[ATTENTION] Recent Email Scam menu

User Tag List

Page 2 of 3 FirstFirst 123 LastLast
Results 16 to 30 of 44
  1. #16
    Nikentic's Avatar Elite User
    Reputation
    453
    Join Date
    Oct 2007
    Posts
    1,556
    Thanks G/R
    10/4
    Trade Feedback
    6 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    List of where you can find & delete it:
    C:\Users\Jonathan\Documents\SYS
    C:\Users\Jonathan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    C:/Users/<your username>/AppData/Local/Temp/cernel.exe

    Check MSConfig for AARC

    Open Regedit, go to
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    Remove AARC

    Last edited by Nikentic; 04-26-2010 at 02:58 PM.

    [ATTENTION] Recent Email Scam
  2. #17
    Zantas's Avatar Contributor
    Reputation
    258
    Join Date
    Dec 2007
    Posts
    1,114
    Thanks G/R
    0/2
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thank you for reporting,
    https://i45.tinypic.com/157df7r.jpg


  3. #18
    Apoc's Avatar Angry Penguin
    Reputation
    1388
    Join Date
    Jan 2008
    Posts
    2,750
    Thanks G/R
    0/13
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    A little more info from a cursory look through the exe:

    It searches the SQLite database that Firefox uses. (Haven't checked if it looks through Chrome/IE yet)

    With that in mind; if you have any stored passwords, I suggest changing them now.

    Edit: It does look through Chrome and IE as well. (Looking for Opera now)

    Edit: Filezilla is also on the list of things it checks.

    It also grabs the windows XP key. Among other things.
    Last edited by Apoc; 04-26-2010 at 03:17 PM.

  4. #19
    Kamon's Avatar Member
    Reputation
    3
    Join Date
    Oct 2006
    Posts
    65
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    So..I got the email right before I left my dorm. I clicked the link and it looked like minecraft (something i am very familiar with) but I didn't have time to dick around with it and denied the java access. Am I infected?

  5. #20
    Nikentic's Avatar Elite User
    Reputation
    453
    Join Date
    Oct 2007
    Posts
    1,556
    Thanks G/R
    10/4
    Trade Feedback
    6 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Kamon, no you are lucky

  6. #21
    Kamon's Avatar Member
    Reputation
    3
    Join Date
    Oct 2006
    Posts
    65
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Ah, good.

    Thinking about it..I might have MSE on my desktop...don't recall..heh. My paranoid side is going to make me scan when I get back to my room. Never hurts anything.

  7. #22
    darkpatato's Avatar Member
    Reputation
    -8
    Join Date
    May 2008
    Posts
    50
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I have deleted the file.
    Also your virus scanner will detect it!
    I wanna haz a cookie!

  8. #23
    darkpatato's Avatar Member
    Reputation
    -8
    Join Date
    May 2008
    Posts
    50
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    SORRY FOR DOUBLE POST BUT!

    Originally Posted by Apoc View Post
    A recent email was sent out from [email protected].

    It is a scam, and was not sent from us. Please disregard the email. If you did open the page, I highly suggest you scan your computer immediately.


    Kaspersky is known to find the virus coming from the page, as well as Microsoft Security Essentials.


    Also, open up your task manager, and search for 'cernel.exe' and kill the process.


    You'll find the downloaded exe in C:/Users/<your username>/AppData/Local/Temp/cernel.exe


    I do apologize for the intrusion attempt. (I take responsibility for this one, I wasn't quite fast enough to load the virus in a sandbox earlier)


    If you have any other questions, please don't hesitate to ask.

    Additional info:

    The IP address who took advantage of our system has been banned. (Unfortunately, a little too slow)
    Other measures have been put in place to avoid this happening again in the future.

    We are NOT affiliated with the website mentioned in the email. If you want to play the REAL game, you may visit www.minecraft.net to play. (Yes, it's legit. And yes, it requires Java.)


    Prevention & Deletion:

    Remove the cernel.exe from your /AppData/*/Temp folders.
    Remove the 'SYS' folder from C:/Users/<Your username>/ folder. (It only contains cernel.exe)

    Start -> Run -> msconfig -> Startup Tab -> Untick 'AARC' and any other startup items that show 'cernel.exe' in the Command location.

    Last notes:

    Just because I found it funny. The 'virus' is a VB.NET application.
    i will post a guide with photo's tomorrow btw

  9. #24
    psychobandit's Avatar Member
    Reputation
    14
    Join Date
    Jun 2007
    Posts
    226
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    This may come across as rude but I swear I don't mean it to be. But I have got to ask!
    Why on earth are so many of you clicking on the link in this e-mail? I mean, with all the virus/adware/spyware out there & the many many identity theft e-mails that get sent out, I thought it was pretty much clear that if you receive an unsolicited e-mail, even from a trusted source, you never ever click the link until you at least verify it is legitimate.

  10. #25
    wac's Avatar Member
    Reputation
    35
    Join Date
    Jul 2008
    Posts
    342
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Dear Psychobandit.

    How can they know it's an 'unsolicited' e-mail? It appears to be from the MMOwned Admin, geez.
    And how can you verify it's legitimate before you open it?

    Please take this with some salt, as I haven't checked my mail and I haven't seen the link.

    But whatever, people who got infected got infected. People who didn't GZ .
    Great handling btw Apoc. <3
    OMNOMNOMNOMNOM!

  11. #26
    Dragonshadow's Avatar ★ Elder ★
    Reputation
    1170
    Join Date
    Apr 2007
    Posts
    3,858
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    You're an idiot for clicking on a .tk link >.>
    Look at your post, now back to mine; Now back to your post, now back to mine. Sadly, it isn't mine, but if you stopped trolling and started posting legitimate content, it could look like mine. Look down, backup, where are you? You're scrolling through threads, reading the post your post could look like. What did you post? Back at mine; It's a reply saying something you want to hear. Look again and the reply is now diamonds.

    Anything is possible when you think before you post. The moon is shrinking.

  12. #27
    7itanium's Avatar Banned
    Reputation
    706
    Join Date
    Jul 2008
    Posts
    1,838
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I didnt get an email

    if I had I most likely woulda known it was fake immediately as I always check the file extension etc. But I can certainly see how it coulda been misleading.. we all consider MMOwned staff to be a trusted source when it comes to downloading things.

    Apoc did an epic job vanquishing this beast. so thanks for that


    To those of you who havent checked, or havent removed this yer I suggest you do so now as it has the potential to wreak havok on pretty much every aspect of your online environment. Also be sure to change EVERY password that you can possibly think of, since it has the qualities of a cookiestealer this is crutial.

  13. #28
    XC4T4LY5TX's Avatar Banned
    Reputation
    136
    Join Date
    Jul 2007
    Posts
    833
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thx for saving the day again Apoc

  14. #29
    [Pat]'s Avatar Contributor
    Reputation
    96
    Join Date
    Jan 2008
    Posts
    447
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    good reason why I block all emails that arent from newegg, blizzard and a few trusted sources that I need.
    Best Metal Fest in the World.
    https://www.rockstarmayhemfest.com/mayhem/index.asp

  15. #30
    Confucius's Avatar Super Moderator Don't Look Back in Anger

    CoreCoins Purchaser Authenticator enabled
    Reputation
    1418
    Join Date
    Oct 2007
    Posts
    2,814
    Thanks G/R
    302/311
    Trade Feedback
    7 (100%)
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)
    Glad I didn't get this would be hard changing all my passwords from stuff about pandas, thanks for the warning apoc!

Page 2 of 3 FirstFirst 123 LastLast
All times are GMT -5. The time now is 10:03 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search