January 03, 2006

Protect the innocents!

I came home last night at around nine o'clock PM. As soon as I opened the door, my sister came crying to me, saying that she was hacked. Apparently, her friend left his YM account open inside an internet cafe, and someone there took over that account. Not knowing this, she obliged to the request to send her the pin codes to 2 500-peso Globe load through YM to help out the friend who was apparently desperate to contact her grandfather since his grandmother passed away in the United States. The bastard even asked if that's all the money she had. Luckily, she did not send anymore pincodes to that inhuman being because there were doubts lingering in her mind by this time.

Then, that animal even sent her a file, and asked her to open it. And she did, thrice just because it wouldn't open. The evil-doer even asked her if she executed the file, to which she replied that she did, but nothing was happening.

Unbeknownst to her, that file is a trojan horse, a malicious program that is disguised as legitimate software. What's worse, that trojan was a password-stealing program that gets its information from the local file system and sends it via e-mail to the hacker. It sends the local username and password, local IP Address, operating system information, registry startup information and the Yahoo username and password combination.

I experienced slowness when I first tried to check the computer, so I disconnected and removed any connections from the internet to prevent anything to be transmitted anymore. I rebooted twice, once in safe mode, and did various checks all throughout. So far, I haven't seen anything, or even any trace that the trojan was activated. I haven't seen any damages yet. I'm hoping though that my newly-installed firewall managed to block any transmission or execution of that trojan.

My sister is still able to use her Yahoo! username/password combination so that's good news, and a big *BLEAH* to that person with no conscience. She did lose a thousand pesos though.

To end this, I warn everyone not to accept any file that seems weird, or even send code combinations through e-mail or online messenger services even from a person you know or you think you know. Don't accept files especially if they end in *.bat, *.scr, *.pif, *.com, or *.exe.

Watch out for any of these filenames.
  • Anti_booter.exe
  • Arian.exe
  • baby.exe
  • book.bat
  • Boos.exe
  • Britney_Spears.exe
  • com.com
  • love.exe
  • Mypic.bat
  • Mypic.cmd
  • Mypic.com
  • Mypic.exe
  • Mypic.jpg.exe
  • Mypic.jpg.pif
  • Mypic.jpg.scr - This was the filename sent by that devil.
  • Mypic.pif
  • Mypic.scr
  • Norton.exe
  • pif.pif
  • Sender.exe
  • Smasher_7.exe
  • Svchost.exe
  • Telnet.cmd
  • WinXP_Patch.exe
  • Yahoo_Cracker.exe

    Protect yourself and your love ones with multiple firewalls, updated spyware and virus cleaners. Protect the innocents with information.

    Blessed be.
  • No comments: