***all AD members WARNING on for AOL/AIM hacker from AD

Shibby

Member
Joined
Sep 5, 2003
Messages
49
Reaction score
0
If you get this message in your profile, "I have found minervaqua732's picture" with a link to it in the profile too, DO NOT CLICK ON IT!!!!!

This is a notification on to every AD member, This sn minervaqua is my gf's sn for AIM and she had 100 percent nothing to do with this, she has no computer skills to hack anything. Please do not blame her on about this.

I will notify AOL on about this problem and see what can be done.

it seem to have hit every AD members that are linked to her i think. so far all the complains have been from AD members.

We apoligize that we did not respond to everybodys IM on their complains about that profile issue.


Again, we deeply apolgize on about this problem. When we find out who has done this, I will notify AOL, the Police, and the AD adminstrator.
**** forget about the Police part, i was too mad and i typed it in anyways.. I know the police cant really do anything. Well i was mad... forget about that thanks..****


Mods if possible keep this sticky for a while so more people will see it and prevent them from clicking on the link.

so far from what i have been told, that some people clicked on the link and it sent several pop up ads up and error messages asking them to down load stuff from microsoft.com. its all false.


Please let us know who all has been hit and got those messages in their profiles. thanks.
 
Last edited:
Thanks to my Trillian, I can simply roll over the link and see the URL. I can recognize a good and a bad URL. Also, I rarely click on links that are shown instantly until after I've been in a good converstation with that person. Also, if a person wants to show you a picture... simply send you the picture, not link you to it.
 
i sure hope somebody get that bastard's ass busted! :pissoff:
 
VamPyroX said:
Thanks to my Trillian, I can simply roll over the link and see the URL. I can recognize a good and a bad URL. Also, I rarely click on links that are shown instantly until after I've been in a good converstation with that person. Also, if a person wants to show you a picture... simply send you the picture, not link you to it.

You can do that too on AIM, just put mouse over (no clicking) the link and wait a couple of seconds and the link will show up over it.

And, yeah, it is best not to click anything unless the person you KNOW is sending to you is on the subject and telling you what it is.

If it is something sent out of the blue and no conversation was made, I wouldn't click anything.
 
I hope they find who ever did this and attempted to harm AD in any aspect for some funny reason i have a funny feeling abt this.... I ll PM u with a question in a little while...
 
I think this person choose a random or possibly all of our sn out from the aim icon shown under your sigs. Im not so sure yet tho.. Still waiting on a respond from AOL, on there it said up to 36 hrs before i get a reply..

Now my gf just did her 4th or so profile clearing.. and it still comes back!!! WTF!!! anybody still getting it in their profiles?
 
Yeah, I got hit too.. I hope they find who is the hacker and why it did happen and etc asap.

:madfawk: at hackers!!!!!!
 
I am sorry to hear that your gf's sn got hacked in. I hope whoever did this will get busted soon. Have you thought of changing password for AIM, etc?

:madfawk: at hackers.
 
It's not worth changing your password since it just keep coming back - Shibby, my sweetie, has been helping me out BIG time with this situation (YUP - He's the hero!) So I decided it was time to delete my screenname & changed my AIM screenname for good.

I've been blamed for all this mess but am glad it's cleared up now - I do have a suspect but I rather not point it out until proof comes up.

So those who don't see my screenname online anymore, it's cuz I changed the screenname for good and this time I'm going to be more strict with who I give it out to.

Keep us updated as well.
 
Last edited:
Sure hope that person is caught and punished for the damages he/she has caused. Chin up and think positive, Shibby and AquaMaiden! We all are here to give you the support you need. :thumb:
 
VamPyroX said:
Thanks to my Trillian, I can simply roll over the link and see the URL. I can recognize a good and a bad URL. Also, I rarely click on links that are shown instantly until after I've been in a good converstation with that person. Also, if a person wants to show you a picture... simply send you the picture, not link you to it.

Thanks to my iChat. blah blah blah *brag* Like you said! :D
 
Here's the respond that I got from AOL Webmaster - read along and use that for your own protection:)

------------------------------------------------------------

Hi! I am Joan B. from the TechMail Department. I would like to thank you for
spending time in writing to us. It is my privilege to be of assistance to you
and all our members.

I understand that your AIM Account has hacked.

I apologize for the inconvenience that you have been experiencing. I appreciate
your patience with this matter and I am here to help you.

