Jump to content

Vundo


Recommended Posts

Guest pcdevelop
Posted

Re: Caution! Re: Vundo

 

1) OneClick Spyware Expert has nothing similar with rogue products or

spyware

2) If you have no objective arguments - pls keep silent!

"jen" <jen@example.com> wrote in message

news:OYRZDTcHJHA.788@TK2MSFTNGP06.phx.gbl...<span style="color:blue">

> "pcdevelop" <biz0008@gmail.com> wrote in message

> news:%234zL%23eVHJHA.1156@TK2MSFTNGP05.phx.gbl...<span style="color:green">

>> How do you know that you are infected exactly by Vundo?

>> Try Quick Scan using OneClick Spyware Expert -

>> hxxp://privacy-care.com/bin/SpywareExpertInstall.exe

>> "Mhaxx" <supermhaxx@despammed.com> wrote in message

>> news:gba8tf$f0q$1@tdi.cu.mi.it...<span style="color:darkred">

>>> I'm afraid to have trojan Vundo: how to be sure to have it?

>>> I've just launched Spybot and NOD32 and they haven't detected anything.

>>> Please, tell me!

>>> P.S. maybe you need the HiJackThis log?</span></span>

>

> This domain(check it out) and poster appears very dodgy!

> I would not click or go there...

>

> -jen

>

>

> </span>

Posted

Re: Caution! Re: Vundo

 

Don't despair, Massimo!

 

I downloaded it too - just to test - and my PC is still functioning! I shall uninstall it though.

 

My best advice is that having already been 'hit' a completely clean reinstallation should be

undertaken - remove partions and format. However, if you don't wish to go that far, you could try

scanning with Malwarebytes - here's a link to their web site:- www.malwarebytes.com

 

Hope this is of help!

 

Dave

 

--

"Mhaxx" <supermhaxx@despammed.com> wrote in message news:gbcs48$tg5$1@tdi.cu.mi.it...<span style="color:blue"><span style="color:green">

>> This domain(check it out) and poster appears very dodgy!

>> I would not click or go there...</span>

>

> Oh.. I downloaded the "OneClick Spyware Expert" and scanned my PC. Is there

> any risk? :-(

>

> Massimo

>

>

> P.S. no Vunde found

>

>

> </span>

Guest Peter Foldes
Posted

Re: Caution! Re: Vundo

 

Not according to the link you posted ding bat. Here I post it for your convenience

 

You posted

 

http://pqlr.org/bbs/viewtopic.php?t=1171

 

MY my how your story keeps changing as per your son now. I can post what you posted about 2 years ago,

 

Besides being a Troll and a royal pain you also are showing signs of having the Alzheimer desease.

 

David I will now stop with this and this is the last reply to you here

 

Bye and have a nice day

 

 

--

Peter

 

Please Reply to Newsgroup for the benefit of others

Requests for assistance by email can not and will not be acknowledged.

 

"~BD~" <BoaterDave@nospam.invalid> wrote in message news:eYMCaphHJHA.1160@TK2MSFTNGP05.phx.gbl...<span style="color:blue">

> You have become very confused, Peter. Perhaps it is your advancing years and/or the stroke you

> suffered too.

>

> I'm pleased to report that my surviving son has now completed his service with the USAF and has

> brought my grandsons back to the UK! style_emoticons/

>

> FYI - there is no requirement to 'sign-in' to Jenn's BB - all are free to explore!

>

> Dave

>

> <snip>

>

></span>

Guest David H. Lipman
Posted

Re: Caution! Re: Vundo

 

From: "pcdevelop" <biz0008@gmail.com>

 

| 1) OneClick Spyware Expert has nothing similar with rogue products or

| spyware

| 2) If you have no objective arguments - pls keep silent!

 

You mean arguments like the bogus phone number in the site's registration ?

 

Or the fact the ESTDomains is so well know for its connections to hosting malware

especially fake anti malware ?

 

Or the fact there is ZERO real information at; hxx//privacy-care.com

 

Or the fact this is supposed to be a NEW anti malware (July) and the site was registered

in May ?

 

Or the fact that the web site indicates that teh Zafi worm, Netsky and Bagle were the "top

threats in the last 24 hours".

 

and BTW, is it "Pricacy-care Lab" and "PricacyCare Lab." when this is supposed to be

"English" and the site is registered from Hazard Kentucky ?

 

 

 

--

Dave

http://www.claymania.com/removal-trojan-adware.html

Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp

Guest pcdevelop
Posted

Re: Caution! Re: Vundo

 

I meant arguments concerning application OneClick Spyware Expert, not site. Thank you for constructive criticism, Dave!

 

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message news:um0RtEjHJHA.4060@TK2MSFTNGP03.phx.gbl...<span style="color:blue">

> From: "pcdevelop" <biz0008@gmail.com>

>

> | 1) OneClick Spyware Expert has nothing similar with rogue products or

> | spyware

> | 2) If you have no objective arguments - pls keep silent!

>

> You mean arguments like the bogus phone number in the site's registration ?

>

> Or the fact the ESTDomains is so well know for its connections to hosting malware

> especially fake anti malware ?

>

> Or the fact there is ZERO real information at; hxx//privacy-care.com

>

> Or the fact this is supposed to be a NEW anti malware (July) and the site was registered

> in May ?

>

> Or the fact that the web site indicates that teh Zafi worm, Netsky and Bagle were the "top

> threats in the last 24 hours".

>

> and BTW, is it "Pricacy-care Lab" and "PricacyCare Lab." when this is supposed to be

> "English" and the site is registered from Hazard Kentucky ?

>

>

>

> --

> Dave

> http://www.claymania.com/removal-trojan-adware.html

> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp

>

>

></span>

Posted

Re: Caution! Re: Vundo

 

"Mhaxx" <supermhaxx@despammed.com> wrote in message news:gbd2l7$64f$1@tdi.cu.mi.it...<span style="color:blue"><span style="color:green">

>> scanning with Malwarebytes - here's a link to their web site:-</span>

> www.malwarebytes.com

>

> I can't download: can you?

>

> Massimo

>

>

></span>

 

Hello again!

 

I just tested a download - and, yes, I can!

 

If you have access to another computer, download the programme and burn to a CD. There's a chance

you will then be able to run it on your own computer.

 

Are you able to access the Internet at the moment? Can you download anything at all? I know how

frustrated you must be feeling. I'm sorry it took a while to come back to you!

 

Dave

Guest Peter Foldes
Posted

Re: Caution! Re: Vundo

 

Here you go. You can download it from this link

http://www.download.com/Malwarebytes-Anti-...4-10804572.html

--

Peter

 

Please Reply to Newsgroup for the benefit of others

Requests for assistance by email can not and will not be acknowledged.

 

"Mhaxx" <supermhaxx@despammed.com> wrote in message news:gbd2l7$64f$1@tdi.cu.mi.it...<span style="color:blue"><span style="color:green">

>> scanning with Malwarebytes - here's a link to their web site:-</span>

> www.malwarebytes.com

>

> I can't download: can you?

>

> Massimo

>

></span>

Guest FromTheRafters
Posted

Re: Caution! Re: Vundo

 

"Mhaxx" <supermhaxx@despammed.com> wrote in message

news:gbcs48$tg5$1@tdi.cu.mi.it...<span style="color:blue"><span style="color:green">

>> This domain(check it out) and poster appears very dodgy!

>> I would not click or go there...</span>

>

> Oh.. I downloaded the "OneClick Spyware Expert" and scanned my PC. Is

> there

> any risk? :-(</span>

 

Yes, had it been new malware you would have bitten by it.

I'm not saying it is or it isn't - only that what you describe is

bad behavior securitywise.

 

I'm assuming here that you have some anti-malware scanning

software running to attempt to find malware "on access" - but

if you don't, things are even worse than I thought.

 

The best approach (if you insist on running unneeded programs)

is to download them and have them scanned 'thoroughly' by as

many malware detectors as you can muster - then wait as long

as you can and do it again (to lessen the day zero threat). If it

still appears to be clean (that is 'no malware found' which isn't

really the same as clean ) then go ahead and run it.

 

You still take your chances, but at least a good attempt was

made at safe practice.

Guest David H. Lipman
Posted

Re: Caution! Re: Vundo

 

"pcdevelop" <biz0008@gmail.com> wrote in message

news:ur2ZEljHJHA.4296@TK2MSFTNGP02.phx.gbl...

I meant arguments concerning application OneClick Spyware Expert, not site. Thank you for

constructive criticism, Dave!

 

You mean like obfuscating information in supposed JPEGs through XOR 19 ?

 

--

Dave

http://www.claymania.com/removal-trojan-adware.html

Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp

Guest Andrew Taylor
Posted

Re: Caution! Re: Vundo

 

"~BD~" <BoaterDave@nospam.invalid> wrote in message

news:eYMCaphHJHA.1160@TK2MSFTNGP05.phx.gbl...<span style="color:blue">

>

> FYI - there is no requirement to 'sign-in' to Jenn's BB - all are free to

> explore!

></span>

David

 

I also got " Please enter your username and password to log in. "

 

It seems to be a religious site anyway?

