Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

ATTN; ICQ Users

2 views
Skip to first unread message

Cruiser

unread,
Jan 21, 2001, 10:13:40 AM1/21/01
to
I just came across this.
Maybe old news, but new to me.
=============================

Mirabilis' ICQ Client Searches
For Pirate Software!

MAKE SURE YOU PASS THIS URL ON TO ALL YOUR ICQ BUDDIES! :)

If you have installed software that's been illegally obtained, you will be
caught!

It's recently come to the attention of ICQ users that Mirabilis are
obtaining application specific data from users system registries.

The registry value
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\DefaultPrefs\Auto Update has been
built in to Mirabilis' ICQ client since its first release.

The original intention of this registry key was to enable automatic ICQ
version updates without the user needing to download the latest version of
the client. Although this was the original intention by Mirabilis, since the
takeover by AOL this feature has been put to bad use.

It has allowed the Mirabilis server to modify your ICQ client and send it
commands when connecting to their servers. It's been seen to instruct PC's
to send various components of the system registry to the ICQ servers
periodically. This allows Mirabilis to see what software you have installed
on your computer, serial numbers used, your name, your company and in some
instances even your home address!

The information is being obtained. This could be sold to large software
vendors such as Microsoft who trying to combat software globally. If they
have no intention of selling this information taken from your computer
without your knowing, why are they doing it?

Should You Be Worried?

Unless you have pirate software on your computer, you have no cause for
alarm.

If you have pirate software installed on your computer be sure that Windows
is registered to a fake name. If this is not the case, follow the
instructions below to disable this automatic updating feature installed by
Mirabilis.

How Can I Prevent Mirabilis From Doing This?

The following instructions are intended only for those confident in
modifying the Windows registry using Registry Editor! (regedit.exe)

Step One
In registry editor find the key:
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\DefaultPrefs\

Step Two
Change the value of Auto Update to "No"

Should Mirabilis decide to put this feature to use by updating your client
automatically
you will still need to download it manually.

Macintosh and Java versions of the ICQ client are not affected!!!

More information pertaining to this problem can be found at :
http://www.wired.com/news/news/technology/story/4987ay.html


BillyBoy

unread,
Jan 21, 2001, 10:32:30 AM1/21/01
to
Cruiser wrote:

MAYBE THAT IS WHAT NY FIREWALL IS CONSTANTLY CATCHING ..
I GOT ZONEALARM GET 15 TO 20 HITS A DAY..


Maagic

unread,
Jan 21, 2001, 11:48:49 AM1/21/01
to
1. This is a bogus rumo(u)r
2. Programs like these DO EXIST. They're called Spyware. You can learn
more about them at http://grc.com

--
-Maagic
aka Bryan Foster
Webmaster of the Rick and Bubba Experience
http://www.rickandbubba.net

Dudley S. LAPD

unread,
Jan 21, 2001, 11:55:29 AM1/21/01
to
"Maagic" <ma...@cybrtyme.com> wrote in message
news:3A6B12F1...@cybrtyme.com...

> 1. This is a bogus rumo(u)r
> 2. Programs like these DO EXIST. They're called Spyware. You can learn
> more about them at http://grc.com
>

What are rumo(u)rs if not bogus?

:)

Dudley S. LAPD
de...@petrel-cassoulet.demon.co.up
For e, remove -cassoulet and change up to uk


The Avon Lady

unread,
Jan 21, 2001, 12:07:32 PM1/21/01
to
In article <t6lvak7...@corp.supernews.com>,

"Cruiser" <cou...@aol.not> wrote:
> More information pertaining to this problem can be found at :
> http://www.wired.com/news/news/technology/story/4987ay.html

Not found. I searched the entire site and it's not there.

Lipstick anyone?


Sent via Deja.com
http://www.deja.com/

The Avon Lady

unread,
Jan 21, 2001, 12:17:47 PM1/21/01
to
In article <3A6B12F1...@cybrtyme.com>,

Maagic <ma...@cybrtyme.com> wrote:
> 1. This is a bogus rumo(u)r
> 2. Programs like these DO EXIST. They're called Spyware. You can learn
> more about them at http://grc.com

Thanks! After all the serachning I did at WIRED.COM. Now ya tell me? ;)

HOWEVER.....

There are ICQ hacks out there. When you're using ICQ, they can identify
your IP address, spoof your ID in chatrooms and more. I managed to
find the hack program on some Russian site (I think it was Russian).

This is for real. It happened to me. I was embarrased straight out of a
chatroom.

I emailed Mirabelus and they answered that they view the matter with
the greatest concern and will get back to me A S A P.

That was over 2 months ago. Haven't heard from them since. Did NL buy
them up?

Chris G.

unread,
Jan 21, 2001, 8:45:34 AM1/21/01
to
Sheet....now you tell me after I forwarded that post to like 9 other
people....damn. :( By the way is their a site somewhere showing this to
truly be just a rumor?
Chris G.
aka-Miles Teg


"Maagic" <ma...@cybrtyme.com> wrote in message
news:3A6B12F1...@cybrtyme.com...

Maagic

unread,
Jan 21, 2001, 5:03:56 PM1/21/01
to
www.icq.com has a page of rumors.. dunno the exact URL..it's somewhere
down the bottom of the main page. Basically they say that Mirabilis
(ICQ) will never send out mass mailings saying forward it to everyone on
your list. All those are fake. In the past they've claimed that ICQ was
going to start charging people to use ICQ, that ICQ messages contained
viruses, etc. All bogus.

Maagic

unread,
Jan 21, 2001, 5:04:50 PM1/21/01
to
True, but if a person is THAT DETERMINED, he can find out your IP using
a number of programs, not just ICQ.

--

Max Andersen

unread,
Jan 21, 2001, 7:15:32 PM1/21/01
to
Nevertheless, ICQ had a problem once. I had a little house appearing when
people added me to their contact list. That was a german guy, who had made
it. I got a link from someone describing my house......it was a trojan built
in my ICQ-version and enabled users to download from my harddrive. It wasn't
the biggest risk, because they couldn't delete anything. They also had to
know the full path of my file to get it. But my friend send me my
autoexec.bat in an e-mail and i uninstalled icq........later I installed it
again.

Blood'N'Honour

"Maagic" <ma...@cybrtyme.com> wrote in message

news:3A6B5D02...@cybrtyme.com...

John

unread,
Jan 21, 2001, 8:07:50 PM1/21/01
to
All those who advised that this is bogus are right. I've got ZoneAlarm and
have had NO probes for over a week, n' none that could get raced to
Mirablis.
Kiwi;?

Cruiser advised:

G

unread,
Jan 21, 2001, 8:25:49 PM1/21/01
to
Why didn't you contact or go to www.urbanlegends.com ?
They seem to get it all there...
Damn the other day, I got a email from an old buddy. Saying don't download
this email "Budwiser Frogs." I knew it was bogus right off hand. Because it
says don't download it you'll get infected. That is so untrue, u got to run
some attached file first to get infected. I went the to web site above to
get proof of this Hoax. I did get it and then remembered I got this along
time ago. I HATE EMAIL CHAIN LETTERS!.. I was getting them at least 4 times
a week. until I fought back about the problem. I told all my contacts. That
if they send me another email chain letter and it is a Hoax. I will send
everyone I know a letter with there name on it. Saying they won the Email
Chain Letter Award of the week. Congratulations on it and tell everyone to
congrate them. Being foolish not checking up on it. Because it takes you
maybe at the most 5 minutes out of your time to find out. Boy those letters
have stopped. until now, last one I received was months ago...

--

G-=WKA=- USA

Rizla Ranger (Revivin') UK

unread,
Jan 21, 2001, 9:57:43 PM1/21/01
to
LMAO!


I hate 'em too!


except the one's like Clair Swires LOL

say Feliz Cumpleanos to R from me :)

Max Res!

Riz :)


"G" <m...@home.com> wrote

Chris G.

unread,
Jan 21, 2001, 4:00:11 PM1/21/01
to
Yeah I've seen that ICQ trojan. I had a copy of ICQ that had it and Norton
Anti-Virus caught it.
Chris G.
aka-Miles Teg


"Max Andersen" <m...@militant.dk> wrote in message
news:94ftp5$25r$1...@news.inet.tele.dk...

Chris G.

unread,
Jan 21, 2001, 4:01:11 PM1/21/01
to

Well yeah it's assumed that Zone Alarm wouldn't have a problem with ICQ
regardless because you're allowing it access the internet right? Or no?
Chris G.
aka-Miles Teg

"John" <je...@paradise.net.nz> wrote in message
news:98012535...@shelley.paradise.net.nz...

Maagic

unread,
Jan 21, 2001, 10:56:37 PM1/21/01
to
yeah..the big one goin round now is the Snow White & The Seven Dwarves :
The Real Story one... has a virus attached but if you don't download the
file and then run it, you're safe... actually you shouldn't download and
run ANY attachments even if they're from people you know because some
viruses are tricky and they send a message to everyone in your address
book and it looks like YOU sent it.

--

Kevin D. Foster

unread,
Jan 22, 2001, 4:09:45 AM1/22/01
to
Max Andersen wrote:
>
> Nevertheless, ICQ had a problem once. I had a little house appearing when
> people added me to their contact list. That was a german guy, who had made
> it. I got a link from someone describing my house......it was a trojan built
> in my ICQ-version and enabled users to download from my harddrive. It wasn't
> the biggest risk, because they couldn't delete anything. They also had to
> know the full path of my file to get it. But my friend send me my
> autoexec.bat in an e-mail and i uninstalled icq........later I installed it
> again.

The little house is an indicator for the ICQ homepage, and it should
be disabled, due to known security problems.

--

-=[ Keeper ]=- ICQ# 8105495
kee...@lycosmail.com kdfo...@home.com
http://members.home.com/keepershaven/

Chris G.

unread,
Jan 22, 2001, 1:40:38 AM1/22/01
to
Yeah no kidding. I still keep getting that damn snow white email alot from
the dreaded HAHAHA. Actually it's not one person like I thought it was.
I've been tracking down the IP's and they're always from all over the world
with no sign of the email being bounced. I think it just spreads itself
automatically. However I have notified the originating IP to let their user
know that they have the virus on their computer system.
Chris G.
aka-Miles Teg

"Maagic" <ma...@cybrtyme.com> wrote in message

news:3A6BAF75...@cybrtyme.com...

George Marsden

unread,
Jan 22, 2001, 6:13:47 PM1/22/01
to


One thing to keep in mind is that some viruses are hidden in
attachements that do not appear to be executable files because of the
default settings in Windows 98/ME. The default settings in Windows are
"Do not show hidden or system files" and to "Hide file extentions for
known file types". This means that if you have not changed the default
settings and you recieve an e-mail with an attachment "nicegirl.jpg"
the actual file may be "nicegirl.jpg.exe", "nicegirl.jpg.vbs", or
"nicegirl.jpg.bat". This is one way that viruses can be slipped past
the average user who knows "I should not open any EXE files that come
as attachments".

To avoid this problem you can change the default settings by doing the
following:
Start - Settings - Folder Options - View
Change the setting under "Hidden Files" to "Show all files"
Uncheck the box next to "Hide file extensions for known file types"
Then click "Apply" and then "OK"

The only bad thing about doing this is that you will now need to
include file extentions when you name a file. For example if you are
renaming a Word document you must include the ".doc" extention at the
end. Small price to pay in my book.

-Billy Bob
Your ever present DF1 and DF2 target.

Rizla Ranger (Revivin') UK

unread,
Jan 22, 2001, 6:18:54 PM1/22/01
to
Many many thanks for that
informative instruction sir!


Respec'!


"George Marsden" <g...@removethistheriver.com> wrote

Wr@ngler

unread,
Jan 22, 2001, 6:58:04 PM1/22/01
to
And yet:

Some file extensions will *still* be invisible in spite of all that,
requiring you to manually erase the registry entries "NeverShowExt" under
'HKEY_CLASSES_ROOT\DocShortcut' and 'HKEY_CLASSES_ROOT\ ShellScrap'. IIRC,
that should make all extensions visible except the 'shortcut' files, a fact
that could be changed by doing the same under 'HKEY_CLASSES_ROOT\lnkfile',
but I don't think that's necessary, really...

***Warning***
If you don't know how to edit the registry, don't. Back it up first, etc.
and continue 'à tes propres risques et perils', as they say. Screwing up
your registry can seriously screw up your system, so be careful, yadda,
yadda, yadda...

--
~*Wr@ngler*~

Kevin D. Foster

unread,
Jan 22, 2001, 8:18:01 PM1/22/01
to
"Wr@ngler" wrote:
>
> And yet:
>
> Some file extensions will *still* be invisible in spite of all that,
> requiring you to manually erase the registry entries "NeverShowExt" under
> 'HKEY_CLASSES_ROOT\DocShortcut' and 'HKEY_CLASSES_ROOT\ ShellScrap'. IIRC,
> that should make all extensions visible except the 'shortcut' files, a fact
> that could be changed by doing the same under 'HKEY_CLASSES_ROOT\lnkfile',
> but I don't think that's necessary, really...

Yeah, you don't want your .lnk files visible. Probably your .pif
files too.

George Marsden

unread,
Jan 23, 2001, 2:12:53 PM1/23/01
to
Thanks for that info, I love it when I learn new stuff unexpectedly.

What file extensions, besides .lnk (shortcut) remain hidden after you
change to "show all files " and uncheck "hide file extensions for
known file types"? Are any of these file types likely candidates for
hiding a virus?

The Avon Lady

unread,
Jan 23, 2001, 3:14:32 PM1/23/01
to
In article <3a6dd775...@news.theriver.com>,

g...@removethistheriver.com (George Marsden) wrote:
> Thanks for that info, I love it when I learn new stuff unexpectedly.
>
> What file extensions, besides .lnk (shortcut) remain hidden after you
> change to "show all files " and uncheck "hide file extensions for
> known file types"? Are any of these file types likely candidates for
> hiding a virus?

For starters, see:

http://www.zdnet.com/zdhelp/stories/main/0,5594,2590847,00.html

http://www.zdnet.com/zdhelp/stories/main/0,5594,916413,00.html

Wr@ngler

unread,
Jan 23, 2001, 6:38:07 PM1/23/01
to
Well, actually this one for example comes as a .pif file:

http://www.symantec.com/avcenter/venc/data/w95.mtx.html

And it's a real nasty bugger, I've seen it in action, hehehe

So I'd just leave only the .lnk extensions invisible. You also see the .dun
of dialup-links, which is rather useless AFAIK, but that doesn't really
matter....

--
~*Wr@ngler*~

0 new messages