Beware!!! - Branded Hackers - screenshot sent via Google mail servers

Discussion in 'General Chat' started by coolmaste, Aug 9, 2007.

  1. #1
    I have found a suspicious file named 'UBGT.exe' in my c://windows/system32/sys32 folder. The sys32 folder is hidden and I found many screenshots of my PC activities.
    It’s very stranger and it is connecting to Google mail servers and sending my PC activities in jpg format. The IP which the screenshots are forwarded is of GOOGLE. Is this a new Spy ware or some activities from Google? It is totally ridiculous. I am Ad sense and Ad words user, is this a Google’s new software to spy on this programs. I hope this is not related to Google because I do have respect for it. Whatever it is it is disgusting and must be Professional Hackers or the branded Hackers. . My NoD32 antivirus did not detect it. I installed Seagate firewall and stopped its activities. Yeh, everyone please check your PC’s.


    Here are the screenshot of it:
    [​IMG]

    IP belongs to GOOGLE:
    [​IMG]

    Who is Information of the IP :
    [​IMG]
    :mad:
     
    coolmaste, Aug 9, 2007 IP
  2. funindya

    funindya Peon

    Messages:
    1,025
    Likes Received:
    27
    Best Answers:
    0
    Trophy Points:
    0
    #2
    gosh that was disgusting.....
     
    funindya, Aug 9, 2007 IP
  3. KingofKings

    KingofKings Banned

    Messages:
    5,975
    Likes Received:
    143
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Damn thanks for the head up.. I'm checking my PC right now!
     
    KingofKings, Aug 9, 2007 IP
  4. matzii

    matzii Well-Known Member

    Messages:
    162
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    101
    #4
    thanks for the hint!! i hope u an find the source!
     
    matzii, Aug 9, 2007 IP
  5. shieldme

    shieldme Peon

    Messages:
    468
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #5
    eak! scary stuff *checking right now*
     
    shieldme, Aug 9, 2007 IP
  6. longhornfreak

    longhornfreak Well-Known Member

    Messages:
    2,067
    Likes Received:
    95
    Best Answers:
    0
    Trophy Points:
    140
    #6
    I think that means its being sent to gmail. So someone is receiving your screenshots with gmail.

    I am a avid google user and I didn't see that file.
     
    longhornfreak, Aug 9, 2007 IP
  7. ermac0

    ermac0 Peon

    Messages:
    9
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    It's rather application trying to send emails via google mail servers. Probably kinda spam worm. It is not related to Google, only uses its servers to send unwanted mail.
     
    ermac0, Aug 9, 2007 IP
  8. coolmaste

    coolmaste Peon

    Messages:
    120
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #8
    I have not yet deleted the file, I am trying to get in the .exe. I have reported this to Google and asked for the explanation.
     
    coolmaste, Aug 9, 2007 IP
  9. TheDrew831

    TheDrew831 Active Member

    Messages:
    464
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    60
    #9
    Sounds like you have spyware and the creator of the program is just using gmail to get your info. I don't think google is actually related.
     
    TheDrew831, Aug 9, 2007 IP
  10. SoniCute

    SoniCute Active Member

    Messages:
    585
    Likes Received:
    18
    Best Answers:
    0
    Trophy Points:
    60
    #10
    By default folder sys32 doesnt exist.I recommended to download and install Spybot - Search & Destroy.Below is download page the softwares.

    http://www.spybot.info/en/index.html
     
    SoniCute, Aug 9, 2007 IP
  11. bryandy

    bryandy Peon

    Messages:
    774
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #11
    wow scary stuff, good thing i use a mac ;)
     
    bryandy, Aug 9, 2007 IP
  12. zinruss

    zinruss Notable Member

    Messages:
    3,288
    Likes Received:
    237
    Best Answers:
    0
    Trophy Points:
    270
    #12
    I don't have gmail where i believe other users may offer their helping hand. Everyone who have gmail, please check and update this thread if you are effected. This thread will be another case study for a lot of webmasters here.

    Quote for today: It is time to learn linux :)
     
    zinruss, Aug 9, 2007 IP
  13. coolmaste

    coolmaste Peon

    Messages:
    120
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #13
    I hope it has just sending screenshot not my passwords or any important documents. Strange thing here is there is no information about UBGT.exe file in Google search.

    if it is worm which is the best application to remove it. NOD32 did not detect it.
    :-(
     
    coolmaste, Aug 9, 2007 IP
  14. KingofKings

    KingofKings Banned

    Messages:
    5,975
    Likes Received:
    143
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Alright I checked my PC.. didn't find anything.. phew.. :)
     
    KingofKings, Aug 9, 2007 IP
  15. SoniCute

    SoniCute Active Member

    Messages:
    585
    Likes Received:
    18
    Best Answers:
    0
    Trophy Points:
    60
    #15
    100% AGREE!!

    Windows is easy,make one person more reach.
    Linux is complicated,full question but make our brain work correctly :D
     
    SoniCute, Aug 9, 2007 IP
  16. getjimmy

    getjimmy Prominent Member

    Messages:
    17,260
    Likes Received:
    1,005
    Best Answers:
    0
    Trophy Points:
    360
    #16
    Try latest version of kaspersky antivirus.
     
    getjimmy, Aug 9, 2007 IP
  17. twistedspikes

    twistedspikes Notable Member

    Messages:
    5,694
    Likes Received:
    293
    Best Answers:
    0
    Trophy Points:
    280
    #17
    thanks for the info, checking now.
     
    twistedspikes, Aug 9, 2007 IP
  18. coolmaste

    coolmaste Peon

    Messages:
    120
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #18
    Thanks! Let me download it and see the result
     
    coolmaste, Aug 9, 2007 IP
  19. logosurge

    logosurge Peon

    Messages:
    21
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #19
    Thats messed up.. how did you come across the file?
     
    logosurge, Aug 9, 2007 IP
  20. GRIM

    GRIM Prominent Member

    Messages:
    12,638
    Likes Received:
    733
    Best Answers:
    0
    Trophy Points:
    360
    #20
    Sounds like a key logger to me, anyone you know might want to check up on your 'activities?'
     
    GRIM, Aug 9, 2007 IP