Posted

Re: Caution! Re: Vundo

 

See below

 

"Andrew Taylor" <andrewcrumplehorn@spamcopSUBVERSIVE.com> wrote in message

news:48db0f93$1@newsgate.x-privat.org...<span style="color:blue">

> "~BD~" <BoaterDave@nospam.invalid> wrote in message news:eYMCaphHJHA.1160@TK2MSFTNGP05.phx.gbl...<span style="color:green">

>>

>> FYI - there is no requirement to 'sign-in' to Jenn's BB - all are free to explore!

>></span>

> David

>

> I also got " Please enter your username and password to log in. "

>

> It seems to be a religious site anyway?

>

></span>

 

 

Hello Andrew - I trust you are keeping well. Are you still at work?

 

Good to hear from you after such a long time. It's very lonely out here in cyberspace all by myself!

:-(

 

Regardless - see what you find here http://www.malwarebytes.org/forums/index.php?showtopic=6481

 

I'm really sorry about the previous link I posted - I 'logged out' and tried again and had the same

result as you and Peter evidently did. 'My bad' as I've learnt to say! style_emoticons/ I've used Jenn's BB as

a place to store possibly helpful reminders for me - and also as bait ........ 'cause bad guys

always make mistakes - eventually!

 

If you'd like to come and join the group let me know either here, at 'boaterdave at hotmail.co.uk'

or at my AOL address if you still have it. I'll then advise Jenn who has had much trouble with SPAM.

Maybe there are posts which you can read without being a Member - if you can only see those of a

religious nature I'd be very interested to know (damn good cover eh? <wink>)

 

Warm regards,

 

Dave

 

--

Posted

Re: Caution! Re: Vundo

 

Now I can, thanks.

 

It seems I don't have the virus/malware.. that's good, thanks a lot to all.

 

Massimo

Posted

Re: Caution! Re: Vundo

 

> > Oh.. I downloaded the "OneClick Spyware Expert" and scanned my PC. Is<span style="color:blue"><span style="color:green">

> > there

> > any risk? :-(</span>

>

> Yes, had it been new malware you would have bitten by it.

> I'm not saying it is or it isn't - only that what you describe is

> bad behavior securitywise.</span>

 

Has someone tried to download and run that file other me?

 

Anyway no new virus/malware seems to be there after I scanned my PC with

that program. I hope so.. :-(

 

Massimo

Guest FromTheRafters
Posted

Re: Caution! Re: Vundo

 

"Mhaxx" <supermhaxx@despammed.com> wrote in message

news:gbfqf9$r8o$1@tdi.cu.mi.it...<span style="color:blue"><span style="color:green"><span style="color:darkred">

>> > Oh.. I downloaded the "OneClick Spyware Expert" and scanned my PC. Is

>> > there

>> > any risk? :-(</span>

>>

>> Yes, had it been new malware you would have bitten by it.

>> I'm not saying it is or it isn't - only that what you describe is

>> bad behavior securitywise.</span>

>

> Has someone tried to download and run that file other me?</span>

 

Probably, many people have unsafe computing habits. I'm not

chastising you, it's just information for anybody reading.<span style="color:blue">

>

> Anyway no new virus/malware seems to be there after I scanned my PC with

> that program. I hope so.. :-(</span>

 

I'm sure if one of the experts here knew it was definitely bad

he or she would post to caution you - and provide guidance.

Guest David H. Lipman
Posted

Re: Caution! Re: Vundo

 

From: "jen" <jen@example.com>

 

| "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message

| news:uP6xVQdHJHA.944@TK2MSFTNGP03.phx.gbl...<span style="color:blue"><span style="color:green">

>> From: "jen" <jen@example.com>

>> | Have you checked out the SpywareExpertInstall.exe that was posted

>> yet?

>> Of course, when it was first posted there was 1 heuristic on VT on the

>> Inno Setup.

>> Today, no hits on VT.

>> Further examination is forthcoming...</span></span>

 

| Good... Let us know the results style_emoticons/

 

| -jen

 

 

Registration Service Provided By: YOUR WEB POINT - E-GOLD DOMAIN REGISTRATIONS

Contact: +7.9016156086

Website: http://www.yourwebpoint.com

 

Domain Name: PRIVACY-CARE.COM

 

Registrant:

PricacyCare Lab.

George (biz00025@gmail.com)

Rewsen

Hazard

Kentucky,41701

US

Tel. +1.80951246932

 

Creation Date: 17-May-2008

Expiration Date: 17-May-2009

 

Domain servers in listed order:

No NameServers Defined.

 

Administrative Contact:

PricacyCare Lab.

George (biz00025@gmail.com)

Rewsen

Hazard

Kentucky,41701

US

Tel. +1.80951246932

 

 

Status:SUSPENDED

Note: This Domain Name is Suspended.

 

As of yet, there is no conclusion if the software mentioned in reference to the above is

"malicious".

