ATTENTION 1.0.509 release has numerous new bugs !

  • Thread starter Thread starter Travis Mitchell
  • Start date Start date
Bill said:
I'd actually like to keep these groups fairly clean--i.e. I don't want to
have a public listing of "bad" sites. Risky for inexperienced folks, not
good PR for Microsoft, etc. Some spyware vendors have threatened legal
action against posters in newsgroups, although I don't think anything has
come of it.

Well, I cancelled my search ............. ;)
 
Bill said:
Danny - I don't know how you "prepped" the system you used for this test.
Are you able to do a similar test, but, after scanning clean with .509, can
you do the step Steve Dodson suggested--do a Tools, Suspected Spyware
report, and post the URL for your report here?

Maybe then do .501, scan, clean, and another such suspected spyware report,
with a URL?

I can not duplicate the process without finding some source of
infestation. What I did is run .509 and it found no hits ran clean two
times in a row. Then I uninstalled .509 and installed .501 and got hits.
I could go back to .509 and verify that all is still clean, however,
without reinfestation I would not be able to retest. I have a floppy
disk with a file that was a .wmv file of questionable origin that use to
infest my machine when ever I wanted to, however, I recently upgraded
from ver. 9 of Windows Media Player to ver. 10 and now my infested file
will not play. That is good to know! Anyone know of a way I can tell WMP
10 to play the file any ways? I get a C00D11CD: unknown error when I try
to play the movie now. I guess I could blow away the hard drive and
reinstall without doing upgrades and patches, hate doing that though due
to time constraints.
 
JohnF. said:
I found the right address - I'm hosed now! All I'm missing is the homepage
hijacker.

JohnF.


John, can you provide a URL please, I have so many clients who get this
crap all the time and I have to go in and remove it. I try my damnest to
get infected and I can not ever find this stuff on purpose. I know this
is a MS group but I have to say that I use Netscape 7.2 and have used
Netscape since version 1. All my clients use IE, OE and O. Think that
has something to do with it? In any case give me a URL and I will resort
to using IE just for the testing.

Danny
 
Thanks--I wasn't sure whether you had a collection of perhaps similarly
infected machines at your disposal.

I can point you to some relatively "clean" sites--where you'll get just one
VX2 version, for example, but you need a good load. See if you can get
JohnF's collection, perhaps. Ideally, without posting it here, if possible.

I'm uncertain of the nature of what may be in question between the two sets
of detections--I wouldn't expect it to be the "big" stuff--so getting some
range of bugs would make for a better test. Be careful, though. If I were
doing this test, and maybe I will--I'd do it with a virtual machine, rather
than a real one.
 
Bill said:
Thanks--I wasn't sure whether you had a collection of perhaps similarly
infected machines at your disposal.

I can point you to some relatively "clean" sites--where you'll get just one
VX2 version, for example, but you need a good load. See if you can get
JohnF's collection, perhaps. Ideally, without posting it here, if possible.

I'm uncertain of the nature of what may be in question between the two sets
of detections--I wouldn't expect it to be the "big" stuff--so getting some
range of bugs would make for a better test. Be careful, though. If I were
doing this test, and maybe I will--I'd do it with a virtual machine, rather
than a real one.

I have no problem with the machine I have one machine that I refer to as
my test bed PC. Everything goes there before it goes to my production
PC, that way if thing go bad I just format and reinstall. I have a note
to JohnF maybe he can e-mail the URL's.

Danny
 
JohnF. said:
I found the right address - I'm hosed now! All I'm missing is the homepage
hijacker.

JohnF.

John, can you e-mail with some of those URL's please, Thank you.

--
Danny Kile
Certified FCC, ISCET, A+ , Network+

Please reply to the Newsgroup ONLY
Your cooperation is appreciated.
 
Back
Top