Reply
Old November 19th, 2002 Top | #1
Kirrie2001
 
Kirrie2001's Avatar
Unregistered
Posts: n/a

Default Warning !!!!!

I found this on the Langalist today. Hope it is of some use.


SPYWARE WARNING - Level: HIGH RISK!
Last night, I got a phonecall from a friend that wanted me to have a look at his PC. Thinking it was going to be an easy job, was an understatement! Internet Explorer would run but not access websites at all. I spent a total of 4hrs trying to get it up and running and failed!
It seems there is a new serious spyware component that can download itself and install, without your knowledge. The last advertising company that I can remember using this technique was RealNames, last year - no longer in operation. Now, there is one originating from the link below.
w.w.w.i.g.n.k.e.y.w.o.r.d.s..c.o.m <<<------ DO NOT CLICK ON THIS ADDRESS!!!!! (I have disabled this link for security reasons!!) - Currently, there is no known cure for this parasite. Ad-aware, Pest Patrol or any other spyware checker will not alert you or disable it. If you can 'BLOCK' this domain, then do so NOW! The uninstaller this company has on their website does not remove the spyware, browser functionality is still affected after using their removal tool.
The parasite will add 3 files to your system, and enter Registry entries. The main culprits come in the form of bho.dll and winstart.exe. The winstart.exe will execute upon restarting under msconfig. Deleting these files, does not get rid of this problem. Even un-installing your browser and re-installing will not cure this infection.
Many reports worldwide, concerning this spyware are growing. Some people have even gone to reformatting their systems. Their have been reports that it affects the search page of Internet Explorer and MSN Messenger.
Some ways of prevention are:
Do not trust a 'Certificate from IGN' as trusted - should you ever receive a dialogue of this description.
Be very careful of ActiveX Control downloads.
Do not click Yes to any popups asking for permission to download.
Make sure your Security settings are set to at least Medium or Higher.
Remember this is not a virus, so your Antivirus program will not detect it, nor will it show as an attack on a firewall program - this parasite comes directly through your browser, and render it useless!
L8rs...
H
P.S. - It looks like I will need to reformat my friends drive!

Link edited, we don't want someone elses computer getting messed up - Jewelzz
  Reply With Quote
Old November 19th, 2002 Top | #2
 
Hipster Doofus's Avatar
Good grief Charlie Brown
Joined: May 2002
Location: Melbourne Australia
Posts: 5,920
Reputation: 560
Power: 187

Default

I wonder if it affects all browsers or just IE? Good post Kirrie.

Pentium 4 2.6ghz 400mhz @ 3.07ghz 472mhz / Gigabyte GA-8IHXP v2.1 / RAMBUS PC 800 768mb / Sapphire Radeon 9600XT 256mb / 2 x Maxtor 80gb ATA133 DiamondMax, RAID0 :: 1 x Western Digital 7200 40gb / Liteon DVD-RW Dual Layer SOHW-1633S @ 1653S / Liteon 52x24x52 CD-RW LTR-52246S / Zalman CNPS7000A-Cu Fan / Antec TruePower 480w / RD3XP Gladiator Rounded Cables
Hipster Doofus is offline   Reply With Quote
Old November 19th, 2002 Top | #3
 
Tabula Rasa's Avatar
Stranger Than Kindness
Joined: July 2002
Location: Israel
Posts: 3,233
Reputation: 450
Power: 157

Default

One of the more important reasons to install windows updates is to avoid things like that, there is a web page that is running a script that formats a visitors computer unless he has the security updates of SP1 .

But what else can you expect from an OS built around a web browser.
Tabula Rasa is offline   Reply With Quote
Old December 3rd, 2002 Top | #4
wn van deursen
 
wn van deursen's Avatar
Unregistered
Posts: n/a

Default Re warning

The way I see it SP1 is not up against this parasite (& others to come). Putting this domain name on Block seems a good idea to me, but it would help to know where I can find the option to do so, haven't done it before.
  Reply With Quote
Old December 3rd, 2002 Top | #5
 
damnyank's Avatar
I WILL NOT FORGET 911
Joined: March 2002
Location: Petal, Mississippi
Posts: 2,354
Reputation: 390
Power: 151

Default

Tools, Internet Options, Privacy, under Web Site click Edit, type in site you want to block, and click block.
damnyank is offline   Reply With Quote
Old December 4th, 2002 Top | #6
wn van deursen
 
wn van deursen's Avatar
Unregistered
Posts: n/a

Default re warning

So simple. ThkU Damnyank
  Reply With Quote
Old December 4th, 2002 Top | #7
 
canadian_divx's Avatar
Canadian_divx
Joined: June 2002
Location: waterloo, Ontario, Canada, Planet Earth
Posts: 1,551
Reputation: 150
Power: 137

Default

i wounder if the education networks ahve this blocked because if they dont it could cause them real probems
canadian_divx is offline   Reply With Quote
Old December 7th, 2002 Top | #8
Boy_alien
 
Boy_alien's Avatar
Unregistered
Posts: n/a

Default

how do u know if its on your comp already? how can u find out?
  Reply With Quote
Old December 7th, 2002 Top | #9

OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,256
Reputation: 4260
Power: 298

Default

Thanks for the heads up Kirrie
NetRyder is offline   Reply With Quote
Old December 7th, 2002 Top | #10
 
vivid_vibe's Avatar
OSNN Senior Addict
Joined: December 2002
Posts: 406
Reputation: 250
Power: 122

Default

Jeez, I think I'll add that site to my HOSTS file. Anybody need help doing that, e-mail me.

vivid
vivid_vibe is offline   Reply With Quote
Old December 7th, 2002 Top | #11

OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,256
Reputation: 4260
Power: 298

Default

That's a great idea vivid
NetRyder is offline   Reply With Quote
Old December 7th, 2002 Top | #12
wn van deursen
 
wn van deursen's Avatar
Unregistered
Posts: n/a

Default re warning

Boy_alien asked How Do You Know It's Already There.
Kirrie suggests you'll find it in your Registry. But I'm not sure Registry will feature it under the domain (that dares not speak its name...) and if you have many entrees in your Reg it may be difficult to trace...? Anyway, Boy_alien, won't you notice by simply seeing your pc going bonkers?
  Reply With Quote
Old December 7th, 2002 Top | #13
 
lieb39's Avatar
Apple lover, PC User
Joined: November 2002
Location: Australia
Posts: 526
Reputation: 0
Power: 121

Default Just another way to block the website

Just another way to block that website,
Whenever you type a domain in, ex www.hotmail.com, it first checks your host file if it is anything "special", and if it is not than it will contine as normal. But if it does find it than it will redirect to where ever the hosts file says (this is a very good way to block ads) So you can make ads or this website just get a error file by;

1. open run, type this in;
notepad c:\windows\system32\drivers\etc\hosts
hit enter
2. You might have a short or long file, in either case just make sure you have this at the very top (if not, copy paste)

# localhost: Needs to stay like this to work
127.0.0.1 localhost

3. than go to the last line on this file and type;
127.0.0.1[space][the website you want to block]

ex. 127.0.0.1 ad.adsmart.com
this will block out ad.adsmart.com
(if it is a www site type www.website.com)

This makes the computer look on your own computer for the page, and it will come back in error.

Enjoy!

lieb39

Did a post help you, or solve a problem you were having?
Click the button under the member's avatar to increase his/her reputation, and to encourage useful posts on the forum.
lieb39 is offline   Reply With Quote
Old December 9th, 2002 Top | #14
Boy_alien
 
Boy_alien's Avatar
Unregistered
Posts: n/a

Default

yeah i guess. thanks for the heads up.
  Reply With Quote
Old December 9th, 2002 Top | #15
 
Octopus's Avatar
OSNN Veteran Addict
Joined: March 2004
Posts: 1,200
Reputation: 20
Power: 112

Default

there is nothing in that site I removed all the dots and then clicked, the page is white.
Octopus is offline   Reply With Quote
Old December 9th, 2002 Top | #16
Bluecat
 
Bluecat's Avatar
Unregistered
Posts: n/a

Default

Originally posted by Octopus
there is nothing in that site I removed all the dots and then clicked, the page is white.
You sure it hasn't caused an adverse effect to your desktop background? hehe
  Reply With Quote
Old December 21st, 2002 Top | #17
ZAnwar
 
ZAnwar's Avatar
Unregistered
Posts: n/a

Default

It hasn't done something to my PC either!
  Reply With Quote
Old December 21st, 2002 Top | #18
Burpster
 
Burpster's Avatar
Unregistered
Posts: n/a

Default

no biggie ...there is an uninstaller for it ...relaxxxx
  Reply With Quote
Old December 23rd, 2002 Top | #19
PCdabbler
 
PCdabbler's Avatar
Unregistered
Posts: n/a

Talking Thanks !

Thanks People, you have indirectly helped me over a small problem ... some time ago I ran an Ad killer, and have been looking to remove it ever since ! Well, it turns out that it had Filled my HOSTS file with redirects to 127.0.0.1 for just about EVERY Ad server, making my HOST file huge !! It did work though, but got annoying seeing all those page not found errors, and it did slow down surfing due to the HOSTS file size I suppose.
  Reply With Quote
Old January 21st, 2003 Top | #20
 
Kush's Avatar
High On Life!
Joined: January 2002
Location: Montreal, Quebec
Posts: 4,590
Reputation: 1300
Power: 185

Default ahhhhh!

ahhh i had this parasite and i got rid of it using spy bot. at least i think it did!


If Someones post is helpful or makes you laugh, reward the person by clicking on this button--->
Kush is offline   Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Consumer Warning ZeroHour Funny Farm 3 June 18th, 2004 9:10pm
Test Images - ** Warning ** Large File Size ** Warning ** PseudoKiller Desktop Customisation 24 November 12th, 2003 10:14am
Warning Warning!! Teddy Entertainment & Sports 8 July 3rd, 2003 8:07pm
Warning - Avg Hipster Doofus Windows Desktop Systems 2 October 10th, 2002 12:10pm
Serious Warning Hipster Doofus Windows Desktop Systems 7 September 17th, 2002 4:13am