Re: buddylinks worm

From: Alexander Kiwerski (alex_at_winstar.net)
Date: 02/12/04

  • Next message: Chip Mefford: "Something new? bind dos? exploit?"
    To: incidents@securityfocus.org
    Date: 12 Feb 2004 11:34:15 -0800
    
    

    On Wed, 2004-02-11 at 08:16, Dennis Cheung wrote:
    > A friend has gotten infected with this "revolutionary" product. Has
    > anyone tried removing this thing manually before? The buddylinks site
    > has a unsubscribe feature that claims to work, but at the moment I am
    > reluctant until I figure out what exactly this thing is.
    >
    > -Dennis

    Well, on Windows 2000 an entry appears in 'Add/Remove Programs' for this
    lovely little package. Removing it there seems to remove it from the
    machine and cease the activity, at least on the one workstation here
    that got nailed.

    Also seems that setting IE to prompt for downloading signed Active-X
    controls instead of the default of just downloading them prevents the
    install in the first place of course.

    Anyone know if people using Netscape, Mozilla or any browser other than
    IE get "infected" by this?

    /Alex K.

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.astaro.com/php/contact/securityfocus.php
    ----------------------------------------------------------------------------


  • Next message: Chip Mefford: "Something new? bind dos? exploit?"

    Relevant Pages

    • RE: Retina
      ... Thanks for all your comments on this, I shall be downloading an eval ... Find a cheaper internet access deal - choose one to suit you. ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
      (Security-Basics)
    • ActiveX problem and virus infection
      ... "your current security settings prohibit running ActiveX controls on ... when my Windows desktop is loading, ... problem hasn't prevented me from downloading and installing the ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • ActiveX error and virus infection
      ... "your current security settings prohibit running ActiveX controls on ... when my Windows desktop is loading, ... problem hasn't prevented me from downloading and installing the ...
      (microsoft.public.windowsxp.general)
    • Re: man in the middle
      ... Watch your active x when downloading free programs.... ... How about wuacle.exe which is the windows update program being modified ... How about including the 92 security patches in new os instalation cds so ... didn't matter how often I would reformat and reinstal the os after I ...
      (microsoft.public.security)
    • Re: WindowsUpdate_80070020 WindowsUpdate_dt000
      ... so I turned off all the security to my computer ... to supplement the log messages and allow you to infer the problem file ...
      (microsoft.public.windowsupdate)