 

 

--

Dave

http://www.claymania.com/removal-trojan-adware.html

Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp

Posted

Re: Caution! Re: Vundo

 

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message

news:%23CiFXf1HJHA.2156@TK2MSFTNGP05.phx.gbl...<span style="color:blue">

> From: "jen" <jen@example.com>

> | "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message

> | news:uP6xVQdHJHA.944@TK2MSFTNGP03.phx.gbl...<span style="color:green"><span style="color:darkred">

>>> From: "jen" <jen@example.com>

>>> | Have you checked out the SpywareExpertInstall.exe that was posted

>>> yet?

>>> Of course, when it was first posted there was 1 heuristic on VT on

>>> the

>>> Inno Setup.

>>> Today, no hits on VT.

>>> Further examination is forthcoming...</span></span>

> | Good... Let us know the results style_emoticons/

> Registration Service Provided By: YOUR WEB POINT - E-GOLD DOMAIN

> REGISTRATIONS

> Contact: +7.9016156086

> Website: http://www.yourwebpoint.com

>

> Domain Name: PRIVACY-CARE.COM

>

> Registrant:

> PricacyCare Lab.

> George (biz00025@gmail.com)

> Rewsen

> Hazard

> Kentucky,41701

> US

> Tel. +1.80951246932

>

> Creation Date: 17-May-2008

> Expiration Date: 17-May-2009

>

> Domain servers in listed order:

> No NameServers Defined.

>

> Administrative Contact:

> PricacyCare Lab.

> George (biz00025@gmail.com)

> Rewsen

> Hazard

> Kentucky,41701

> US

> Tel. +1.80951246932

>

>

> Status:SUSPENDED

> Note: This Domain Name is Suspended.

>

> As of yet, there is no conclusion if the software mentioned in

> reference to the above is

> "malicious".</span>

 

Thanks, David style_emoticons/ Please let us know the final conclusion...

 

-jen

Posted

Re: Caution! Re: Vundo

 

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message

news:%23CiFXf1HJHA.2156@TK2MSFTNGP05.phx.gbl...

[snip]<span style="color:blue">

> As of yet, there is no conclusion if the software mentioned in

> reference to the above is

> "malicious".</span>

 

BTW, it was put up on Softpedia on the 23rd...

 

OneClick Spyware Expert 1.14:

http://www.softpedia.com/get/Security/Secu...re-Expert.shtml

 

-jen

Posted

Ooops! Sorry.

 

"Andrew Taylor" <andrewcrumplehorn@spamcopSUBVERSIVE.com> wrote in message

news:48db0f93$1@newsgate.x-privat.org...<span style="color:blue">

> "~BD~" <BoaterDave@nospam.invalid> wrote in message

> news:eYMCaphHJHA.1160@TK2MSFTNGP05.phx.gbl...<span style="color:green">

>>

>> FYI - there is no requirement to 'sign-in' to Jenn's BB - all are free to

>> explore!

>></span>

> David

>

> I also got " Please enter your username and password to log in. "

>

> It seems to be a religious site anyway?

>

></span>

 

Oh dear! Sorry Andrew (and to Peter too) - Jenn must have altered things

without me noticing (I'm usually 'logged-in' all the time), but I do know

she has been bothered by bots and SPAM.

 

It isn't simply for religious matters at all. In particular I have placed

items there so that they don't get lost - easier to find there than on the

many CD's I've used to store data so that I can quickly flatten and rebuild

my 'test' computer.

 

I'm sure you will be made most welcome if you'd like to register and join me

there. It's a friendly place and my posts are not removed!

 

Are you still at work? Enjoying it?

 

Warm regards,

 

Dave

Posted

Re: Caution! Re: Vundo

 

Hi Andrew

 

Jenn's site is also very good for my 'fishing' <wink>

 

Here's a note from Jenn:- (You'll note that the IP address is that for

Peter Foldes)

 

 

 

 

jenn wrote:

NNTP-Posting-Host: modemcable208.248-70-69.mc.videotron.ca

69.70.248.208

 

Time Period:

9/19/2008 8:36:22 PM - 9/24/2008 9:16:37 PM

Hits

69.70.248.208 26 - 26 times

 

He hits my bbs and stays long enough to view and leave, looks like to

me.

  • 2 weeks later...
Posted

Re: Caution! Re: Vundo

 

Hi Peter

 

Just thought I'd let you know that the link provided should be 'working'

now.

 

HTH

 

Dave

 

--

"Peter Foldes" <okf22@hotmail.com> wrote in message

news:OoZSIxiHJHA.456@TK2MSFTNGP06.phx.gbl...

Not according to the link you posted..

 

http://pqlr.org/bbs/viewtopic.php?t=1171

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...