Trojan on Atrivo
I got a comment from Connie Perkins on annelisabeth:
It’s May 21st, and William Lu is “listening” on my computer right now, switching between IP numbers 69.50.161.126 and 69.50.171.146, both coming in on my port #1160. Does anyone know what this maggot wants???!!!! Can someone tell me how to manually close ports, and how to find out what has one opened in the first place? I keep getting spam e-mail everyday now, and I have it automatically set up to go straight to the trash can, but when I go to delete the “deleted” files, they are not there, but others are. Can this Wiliam Lu person be ratted out to anyone that will make him stop getting on my computer, I mean…isn’t there something called the “Privacy Act?” I have nothing this guy wants, unless he gets a thrill watching what I read about breast cancer!!? Ughhh!
I believe it’s a trojan, as described by McAfee.
Geekstogo has a discussion on removing it.
What’s interesting is that both machines and a third are hosted on Atrivo. One is on ESThost. I’ve sent mails to both Abuse at Atrivo and a guy at ESThost. Let’s see if they terminate this one…
If there are any programmers out there who’d consider helping me figure out what’s in a chm file, please let me know. That’s a file dropped by 69.50.188.110, which is part of this scheme.
I don’t know what is in this specific chm file, but chm files are Microsoft Compiled HTML Help files. I assume they can use VBScript code to do some nasty stuff with Windows. And being compiled, they might have a hidden payload in there which could be run automatically or by the VBScript.
I know this is an old post, but it came up on Google. Atrivo/Intercage is known to host a LOT Of domains running exploits. See here:
http://www.webhelper4u.com/CWS/cwsal_atrivo_ips.html
And this link says ESThost is a customer of Atrivo/Intercage:
http://lists.sosdg.org/pipermail/sosdg-nanab/2005-September/009878.html
[...] new fake code site, movscodec(dot)com, hosted (not surprisingly) by the infamous Intercage/Atrivo [...]
They are advertising child porn as well !
IP address 69.50.190.135
Look up there latest spam blast search term
iki888.angelfire.com
Which leads through 3 pages hosted on ip 69.50.190.135 and choc full of malware