1. SPS Accounts:
    Do you find yourself coming back time after time? Do you appreciate the ongoing hard work to keep this community focused and successful in its mission? Please consider supporting us by upgrading to an SPS Account. Besides the warm and fuzzy feeling that comes from supporting a good cause, you'll also get a significant number of ever-expanding perks and benefits on the site and the forums. Click here to find out more.
    Dismiss Notice
Dismiss Notice
You are currently viewing Boards o' Magick as a guest, but you can register an account here. Registration is fast, easy and free. Once registered you will have access to search the forums, create and respond to threads, PM other members, upload screenshots and access many other features unavailable to guests.

BoM cultivates a friendly and welcoming atmosphere. We have been aiming for quality over quantity with our forums from their inception, and believe that this distinction is truly tangible and valued by our members. We'd love to have you join us today!

(If you have any problems with the registration process or your account login, please contact us. If you've forgotten your username or password, click here.)

Virus/Popup

Discussion in 'Sorcerous Sundries' started by dman18, Aug 30, 2003.

  1. dman18 Gems: 9/31
    Latest gem: Iol


    Joined:
    Apr 6, 2003
    Messages:
    340
    Likes Received:
    0
    I went to a website called wildbillsatlanta.com and i think that it installed one of the popup things on my computer. Or it might have been a virus. Everytime I get on the internet it gives me a weird homepage, usually about womens health. Then, a popup comes that covers the whole screen, task bar and all, and there is no way to get out of it besides Alt, Ctrl, Delete, then end the task. It usually comes up with a virus alert or this message will self distruct in x seconds. With the virus alert one, it looks like a written script, obviously not a real virus alert, but it says, "If you have a virus you CDROM Drive will eject, then press enter." Another full-screener comes up thats blank except saying press enter, when you do, the CDROM drive pops open and this really freaky laugh is sounded.

    I know that there have been similar posts about popups and viruses, but I would like to know if anyone else has experienced this and also I would like to know how to check for the stuff on my computer files. THe reason I posted in SS is because the first full-screen virus alert thing came up when i was in SP and the SP chatroom, not mIRC. I didn't know if one of the advertisers did it or if i did get it from the Wild Bills website.
     
  2. Wordplay Gems: 29/31
    Latest gem: Glittering Beljuril


    Joined:
    Oct 14, 2002
    Messages:
    3,453
    Likes Received:
    1
    Question #1: Do you have a firewall? You know, without it any program can eject your CD drive... thingie... via internet.

    Question #2: Do you have a virus scanner? If not, install a free one (like F-PROT), scan, and uninstall it if you wish.

    Question #3: Are you sure you don't have a trojan? To me it sounds like one (hijacking your homepage, showing pop-ups...) Visited pron sites lately? :D
     
  3. dman18 Gems: 9/31
    Latest gem: Iol


    Joined:
    Apr 6, 2003
    Messages:
    340
    Likes Received:
    0
    1. Yes, I am in the utmost certainty that I have a firewall, considering my brother and I configured this computer.

    2. Yes, we have Norton antiviru, which I'm pretty sure is the latest version, if not, second latest version, which could mean problems.

    3. No, I haven't visited any porn sites on this computer considering i am usually only here for two days every two weeks. But a Trojan might be a likely answer. I have scanned but it picked up nothing, besides the odd "Got out of quarantine virus" which i have deleted.

    WHat I think happened was it just changed my hompepage, which i have changed back, and the homepage was causing the weird pop ups, I will keep scanning for viruses and keep checking my system so keep the advice coming.
     
  4. Ahrontil Gems: 8/31
    Latest gem: Skydrop


    Joined:
    May 26, 2003
    Messages:
    272
    Likes Received:
    0
    Short answer, go here
    http://www.microsoft.com/downloads/details.aspx?FamilyId=36814221-8194-4492-BB29-94DB3D4CB682&displaylang=en


    I've said it before and I'll say it again;

    Don't ever tell your priest, don't ever tell your doctor and don't ever tell a living soul, that you like country music. ;)

    Wild Bill's site is OK, it doesn't even try to download an ad-tracking cookie. (Its claim to have the prettiest girls this side of the Mississippi might be stretching the truth a bit, but hey, it's all just healthy thigh slapping farm boy fun, yeeha!)

