

![]() |
| ![]() | |||||||
|
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #641 (permalink) |
| Never Sleep™ Name: Stian Last Online: Today 02:02 PM iTrader: (131) Join Date: Jan 2007
Posts: 5,809
DNF$: 3,807 Location: EHOT.net
Country: | I can guarantee you that both Ad-Aware and SpyBot is updated daily with information on all thinkable versions of different keyloggers and how to detect them. If your (updated) AdAware/SpyBot application can't detect the keylogger, neither can Symantec products or any other antivirus application. Removing virii/spyware/malware/trojans is part of what I do for a living. |
| | |
| Sponsored Ads |
| | #643 (permalink) |
| Never Sleep™ Name: Stian Last Online: Today 02:02 PM iTrader: (131) Join Date: Jan 2007
Posts: 5,809
DNF$: 3,807 Location: EHOT.net
Country: | First run AdAware in safe mode without networking (Full System Scan, not "Smart Scan"), remove any malware if detected. Restart in safe mode, run SpyBot and let it scan through. Remove any malware detected, if any. This should keep this shit off your computers. Of course there is no guarantee, but if you at the same time have a good firewall and live antivirus-service running, then you should be pretty safe. |
| | |
| | #644 (permalink) |
| DNF Addict Last Online: 11-05-2009 11:40 AM iTrader: (34) Join Date: Jun 2004
Posts: 1,636
DNF$: 5,995 Location: Jaipur
Country: | @kamloops - I removed your live link. However, what language is the above content in?
__________________ - Domain Flipping Tutorial | How to Choose a Web Host |
| | |
| | #645 (permalink) |
| DNF Addict Name: John J. Last Online: Today 05:59 AM iTrader: (74) Join Date: Feb 2003
Posts: 3,314
DNF$: 4,372 Location: Neither here nor there
Country: | Luckily I have been out of the game while a lot of this was going on and it appears that it has been going on since '06. I'm sure that all of you have realized that this guy isn't 16 years old. If he was that would have made him 14 when he started. Anyway just a tad bit of input. I think there is a issue with this using someone else's whois info. In the past couple of months I've received transfer requests myself on names I've never owned. And I might add they were pretty decent names. I've likely dumped the emails by now but going to look back through them and do little digging if I can. Also as far as package drop-off. It is very common in these types of scams to have packages dropped off at locations that aren't associated with the scammer. It's assumed this is an apartment complex. Well if you think about it many apartment complexes have empty apartments. The delivery guy isn't likely to know this so he/she just drops the package off. Scammer knows the delivery time so he/she just sits and waits. This sort of thing also happens at empty houses. And like others have stated we need to consider what we are doing when making transactions. There have been several people that have stated they "thought" it seemed fishy but went ahead any way. Maybe it's just because I'm not big on fish but when something smells fishy to me I don't eat it. There should be no reason why someone can't divulge their information. And last but not least and I hate to be the one to say this. But how long has the appraisal scams been going on? As long as I can remember. The "feds" have done nothing as far as I can tell about that. Or maybe appraisal scams and domain scam is one in the same? Either way this person is very domain savvy and it wouldn't surprise me in the least if it turns out to be someone among us and like someone else said maybe even here at this very moment under another name. From my experience with a crooked individual in the past. He portrayed himself as an upstanding citizen but he did what he had to do to support his lavish and drug addicted lifestyle and that generally involved screwing people over. Funny thing about this fact is he was involved with one of these names.
__________________ "No tyranny is so irksome as petty tyranny: the officious demands of policemen, government clerks, and electromechanical gadgets." - Edward Abbey |
| | |
| | #646 (permalink) |
| Platinum Lifetime Member Last Online: 11-06-2009 12:30 PM iTrader: (6) Join Date: Mar 2006
Posts: 495
DNF$: 1,261 Location: Kamloops | I dont know what laugauge it is, wish I did, one of the files is in english. And there is some very private info in there logged, Id and passwords for web based email accounts on Yahoo and Aol I tried one and it worked. Plus there was enough info to steal domains. Its easy to see how these guys are stealing them now! Not sure what I should do with this info, wish I could figure out how I got into the root to get those files as there was so much more there as well. Maybe enought to nail these guys! I think it is turkish, using the whois info for the site I found this about the guy xremotex@hotmail.com Age: 22 Gender: Male Location: istanbul, Turkey Last edited by Kamloops; 03-11-2008 at 02:31 PM.. Reason: Automerged Doublepost |
| | |
| | #647 (permalink) |
|
Country: | From what I have been told there are sites that have a main goal of hacking and selling yahoo/hotmail etc accounts. Almost a game to them but when they couple it with domaining we see the results. Can they target a email, they must and so where there is a will there is a way. Someone told me they find old files on an old email and use that info ? I am not the best tech guy so it is all mumbojumbo to me. |
