AIM Profile hacks

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Mitth`raw`nuruodo
Harry Potter on Acid
Posts: 2867
Joined: 2003-03-23 07:38pm

AIM Profile hacks

Post by Mitth`raw`nuruodo »

I've been seeing these a lot recently, they replace users' AIM profiles with things such as "Happy Holidays Everyone!! New Years 2003 Partayy!" or "I CAN'T BELIEVE I FOUND %N'S PICTURE HERE!!!! HAHAHAHA" They have a link they expect you to click, which I'm assuming is a Bad Thing (I never clicked one.).

Is there any way to get rid of these once they have taken over your profile? They seem to come back whenever you try to change your profile.
<< SEGNOR: Grand Admiral of the Gnomish Hordes >< GALE: Equal Opportunity Lover >< SDNet Keeper of the Lore >< Great Dolphin Conspiracy >>
My Audioscrobbler

Cult of Vin Diesel - When you mix Vin Diesel with a strong acid you get salt water.
User avatar
Shrykull
Jedi Master
Posts: 1270
Joined: 2002-07-05 09:11pm

Post by Shrykull »

I had that, all I did was change my profile and it never came back.
User avatar
Exonerate
Sith Marauder
Posts: 4454
Joined: 2002-10-29 07:19pm
Location: DC Metro Area

Post by Exonerate »

If it keeps coming back, I'm guessing it might be a virus that keeps re-writting the profile each time Windows starts up. There has to be some other component if it keeps coming back...

BoTM, MM, HAB, JL
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

I think it's the BuddyLinks Virus. The company who created it is called PSD Tools.

IMNSHO, PSD needs to burn in Hell...
Image Image
User avatar
Mitth`raw`nuruodo
Harry Potter on Acid
Posts: 2867
Joined: 2003-03-23 07:38pm

Post by Mitth`raw`nuruodo »

Nope, not quite.

Exact text of one of the profile viruses:
I can't believe I found <your screename>'s Picture here*
HAHAHA
*URL leads to http:// www. buddypicture.net ... Do not visit! It's probably not good. (duh.)

Italics mine, just to show that it's something I changed. It'll usually show your screename.
<< SEGNOR: Grand Admiral of the Gnomish Hordes >< GALE: Equal Opportunity Lover >< SDNet Keeper of the Lore >< Great Dolphin Conspiracy >>
My Audioscrobbler

Cult of Vin Diesel - When you mix Vin Diesel with a strong acid you get salt water.
User avatar
Mad
Jedi Council Member
Posts: 1923
Joined: 2002-07-04 01:32am
Location: North Carolina, USA
Contact:

Post by Mad »

It's known as the Buddypictures Virus (though technically it's not a virus). It also tends to install realphx onto your system, as well. Those pages have instructions for removing the garbage.

To my knowledge, the adware only installs through Internet Explorer. And, apparently, it does so silently. When people get infected by it, they tend to complain that "the page doesn't work" or it's a blank page. So they refresh it several times trying to get it to work. I admit that I have clicked on the link before, as well... except that I was using Firebird and so was immune to its attack. The page tells visitors that by visiting the page, they agree to allow adware to be installed.
Later...
User avatar
aphexmonster
Jedi Council Member
Posts: 1668
Joined: 2003-04-12 10:42pm
Location: Sacramento
Contact:

Post by aphexmonster »

ahhh... thats why the page was blank


i clicked on it myself, but my computer prompted me that information was being sent to my computer and i closed the application ...


those bastards
-monster
my sig is totaly lonely now =(
Post Reply