6MT.net now has a Photo Gallery available to all users. Upload your photos today!
Infiniti G35 Coupe / Sedan Infiniti G35

Go Back   6MT.net Infiniti G35/G37/GTR Forums > Off-Topic Discussion > Totally Off Topic
Home Forum Active Topics / Realtime Photo Gallery 6MT Shop Register Mark Forums Read


       
» Site Navigation
 > F.A.Q.
»
»
» Other Sites
Google Ads

» Log in
User Name:

Password:

Remember Me?
Not a member yet?
Register Now!
» Wheel & Tire Center

Google Ads

Reply
 
LinkBack Thread Tools
Old 11-25-2003, 09:03 PM   #1 (permalink)
Over 2,500 Posts
 
dholly's Avatar
 
Join Date: May 2003
Location: Upstate NY
Posts: 3,698
Send a message via AIM to dholly
Default SH!T, I got 'parasites'!

[image]http://jabberwoq.com/images/emoticons/xbones.gif[/image] DEATH to the A**HOLE who started Download.Trojan, Adware.Binet and Belt.exe. I just spent two days cleaning some particularly insidious bugs off my network and I'm pissed. How do you guys protect against 'Parasites'?

If you don't know what I'm talking about, count your blessings. Parasites, or "unsolicited commercial software", are programs that get installed on your computer which you never asked for, and which do something you probably don’t want them to, for someone else’s profit. They will:

- plague you with unwanted advertising ('adware');
watch everything you do on-line and send information back to marketing companies ('spyware');
- add advertising links to web pages, for which the author does not get paid, and redirect the payments from affiliate-fee schemes to the makers of the software (such software is sometimes called 'scumware');
- set browser home page and search settings to point to the makers' sites (generally loaded with advertising), and prevent you changing it back ('homepage hijackers');
- make your modem (analogue or ISDN) call premium-rate phone numbers ('dialers');
- leave security holes allowing the makers of the software or, in particularly bad cases, anyone at all to download and run software on your machine;
- degrade system performance and cause errors thanks to being badly-written;
- provide no uninstall feature, and put its code in unexpected and hidden places to make it difficult to remove.

The problem with AntiVirus software is that, technically, most unsolicited commercial software isn’t viral: it doesn’t spread from computer to computer, it just installs and runs on one system.

That doesn’t mean it’s not harmful, but AntiVirus software does not attempt to detect all software that could be harmful. Whether it should is a tricky argument that ends up a question of where you draw the line. Actually some AntiVirus programs do detect some of the parasites, but not nearly all, and certainly not all versions of them. Parasites that install using IE security holes are more likely to be targeted by the AntiVirus software vendors, but the selection of targets seems for the most part to be pretty arbitrary.

In addition to all MS and daily NAV Live Updates, I use ZoneAlarm and PanicWare PopUp Stopper, plus AdAware and SpyBot Search & Destroy to kill parasites that make it through the firewalls. The aforementioned buggers got through my 1.) hardware firewall; 2.) router IP firewall; 3.) XP Pro LAN firewall; 4.) ZoneAlarm firewall; 5.) Symantec NAV Pro. They could not be completely removed by NAV in Safe Mode with System Restore disabled. I actually had to brave Registry changes. Very scary, one wrong digit and you're dead, but found help on the TECH SUPPORT GUY Forums.

Obviously, anti-parasite software that works as a complement to AntiVirus software is as important as teh AntiVirus software itself. But this is only a fix after the fact, not a preventative measure, and I getting sick of the network maintenance.

So, IS THERE ANYTHING ONE CAN DO TO STOP PARASITES FROM GETTING ONBOARD IN THE FIRST PLACE? Any helpful suggestions?

Thanks, maybe we got an expert on the board?

2004 | 6MTs | Diamond Graphite/Graphite
Upstate NY

dholly is offline   Reply With Quote
Sponsored Links
Advertisement
 
Old 11-26-2003, 10:28 AM   #2 (permalink)
Over 2,500 Posts
 
Join Date: Jul 2003
Location: USA
Posts: 3,952
Default

Try Ad-Aware. It's a great tool for removing spyware and other parasites.

2003.5 Sedan 6MT | Sport/Aero/Premium | Desert Platinum/Willow | 350Z intake | Pictures
struan87 is offline   Reply With Quote
Old 11-26-2003, 10:41 AM   #3 (permalink)
Over 500 Posts
 
Join Date: Jun 2003
Location: USA
Posts: 869
Default

also Spybot Search & Destroy is a good one. I know a bunch of people that use both.

---------------
AIM: Sirmilton3
MSN: Sirmilton22@hotmail.com
'03.5 6MT Sedan | Brilliant Silver | Graphite Leather | Premium | Aero | Heated Seats
Sirmilton is offline   Reply With Quote
Old 11-26-2003, 11:00 AM   #4 (permalink)
Over 2,500 Posts
 
dholly's Avatar
 
Join Date: May 2003
Location: Upstate NY
Posts: 3,698
Send a message via AIM to dholly
Default

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">In addition to all MS and daily NAV Live Updates, I use ZoneAlarm and PanicWare PopUp Stopper, plus AdAware and SpyBot Search & Destroy to kill parasites that make it through the firewalls.<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">Thanks, already use 'em both. (I know it's a long read, but I needed to vent and it was therapeutic!)

Question is...is there any way WAY TO PREVENT getting bugged in the first place??? I don't like the feeling of venerability on a business network but need to be connected. Some smart soul has the answer!

2004 | 6MTs | Diamond Graphite/Graphite
Upstate NY

dholly is offline   Reply With Quote
Old 11-26-2003, 11:15 AM   #5 (permalink)
Over 2,500 Posts
 
Join Date: Jul 2003
Location: USA
Posts: 3,952
Default

The best way is to be careful what you download. I know lots of people who see a popup and say "WHY YES I WOUDL LIEK TOO GET UP-TOO-TEH-MINUTE WETHER REPORTS!!!!!!1", then download weatherbug and the 50 spywre programs packaged with it. That's an obvious one, but lots of other seemingly innocuous software packages have spyware in them. But no matter how careful you are, something will get in. It's inevitable when you consider the amount of effort being poured into it by marketers.

2003.5 Sedan 6MT | Sport/Aero/Premium | Desert Platinum/Willow | 350Z intake | Pictures
struan87 is offline   Reply With Quote
Old 11-26-2003, 12:07 PM   #6 (permalink)
Over 1,000 Posts
 
Join Date: Jul 2003
Location: USA
Posts: 1,768
Send a message via AIM to bizz
Default

[timebomb]

<font face="Verdana"><center>2003.5 Infiniti G35 Sedan | Brilliant Silver - Graphite Leather - Premium Package - Winter Package - Auto
350z intake tube - stillen cai - clear corners - skyline pedals - diomand subs
View my car at http://www.cardomain.com/memberpage/440604/</center></font id="Verdana">
bizz is offline   Reply With Quote
Old 11-26-2003, 01:11 PM   #7 (permalink)
Over 2,500 Posts
 
dholly's Avatar
 
Join Date: May 2003
Location: Upstate NY
Posts: 3,698
Send a message via AIM to dholly
Default

Stru, I take the security of my office network seriously - my livlihood depends on it. I never open pop-ups that make it through my blocker. No XXX surfing at the office either.

When you already run effective pop-up blocker and AntiVirus software, it's just frustrating as hell to have to spend the time to manually hunt the buggers down when your AntiVirus and parasite removal tools cannot catch or completely delete them. Better to effectively "head 'em off at the pass", if possible.

Here's two additional changes I made yesterday.

Problem: Dynamically inserted HTML fragments by parasites. Any application that hosts the WebBrowser control (5.5+) is affected since this exploit does not require Active Scripting or ActiveX. Some of these applications are:
Microsoft Internet Explorer
Microsoft Outlook
Microsoft Outlook Express

Solution: Since the injected <object> runs in the "My Computer" Zone changing the Internet Zone's settings wouldn't affect it, but changing the correct zone's settings will prevent this exploit from running.

Here is the registry information:

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVe rsionInternet Settingsones\0]

You need to change the value of "1004" (DWORD) to 3. (Click on "1004" to change value) For more detail go to: GreyMagic Security Advisory GM#001-IE

Problem: AdWare, SpyWare, etc. get thru firewalls.

Solutions: With IE running, got to Tool>Internet Options>Advanced Tab. Then scroll to "Browsing" and DE-SELECT both "Enable Install on Demand (Internet Explorer)" and "Enable Install on Demand (Other)" option boxes. Click OK. I had the first one disabled but not the latter. We'll see if this helps block those that otherwise would make it thru.

Disclaimer: These tips come from a Tech forum, use at your own risk.


2004 | 6MTs | Diamond Graphite/Graphite
Upstate NY

dholly is offline   Reply With Quote
Old 11-26-2003, 01:16 PM   #8 (permalink)
Over 2,500 Posts
 
Join Date: Jul 2003
Location: USA
Posts: 3,952
Default

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">Originally posted by dholly

Stru, I take the security of my office network seriously - my livlihood depends on it. I never open pop-ups that make it through my blocker.
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
Certainly, I didn't mean to imply that you didn't. I was just venting about people I know that don't.[banghead]

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">
No XXX surfing at the office either.
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
I like how you made sure to qualify that... [boink]

2003.5 Sedan 6MT | Sport/Aero/Premium | Desert Platinum/Willow | 350Z intake | Pictures
struan87 is offline   Reply With Quote
Old 11-26-2003, 01:33 PM   #9 (permalink)
Over 2,500 Posts
 
dholly's Avatar
 
Join Date: May 2003
Location: Upstate NY
Posts: 3,698
Send a message via AIM to dholly
Default

I won't even open an email attachment from my own mother unless its pre-qualified and scanned! And, I abhor poeple who refuse to spend $20 to protect themselves and, more importantly, to prevent the spread of virus' to others. Most are simply ignorant but they cause alot of damage. Now, regarding my personal viewing preferences, the laptop I have hooked up to a DLP HD projector and 12' screen in the home theater room has been known to show some pretty funky stuff (amazing all the things you miss with a tiny monitor!). [bigeyes]

2004 | 6MTs | Diamond Graphite/Graphite
Upstate NY

dholly is offline   Reply With Quote
Old 11-26-2003, 02:11 PM   #10 (permalink)
Over 2,500 Posts
 
Join Date: Jul 2003
Location: USA
Posts: 3,952
Default

I'll have to try that []

2003.5 Sedan 6MT | Sport/Aero/Premium | Desert Platinum/Willow | 350Z intake | Pictures
struan87 is offline   Reply With Quote
Old 11-26-2003, 02:40 PM   #11 (permalink)
Over 1,000 Posts
 
Join Date: Mar 2003
Location: USA
Posts: 1,738
Default

My advice:

Get a Mac. (as I put on my flame retardant suit)

[]

lead_foot is offline   Reply With Quote
Old 11-26-2003, 02:50 PM   #12 (permalink)
Over 2,500 Posts
 
dholly's Avatar
 
Join Date: May 2003
Location: Upstate NY
Posts: 3,698
Send a message via AIM to dholly
Default

I got nothin against MACs, but I think the prob begins with Mr. Softie's IE. Other browsers don't seem to suffer from the same exploitable loopholes in their code. Another popular MS app, Outlook, is a PITA to police on a corporate network. I know MANY Co.'s that have dumped it in favor of Eudora. I'm just trying not to make this a second career.

2004 | 6MTs | Diamond Graphite/Graphite
Upstate NY

dholly is offline   Reply With Quote
Old 11-26-2003, 03:10 PM   #13 (permalink)
Over 2,500 Posts
 
dholly's Avatar
 
Join Date: May 2003
Location: Upstate NY
Posts: 3,698
Send a message via AIM to dholly
Default

OK, now I KNOW I'm being followed. Just noticed that the "Ads by Google" to the right of this post review area include:

SpyKiller SpyWare Remover
enigmasoftware SpyWare/Adware Remover
StopSign Free Spyware Remover
Free SpyCleaner

WTF!?? I must be in the Twilight Zone!

2004 | 6MTs | Diamond Graphite/Graphite
Upstate NY

dholly is offline   Reply With Quote
Old 11-26-2003, 05:11 PM   #14 (permalink)
Over 2,500 Posts
 
Join Date: Jul 2003
Location: USA
Posts: 3,952
Default

<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote">Originally posted by dholly
SpyKiller SpyWare Remover
enigmasoftware SpyWare/Adware Remover
StopSign Free Spyware Remover
Free SpyCleaner
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">
I think it targets the ads based on the text in the thread. I've seen ads for WRXs in threads talking about them.

2003.5 Sedan 6MT | Sport/Aero/Premium | Desert Platinum/Willow | 350Z intake | Pictures
struan87 is offline   Reply With Quote
Old 11-26-2003, 05:53 PM   #15 (permalink)
Over 2,500 Posts
 
dholly's Avatar
 
Join Date: May 2003
Location: Upstate NY
Posts: 3,698
Send a message via AIM to dholly
Default

Yeah I know, but I thought it was kinda funny given the thread topic.

On a serious note to those who use them, how often do you do your AdAware and SpyBot scans? Ever find a bug they (or your AV) couldn't kill?

2004 | 6MTs | Diamond Graphite/Graphite
Upstate NY

dholly is offline   Reply With Quote
Reply


  6MT.net Infiniti G35/G37/GTR Forums > Off-Topic Discussion > Totally Off Topic




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Powered by vBadvanced CMPS v2.2.1 (vB 3.6)

All times are GMT -5. The time now is 05:57 AM.

Powered by vBulletin Version 3.6.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2006, 6MT.net. All Rights Reserved.
  • AutoForums.com
  • Truck
  • European
  • Import
  • Domestic
  • Manufacturer

AutoForums.com is the premier network of enthusiast-owned enthusiast-operated automotive communities.
We operate more than 100 automotive forums where our users consult peers for shopping information and advice, and share experiences and opinions as a community.

Visit AutoForums.com today.

For advertising information, please visit our AutoForums.com website and Contact Us, or send an email message to sales@autoforums.com.