Results 1 to 3 of 3

Thread: Ironic.

  1. #1


    I've been getting AIM spam lately. Mostly from generated names like aim236236437 and similar.

    I decided to play Mr. Detective with the latest. It linked to here:

    From there I got 2 domains:

    Some things I noticed:

    1. User account "cheez" spammed me to hopefully earn .003 cents from
    2. sounds a lot like windows update.

    3. windupdates has removal instructions on it's main page, obviously because people didn't want it there in the first place. I'm wondering what exploit it uses to get on your box in the first place, or if you unwillingly click OK to an activex download.

    What is Wind Updates?

    Wind Updates is free ad delivery software which provides targeted advertising offers.

    How did Wind Updates get installed on your computer?

    You downloaded Wind Updates from a Website that is able to offer its content for free because it shows the Wind Updates ActiveX popup. The Wind Update program is installed only once the user has agreed to it by clicking “ yes” on the ActiveX. Though the ActiveX, the user can review the license terms and privacy policy before installing the software. Each and every distributor is carefully reviewed to make sure that their distribution techniques abide by a strict code of conduct.

    If you do not remember having seen an ActiveX prompt, you might have downloaded Wind Updates from a popular free software product (screensavers, games, file sharing software, etc.). Users always have to opt-in before installing the Wind Updates software.

    Removal instructions:
    Wind Updates supports many free software products through its advertising relevancy technology. If you remove Wind Updates from your system, certain free software that you installed may no longer function properly and you may have to reinstall them from a backup.

    If you are sure that you want to remove Wind Updates from your computer just follow these two easy steps:

    * Click Start -> Control Panel -> Add/Remove Programs
    * Scroll to Wind Updates and click Remove
    4. info@(no spam) is the listed contact address on exitforcash. Funny, they can dish spam out but can't take it.

    Contact information:
    status: production
    organization: CDT Inc.
    owner: Domain Manager
    address: P.O. Box 181
    address: TMR P.O.
    city: Mont-Royal
    state: Quebec
    postal-code: H3P3B9
    country: CA
    Administrative Contact:
    Waveflow Inc., Waveflow Inc.
    PO Box 87
    Baysville, ON P0B 1A0
    --------------------------------- has no website.

    It seems these spammers are from Canada? I'm guessing they tried to get money for referrals from windupdates and exitforcash from the same linked page.

  2. #2
    Senior Member
    Join Date
    Jun 2004
    Thx man i have been haveing this same problem. But i just stopped using aim for a while. But now that i know what is going on hopefully i can set her

    oh yah by the way nice Mr. Detective Wish i could of figured it out actually.

  3. #3
    ********** |ceWriterguy
    Join Date
    Aug 2004
    We should give these idjits a dose of their own medicine, and spam them with technical stuff so far beyond their comprehension as to cause their brains to implode. where's maddox when ya need him?
    Even a broken watch is correct twice a day.

    Which coder said that nobody could outcode Microsoft in their own OS? Write a bit and make a fortune!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts