New AIM Spammer, watch out!

RichC

Member
Mar 29, 2001
131
0
0
Do not open any links from any of your AIM buddies that links you to the site www.wgutv.com. It's a new type of spam program disguised as a game. What it will do is it will send itself to everybody on your AIM buddy
list. This info is all preliminary, but me and a few friends think this is how it works. It's from a site called www.buddylinks.net. There's a game in there and if you run the game, it will send a link to everybody on your buddy list without your knowledge. If your friends click that link, it'll send them to the same game, which will start another wave of spam IM's. Let me know if any of you have any additional information. Please spread this news around (although the act of spreading this news will also create spam, but at least we have some control over it).
 

RhythmAddict

Member
Sep 15, 2003
114
0
0
I got an IM from this earlier today...
The exact URL it pointed me to was "http://www.wgutv.com/osama_capture.php?MVqz" It asks you to DL the applet or whatever and it is a thawte signed cert....I actually got about 20% done, and thought it was fishy so I cancelled. THerefore I can't conclusively state whether or not this does install whatever buddlinks.net software, although it certainly does sound like it. I have gotten numerous IM's today telling me to follow that link...Any futher info people?
 

Woodie

Platinum Member
Mar 27, 2001
2,747
0
0
Yes...we're seeing lots of activity here. Shutting down AIM for the moment.

Any info on affected versions? (I'm using Trillian, and haven't seen it)
 

RhythmAddict

Member
Sep 15, 2003
114
0
0
Yep...Went over to the server room and blocked 63.251.131.235 - which is the address that buddlinks.net and wgutv.com both resolve to...

<snip>
Organization:
buddylinks
Drew Williams
1770 Mass Ave #213
Cambridge, MA 02140
US
Phone: 617 661 4664
Email: support@buddylinks.net

Registrar Name....: Register.com
Registrar Whois...: whois.register.com
Registrar Homepage: http://www.register.com

Domain Name: BUDDYLINKS.NET

Created on..............: Fri, Jan 09, 2004
Expires on..............: Sun, Jan 09, 2005
Record last updated on..: Tue, Feb 10, 2004

Administrative Contact:
buddylinks
Drew Williams
1770 Mass Ave # 213
cambridge, MA 02140
US
Phone: 617 661 4664
Email: support@buddylinks.net

Technical Contact:
Buddylinks
Drew Williams
1770 Mass Ave # 213
Cambridge, MA 02140
US
Phone: 617 661 4664
Email: support@buddylinks.net

Zone Contact:
Buddylinks
Drew Williams
1770 Mass Ave
Cambridge, MA 02140
US
Phone: 617 661 4664
Email: support@buddylinks.net

Domain servers in listed order:

NS1.BSN.PNAP.NET 63.251.129.1
NS2.BSN.PNAP.NET 63.251.129.33
</snip>

AND...

<snip>
Organization:
wgutv
Drew Williams
1770 Mass. Ave #213
Cambridge, MA 02140
US
Phone: 6176614664
Email: support@wgutv.com

Registrar Name....: Register.com
Registrar Whois...: whois.register.com
Registrar Homepage: http://www.register.com

Domain Name: WGUTV.COM

Created on..............: Tue, Dec 09, 2003
Expires on..............: Thu, Dec 09, 2004
Record last updated on..: Tue, Feb 10, 2004

Administrative Contact:
wgutv
Drew Williams
1770 Mass. Ave # 213
Cambridge, MA 02140
US
Phone: 6176614664
Email: support@wgutv.com

Technical Contact:
wgutv
Drew Williams
1770 Mass. Ave #213
Cambridge, MA 02140
US
Phone: 6176614664
Email: support@wgutv.com

Zone Contact:
wgutv
Drew Williams
1770 Mass. Ave # 213
Cambridge, MA 02140
US
Phone: 6176614664
Email: support@wgutv.com

Domain servers in listed order:

DNS11.REGISTER.COM 216.21.234.76
DNS12.REGISTER.COM 216.21.226.76
</snip>
 

Matthias99

Diamond Member
Oct 7, 2003
8,808
0
0
<mafia>Does youse wants I should drive over to Drew's place and have a few, uh, words wit' him? That oughta solve our problem real quick-like.</mafia>

Seriously, though, I'd email AOL and tell them about this. They probably have enough muscle to make his ISP pull the plug.
 

RhythmAddict

Member
Sep 15, 2003
114
0
0
Originally posted by: Matthias99
<mafia>Does youse wants I should drive over to Drew's place and have a few, uh, words wit' him? That oughta solve our problem real quick-like.</mafia>

Seriously, though, I'd email AOL and tell them about this. They probably have enough muscle to make his ISP pull the plug.

I second that...

For now, I think the best move is to just block that IP. Then the users will click on the link nothing will happen, so they'll complain about that instead
I'm pretty sure this will only successfully work through AIM - but i'm not sure?
Does anyone know if the buddylinks.net software (whatever that may be/is known as) is on the adaware/spybot S&D remove list?? I guess I have to assume that's the only resolution, unless of course you can just go to add/remove programs and erase it - something gives me the feeling that won't happen though.
 

Buzzman151

Golden Member
Apr 17, 2001
1,455
0
0
Originally posted by: RhythmAddict
Originally posted by: Matthias99
<mafia>Does youse wants I should drive over to Drew's place and have a few, uh, words wit' him? That oughta solve our problem real quick-like.</mafia>

Seriously, though, I'd email AOL and tell them about this. They probably have enough muscle to make his ISP pull the plug.

I second that...

For now, I think the best move is to just block that IP. Then the users will click on the link nothing will happen, so they'll complain about that instead
I'm pretty sure this will only successfully work through AIM - but i'm not sure?
Does anyone know if the buddylinks.net software (whatever that may be/is known as) is on the adaware/spybot S&D remove list?? I guess I have to assume that's the only resolution, unless of course you can just go to add/remove programs and erase it - something gives me the feeling that won't happen though.


not as of this morning. it will probably take adaware a couple days and it seems spybot only gets updated every couple months


on a side note... i had a friend convinced last night it was a virus.... omg watching him soil his pants over aim has to be one of the funniest things i've seen in some time

 

martind1

Senior member
Jul 3, 2003
777
0
0
I live and work around boston, looks like i am going to have to take an extended lunch ...
 

Poohbee

Senior member
Oct 10, 1999
787
0
71
I spent close to a couple hours trying to help a friend get rid of this thing..

Apparently it goes into the registry and changes some stuff in there and then puts a program called ShellInstaller.ocx

To see if you have been infected open up a DOS Command prompt (START > RUN > type CMD) And enter the following command "dir /s %SYSTEMDRIVE%\shellinstaller.ocx" (without the quotes). If it finds anything you are infected. :frown:

BTW, that worm also downloads other nasties and changes your Internet Explorer config to Install things without your permission when you go to a website.

To remove that Worm/Virus Follow the link:

AIM Worm/VIRUS Removal Instructions

EDIT: Hmm it seems like this one gets rid of another type of worm similar to the one described by the OP.

Try this forum where they talk about the worm: (Scroll down to JizJizJiz's posting)

Alternate AIM Worm/Virus Removal Link

Hope one or both of these work out for you all.

Enjoy
 

perry

Diamond Member
Apr 7, 2000
4,018
1
0
Originally posted by: martind1
I live and work around boston, looks like i am going to have to take an extended lunch ...

I know someone that checked in to that... Address goes to Mailboxes Etc, phone number is for a bagel shop near by.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |