Re: Extremely odd thing with Giganews DMCA?

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 09/19/05


Date: Mon, 19 Sep 2005 17:31:30 GMT

From: "roadburner" <roadburner^at^comcast^dot^net>

| I posted this to alt.privacy this AM. I got an e-mail that I should repost it
| here. Hope nobody minds.
|
| I was reading APAS a few minutes ago via Giganews.
|
| A message popped up on the screen asking me about transferring bookmarks. I
| looked at the taskbar and saw it was Firefox. I assumed it was asking me if I
| wanted to transfer my IE bookmarks to it. Neither IE or Firefox were running
| at the time.
|
| I answered the popup with OK. Next, Firefox opened up the following page:
| http://www.giganews.com/dmca.html
|
| The only things running at the time were Mercury, OE, and News Agent.
|
| Grisoft AVG, MS Antispyware, and PGP were running in tray.
|
| I should add that the PC is behind a cable modem and a Netgear wireless router
| though directly connected to the router.
|
| Has anyone else had this happen? I am not now or ever have posted or
| downloaded any copyrighted materials. I have had this account with them for
| about 1 1/2 years.
|
| How in the heck did that happen? I checked my Firefox bookmarks and sure
| enough, it looks like it transferred my IE bookmarks into it. But the page I
| referred to that popped up was not one of the bookmarked pages.
|
| I should add that this is a new PC. I have only set it up this weekend so
| there are very few bookmarks. It is a Dell with XP Pro and the way it was
| shipped included Dell bookmarks. The Dell bookmarks got transferred to
| Firefox. That is how I know for sure it was Firefox asking to transfer
| bookmarks.
|
| Anybody have any clues as to what fired things off? Kind of scarey. I would
| hate to think that Giganews can control Firefox on this PC. Should I dump
| Firefox? Is there some exploit in it? I installed Firefox because I thought it
| was secure. How the heck could it be remotely turned on? Remember, it wasn't
| running at the time. It was remotely started by someone else.
|
| Could it be I got a trojan? Don't know how. Everything on this PC (not much)
| is legit software. Nothing strange.
|
| Really wondering what the heck is going on? How? Why that page? Makes me
| nervous as all get out.
|
| AVG has completed a test of everything without finding anything.
|
| Regards,
| roadburner

For non-viral malware...

Please download, install and update the following software...

Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/

SpyBot Search and Destroy v1.4
http://security.kolla.de/

After the software is updated, I suggest scanning the system in Safe Mode.

For viral malware...

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: OT: Foxfire, why I should or should not consider it
    ... I'm a huge Mozilla fan. ... Had earlier editions of Firefox ... >Firefox has provisions to migrate bookmarks from IE, ... think I'll go ahead and download Firefox ...
    (rec.outdoors.rv-travel)
  • [FC2] Problem with Firefox
    ... I installed firefox from the DAG repo and I use the bookmark FTP plugins ... download and upload my bookmarks on my ftp when I open or close ... But I have now as soon that I open a new firefox windows, ... the bookmarks even if there is only a windows open. ...
    (Fedora)
  • Re: Extremely odd thing with Giganews DMCA?
    ... >> A message popped up on the screen asking me about transferring bookmarks. ... >> looked at the taskbar and saw it was Firefox. ... On the primary machine that used to host the Tor router, ... Only Tor was permitted to use those ports. ...
    (alt.privacy)
  • Re: Extremely odd thing with Giganews DMCA?
    ... >>A message popped up on the screen asking me about transferring bookmarks. ... >>looked at the taskbar and saw it was Firefox. ... >>The only things running at the time were Mercury, OE, and News Agent. ... on a software firewall and only permit connections to those ports through Tor ...
    (alt.privacy)
  • Re: TVGuide.com now officially useless
    ... Other browsers have that "go" menu but Opera ... I downloaded Firefox 1.5 and gave it a quick test run. ... I still don't like the toolbar, it reminds me too much of IE and the ... Firefox has a bookmarks toolbar and it can import Opera ...
    (rec.arts.tv)