Help - Search - Members - Calendar
Full Version: ATI has a hacker in their midst
Vault9 Forums > Tech Den > Binary Refinery > The Backdoor
LegendofMax
This is a follow up from my "Hidden Virus" Topic.

Okay since last i have run about 4 virus scans and found ziltch. My my dad smsed me earlier today saying he has found a lead on why the pc is behaving like this. He gave me a link and i followed.
WHAT I FOUND WAS SHOCKING!
Read:

QUOTE
Updated: February 13, 2007 11:48:23 AM Type: Spyware Risk Impact: High Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Behavior

Spyware.Mom is a spyware program that monitors user activity and takes screenshots periodically or when certain keywords are detected.

Symptoms

Your Symantec program detects Spyware.Mom.

Transmission

This security risk can be manually installed or installed as a component of another program.

Protection
  • Virus Definitions (LiveUpdate™ Daily) February 16, 2006
  • Virus Definitions (LiveUpdate™ Weekly) February 22, 2006
  • Virus Definitions (Intelligent Updater) February 16, 2006
  • Virus Definitions (LiveUpdate™ Plus) February 16, 2006


This was made by one member of the ATI team who programmed the RADEON series!!
Meaning that a hacker has planted a virun in every ATI RADEON driver, but the virus lays dormant to stay hidden from program checks and virus scanners. But recently patch 7.2+ has been release, yes the patch updates your driver BUT IT ALSO ACTIVATES THE VIRUS!
The virus slows ur pc to a halt, causes crashes and records data. All ATI users must download this scanner from uniblue and resolve it asap. Appartley this hacker is syphoning pin codes credit card info and using it to use illigal transaction. If you have a ati radeon driver and ur pc is suspiously slow reboot immidiatley and use the uniblue scanner. Report have been filed that thousands of dollars are withdrawn from back accounts globally!


V9ers this is shocking news, and the best part ATI DOESNT KNOW WHATS GOING ON! they know there is a problem but they dont know why!
Beware when bye Radeon product in future.

Good luck!

Edit: Nortan seems to have the issue underhand. NOD is still struggling to find the virus and aniblue is a bad virus scanner. My vote update nortan and kick some ass.

~LOM out.
RustPuppet
If you Google this information you'll see that one of CCC's files is supposed to be called mom.exe, the same name of a known trojan.

The one in the 7.2 and 7.3 drivers is perfectly safe.
LegendofMax
we have 7.4 and this causes crashes and slow speed >.< (luckily its on our home pc not my speedbox and im network admin smile.gif )
RustPuppet
Seems lots of people are having issues with 7.4, so it might be a good idea to roll back.
LegendofMax
need 7.4 to play cnc3 =[
RenegadeNukes
So has the issue with your GPU..

Has it been sorted yet?
Fishfly
hmmm ya I seem to see that file in my system...

it seems as it's just a concidence with the naming convention that it's the same as the virus called mom...

that file is an implementation of dot net file and does not have anything to do with the keylogger spyware biggrin.gif
Mr. Magic Matrix
So what exactly does mom.exe actually do to your system?
JuCa
Breastfeeds?
John1111
You guys are fucking idiots.
Fishfly
check the TROLL!
Valheru
QUOTE(John1111 @ Jun 1 2008, 12:54 AM) *
You guys are fucking idiots.

Says the dumbass that replies to a year old topic....
rurounikenshin
hahahahha!!!

what a J( at )ckass!
RustPuppet
QUOTE(John1111 @ Jun 1 2008, 12:54 AM) *
You guys are fucking idiots.

And you're fucking banned. Smartass.
Nitro Guy
awh confused.gif me wanted to see wat his reply would be
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.