Adware, malware, spyware, hijacker discussion and information

[Gain Knowledge]  [Install Prevention]  [Maintain Security]  [Spyware Removal Help]


It is currently Sat May 25, 2013 9:17 am

All times are UTC - 7 hours




Post new topic Reply to topic  [ 1 post ] 
Author Message
 Post subject: StopGuard, Winguard or VipFares hijackers:
PostPosted: Fri Mar 18, 2005 12:41 am 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15966
Location: PHX, AZ
Approx Date surfaced: Sept-Oct 2004

Causing tremendous system troubles with all OSes. Users infected by visiting sites, clicking on popups. Infection mutates with every reboot, creates legit looking files in HJT logs. Very difficult to remove, we have a fix for it, with very good success rates thus far. See the links below to file a complaint and see the actions being taken.
http://www.cdt.org/action/spyware/
http://www.cdt.org/privacy/spyware/

Examples of infection in HJT logs:
C:\WINDOWS\AppPatch\ftpas.exe
C:\WINDOWS\Web\dvdutil.exe
C:\WINDOWS\Tasks\inetole.exe
O2 - BHO: CATLEvents Object - Random CLSID & dll
O4 - HKLM\..\Run: [*Name here will be the same as the .exe] C:\WINDOWS\bad folder\bad.exe
O4 - HKLM\..\RunOnce: [*Name here will be the same as the .exe] C:\WINDOWS\bad folder\bad.exe rerun
O4 - HKCU\..\RunOnce: [*MS Setup] C:\WINDOWS\System32\bkinst.exe ren <<or something similar.

UPDATE-2/18/2005:
This infection has more or less disappeared, and the fix is fairly easy, tho, it does have some things to bear in mind when fixing.

_________________
Image



IP:
top
Top
 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 1 post ] 

All times are UTC - 7 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  

Who is online

Who is online In total there is 1 user online :: 0 registered, 0 hidden and 1 guest (based on users active over the past 5 minutes)
Most users ever online was 282 on Tue Sep 25, 2012 11:30 am

Users browsing this forum: No registered users and 1 guest

New posts    No new posts    Forum locked
Powered by phpBB