Re: Spyware/adware and Internet Explorer

From: Bert Gold (Bert_member_at_newsguy.com)
Date: 02/03/04


Date: 3 Feb 2004 13:43:31 -0800

I believe my system is under attack.

I cannot remove internet explorer from my system to test whether
the pop ups can launch browsers in the absence of Internet Explorer
SpyBot provides details of unwanted cookies and programs installed
in the past 6 hours as:
-----NOW----
Advertisting.com
Alexa Related
Avenue A, Inc.
BFast
Comet Cursors: Interface (REGISTRY)
Commission Junction
DoubleClick
DSO Exploit (REGISTRY)
Gator
HitBox
LinkSynergy
Media Plex
Value Click
Virtual Bouncer
VX2/f: Class (REGISTRY)
VX2/f: Class ID (REGISTRY)
VX2/f: Type Library (REGISTRY)
VX2/f: Typelib (REGISTRY)
Windows Media Player: Client ID (REGISTRY)
Xupiter.Sqwire: Installer
----10:50 AM EDT-------

My browser (IE 6, service pack 1)
fails the test below:

http://secunia.com/Internet_Explorer_File_Download_Extension_Spoofing_Test/
because the .pdf file dialog box interchange
DOES OCCUR.

I am using:
SpyBot
MRU Blaster
Cookie Monster
Ad-Aware
and of course
McAfee Virus Scan Enterprise

All with new definitions files in
the past 24 hours.

Technicians looking at the system
have suggested backing up data and wiping.

I am behind a firewall.

MRU Blaster just found two Windows UserAssist MRU - {8HEX-4HEX-4HEX-12HEX}
and SpyBot just found one Alexa Related in C:\WNNT\Web\RELATED.HTM

Any suggestions?

Bert Gold



Relevant Pages

  • Re: Spyware/adware and Internet Explorer
    ... the pop ups can launch browsers in the absence of Internet Explorer ... Comet Cursors: Interface (REGISTRY) ... VX2/f: Class ID ... because the .pdf file dialog box interchange ...
    (comp.security.misc)
  • RE: browes problem
    ... Important This article contains information about modifying the registry. ... 256986 Description of the Microsoft Windows Registry ... Your Internet Explorer home page has been changed to a different Web site ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • RE: Yes, Another Hijacked browser- VERY nasty
    ... Important This article contains information about modifying the registry. ... 256986 Description of the Microsoft Windows Registry ... Your Internet Explorer home page has been changed to a different Web site ... You cannot change your home page selection to the Web site that you want. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • RE: home page
    ... Important This article contains information about modifying the registry. ... 256986 Description of the Microsoft Windows Registry ... Your Internet Explorer home page has been changed to a different Web site ... You cannot change your home page selection to the Web site that you want. ...
    (microsoft.public.windowsxp.accessibility)
  • RE: homepage
    ... Important This article contains information about modifying the registry. ... 256986 Description of the Microsoft Windows Registry ... Your Internet Explorer home page has been changed to a different Web site ... You cannot change your home page selection to the Web site that you want. ...
    (microsoft.public.windowsxp.security_admin)

Quantcast