Your Universal Remote Control Center
RemoteCentral.com
Custom Installers' Lounge Forum - View Post
Previous section Next section Previous page Next page Up level
Up level
The following page was printed from RemoteCentral.com:

Login:
Pass:
 
 

Page 2 of 2
Topic:
Adware on Remote Central
This thread has 29 replies. Displaying posts 16 through 30.
Post 16 made on Monday July 5, 2004 at 20:35
Ernie Bornn-Gilman
Yes, That Ernie!
Joined:
Posts:
December 2001
30,104
Daniel,
Someone on your staff (oops, do you have a staff?) should be up on DoubleClick, not just hoping it is no big deal. I believe a simple cookie can also be used as a hook to engage a key-stroke program, whereby every stroke on your keyboard is sent to a web site.

There you have it, your hopeful comment and my paranoid fear.

Perhaps you need to look into DoubleClick. The two URLs below, although somewhat outdated, are among the first few that come up in a google search. The first is all gung-ho about doubleclick from the site manager's and advertiser's point of view. The second discusses doubleclick amassing a database of ALL internet use, computer by computer!

[Link: doubleclick.com]

[Link: unquietmind.com]
A good answer is easier with a clear question giving the make and model of everything.
"The biggest problem in communication is the illusion that it has taken place." -- G. “Bernie” Shaw
Post 17 made on Monday July 5, 2004 at 23:38
Rsinic
Founding Member
Joined:
Posts:
May 2002
9
Zonealarm 4 fellas... thats all that needs to be said. Maybe a secondary like Google toolbar couldn't hurt.
Post 18 made on Monday July 5, 2004 at 23:57
Impaqt
RC Moderator
Joined:
Posts:
October 2002
6,233
On 07/05/04 18:04, ErikS said...
The google toolbar/popup blocker works great for
popups but is considered to be a spyware program
in that it sends your web activity log to google
for whatever reason. This may or may not include
login names and passwords so be careful.

Only if you clicked it was OK to do this when you first installed the toolbar. Gogles policy is VERY clear and this "feature" is not required to use the toolbar/popup-blocker. The Toolbar is NOT spyware, and certainly does NOT include names and passwords.

I've been using the toolbar and deskbar since before they came out for public consumption.


OP | Post 19 made on Tuesday July 6, 2004 at 10:11
avgenius1
Founding Member
Joined:
Posts:
May 2002
448
Rsinic,

My brother is running ZoneAlarm and just got hammered with a trojan hijacker/downloader. If a hacker wants to get stuff on your machine, he/she will. All we can do is just try and protect ourselves.

Daniel,

I havent seen another instance of DoubleClick since my last post, yesterday. I am of the mind that one of your advertisers is possibly(not pointing any fingers, just speculation) had DoubleClick running in an ad. Dont know enough about DoubleClick implementation to say for certain.

HDTVJunkie,

I dont run HijackThis. I tried it but it seemed like I got more adware with than without. Could be the fact that I got it from download.com, have gotten all kinds of junk on that site but for every one 'bad' program I have downloaded 10 good ones. Its the internet, what else can I say?
"Some may never live but the crazy never die" ~ Hunter S. Thompson
"There will be plenty of time to sleep when I am dead" ~ Me
Post 20 made on Tuesday July 6, 2004 at 21:30
Larry Fine
Loyal Member
Joined:
Posts:
August 2001
5,002
On 07/06/04 10:11, avgenius1 said...
My brother is running ZoneAlarm and just got hammered
with a trojan hijacker/downloader.

How does one know? What are the visible signs? In other words, how does the Trojan manifest itself?

"How do it know?"

Danke,
Larry,
www.fineelectricco.com
OP | Post 21 made on Wednesday July 7, 2004 at 10:19
avgenius1
Founding Member
Joined:
Posts:
May 2002
448
Larry,

This particular trojan contained a browser hijacker, a search hijacker, norton 'defeater' and overwrite protection. Most of these 'bugs' are harmless, very annoying and a bit time consuming to fix. The biggest part of the problem with these types of programs seems to be the 'background browser' which is downloading all kinds of other auto-executables and worthless crap. I fixed a laptop for a friend of mine recently and she had 30, yes 30, different trojans. Worst I have seen to date. The worst part of it was that the browser hijacker was forcing her to 'blacklisted' sites (child pornography), any type of search ran through 'CoolWWWWeb', if you actually got to google or yahoo the browser would just hang, increased her processes in XP to 137 running and AdAware found 1323 objects. Totally trashed the box, simple solution to fix was to format. Spent three days trying to fix everything but couldnt get it all.
She got this through email. Nortons wasnt up to date when I got the box from her, finally got it updated and it didnt find ANY of the bugs. Downloaded AVG and it found them all but it couldnt remove but half of them, even in safe mode. I guess to answer your question about manifestation Larry, when you get one of these bugs you will know it, no question. Just keep security as tight as you can stand it on your computers and hope for the best. If you get a bug, back up your data(you probably do this regularly anyway), find your reinstall disks, run all of the above mentioned software in this post, get ready to manually edit the registry and pray, lots of praying.
Seems like there are a lot of bored 'script-kiddies' out there who think that they are '1337 h4x0r' but in reality they are just dumb.
"Some may never live but the crazy never die" ~ Hunter S. Thompson
"There will be plenty of time to sleep when I am dead" ~ Me
Post 22 made on Wednesday July 7, 2004 at 10:44
Impaqt
RC Moderator
Joined:
Posts:
October 2002
6,233
THe Best scanner to run to check for Trojans and Host takeovers is "Hijack This!"

