PDA

View Full Version : Forum Virus Warning


GSeybold
09-29-2008, 09:52 PM
I don't know if I can post this here but I thought I would alert you. I'm sure this has already been discussed some where but a lot of forums have been hit with this over the past few days.

Spammer with user name "Jessie" or "Patricia" PM members with the following- No post counts over a two week registration account.

Hi,
I'm new here, how's it going?

"Buddhism has the characteristics of what would be expected in a cosmic religion for the future: it transcends a personal God, avoids dogmas and theology; it covers both the natural & spiritual, and it is based on a religious sense aspiring from the experience of all things as a meaningful unity" - Albert Einstein

---
Patricia
http[colon]//patricia2.t35.com

IP id 209-59-46.129

IP Data
OrgName: Global Tac, LLC
OrgID: GTL-30
Address: 7454 Lancaster Pike #500
City: Hockessin
StateProv: DE
PostalCode: 19707
Country: US

NetRange: 209.59.32.0 - 209.59.63.255
CIDR: 209.59.32.0/19
NetName: GLOBETAC1
NetHandle: NET-209-59-32-0-1
Parent: NET-209-0-0-0-0
NetType: Direct Allocation
Comment:
RegDate: 2005-12-16
Updated: 2007-04-02

OrgTechHandle: ADMIN1003-ARIN
OrgTechName: Administrator
OrgTechPhone: +1-302-352-1751
OrgTechEmail: ****@globetac.net

Virus


--------------------------------------------------------------------------------

Malware type: Backdoor

Aliases: Backdoor.Win32.mIRC-based (Kaspersky), IRC/Flood.gen.e (McAfee), Backdoor.IRC.Bot (Symantec), Troj/Mirchack-A (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No
Overall risk rating:
Low

--------------------------------------------------------------------------------

Reported infections:
Low
Damage potential: High
Distribution potential: Low


--------------------------------------------------------------------------------

Description:


This backdoor may be dropped by other malware. It may arrive bundled with malware packages as a malware component. It may be downloaded unknowingly by a user when visiting malicious Web sites.

It creates folders. It drops files/components.

It creates registry key(s)/entry(ies) as part of its installation routine.


Again, I hope this is okay to post here. I'm just so pissed right now. Like I have time for this chit. :mad:


Linda

SVTCobraLTD
09-29-2008, 10:33 PM
I got this person on my site at one time. Banned right away.

GSeybold
09-29-2008, 10:43 PM
How did you know to ban right away? Was there signs I need to watch for? I stopped her/it at about 8 PMs in. Probably more.

SVTCobraLTD
09-29-2008, 10:48 PM
I pay attention to all new registrants. My site is specific to a US State so its kinda obvious when someone is not from the area. I now made a user group named "New Member" because of this, the groups first post is moderated except ones posted in the introduction forum. Plus they are unable to send PM's. Once they make one post, they are moved to the Junior Member group where it is not so restrictive.

GSeybold
09-29-2008, 10:50 PM
Ah Okay. THank you very much for this.