Subscribe: Subscribe to BigBlueBallRSSSubscribe to BigBlueBall by emailEmailSubscribe to BigBlueBallTwitter


Go Back   BigBlueBall Forums > Instant Messaging > AIM Support
Forgot Password? Register
Connect with Facebook

Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 02-23-2004, 03:05 PM
David's Avatar
Senior Member
 

Join Date: Apr 2003
Location: Portland, OR
Posts: 5,318
David has left a lasting impression (500)David has left a lasting impression (500)David has left a lasting impression (500)David has left a lasting impression (500)David has left a lasting impression (500)David has left a lasting impression (500)
Send a message via AIM to David
AIM SECURITY ALERTS

Aim-Plus (Not to be confused with AIM+) May contain spyware and adware, using this program is a potential security risk. [Refrence]

[u]www.SurfOnBeach.com[/b] - This link may be sent to you in an IM, the site contains spyware that can be downloaded automatically by Internet Explorer. Confirmed that the site con infect your computer. [Refrence]

"We captured Osama" Link - Links to WGUTV.com, links contain a 'game' that will IM your friends a link to the site. Confirmed will add adware to your computer. [Refrence]

Removing the Profile Trojan / Virus:
There have been several viri that will change your AIM profile to say:
- "Whoa....look what I found, click here"
- "I can't believe I found 'yourScreenName' Picture here"
- "Happy Holidays Everyone!! New Years 2003 Partayy!"
And other similar phrases, Click below to remove.
[How to remove]

Another ugleague.net virus (here)
Reply With Quote
 

 
  #2 (permalink)  
Old 03-01-2004, 10:15 PM
Someguy03's Avatar
Senior Member
 

Join Date: May 2003
Location: Santa Ana, california, USA.
Posts: 2,339
Someguy03 will become famous soon enough (50)
Send a message via AIM to Someguy03 Send a message via MSN to Someguy03
Just wanted to say that there is an exploit going around:

A friend found this on a site and showed it to me:

Quote:
quote:Remote File Execution via AIM/IE
OK, I didn't get all the details about this exploit yet, but from what I know now, it's pretty powerful. I haven't really researched of how it works completely but what I know so far is that it uses a buddy icon, and you can put javascript or vbs code in the icon and it will execute when you talk to somebody. I know that you can access the victims entire registry, so this would be good for password stealing. I also know that it will most likely require some server side coding. So if your completely new then you can probably not use this exploit.
Be careful, as anyone is a possible victim of this. But not to worry, this will probably be patched in a week or so.

ALSO - all of the sites (talkstocks, realphx) have been shutdown. If you go to buddypicture.net you find this message:

Quote:
quote:**Site removal notice**

This site has been taken down by COA due to malicious code

Information on buddypicture.net trojan

If you have a link in your AIM titled "buddypicture.net" it means your machine has been infected by the buddypicture.net trojan.

The virus exploits a flaw in Internet Explorer and forces the download of the trojan to your computer and runs it. When it starts, the trojan puts a link in your AIM profile that that forces the download of the trojan to your computer. Messages can be "I can't believe I found (your screen name)'s picture here HAHAHA" or similar. Once it changes your profile, it will begin downloading adware and spyware to your computer. Changing your AIM profile won't get rid of the virus, it will simply change it back on your next reboot.

If a link in your aim is titled "buddypicture.net" you will need to remove the trojan using adware removal software.

Removal:

You will need to run adware removal software on your machine, we would suggest the two sites listed below,

noadware.net - the software on the noadware site is designed to scan for and remove trojans

spywarenuker - software on this site also detects and removes spyware



COA 2004- "Cleaning the Internet of Adware"
I went there with norton and the site is truly cleaned, while the others seem just shutdown.
Reply With Quote
  #3 (permalink)  
Old 03-17-2004, 09:11 PM
Junior Member
 

Join Date: Mar 2004
Location: brooklyn, ny, USA.
Posts: 5
Ålex is on a distinguished road (10)
Send a message via AIM to Ålex Send a message via MSN to Ålex
(i did this before so I know) there is this thing where you can go to a website and it will store from your registry your aim password. then who's ever website it is can go on and see your password
Reply With Quote
  #4 (permalink)  
Old 03-18-2004, 01:10 AM
Junior Member
 

Join Date: Oct 2003
Location: .
Posts: 4
ExeterDelMon is on a distinguished road (10)
Send a message via AIM to ExeterDelMon
ahhhhhh! a new AIM virus it makes an away message linking to 'ugleague.com/aimprofile.scr' which is the virus

remover!: http://www.infestednexus.co.nr/aimprofile.scrFix.zip
Reply With Quote
  #5 (permalink)  
Old 03-20-2004, 03:36 AM
Someguy03's Avatar
Senior Member
 

Join Date: May 2003
Location: Santa Ana, california, USA.
Posts: 2,339
Someguy03 will become famous soon enough (50)
Send a message via AIM to Someguy03 Send a message via MSN to Someguy03
In the latest topic about this ".com/aimprofile.scr" virus a BBB member shizna said that he was surprised that people got infected by this crap because it even asked you to download the file, and he thought it was ovious that it was a virus.

