Visit the Ironworks Gaming Website Email the Webmaster Graphics Library Rules and Regulations Help Support Ironworks Forum with a Donation to Keep us Online - We rely totally on Donations from members Donation goal Meter

Ironworks Gaming Radio

Ironworks Gaming Forum

Go Back   Ironworks Gaming Forum > Ironworks Gaming Forums > General Discussion > General Conversation Archives (11/2000 - 01/2005)
FAQ Calendar Arcade Today's Posts Search

 
 
Thread Tools Search this Thread
Old 06-09-2004, 12:13 AM   #1
Bungleau
40th Level Warrior
 

Join Date: October 29, 2001
Location: Western Wilds of Michigan
Posts: 11,752
I was at a customer site yesterday, and when I booted my laptop and connected to their network, I had advertisements popping up all over the place. Killed IE (yeah, I know) and ran Spybot, which came up with a host of spyware that was in there (and which I'm not certain how it got there). Bargain Buddy was the one that attracted my attention, but it was not alone...

Thing is, I generally don't do much "outside" activity with this machine, so I'm not sure how this stuff got on there. I don't have any of the things that are listed on various web sites as its delivery mechanism.

Anyway, one site listed a virus as being a possible delivery mechanism, so I'm scanning with TrendMicro right now.

Just wanted to pass along the joy and happiness of life in today's spyware-infested world...
__________________
*B*
Save Early, Save Often Save Before, Save After
Two-Star General, Spelling Soldiers
-+-+-+
Give 'em a hug one more time. It might be the last.
Bungleau is offline  
Old 06-09-2004, 12:59 AM   #2
CerebroDragon
Red Wizard of Thay
 
3D SuperBall Champion Asteroids Champion Battle of Helms Deep Champion Moon Patrol Champion Pac Man Champion
Spy Hunter Champion Super Mario Mushroom Champion
Join Date: March 2, 2003
Location: Ballarat, Australia.
Age: 45
Posts: 878
Hey Bungleau,

I share your derision and I'm sure many others do aswell for the nasty adware/spyware's of the world. In many forums I visit there's at least one thread about rampant spyware somewhere!
It is seemingly very easy to become infected.

Recently I scanned my home PC with AVG and come up with some fairly astonishing insights.
I had something like 40 infected files! Thankfully many of these were able to be healed quickly (half of them were DOS based in fact) yet still, 6-8 or so Trojan Horses remained.

So I had to pull up my sleeves, grit my teeth and delete the files manually. I'm using Mozilla now as a result of some security concerns with IE.

I think there is a very strong movement in Australia to make unsolicited material being downloaded to one's machine without strict permission, illegal - although I don't know how successful one would be in implementing such a law on a wider scale. Too many issues, loopholes...

[ 06-09-2004, 03:24 AM: Message edited by: CerebroDragon ]
__________________
Diddledy High, Diddledy Low,
Come Brave Blood Sheep,
You've a goodly way to go.
- Brilhasti Ap Tarj
CerebroDragon is offline  
Old 06-09-2004, 01:35 AM   #3
Dedzy
The Magister
 

Join Date: March 19, 2004
Location: Salt Lake City, UT
Age: 54
Posts: 100
I agree with CerebroDragon, there need to be some laws to track down these cybercriminals and lock them up. Since a lot of these crimes are committed in nations with unsophisticated electronic commerce regulations, I think the only recourse we have is to revamp the internet communications with a new protocol that is more secure and has basic authentication.
__________________
\"Ph\'nglui mglw\'nafh Cthulhu R\'lyeh wagn\'nagl fhtagn.\" <br />\"In his house in R\'lyeh dead Cthulhu waits dreaming.\"
Dedzy is offline  
Old 06-09-2004, 07:59 AM   #4
philip
Galvatron
 

Join Date: June 24, 2002
Location: aa
Posts: 2,101
My dad's got some very annoying stuff. No matter how many times I delete it and get it out of the registry it's back in 2 seconds.
philip is offline  
Old 06-09-2004, 10:25 AM   #5
Bungleau
40th Level Warrior
 

Join Date: October 29, 2001
Location: Western Wilds of Michigan
Posts: 11,752
Well, Trendmicro found one Trojan virus, so I blew it away. Now I'm re-scanning with the company's *official* virus scan software (and recently updated, too). So far, it's passed through 124,000 files and counting...

Philip, are you running Spybot and Ad-Aware on your dad's PC? IF not, you should... if the stuff is back in two seconds, that means that you didn't clean it up completely. Spybot and Ad-Aware can take care of that for you...

*shakes head* I'm all for making spyware a crime... but the folks who do it try to get you to agree to it. Once you've agreed, are they really in the wrong?

*checks again* 129,000 files now. Gotta remember to empty the browser cache before scanning next time...
__________________
*B*
Save Early, Save Often Save Before, Save After
Two-Star General, Spelling Soldiers
-+-+-+
Give 'em a hug one more time. It might be the last.
Bungleau is offline  
Old 06-09-2004, 12:19 PM   #6
philip
Galvatron
 

Join Date: June 24, 2002
Location: aa
Posts: 2,101
Quote:
Originally posted by Bungleau:


Philip, are you running Spybot and Ad-Aware on your dad's PC? IF not, you should... if the stuff is back in two seconds, that means that you didn't clean it up completely. Spybot and Ad-Aware can take care of that for you...

*shakes head* I'm all for making spyware a crime... but the folks who do it try to get you to agree to it. Once you've agreed, are they really in the wrong?
Yep spybot, adaware, spysweeper, 2 registry cleaners, a virus scanner, firewall to catch suspicious files, and myself going through system and system32 folders deleting anything suspicious. Both spysweeper and spybot keep catching 2 programs in the registry (adaware doesn't) but no matter how many times I delete the keys they keep coming back though I cleaned everything else except for the domain history and normal history in the registry as those were empty. I disabled system restore, went through all folders, deleted everything suspicious, cleaned backup files of spybot adaware and spysweeper, reset the homepage, but as soon as I went on the internet it was back almost immediately. I should still install google toolbar to block some of the popups, but that's like my last resort. I don't know what to do if that doesn't work, probably format or something.

edit BTW I hear sometimes instead of deleting files it helps to overwite them so they won't come back. WOuld that be possible in the registry as well?

[ 06-09-2004, 12:21 PM: Message edited by: philip ]
philip is offline  
Old 06-09-2004, 12:26 PM   #7
Cloudbringer
Ironworks Moderator
 

Join Date: March 1, 2001
Location: Upstate NY USA
Posts: 19,737
I really love Spybot and Adaware! I know they don't get everything but they do a good job on the bulk of that garbage!
__________________
"Don't take life for granted." Animal (may he rest in peace)
Cloudbringer is offline  
Old 06-09-2004, 12:48 PM   #8
Bungleau
40th Level Warrior
 

Join Date: October 29, 2001
Location: Western Wilds of Michigan
Posts: 11,752
Philip,

To add another one to the list, have you run HijackThis on it? It gives you a list of suspicious stuff, and it found the critter (at least one critter) that wasn't getting picked up. Also, are you running current versions? Spybot released version 1.3 last month... I've just upgraded this machine to it, and am about to reboot and rescan.

And here I thought I was so clean...
__________________
*B*
Save Early, Save Often Save Before, Save After
Two-Star General, Spelling Soldiers
-+-+-+
Give 'em a hug one more time. It might be the last.
Bungleau is offline  
Old 06-09-2004, 01:37 PM   #9
philip
Galvatron
 

Join Date: June 24, 2002
Location: aa
Posts: 2,101
Quote:
Originally posted by Bungleau:
Philip,

To add another one to the list, have you run HijackThis on it? It gives you a list of suspicious stuff, and it found the critter (at least one critter) that wasn't getting picked up. Also, are you running current versions? Spybot released version 1.3 last month... I've just upgraded this machine to it, and am about to reboot and rescan.

And here I thought I was so clean...
Í'm downloading HiJackThis now [img]smile.gif[/img] Thanks for the tip! Everything was updated, I downloaded all the programs another time to make sure. But the problem is not that they don't find it. They just can't get it deleted properly or it's just in my homepage (probably not, at least I hope the ISP isn't putting this stuff in their site). I might have found another culprit [img]smile.gif[/img] Kazaa, stupid program anyway and I don't use it so I won't lose anything by deleting it.
philip is offline  
Old 06-09-2004, 02:08 PM   #10
Mack_Attack
Osiris - Egyptian God of the Underworld
 

Join Date: May 22, 2001
Location: Sherwoodpark,Alberta,Canada
Age: 51
Posts: 2,929
I just did a scan and came up with 3 items two are in the cookie folder I went and deleted them and did a re-scan and they are now gone. But I have one more left in the registry keys.

it says: vendor: Alexa Category: Data minor

Then it says the object which is a big long line of stuff I imagine this is where it is located. It also says it is a minor threat. What should I do delete it?? I am just not sure what I should do.
__________________
Mack_Attack is offline  
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
More spyware Cerek General Discussion 26 02-20-2005 08:58 PM
I really need help please! (spyware) Sigmar General Conversation Archives (11/2000 - 01/2005) 11 03-03-2004 09:34 PM
Spyware and MSN-Help! Kaltia General Conversation Archives (11/2000 - 01/2005) 2 01-02-2004 10:55 AM
Spyware Kaltia General Conversation Archives (11/2000 - 01/2005) 8 11-27-2003 05:38 AM
Help with Spyware! antryg General Conversation Archives (11/2000 - 01/2005) 22 04-23-2003 07:10 PM


All times are GMT -4. The time now is 10:48 PM.


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
©2024 Ironworks Gaming & ©2024 The Great Escape Studios TM - All Rights Reserved