf stupidly clicked on a download link, seemingly the url was spoofed rather well from Yahoo photo's, sadly once down and opened this thing ran havoc.

Taught her to update her AV and Firewall much more often.
AndrewJ is offline   Reply With Quote
Old 10-05-2005, 11:59   #9
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: Warning about this link

Quote:
Originally Posted by marco0840
Quote:
Originally Posted by AndrewJames
I need to put a urgent warning out to everyone.

Earlier tonight my gf was using her laptop on her msn list and this link was sent by her friends with lmao is this you? Like most people in msn you click the link expecting joke this is no joke and no spamming matter.

http://pictures.templates4friends.co...xx@hotmail.com

Was the link and I am serious now do not click it, it opens loads of msn windows spams its self stupid, and then it disabled my sygate personal firewall and my avast! home system, i had to reenable via services in control panel, also my network which runs via ethernet is down so my new pc is offline right now.

I have no idea how to stop this other then formatting both systems I have scanned scanned and even more scanned this HD and found nothing.

All I know is some program runs this called project1 and its making a mockery of this laptop right now.

Edit: Link modified (Paul).
Dear people,
My name is Marco Hesselink, owner of www.templates4friends.com, and I have no idea how a virus can go around with above mentioned link.
I have no physical hosting, and a redirect only to an other website, also templates.
I really do hope anybody can explain to me, if I can do something to resolve this problem, or that somebody else is just missusing my domainname.
Marco Hesselink
Germany
I suggest you look at your website, visiting in the (safe) Firefox I get the following screenshot, which is a binary application download.
I might disassemble the code properly if I want but for now I'll just let you know that you have the following errors within it.
Quote:
Warning: fopen(cnt): failed to open stream: Permission denied in /var/www/html/pictures.php on line 15

Warning: fwrite(): supplied argument is not a valid stream resource in /var/www/html/pictures.php on line 16

Warning: fclose(): supplied argument is not a valid stream resource in /var/www/html/pictures.php on line 17
The site is using PHP to write out a binary stream directly to the browser, in IE it will probably run the code automatically although I'm not going to bother trying.
__________________

Update: This is an IRC backdoor trojan.
What will this do?
Basically it recruits your PC as a "bot", and can then be used to conduct DDOS attacks or spread Spam via commands issued to it in the IRC channel it connects to.
I'm going to get the entire domain blocked at my company firewall in a minute.
Richard M is offline   Reply With Quote
Old 10-05-2005, 11:59   #10
Inactive
 
Join Date: May 2005
Posts: 5
marco0840 is an unknown quantity at this point
Re: Warning about this link

Quote:
Originally Posted by Richard M
I suggest you look at your website, visiting in the (safe) Firefox I get the following screenshot, which is a binary application download.
I might disassemble the code properly if I want but for now I'll just let you know that you have the following errors within it.


The site is using PHP to write out a binary stream directly to the browser, in IE it will probably run the code automatically although I'm not going to bother trying.
Thank you for your reaction, although I must admit I do not really understand.
I do know I have a virtuel server, based in USA. In my PLESK I click on Setup and I can see
"Hosting (Domain has frame forwarding to the URL http://www.boxedart.com/cgi-bin/affi...i?id=marco3bib)"
no physical hosting, no Email accounts open, I even have no Webmail available now.

Can you see from which IP Adress this is coming, because my domain has a perment IP adress, and if that is different from the link, someone is cheating on my outside my domain.

Sorry if my englisch is sometimes difficult to understand.
marco0840 is offline   Reply With Quote
Old 10-05-2005, 12:04   #11
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: Warning about this link

Quote:
Originally Posted by marco0840
Quote:
Originally Posted by Richard M
I suggest you look at your website, visiting in the (safe) Firefox I get the following screenshot, which is a binary application download.
I might disassemble the code properly if I want but for now I'll just let you know that you have the following errors within it.


The site is using PHP to write out a binary stream directly to the browser, in IE it will probably run the code automatically although I'm not going to bother trying.
Thank you for your reaction, although I must admit I do not really understand.
I do know I have a virtuel server, based in USA. In my PLESK I click on Setup and I can see
"Hosting (Domain has frame forwarding to the URL http://www.boxedart.com/cgi-bin/affi...i?id=marco3bib)"
no physical hosting, no Email accounts open, I even have no Webmail available now.

Can you see from which IP Adress this is coming, because my domain has a perment IP adress, and if that is different from the link, someone is cheating on my outside my domain.

Sorry if my englisch is sometimes difficult to understand.
There are 2:
> www.templates4friends.com
Server: *.*.*.net
Address: *.*.*.*

Non-authoritative answer:
Name: templates4friends.com
Address: 69.57.138.4
Aliases: www.templates4friends.com

> pictures.templates4friends.com
Server: *.*.*.net
Address: *.*.*.*

Non-authoritative answer:
Name: pictures.templates4friends.com
Address: 64.246.16.76


EDIT: It also resolves to boxedart.com which is:
66.225.226.199
This server is located in Chicago and managed from an address in Florida.
The compromised IP is the one in bold above.
Richard M is offline   Reply With Quote
Old 10-05-2005, 12:07   #12
Inactive
 
Join Date: May 2005
Posts: 5
marco0840 is an unknown quantity at this point
Re: Warning about this link

Quote:
Originally Posted by Richard M
There are 2:
> www.templates4friends.com
Server: *.*.*.net
Address: *.*.*.*

Non-authoritative answer:
Name: templates4friends.com
Address: 69.57.138.4
Aliases: www.templates4friends.com

> pictures.templates4friends.com
Server: *.*.*.net
Address: *.*.*.*

Non-authoritative answer:
Name: pictures.templates4friends.com
Address: 64.246.16.76

EDIT: It also resolves to boxedart.com which is:
66.225.226.199
This server is located in Chicago and managed from an address in Florida.
The compromised IP is the one in bold above.
Thank you, the IP mentioned for the authorized users, is mine, the

66.225.226.199 does not belong to me.

I think my important question: how can I find out who this person is?
marco0840 is offline   Reply With Quote
Old 10-05-2005, 12:11   #13
Cable Forum Team
 
Stephen's Avatar
 
Join Date: Feb 2004
Location: Glasgow
Age: 27
Services: Virgin XL TV, V+ Box, XL BB
Posts: 3,368
Stephen has reached the bronze age
Stephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze ageStephen has reached the bronze age
Send a message via AIM to Stephen Send a message via MSN to Stephen Send a message via Skype™ to Stephen
Re: Warning about this link

I got infected last month through msn by a virus similar to this, it disabled all security services and really messed things up, eventually Norton managed an update and got rid of it, but I had to edit the registry to completly remove all traces and restore the services in windows.
__________________
X360 Gamertag: MartyMcFly88 PSN ID: martymcfly88
Formally known as Darthyoda
NTL:Telewest Business Employee
Stephen is online now   Reply With Quote
Old 10-05-2005, 12:13   #14
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: Warning about this link

http://samspade.org/t/whois?a=66.225...99;server=auto
Richard M is offline   Reply With Quote
Old 10-05-2005, 12:18   #15
Inactive
 
Join Date: May 2005
Posts: 5
marco0840 is an unknown quantity at this point
Re: Warning about this link

Quote:
Originally Posted by Richard M
Dear people,

I deleted the site for now, later maybe I will activate again.
Maybe you can look one more time to see if on my site there is still some activity!

I am really sorry that my domain was indirect the reason of many troubles, but please believe me, I did not have any clue at all.

Marco
marco0840 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 17:22.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)