Trojan on Atrivo

I got a comment from Connie Perkins on annelisabeth:

It’s May 21st, and William Lu is “listening” on my computer right now, switching between IP numbers 69.50.161.126 and 69.50.171.146, both coming in on my port #1160. Does anyone know what this maggot wants???!!!! Can someone tell me how to manually close ports, and how to find out what has one opened in the first place? I keep getting spam e-mail everyday now, and I have it automatically set up to go straight to the trash can, but when I go to delete the “deleted” files, they are not there, but others are. Can this Wiliam Lu person be ratted out to anyone that will make him stop getting on my computer, I mean…isn’t there something called the “Privacy Act?” I have nothing this guy wants, unless he gets a thrill watching what I read about breast cancer!!? Ughhh!

I believe it’s a trojan, as described by McAfee.

Geekstogo has a discussion on removing it.

What’s interesting is that both machines and a third are hosted on Atrivo. One is on ESThost. I’ve sent mails to both Abuse at Atrivo and a guy at ESThost. Let’s see if they terminate this one…

If there are any programmers out there who’d consider helping me figure out what’s in a chm file, please let me know. That’s a file dropped by 69.50.188.110, which is part of this scheme.

4 Responses to “Trojan on Atrivo”

  1. Joe says:

    I don’t know what is in this specific chm file, but chm files are Microsoft Compiled HTML Help files. I assume they can use VBScript code to do some nasty stuff with Windows. And being compiled, they might have a hidden payload in there which could be run automatically or by the VBScript.

  2. suzi says:

    I know this is an old post, but it came up on Google. Atrivo/Intercage is known to host a LOT Of domains running exploits. See here:

    http://www.webhelper4u.com/CWS/cwsal_atrivo_ips.html

    And this link says ESThost is a customer of Atrivo/Intercage:

    http://lists.sosdg.org/pipermail/sosdg-nanab/2005-September/009878.html

  3. [...] new fake code site, movscodec(dot)com, hosted (not surprisingly) by the infamous Intercage/Atrivo [...]

  4. iki888.angelfire.com says:

    They are advertising child porn as well !

    IP address 69.50.190.135

    Look up there latest spam blast search term

    iki888.angelfire.com

    Which leads through 3 pages hosted on ip 69.50.190.135 and choc full of malware

Leave a Reply