    For the webpage to play sounds it needs either Java or ActiveX operational on your machine (it's what allows the swirling cursor follower on Boss Hoggs, sorry, I mean Wild Bill's site to work), which is fine as both are 'almost completely sandboxed' so that they can only manipulate the files on your machine that have been downloaded from the same source site that the executable came from.

    What is altogether more sinister is the cd drive opening. In truth it is normally just built in ActiveX functionality being abused.


    Techno, techno, techno,

    An ActiveX control included with Windows Media Player 9 Series allows Web page authors to create Web pages that can play media and provide a user interface by which the user can control playback. When a user visits a Web page with embedded media, the ActiveX control provides a user interface that allows the user to take such actions as pausing or rewinding the media.

    'Its worse than that, he's dead Jim.'

    A flaw exists in the way in which the ActiveX control provides access to information on the user’s computer. A vulnerability exists because an attacker could invoke the ActiveX control from script code, which would allow the attacker to view and manipulate metadata contained in the media library on the user’s computer. (From Microsoft Technet)


    What the exploit hacker has probably done with your CD-Rom is insignificant when compared to the true capabilities of this vulnerability .


    There is a safe example here. Use it to check the final cure worked. It should eventually report 'Error On Page' on the status bar.

    http://jscript.dk/2001/3/cdrom.jpg

    It's From
    http://lists.netsys.com/pipermail/full-disclosure/2003-June/006079.html

    Full thread
    http://lists.netsys.com/pipermail/full-disclosure/2003-June/006074.html

    And the 1.9MB Microsoft Patch
    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-021.asp

    Or the hand holding, patch everything in sight regardless of the time needed page.( Valid CD Key required for each machine on your network for SP1a patch)

    http://www.microsoft.com/security/security_bulletins/ms03-021.asp


    Please note Trojans also can open your CD. Use a virus checker(AVG trialware from Grisoft is free, and only slightly restricted) to make sure your computer is clean, and don't indulge in unprotected textual intercourse with strange computers.

    Standard list of checks to stay safe.
    Operating system updates.
    Application updates.
    Virus scan.
    Ad-Aware scan.
    Zonealarm server restrictions
    No unnecessary folder shares enabled


    You can also turn off Java and ActiveX and restrict cookies, but the internet will suddenly become a much more frustrating place. Its a risk that most people are still safe enough to take, just don't leave personal details on your computer.
     
  5. dman18 Gems: 9/31
    Latest gem: Iol


    Joined:
    Apr 6, 2003
    Messages:
    340
    Likes Received:
    0
    Yea, thanks Bluin. But I figured out that it was something my mom's boyfriend went to that changed the homepage and the homepage was causing it. I think i just kinda got scared that night becaus emy mom's hardrive crashed a month ago, and two weeks ago she got the Blaster_Worm, and it was midnight and my cat was chasing what i now realize was a lizad and i was just over all freked out when my computer laughed at me. So its all good now.
     
  6. The Great Snook Gems: 31/31
    Latest gem: Rogue Stone


    Adored Veteran

    Joined:
    May 15, 2003
    Messages:
    4,123
    Media:
    28
    Likes Received:
    313
    Gender:
    Male
    Actually it may have been SP's fault. I got the same thing and it changed my home page also.
     
  7. Errol Gems: 23/31
    Latest gem: Black Opal


    Joined:
    Oct 23, 2001
    Messages:
    1,547
    Likes Received:
    0
    Gender:
    Male
    Actually, it can't be 'SP's fault' because Tal has already said he's got no power over what pop-ups feature on the site. Sure, it could be the pop-ups' fault, but not SP's.

    ;)
     
Sorcerer's Place is a project run entirely by fans and for fans. Maintaining Sorcerer's Place and a stable environment for all our hosted sites requires a substantial amount of our time and funds on a regular basis, so please consider supporting us to keep the site up & running smoothly. Thank you!

Sorcerers.net is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to products on amazon.com, amazon.ca and amazon.co.uk. Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates.