Go Back
This forum is a message forum about how to get rich in High Yield Investment Programs, HYIPs, Games and Forex Investments. Please, no advertising except in the advertising folder.

This HYIP forum board has no paid advertisements at all!!! Enjoy your talks without a single banner!

This is the only one HYIP forum that pays for your posts! Depends on your posts' interest we will pay you from 5 to 20 cents per each your post! More information about this action: http://goldentalk.com/t30854.html



Forum Support Team

User Name
Password
Register •  FAQ •  Members List •  Calendar •  Search •  Today's Posts •  Mark Forums Read • 

Go Back   GoldenTalk - The best forum about HYIP (High Yield Investment Programs) > Miscellaneous > Internet Security

Reply
 
Thread Tools Search this Thread
Old 17-04-2006, 01:09 PM   #1
simon
Junior Investor
 
Join Date: Jul 2005
Location: Inner Mongolia,China
Posts: 64
Send a message via MSN to simon Send a message via Yahoo to simon
Default Watch new e-gold trojan!

Search your computer for gdiwxp.dll. Looks most Anti-Spyware program cannot catch it as it is not updated in their database. If you found the file, then your computer is infected with an e-gold torjan. Do not login to e-gold till you get rid of this torjan.

If you are using Internet Explorer, that will be a good idea to choose FireFox.

Here is what mctrask of MommyJobs posted:
Quote:
I’ve been doing some research on the egold trojan and how accounts are getting hacked. The scary part is that from what I read, most anti-virus/spyware programs are not going to catch it because it is not in their databases yet.

Not only that, this trojan does not activate until after you have logged into your egold and it uses your own computer to bypass every security measure, IP confirmation, password SRK, everything.

The trojan uses an exploit in IE to infect your computer. DO NOT USE INTERNET EXPLORER. I can’t stress that enough. Download and use Firefox. Here is a description that I found on how this trojan works:

This Trojan does not employ usual phishing techniques, like logging user keystrokes in text files that can be sent to a remote malicious user. Instead, whenever a user tries to access the
e-gold account login form via the URL http://e-gold.com/acct/login.html, it opens a hidden duplicate Internet Explorer (IE) window accessing that same URL. It then proceeds to fill up the duplicate Web form, which eventually leads to illegal account access.

The Trojan periodically drains the funds of the compromised account by a certain percentage. The stolen funds are then transferred to another e-gold account.

To be able to successfully perform this function, this Trojan uses IE’s built-in Object Linking and Embedding (OLE) automation functions. This method is similar to API hooks used by file-infectors. In this case, this Trojan executes certain functions for every change in the URL address that occurs while the user continues to navigate through the following e-gold Web pages:

* e-gold.com/acct/acct.asp
* e-gold.com/acct/balance.asp
* e-gold.com/acct/spend.asp
* e-gold.com/acct/verify.asp
* https://www.e-gold.com/acct/acct.asp
* https://www.e-gold.com/acct/balance.asp
* https://www.e-gold.com/acct/spend.asp

(Note: Object Linking and Embedding (OLE) is a compound document standard that enables a user to create objects with one application and then link or embed them in another application.)

The Trojan runs on Windows 95, 98, ME, NT, 2000, and XP.

You all need to check your computers for the file named gdiwxp.dll. This is the most recent variant of the trojan that I could find and was still popping up in late March. If you have this file on your computer, you are infected with the egold trojan and and you need to get rid of it immediately.

I don’t know if the file will show up with a simple file search, it may be a hidden. I used Hijack This to look at my registry for the file.

You can download Hijack This for free at:
http://www.download.com/HijackThis/...4-10227353.html

This program is mainly used by people so that they can post a registry log in the tech forums and ask for help. Don’t remove anything in your registry unless you know what you are doing. Just look for the file containing gdiwxp.dll.

If you find the trojan on your computer, you can use Security Task Manager to get rid of it.
http://www.neuber.com/taskmanager/

I also noticed that RegRun has this file in their trojan database and can remove it for you.
http://www.greatis.com/appdata/d/g/gdiwxp.dll.htm

Again, DO NOT USE INTERNET EXPLORER!!!!!!

Mozilla Firefox browser download
http://www.mozilla.com/

Edited to add: I posted this information on another forum and within five minutes someone who had their egold hacked on March 31st found the gdiwxp.dll file on their computer so this must still be the one making the rounds. They also posted that after they were hacked, they started using Firefox with no problems.

One of the symptoms that you are infected with this trojan is that you get the wrong turing number page every time you try to log in. On the page you are redirected to, the links at the top of the page will not work.
__________________
Big Deal
simon is offline   Reply With Quote
Old 17-04-2006, 08:28 PM   #2
jambutty
Geriatric Moderator
 
jambutty's Avatar
 
Join Date: Aug 2004
Location: Darwen, Lancashire, England
Posts: 10,722
Cool

This gdiwxp.dll has been doing the rounds for quite some time now simon but thanks for the warning and the detailed summary.

Those members who have read http://goldentalk.com/t17591.html have been aware of it and have taken whatever steps have been necessary to protect their E-Gold.

But I still have gdiwxp.dll in WINDOWS>SYSTEM32 with a difference. My version is a simple text file with a couple of meaningless words in it and the file attributes have been set to “Read Only”. The theory is that if something tries to infect me again by writing gdiwxp.dll in WINDOWS>SYSTEM32 it can’t because there is a file with that name already in place and it cannot be overwritten.

Since my ‘dummy’ file has been in place I haven't been infected again and I have surfed all the sites that I used to when I got infected the first time.

Maybe I have been lucky or my ruse works. I guess I will never know.

There are some other suspect files that may be variations of the original:
gdiw2k.sys
gdi32.dll
gdi.exe
gdiplus.dll
I’m trying to pluck up courage to do the same with those but as they can be deleted in the normal way maybe they are not nasties.
__________________
Click H E R E for my regular money earners. CAUTION – Using these links to join any of the sites IS NO GUARANTEE that you will make money.
Forum Rules - FAQ's
jambutty is offline   Reply With Quote
Old 18-04-2006, 01:25 PM   #3
jennyd
Senior Investor
 
jennyd's Avatar
 
Join Date: May 2005
Posts: 494
Default

Hi thanks for the post on this. After reading your post jambutty i did a search on my system for "gdiwxp.dll" and came up nada! good right but i did a search with the other suspect files you posted:

gdiw2k.sys
gdi32.dll
gdi.exe
gdiplus.dll

And i came up with alot of these files..... well they are all gone from my system now but was prompted by windows that i needed these files... now im wondering why is that? oh well now im thinking of reformating and loading everything again since i have all my files backed up. Well let me know your opinion.. thanks
__________________
FEEDERFUND / www.OROBIZ.NET
jennyd is offline   Reply With Quote
Old 18-04-2006, 02:03 PM   #4
jambutty
Geriatric Moderator
 
jambutty's Avatar
 
Join Date: Aug 2004
Location: Darwen, Lancashire, England
Posts: 10,722
Cool

Open up WordPad and type a word or two into it and save it as gdiwxp.dll to C:\WINDOWS\SYSTEM32.

Open My Computer and then C:\WINDOWS\SYSTEM32 and find gdiwxp.dll. Click on it once with the RIGHT mouse button and select Properties from the drop down menu that appears. In the window that comes up, near the bottom you will see the Attributes section. Click on Read-only and then Apply and OK. If anything tries to write a file named gdiwxp.dll to your computer it will not be able to and thus you will not get infected by it

Windows will report that a type of file is needed by windows because of its suffix not its content. If you have deleted those other files and your computer still works OK then they weren’t needed, were they? So it would now pay you to do with those like with gdiwxp.dll

Have just deleted gdiw2k.sys and gdiplus.dll and replaced them with Read-only files of the same name. On my computer right now with several programmes running gdi32.dll and gdi.exe are needed by one of them but I don’t know which.

I shall see what develops.
__________________
Click H E R E for my regular money earners. CAUTION – Using these links to join any of the sites IS NO GUARANTEE that you will make money.
Forum Rules - FAQ's
jambutty is offline   Reply With Quote
Old 18-04-2006, 02:35 PM   #5
jambutty
Geriatric Moderator
 
jambutty's Avatar
 
Join Date: Aug 2004
Location: Darwen, Lancashire, England
Posts: 10,722
Smile

With gdiw2k.sys - gdiwxp.dll and gdiplus.dll replaced with Read-only files I closed down my computer toddled off to make myself a brew and came back and booted up again. Everything seems to work OK. Obviously because I can post this.
__________________
Click H E R E for my regular money earners. CAUTION – Using these links to join any of the sites IS NO GUARANTEE that you will make money.
Forum Rules - FAQ's
jambutty is offline   Reply With Quote
Old 21-04-2006, 09:31 PM   #6
misiasiek
Junior Investor
 
misiasiek's Avatar
 
Join Date: Dec 2005
Location: Szczecin, POLAND
Posts: 77
Cool Mozilla Firefox

hahaha, i've always said that IE is scam. I have very old computer so i cant run winxp. win98 with mozilla and i don't need any antivirus program .

PS: IE program to reviewing the Internet from your computer and VICE VERSA :]
__________________
EXTEL => i will return you 50% of my referral commission, just PM me after spend :]
misiasiek is offline   Reply With Quote
Old 13-11-2006, 02:37 AM   #7
Mr_Chiang
Junior Investor
 
Mr_Chiang's Avatar
 
Join Date: Sep 2006
Location: Indonesia
Posts: 40
Send a message via Yahoo to Mr_Chiang
Default

thanks simon, I am scanning my computer for this file
Mr_Chiang is offline   Reply With Quote
Old 23-12-2007, 01:35 AM   #8
zoyla
Junior Investor
 
zoyla's Avatar
 
Join Date: Oct 2007
Posts: 46
Default

Do we have something new on this. This is quite old thread but I need to know about E-Gold Trojans more. DO we have some specific Trojan recently?
zoyla is offline   Reply With Quote
Old 08-01-2009, 04:47 AM   #9
satria
Mőöđě®ãŧőr
 
satria's Avatar
 
Join Date: Nov 2008
Location: Indonesia
Posts: 1,578
Default

Yes, indeed there is a trojan that can infect our computer and try to spend our egold fund in the background without our notice. The trojan is known as Win32.Grams
More info can be found here
http://www.secureworks.com/research/threats/grams/
satria is offline   Reply With Quote
Old 08-01-2009, 06:31 AM   #10
betsybee
Moderator
 
betsybee's Avatar
 
Join Date: May 2005
Location: Canada
Posts: 1,213
Default

Quote:
Originally Posted by satria
Yes, indeed there is a trojan that can infect our computer and try to spend our egold fund in the background without our notice. The trojan is known as Win32.Grams
More info can be found here
http://www.secureworks.com/research/threats/grams/

That story was posted in 2004, seems like a long time ago Probably not many e-gold hijackers these days because it isn't very popular any more.
betsybee is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


New Document
All times are GMT. The time now is 12:11 AM.


Powered by: vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.