It is possible that you unknowingly downloaded a trojan virus through AIM.

Viruses and trojans can be downloaded to your computer by visting some websites,
clicking on links, or installing software. You should always install all OS
patches and security updates and you should always run good virus software with
up to date virus definitions. á
If hyperlinks such as http://10.2.30.40:8180 or another number automatically
appear in IMs that you send, it probably means that your system is infected with
the "W32/Aplore@MM" virus/worm. Both McAfee and Symantec have web pages set up
with descriptions and removal instructions. As always, please only click on
hyperlinks that you know are safe, even when receiving them from people you
trust. á
If your member profile or away message has links in it that you can't delete or
that get replaced automatically, such as www.realphx.com or www.talkstocks.net,
you can try to follow the steps below. If you are a novice computer user, please
get someone more experienced to help you.
Exit AIM so other users don't get infected from you while you are cleaning your
system.
Go to http://windowsupdate.microsoft.com and install all of the critical
updates. This will prevent the current trojans from reinfecting you once you
have cleaned up the files currently installed.
In IE, go to Tools/Options and reset your Home Page (or just click on Use Blank)
if this setting has been hijacked.
Go to the Add/Remove control panel and uninstall the following: òá "Bargain
Buddy"
òá "Lycos Sidesearch" (Unless you intentionally installed this program.)
òá "Web Helper"
òá "Win Favorites"
òá Anything with "n-CASE" in the name.
òá Anything else that looks suspicious.

Install the latest version of Ad-Aware from
http://www.lavasoftusa.com/support/download/.
Launch Ad-Aware and click the Check For Updates button on it. After installing
any new updates, proceed to the next step.
Configure Ad-Aware to do a custom scan with all options selected, and then
proceed with the scan.
When the Ad-Aware scan is complete, click on Finish. Then right-click on the
list of located objects, choose "Select All Objects", and click on Next. Then
click OK on the confirmation dialog to remove all the objects. Ad-Aware will
probably state that it needs to reboot to finish; in that case reboot now
instead of waiting until later.

Delete all unneeded items from the "temp" directory. If you are not sure where
your system's temp directory is, launch "%temp%" from the Run item on the Start
Menu. Many of the trojan files will still be in the temp directory and they may
be launched in the future if they are not removed now.
Launch "msconfig" from the Run item on the Start Menu, and in the Startup tab of
the System Configuration Utility window that appears, uncheck all of the
following: òá Anything that resembles any of the following items
á "Lycos Sidesearch" (Unless you intentionally installed this program.)
"Bargain Buddy"
"Web Helper"
"Win Favorites"
"Power Scan"
"Sqwire"
"syslaunch.exe"
"uc"
"n-CASE"
òá Any item with a very strange name, such as seemingly random characters.

Click OK to save the changes, and reboot when prompted.
Delete the following items (or anything with very similar names): òá From c:\
:
"url.txt" (file)
òá From c:\Program Files\ :
"Bargain Buddy" (folder)
"Power Scan" (folder)
"Sqwire" (folder)
"syslaunch.exe" (file)
òá From c:\Program Files\Common Files\ :
"SQ" (folder)
òá From c:\Windows\ :
"msgcenter_lminv1.exe" (file)
"bi.exe" (file)
"cdt_bbi8016.exe" (file)
"randomiser.exe" (file)
"winfavorites.exe" (file)

Delete any remaining porn links. These will be in the IE Favorites and/or in
various locations on the Start Menu. Ad-Aware may have cleaned out the actual
links so that only the empty folders remain to be deleted.
In IE, go to Tools/Options and do the following: a. Reset your Home Page if it
has been hijacked again.
b. Click on Delete Files in the Temporary Internet Files section, and make sure
to check the option to also delete Offline Content.
c. Click on Clear History in the History section.
d. Click on OK.

Check the profiles one last time for each of your AIM Screen Names, to make sure
that they are not once again pointing to the malicious web site, and delete any
that are.
That should take care of it, as long as you take the following steps going
forward: òá Frequently install all critical Windows Updates in the future.
òá Use a firewall, which can alert you when malicious programs are trying to
use your Internet connection.
òá Keep your antivirus software up to date and scan all of your hard drives
regularly.
òá Frequently run a program such as Ad-Aware or Spybot that can detect and
remove adware and spyware.
òá Be extremely cautious before clicking on any hyperlink that you are not
certain is safe. (When in doubt, check first with the person who sent you the
link.)

Should you wish to speak with someone in person to walk you through, you may
contact our America Online Technical representative at 1-800-827-6364
(1-800-759-3323 for TTY) or contact through AOL KEYWORD: LIVE HELP by signing on
using the AOL software.
á
Please feel free to write back at your convenience for further needs. It's
through communication with members, such as yourself, that help make this
service truly amazing.
á

Joan B.
Customer Care Consultant
The Technical Department
America Online, Inc.
 
something was VERY wrong with my AIM and I'll tell you how it happened.

see, I was reading directions above, and so when it says the name "Bargain Buddy", and I thought that would be the main problem of this virus thingy, so I went to "start", and clicked on "search" and letting the search find that name in the files and folders..and when I found it, I deleted it and uninstall it but something totally worse happened. My AIM is completely gone and I tried to do a new s/n and download AIM all over again, it just won't work because the computer said it needs the Bargain Buddy to do that...and I was like, "wtf??" so even my brother told me that I have to remove ALL the infomation related to AIM and as I did, trying to uninstall the entire AIM, but pieces of information are missing! information that tells the computer to uninstall AIM are missing and it won't uninstall for me...wtf?? so now I have to wait for someone more experienced to help me with this and get my AIM back!
 
Have you tried using Trillian instead of AIM? It has AIM in it and it might work. So far my AIM has been fine, although I've been told it's problematic, but that's because I only have one person on my AIM list heh.
 
Steel said:
something was VERY wrong with my AIM and I'll tell you how it happened.

see, I was reading directions above, and so when it says the name "Bargain Buddy", and I thought that would be the main problem of this virus thingy, so I went to "start", and clicked on "search" and letting the search find that name in the files and folders..and when I found it, I deleted it and uninstall it but something totally worse happened. My AIM is completely gone and I tried to do a new s/n and download AIM all over again, it just won't work because the computer said it needs the Bargain Buddy to do that...and I was like, "wtf??" so even my brother told me that I have to remove ALL the infomation related to AIM and as I did, trying to uninstall the entire AIM, but pieces of information are missing! information that tells the computer to uninstall AIM are missing and it won't uninstall for me...wtf?? so now I have to wait for someone more experienced to help me with this and get my AIM back!


Suggest you try and contact that AOL person and see what you can do about it. Good luck! My laptop is being cleared up and formatted as well and putting XP instead of ME program - damn those hackers who fed my laptop virus!
 
Steel, i would tell you to download again and delete that zipped AIM file you have, and install it and uninstall it and install it remove it over and over 3 or 4 times until it works again. but i would say there might be a bad file in the system files, where AIM can have some files in it. Check your Application data in your "My Documents" and in your name folder, where it has Application data in it, delete those AIM files in there too.

For every program, it puts a registry file in the system registry. Im not sure how to remove those registry files manually..



***EDIT*** whoa, hehe this is Shibby BTW, she was using my computer since i was working on her laptop ;)
 
Steel said:
something was VERY wrong with my AIM and I'll tell you how it happened.

see, I was reading directions above, and so when it says the name "Bargain Buddy", and I thought that would be the main problem of this virus thingy, so I went to "start", and clicked on "search" and letting the search find that name in the files and folders..and when I found it, I deleted it and uninstall it but something totally worse happened. My AIM is completely gone and I tried to do a new s/n and download AIM all over again, it just won't work because the computer said it needs the Bargain Buddy to do that...and I was like, "wtf??" so even my brother told me that I have to remove ALL the infomation related to AIM and as I did, trying to uninstall the entire AIM, but pieces of information are missing! information that tells the computer to uninstall AIM are missing and it won't uninstall for me...wtf?? so now I have to wait for someone more experienced to help me with this and get my AIM back!
:Owned:
 
Steel said:
not anymore. cuz I have it back. :)


Good for you, Steel. :)

I've never had my AIM hijacked or hacked into with a virus -- just have to have a good anti-virus program that'll give you maximum protection. I use AVG Pro 7.0 and it works wonders and is heaps better than Norton's and McAfee. AVG doesn't crash my pc at all whilst the other 2 does.
Plus, be very cautious of who you allow onto your AIM buddylist and talking with, etc. I have heard about it, but it hasn't happened on mine (*knocking on wood!* :lol:)
 
yep. that why I decided to remove AIM off my profiles so no one will know what it is unless they ask
 
Back
Top