Safrguns
Member
+105|6132
I just subverted an attempt by an xfire user to pass me a virus through xfire.

He goes by nickname computer wiz.. or something to that effect.
I did not recognize him as a friend, but assumed I had forgot.

He passed me a file called hitregfix.exe, claiming it would resolve the hitreg problems in BF2.

I was skeptical... i asked how it worked...

I went ahead and accepted it from him, but did not execute.

He said a friend had made it, and that it wasn't a hack, and that it really worked.

I scanned it with my sweeper....  (sirens go off)

I replied  "your friend just gave you a virus".

He immediately logs off xfire without responding,
and my firewall alerted me to an attempt to breach my security. (probably through xfire)

His initial message to me that had brought up the chat box looked suspicious in itself...
It looked like some sort of cd key or something.... I asked him about it,
and he claimed it to be a registration key to Sony Vegas...
I asked what version.... his response indicated it was NOT what he had said it was.
This and the claims he made about the hitreg fix without knowing how it worked is what
made me suspicous.

If you see this guy, see what you can find out about him...
I could not find him in my xfire friends list after our short chat...

AND DONT BELIEVE CLAIMS ABOUT BF2 Hitreg fixes!
d4rkph03n1x
Member
+131|6750

Safrguns
Member
+105|6132

d4rkph03n1x wrote:

http://forums.bf2s.com/viewtopic.php?id=104544

Yeah.
I dont know that he passed me that program...
like i said.. i didn't execute it.

you can call an executable anything you want... doesn't mean you will know what its doing.

My scanner said it was a big fat virus.
JoshP
Banned
+176|5690|Notts, UK
lrn2crc/md5 check?
steelie34
pub hero!
+603|6382|the land of bourbon
in general you shouldn't accept any .exe from anyone you don't know... or run it on a honeypot machine with process explorer running so you can see what it does... then save it for later and send it to people you dont like.
https://bf3s.com/sigs/36e1d9e36ae924048a933db90fb05bb247fe315e.png
Hakei
Banned
+295|5996

JoshP wrote:

lrn2crc/md5 check?
md5 check against what?
I'm Jamesey
Do a Research Noob
+506|6133|Scotland!

JoshP wrote:

lrn2crc/md5 check?
geek

don't accept .exe files from anyone over xfire, friend or not
JoshP
Banned
+176|5690|Notts, UK

Hakei wrote:

JoshP wrote:

lrn2crc/md5 check?
md5 check against what?
the legit version...?

I'm Jamsy wrote:

geek
Hacker

Last edited by JoshP (2009-02-21 07:44:39)

Board footer

Privacy Policy - © 2024 Jeff Minard