Home › Forums › Archives › Instant Messaging › AIM Support › TROJAN ALERT: AMX
- This topic has 7 replies, 4 voices, and was last updated 22 years, 7 months ago by
darkc0ne.
-
AuthorPosts
-
February 14, 2004 at 3:37 am #11059
magistyk
MemberTROJAN ALERT:
http://www.aimthings.com recently released its new AIM add-on called AMX. This add-on is a trojan which sends your aim screen names and passwords to a website.
To be exact, if you open the program in a hex editor you will see that it only contains 3 functions, one to get your aim screen names, one to get your passwords, and one to send the data to a server.
DO NOT DOWNLOAD THIS ADD-ON!
February 14, 2004 at 3:48 am #84664Someguy03
MemberFixer hex edited this and found the error message you recieve when running the exe in the program. So, you arent doing something wrong if you get the message, it is there to fool you and will appear no matter what. If you do run it, i advice you get something like Zone Alarm, wich will moniter outgoing traffic from your computer to the net, and you can stop it from forwarding your password to their server.
February 14, 2004 at 3:51 am #84661David
ParticipantThis is the error:
February 14, 2004 at 3:58 am #84659magistyk
Membersomeguy03, there is no point in even running the program as all it does it send your passwords. If you run it and block it from sending anything, it’s pointless to have it installed.
February 14, 2004 at 4:25 am #84663Someguy03
MemberIt sticks itself in your startup list and runs from where you opened it(run msconfig and youll see). And if you click the error message it doesnt actually close the program, it stays running in the background and you must close it in task manager. It immedialtly connects as soon as you run the program. Everytime it connects it tries to with a new port and its ports are usually around 3200. Im simply saying, run a firewall that moniters traffic until you get rid of it.
I know that some users get curious and want to check it out…
February 14, 2004 at 4:46 am #84660David
ParticipantYup, sure did.
After testing this, I discovered it tries to listen for incoming connections on localhost:7373 and changes ports.
It then attempts to connect to 66.98.214.36 on port 80 *HTTP)
I ran a WHOIS?:
OrgName: Everyones Internet, Inc.
OrgID: EVRY
Address: 2600 Southwest Freeway
Address: Suite 500
City: Houston
StateProv: TX
PostalCode: 77098
Country: USNetRange: 66.98.128.0 – 66.98.255.255
CIDR: 66.98.128.0/17
NetName: EVRY-BLK-14
NetHandle: NET-66-98-128-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.EV1.NET
NameServer: NS2.EV1.NET
Comment:
RegDate: 2003-07-02
Updated: 2004-02-06TechHandle: RW172-ARIN
TechName: Williams, Randy
TechPhone: +1-713-400-5400
TechEmail: admin@ev1.netOrgAbuseHandle: ABUSE477-ARIN
OrgAbuseName: ABUSE
OrgAbusePhone: +1-713-400-5400
OrgAbuseEmail: abuse@ev1.netOrgNOCHandle: NOC1445-ARIN
OrgNOCName: NOC
OrgNOCPhone: +1-713-400-5400
OrgNOCEmail: noc@ev1.netOrgTechHandle: RW172-ARIN
OrgTechName: Williams, Randy
OrgTechPhone: +1-713-400-5400
OrgTechEmail: admin@ev1.netFebruary 14, 2004 at 4:58 am #84662Someguy03
MemberApparently the programmers account was hacked. The file URL was removed.
February 14, 2004 at 5:10 am #84665darkc0ne
MemberJesus… Is it me or are there now loads more virii and exploits being used on AIM..The summer of ’02 i only remember there being the profile bug… What happened?Is AOL started to slip up on the coding or something and are getting lazy?
-
AuthorPosts
- You must be logged in to reply to this topic.