| | |
| | #648 (permalink) | |
| Platinum Lifetime Member Last Online: Today 12:20 PM iTrader: (34) Join Date: Nov 2007
Posts: 3,273
DNF$: 0 Location: Toronto, Canada
Country: | Quote:
The most common way i know of JP is usually by phishing. They send you an email and try to get you to login with your username and password. If you do so it is forwarded to their address. If you fall for it, there goes your email account. | |
| | |
| | #649 (permalink) | |
| Never Sleep™ Name: Stian Last Online: Today 02:02 PM iTrader: (131) Join Date: Jan 2007
Posts: 5,809
DNF$: 3,807 Location: EHOT.net
Country: | Quote:
| |
| | |
| | #650 (permalink) |
| Platinum Lifetime Member Name: Jason Last Online: Yesterday 08:37 PM iTrader: (12) Join Date: Jan 2007
Posts: 529
DNF$: 257 Location: Canada
Country: | I was unaware of that pcproffenno thanks for the info Anyone who visited the link I'm in the middle of decrypting the javascript, visited with a secure browser no js no flash no actionscript, search for a file named jpeg.exe,not sure if there are valid exe's with this name thats just what he's named one file, that is one mentioned early. I'll update you as I get more decrypted. Cheers, Jay
__________________ Gorillas.ca - Lions.ca - Swans.ca PM me for .CA Drop Catching Services (Include Price & Names) |
| | |
| | #651 (permalink) | ||
| Platinum Lifetime Member Last Online: 11-06-2009 12:30 PM iTrader: (6) Join Date: Mar 2006
Posts: 495
DNF$: 1,261 Location: Kamloops | Quote:
I am not the type to just sit back and do nothing. Quote:
Last edited by Kamloops; 03-11-2008 at 02:48 PM.. Reason: Automerged Doublepost | ||
| | |
| | #652 (permalink) |
| Platinum Lifetime Member Name: Jason Last Online: Yesterday 08:37 PM iTrader: (12) Join Date: Jan 2007
Posts: 529
DNF$: 257 Location: Canada
Country: | Looks like it uses activex to download jpeg.exe to your computer. It uses GetSpecialFolder(2) which points to a temporary internet folder. Then uses ShellExecute execute the file! If you viewed the page with javascript, most likely need activex on as well, search for jpeg.exe located in a temp internet folder. I don't know what happends after it is executed as I'm not downloading the file. Hope that helps Jay
__________________ Gorillas.ca - Lions.ca - Swans.ca PM me for .CA Drop Catching Services (Include Price & Names) |
| | |
| | #653 (permalink) | |
| CrossLogix.com Last Online: Today 11:11 AM iTrader: (65) Join Date: Mar 2006
Posts: 2,238
DNF$: 2,167 Location: Matthews, NC. U | Damn, that's exact same pm I got. Guess I wasn't the only one. Quote:
__________________ ![]() Domain Names For Sale | |
| | |
| | #655 (permalink) | |
| Platinum Lifetime Member Name: Bob Last Online: 08-11-2009 09:28 PM iTrader: (0) Join Date: Sep 2007
Posts: 74
DNF$: 0 Location: New Ganada, CA
Country: | Quote:
All the information on this thread has been indexed by Google and will more than likely reside there for generations to come. It's amazing what the Internet can do. It's even more amazing what a mis-guided 16-year old could do with a little help from his friends.
__________________ Calif.Bob @ Gmail.com www.LockOurRate.com .net .org also available. PM Serious Offers Only | |
| | |
| | #656 (permalink) |
| Platinum Lifetime Member Last Online: 11-06-2009 12:30 PM iTrader: (6) Join Date: Mar 2006
Posts: 495
DNF$: 1,261 Location: Kamloops | I dont think I got infected. I did install this which the reviews seem good http://www.snoopfree.com/PrivacyShield.htm Will detect any keyloggers |
| | |
| | #657 (permalink) | |
| CrossLogix.com Last Online: Today 11:11 AM iTrader: (65) Join Date: Mar 2006
Posts: 2,238
DNF$: 2,167 Location: Matthews, NC. U | Quote:
sent from Atech I did go to the site. I got off the site as soon as I see "loading" or whatever it said. I am going to have to scan my notebook.
__________________ ![]() Domain Names For Sale | |
| | |
| | #659 (permalink) | |
| Platinum Lifetime Member Name: Gareth Last Online: 09-12-2009 09:37 AM iTrader: (54) Join Date: Oct 2007
Posts: 494
DNF$: 710 Location: United Kingdom
Country: | Quote:
You can always uninstall your anti-virus software and reinstall it to avoid these issues. Just depends how intelligent the virus is that you have. Always disconnect from source like someone else said and then start installing and running checks. I personally like Zone Alarm (seems to use less system resources than Norton), Firewall, Antivirus, Spyware protection, email protection, instant messenger protection. You get what you pay for really. | |
| | |
| | #660 (permalink) | |
| Platinum Lifetime Member Name: Bob Last Online: 08-11-2009 09:28 PM iTrader: (0) Join Date: Sep 2007
Posts: 74
DNF$: 0 Location: New Ganada, CA
Country: | Quote:
I ran the email address, xremotex@hotmail.com, through RapLeaf.com and found a photo of the user who's online identity is OGUZHAN at Hi5. He is a 22 year old male, which we knew, with a birthday of March 16th. Up until this huge thread, I have never heard of Hi5.com however several of the known alleged conspirators have accounts there. I will look into this further to see if they are at all linked together. CB
__________________ Calif.Bob @ Gmail.com www.LockOurRate.com .net .org also available. PM Serious Offers Only | |
| | |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |