I Have Been Outsmarted!
Please select your language.
All the while i have been labeling myself as a person who is quite good at handling internet security issues. I have Avast! Home Edition, Zone Alarm Pro and AVG to provide maximum protection. All the while i have been able to intercept spywares, trojans or malicious codes from being executed. Everything was nice and cool until 2 days ago i was completely outsmarted by this hacker.
2 day ago when i open up my Google Mail and found this mail from AccountRobot_donotreply@e-gold.com:
Dear e-gold account holder,
Access to your e-gold account has been temporarily disabled due to
the number of incorrect login attempts. This has been done to secure
your account and to protect your private information in case the
login attemps were not done by you.
Account access will remain disabled until this issue will be solved.
If you are the rightful holder of the account, please click on the
title bellow and log in to your e-gold account.
We apologize for any inconvenience this may cause, and appreciate
assistance in helping us maintain the integrity of the entire e-gold
system. Thank you for your prompt attention to this matter.
Please do not reply to this automatically generated email message.
Well, all i can say is that i’m stupid enough to believe this one. Previously i have received something similar but i was able to ignore those phishing mail. Why i choose to believe this mail? It’s because i myself have been aware of unsuccessful attempts to log in to my e-gold account by someone out there. But then i still have little doubt on this one for i know e-gold will not send such mail no matter what.
Well, i made a wrong decision by clicking the link. I enter my username and password and surprisingly i was still able to check my remaining balance using that phishing link. Well, after reactivating my account (according to the email), i log off again. I kept on considering the possibilities of that mail sent by email and suddenly i recalled someone posted a thread regarding the phishing email. That was after 2 hour when i realized something had gone wrong. When i logged into e-gold again, i could do nothing except seeing my display showing me zero balance. All my funds has been stolen!
I lost my hard earned RM400 for being careless… I’m so speechless…
I reported to e-gold that day also and received a reply from e-gold this morning:
Seng,
As you now know the email you received was not sent by e-gold Ltd. It was a fraudulent attempt to compromise e-gold accounts through a scam known as “Phishing”. e-gold will never send you an unsolicited email asking you to access your account from a link in an email or click on a link in an email. Please review the security alert on the e-gold site for more information. If you clicked on the link or if you opened the attachment, there is a strong possibility you may have a Trojan virus on your computer!
If your account was compromised while AccSent was enabled, there is a high probability that you either have a security hole in your computer, which allowed hackers to take control of your computer or you have a Trojan virus, spyware or keylogger software installed on your computer because someone not
only had access to your e-gold passphrase, they also had access to your email address password. AccSent monitors account access attempts and issues a one-time PIN challenge to those coming from IP address ranges or browsers that differ from the last authorized account access. Your account was accessed from remoteip ‘64.224.109.59‘ and a pin was sent to the email
address on the account. The person logged into your email account and retrieved the pin, accessed your e-gold account and made an unauthorized spend from the account.
Until you remove the malicious software from your computer, your account is still vulnerable. Your email account has also been compromised so it is important that you change the password for your account after your computer is cleaned. If the malicious software is still on your computer, someone is able to read your emails, delete your emails or send emails from your account.
Have you run a complete virus scan of all computers used to access your account with updated anti-virus software? You should also check your computer for Spyware and Trojan keyloggers. Some people mistakenly assume that anti-virus software protects them from keyloggers and Spyware. Most anti-virus software does not adequately check for keyloggers and Spyware. If you have checked all the computers used to access your account with only
an anti virus software, we strongly recommend you use a software that specifically checks for Spyware and keyloggers.There are Trojans keyloggers that monitors Internet Explorer windows until a user visits the e-gold login page: e-gold.com/acct/login.html. Once the user is logged in, the Trojan opens a hidden Internet Explorer window in which it accesses the user\’s account balance: e-gold.com/acct/balance.asp. After ascertaining the value of the user\’s account it attempts to transfer
their funds to another account using the hidden window.Most viruses are conveyed by spammed e-mail in the form of HTML messages. The scripts run on viewing, no clicking on attachments is necessary. They may also arrive as image attachments. Once the image is viewed, the program is executed. Either way, the system is now infected and is just waiting for
you to check your e-gold account balance.You can protect yourself by:
* Using another browser instead of Internet Explorer (IE). Firefox by Mozilla is an excellent choice. You can visit www.mozilla.org for more information.
* Do Not auto-preview incoming e-mail.
* Do Not open obvious spam.
* Do run a full virus scan regularly.As of today we know specifically of 9 viruses that could cause a problem similar to the one you are having.
1. Win32/Goldun.ia (One customer said he did not find anything when he ran Norton and McAfee anti-virus software, but he found the Win32/Goldun.ia Trojan when he used a software called ‘Kaspersky’)
2. T SPY_HAXDORY (A customer who was receiving the fake login confirmation page located a virus with Trend Micro Housecall identified as T SPY_HAXDORY. Removing this seemed to solve the problem without having to reinstall windows.)
3. TROJ_GOLDUN.DO which has a file named CPU.EXE found in the c:\windows directory. This was found with Trend Micro’s PC-cillin.
4. cpu.exe (Aladinz.l Trojan) more information regarding this virus can be found at http://www.auditmypc.com/process/cpu.asp5. GDIWXP.DLL
6. pwsteal.trojan
7. Win32.Grams.I which monitors Internet Explorer windows until the user visits the e-gold login page: e-gold.com/acct/login.html. Once the user is logged in Grams opens a hidden Internet Explorer window in which it accesses the user’s account balance: e-gold.com/acct/balance.asp8. Trojan.LdPinch.L
9. Trojan.PWS.GoldSpy e.exe in Directory D:\Documents and SettingsWe investigated and placed a block on account #4114176 to prevent it from receiving additional funds. Unfortunately we will not be able to refund your money because all e-gold spends are final and not reversible as stated in the e-gold account user agreement. e-gold is also contractually prohibited from freezing e-gold accounts or releasing e-gold account information in the absence of a court order or subpoena. You might want to consider obtaining some combination of help from a legal professional or law enforcement to obtain a court order, if the size of your loss warrants expenditure of your resources (time and money) to resolve.
The court order/subpoena should be presented by postal mail to:
e-gold, Ltd.
c/o Andrew S. Ittleman, Esq.
1001 Brickell Bay Drive
Suite 2002
Miami, FL 33131If you are able to receive the records electronically please specify the appropriate email address the records should be emailed to. Please allow a minimum of 2 weeks for the production of any e-gold records.
In order to ensure you get all pertinent information when issuing the court order or subpoena to e-gold Ltd please:
- Ask for e-gold account profile information for account number #4114176
- Ask for transaction history information for account number #4114176
- Ask for information on any other accounts owned or controlled by the individual
- Ask for counteraccount_id profile information. This is the account profile information for any accounts that made payments into or received payments from the subpoenaed account
- If applicable, ask for stabilization of the funds in question “freezing of the account if the funds are still under the control of the perpetrator”Regards,
e-gold Abuse
Well, i have to pay the price for being indifferent towards previous warning. I can only laugh at this statement:
…You might want to consider obtaining some combination of help from a legal professional or law enforcement to obtain a court order, if the size of your loss warrants expenditure of your resources (time and money) to resolve.
Haha, trading RM400 with all sorts of legal crap with unpredictable cost? I don’t think i will do that. Who knows i may lose more?
E-gold suggested that there might be a trojan or keylogger running on my pc using Internet Explorer. Funny, I’m a Mozilla Firefox Supporter. Do i really care about Internet Explorer? The main reason i switch to Mozilla Firefox is because of the security vulnerabilities of Internet Explorer. Thank you Microsoft for giving us this kind of trouble with your ActiveX Technology! But sadly, Mozilla Firefox’s phishing filter does not work on this site: http://www.e-gold.com-el.es/acct/login.html. Now that the site is gone, no more phishing filter is required…
I have been running full system scans using Avast! Home Edition and AVG. Feeling so unsecured i even installed Spyware Terminator by Crawler.com, and a-squared HiJackFree, a-squared Anti-Dialer and a-squared Free by Emsi Software GmbH. So right now i have a total of 6 programs to protect me? Is this a set of effective protection? I don’t know for now but time will tell. Somehow after some scans i managed to eliminate 2 trojan not detected by Zone Alarm, Avast! Home Edition and AVG. So i guess they can provide me value insight of what is running at the background.
To those people dealing with online transaction like me, security is a must and cannot be compromised. I suggest beginner to try out Spyware Terminator. For advanced users, a-squared HiJackFree and a-squared Free will be a flexible option for you to dig out the culprit.
Online Security……
Zzzzzzzzzzz……
Related entries that might interest you:













