CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Is this malware or just spam?????

 
Post new topic   Reply to topic       All -> FavForums -> MIRT Discussion [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Sioli

Trooper
Trooper


Joined: Apr 04, 2006
Posts: 25


PostPosted: Tue May 06, 2008 7:58 am    Post subject: Is this malware or just spam?????
Reply with quote

I am on site and using a client pc so do not want to risk infecting the pc, this email was received today and I think that a heads up is in order. I have extended the links so that they are not triggered by accident.

***********************************************

Dear John

File Error Notification - Instructions To fix File Errors in your Registry:

Your PC may be suffering from serious file errors in your WINDOWS registry which may be the reason why your PC is running so slow, or crashing and freezing from time to time. Also, these can lead to major system problems and possible memory leaks.

Below are instructions that will enable you to Increase Your Computer's Speed, Power, Stability and Reliability in just a few minutes.

Press below to launch the Diagnostics Test download for no cost at all:
http: // partcxxiii.info / scanlink

Once again, there are NO OBLIGATIONS for this FREE OFFER that includes our FREE Software, FREE Analysis, FREE Report and 24 Hour Support !

If after completing the free Diagnostic Test it is brought to your attention that your computer's registry does contain file "errors", then it may be in your computer's best interest to fix the potentially harmful file errors in your registry.

Press below to launch the Diagnostics Test download now:
http: // partcxxiii.info / scanlink




Copyright © 2002 - 2008 All Rights Reserved



-----

To not receive future offers/promotions from "Error Nuker" please press on the below link:
http: // partcxxiii.info / RM

Or send us a letter at:
100 E. San Marcos Blvd.
San Marcos, CA 92069

Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6299
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Tue May 06, 2008 7:26 pm    Post subject:
Reply with quote

Its a rogue and part of a small rogue IP gange :

72.32.242.169-72.32.242.171

These are the rogues in this range :

Adwarebot.com
Free-registrysmart.com
Macrovirus.com
Ad-warealert.com -> adwarealert.com
Errorkiller.com
Malwarebot.com
Registrybot.com

Back to top
View users profile Send private message Send email
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5774

MIRT Premium

PostPosted: Tue May 06, 2008 7:52 pm    Post subject:
Reply with quote

When I visited that link I was redirected to

Code:
http://www.errorkiller.com/index.php?hop=arbydar


I downloaded setup.exe (not-a-virus:FraudTool.Win32.AntiSpywareBot.br Kaspersky) which contained ErrorKiller.exe

Code:
http://www.errorkiller.com/setup.exe


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> MIRT Discussion All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer