Re: Extremely odd thing with Giganews DMCA?

From: roadburner (roadburner^at^comcast^dot^net)
Date: 09/19/05


Date: Mon, 19 Sep 2005 15:06:46 -0400

On Mon, 19 Sep 2005 17:31:30 GMT, "David H. Lipman"
<DLipman~nospam~@Verizon.Net> wrote:

Snipped
>
>For non-viral malware...
>
>Please download, install and update the following software...
>
>Ad-aware SE v1.06
>http://www.lavasoft.de/
>http://www.lavasoftusa.com/
>
>SpyBot Search and Destroy v1.4
>http://security.kolla.de/
>
>After the software is updated, I suggest scanning the system in Safe Mode.
>
>For viral malware...
>
>Download MULTI_AV.EXE from the URL --
>http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
>It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
>http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
>(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
>simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
>remove viruses, Trojans and various other malware.
>
>C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
>This will bring up the initial menu of choices and should be executed in Normal Mode. This
>way all the components can be downloaded from each AV vendor’s web site.
>The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.
>
>You can choose to go to each menu item and just download the needed files or you can
>download the files and perform a scan in Normal Mode. Once you have downloaded the files
>needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
>during boot] and re-run the menu again and choose which scanner you want to run in Safe
>Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
>
>When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
>file.
>
>To use this utility, perform the following...
>Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
>Choose; Unzip
>Choose; Close
>
>Execute; C:\AV-CLS\StartMenu.BAT
>{ or Double-click on 'Start Menu' in C:\AV-CLS }
>
>NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
>FireWall to allow it to download the needed AV vendor related files.
>
>* * * Please report back your results * * *

I'll do it tonight when I get home and report back. Thanks so much. I hadn't
thought of that. I use S&D and Adaware on my other PCs, but this was a new PC
and I didn't think to install those 2 tools.

MULTI_AV.EXE is one I never heard of. Thanks so very much for bringing it to
my attention.

I normally keep my PCs locked down so tight that nothing ever gets through.
Over 13 years on the Internet and many years before beginning with a TRS80, I
have never had any experiences like this. Never had a virus or anything else.
So please excuse me if I seem to have gotten excited. Just something I never
experienced before. It is very troubling to me.

Another troubling thing is a discussion I had about it with another engineer.
I work in real time process control and he works in the networking, Level 2 or
data collection side of things.

He has a NAT router on his home PC. He has 2 children. One of the kids did an
"adoption" of an animal on the net. Not a real animal, just a schooling
project. So each night his daughter has to take care of her adopted cyberspace
animal. As a joke, the other sister asked her Dad to block the site for a
practical joke. He pinged the site, got the IP, and blocked it in his NAT
router. Then he tested his work with Firefox. It took a while, but the site
came up in Firefox. (This guy is our networking expert with over 20 years
experience). The he logged on to her account and was still able to access the
site though some of it was blocked. We are both starting to think Firefox is
the root cause.

Mine is a pretty bare bones system, only a few dedicated and trusted programs
on it. It is destined to sit and execute certain privacy related software such
as a Tor node. Switching between it and the main computer is done by a USB KVM
switch. On the dedicated computer, file and printer sharing is off.

If I can't find the source or a good explanation, I'll reformat and reinstall
the OS.

Once again, may extend my most sincere thanks to you for your suggestions
which I will follow to the letter.

My warmest regards,
roadburner



Relevant Pages

  • Re: spyware removal in win 2000
    ... > The process of removing certain malware may kill your ... > Download and run Stinger.exe, ... > malware garbage from your System Restore backups after ... > Be sure that you also download and install hotfix Q816093, ...
    (microsoft.public.security.virus)
  • Re: spidersearch toolbar
    ... Before you try to remove spyware using any of the programs below, download ... The process of removing certain malware may kill your internet connection. ... malware garbage from your System Restore backups after you've cleaned up. ... Be sure that you also download and install hotfix Q816093, ...
    (microsoft.public.security.virus)
  • RE: WARNING Long Reply - Re: Please help me with this confusion!!
    ... > malware on your machine. ... > Before you try to remove spyware using any of the programs below, download ... > malware garbage from your System Restore backups after you've cleaned up. ... > install malware) Keep it UPDATED. ...
    (microsoft.public.win2000.general)
  • Re: Home page problem
    ... Before you try to remove spyware using any of the programs below, download ... The process of removing certain malware may kill your internet connection. ... malware garbage from your System Restore backups after you've cleaned up. ... Be sure that you also download and install hotfix Q816093, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Visual Basic C++ & runtime error
    ... Before you try to remove spyware using any of the programs below, download ... The process of removing certain malware may kill your internet connection. ... malware garbage from your System Restore backups after you've cleaned up. ... Be sure that you also download and install hotfix Q816093, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)