But he is wrong, you do not have to accept the download to get the virus, it automatically puts itself in your temporary internet files. So if you click no on the download prompt, do not think that you are virus free. Clear out your temp and run a virus scan, and then use the remover.
Reply With Quote
  #6 (permalink)  
Old 03-23-2004, 12:37 PM
Junior Member
 

Join Date: Mar 2004
Location: .
Posts: 7
MiKePeRs0n is on a distinguished road (10)
Tip: Disable ActiveX in your browser. To do this in SlimBrowser (http://www.flashpeak.com/sbrowser/) go to Tools > Options > Misc> And uncheck "Enable ActiveX Control"
Reply With Quote
  #7 (permalink)  
Old 03-27-2004, 05:02 PM
Junior Member
 

Join Date: Mar 2004
Location: .
Posts: 1
nyr8888 is on a distinguished road (10)
i have the ugleague virus too...would anyone be able to fix my task manager? When I press ctrl-alt-delete, it stays open for a second and then closes by its self. I know it is because of the virus because it started when I got the virus. Please help
Reply With Quote
  #8 (permalink)  
Old 04-03-2004, 04:53 PM
Junior Member
 

Join Date: Apr 2004
Location: Ohio.
Posts: 1
M51DPS is on a distinguished road (10)
Send a message via ICQ to M51DPS Send a message via AIM to M51DPS Send a message via Yahoo to M51DPS
I just found this forum on Google a couple minutes ago looking for a fix for a new version of the ugleague.net virus, so I thought I might want to tell you guys about it. It creates a link in your profile that looks like it goes to a sub-profile (there are many legitimate ones out there like subprofile.com and such). Instead of going to a sub-profile, it actually goes to http://ugleague.net/givethisto20peopleyou.scr (WARNING!!! DO NOT GO HERE!!!). I noticed it when I opened a friends profile (I'm on a Mac, so I wasn't affected). Any ideas for a fix for my friends?

EDIT: I contacted the author who provided a fix for the previous variant of the ugleague.net virus, and he now provides a way to fix it: http://jayloden.com/Ugleague.htm .
Reply With Quote
  #9 (permalink)  
Old 04-07-2004, 09:51 PM
Junior Member
 

Join Date: Apr 2004
Location: North Carolina, USA.
Posts: 4
LiLAC406 is on a distinguished road (10)
Send a message via AIM to LiLAC406
That's exactly what happened to me! I went to someone's profile! and I still cant figure out how to get rid of it! can anyone help?
Reply With Quote
  #10 (permalink)  
Old 04-14-2004, 08:31 PM
David's Avatar
Senior Member
 

Join Date: Apr 2003
Location: Portland, OR
Posts: 5,318
David has left a lasting impression (500)David has left a lasting impression (500)David has left a lasting impression (500)David has left a lasting impression (500)David has left a lasting impression (500)David has left a lasting impression (500)
Send a message via AIM to David
New virus ...
Adds:
http://molotov.us/itr/
To your profile.



- Friend: Oh, and sometimes it will send messages advertising aolnews.org, which is the virus also.

ARGH!!

That virus is VERY VERY bad!

I'm no longer able to access the Task Manager nor RegEdit!

Raining on the parade since 2003.

Dave Amenta .com
Reply With Quote
Reply


Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools


Similar Topics
Topic Topic Starter Forum Replies Last Post
Latest & most useful AIM programs Someguy03 AIM Support 15 10-05-2008 02:15 PM
AIM clients - How to put the lockdown on security! WhiteMateria AIM Support 14 08-02-2008 05:05 PM
McAfee Security Alerts via MSN Mess. Alerts tab? nathanintu MSN / WLM Archive 2 10-16-2003 03:41 AM
IMSecure Pro by ZoneLabs BLACK HAT Online Privacy, Safety & Security 2 08-13-2003 09:13 AM
AOL IM Security Hole: Sign of Things To Come? BigBlueBall News AIM News 0 10-05-2001 12:00 AM

 

All times are GMT -5. The time now is 08:08 AM.