This is NOT a program for the amateur computer user, but there are many sites and forums on the internet where you can post your log file and get free advice on what should be fixed and cleaned.

Post 23 made on Wednesday July 7, 2004 at 15:27
avdude
Founding Member
Joined:
Posts:
February 2002
814
Ok,

I just had one blocked...when I came here from CNN.com

It was Aad.avenue

avdude
AVDUDE
"It might work better if it were plugged in and programmed first...just a thought!"
Post 24 made on Wednesday July 7, 2004 at 15:29
avdude
Founding Member
Joined:
Posts:
February 2002
814
and another one...

Avenue A, Inc...

avdude
AVDUDE
"It might work better if it were plugged in and programmed first...just a thought!"
OP | Post 25 made on Wednesday July 7, 2004 at 19:25
avgenius1
Founding Member
Joined:
Posts:
May 2002
448
I havent seen those, only DoubleClick. Its not every time, just occasionally. Cant figure it out.
"Some may never live but the crazy never die" ~ Hunter S. Thompson
"There will be plenty of time to sleep when I am dead" ~ Me
OP | Post 26 made on Wednesday July 7, 2004 at 19:27
avgenius1
Founding Member
Joined:
Posts:
May 2002
448
Correction, got a block on Avenue A as I posted that last post. The banner ad was for a internet dating service, if that helps Daniel.
"Some may never live but the crazy never die" ~ Hunter S. Thompson
"There will be plenty of time to sleep when I am dead" ~ Me
Post 27 made on Wednesday July 7, 2004 at 20:01
DavidatAVX
Founding Member
Joined:
Posts:
August 2001
440
On 07/07/04 19:27, avgenius1 said...
Correction, got a block on Avenue A as I posted
that last post. The banner ad was for a internet
dating service, if that helps Daniel.

Dido on Avenue A.

Dave

Post 28 made on Wednesday July 7, 2004 at 20:22
avdude
Founding Member
Joined:
Posts:
February 2002
814
Daniel,

Just ran a reverse tracer-route on the blocked Avenue A, Inc spyware, and it appears to come either from, or through, the "TRUE" banner add...still trying to get back from there...

avdude
AVDUDE
"It might work better if it were plugged in and programmed first...just a thought!"
OP | Post 29 made on Wednesday July 7, 2004 at 21:05
avgenius1
Founding Member
Joined:
Posts:
May 2002
448
Yeah, that was my thought, that the ad banners contained the adware. Should have thought about trace route, duh. Oh well, glad somebody else has seen this.
"Some may never live but the crazy never die" ~ Hunter S. Thompson
"There will be plenty of time to sleep when I am dead" ~ Me
Post 30 made on Wednesday July 7, 2004 at 23:14
teknobeam1
Active Member
Joined:
Posts:
May 2004
626
worms and trojan programs have become more sophisticated lately. SOme are usingremote PC's to attack you with. It's mac address based, so short of swapping out youir router or NIC, reformatting your HD won't get rid of it. Also, for ME based machines, there are viruses that copy themselves to the "auto restore" folder and as soon as you nukle them with your favourite virus program, voila, they reappear. You have to go in and turn ioff aout restore, etc. it's a timely process. Programs like Zone alarm are a level of defense, but any serious hacker will walk through Zone alarm like a hot knife through butter. A good defense is a router, but in many situations, allowing open ports negates all of the security features offered. True enough, you will be fairly secure if you just don't visit any sites, download anything, or enter a chat room. But then you might as well just cancel your internet subscription. Some devices offer high level firewall protection (PIX) these will deter random hackers. But anyone with skills that is determined to get into your PC probably will. The compromise is a router. It deals with the port scanner type of opportuinty attack. I ussually run "netstat" online. That way if I see a connection happening to my network, I can grab the remote IP address and port number. I can also "kill the socket" (terminate the connection from my end). This ussually let's the intruder know that you are aware they are attempting to get in and most of them will move on.
Page 2 of 2


Jump to


Protected Feature Before you can reply to a message...
You must first register for a Remote Central user account - it's fast and free! Or, if you already have an account, please login now.

Please read the following: Unsolicited commercial advertisements are absolutely not permitted on this forum. Other private buy & sell messages should be posted to our Marketplace. For information on how to advertise your service or product click here. Remote Central reserves the right to remove or modify any post that is deemed inappropriate.

Hosting Services by ipHouse