OT: Kazaa Lite K++ beware

  • Thread starter Tarapia Tapioco
  • Start date
T

Tarapia Tapioco

From: Spyware Weekly Newsletter > September 3, 2003

Surferbar: A Nasty New Hijacker

A nasty new browser hijacker/trojan has been discovered and is spreading
across the web at a rapid pace. Dozens of threads have sprung up
at the
support forums started by people infected with the Surferbar
hijacker.

There are two known variants of this hijacker currently, which
I'll call
Surferbar.a and Surferbar.AFlooder. Both variants hijack Internet
Explorer's
start page to www.surferbar.com.

Surferbar.a is a simple browser hijacker and can be cleaned up
easily using
HijackThis (download). Look for the following entries in
HijackThis and have
it remove them:

O4 - HKCU..RunOnce: [win32] c:program fileswinsrv32.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.surferbar.com/
O3 - Toolbar: SurferBar - {FF7FD490-34E7-4FA1-927A-F5799E6AAD7B}
-
c:pROGRA~1win32.dll

When you have done that, find and delete c:program
fileswinsrv32.exe.

A few victims are convinced they received Surferbar.a after
downloading and
installing Kazaa Lite K++. I haven't had a chance to clarify if
they meant the
software itself installed the hijack, if a pop up ad on a mirror
site installed it,
or if they both used the same download mirror. Presently, this
information is
very much unconfirmed. However, I recommend staying away from
Kazaa
Lite even without this problem, as it's an unauthorized cracked
version of the
real Kazaa.

Surferbar.AFlooder is rather more complicated. In addition to
hijacking the
start page and adding an unwanted toolbar, this variant appears
also to be
either a keylogger or a remote access trojan (or both), and
possibly an SMTP
proxy for spammers to use to relay spam.

Surferbar.AFlooder uses an obscure method of writing data to an
NTFS-formatted hard drive to embed itself directly into your
system32 folder.
Not inside the folder, actually embedded within the folder
itself. It sounds
nuts, but the NT File System allows that to happen using
something called
"Alternate Data Streaming" (ADS).

ADS allows you to store information "under the hood" of the file
system,
where normally you cannot see or manipulate it. Think of ADS
information as
metadata, similar to track/artist/title information that can be
stored in an MP3.
Unfortunately, Microsoft has provided no way to view or
manipulate this ADS
information without the use of third-party tools.

Fortunately, this parasite includes a not-so-secret uninstall
command, which is
revealed in a string of text within the file. If you or someone
you are helping
has been hijacked to surferbar.com, but you do not have the
winsrv32.exe
startup entry, then you probably have the AFlooder variant. Your
HijackThis
results will be similar to this:

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.surferbar.com/
O3 - Toolbar: SurferBar - {FF7FD490-34E7-4FA1-927A-F5799E6AAD7B}
-
c:pROGRA~2win32.dll
O4 - HKLM..Run: [tywsmhd] rundll32
C:WINDOWSSystem32:tywsmhd.dll,Init 1

Removing these entries with HijackThis is of no use. A program
running in
the background immediately will reinstall any entries that are
removed. Even
booting to safe mode won't help with this.

Pay attention to the path of the dll file,
C:WINDOWSSystem32:tywsmhd.dll
in the example above. The exact name of the dll will be different
each time.
Click the "Start" menu, select "Run", and type: rundll32
C:WINDOWSSystem32:tywsmhd.dll,Uninstall. Remember to change the
name of dll file to match that found on your computer. Click on
"OK", and
that should uninstall the parasite completely.

Those of you reading this online, please bear in mind that is
information was
written on September 2, 2003, and may be out of date by the time
you read
this. If these instructions do not help you remove this parasite,
please ask for
assistance at our support forums.

Links:

http://tomcoyote.org/hjt/ :: Download HijackThis
http://www.spywareinfo.com/forums/ :: SWI Forums
http://patriot.net/~carvdawg/docs/dark_side.html :: Alternate
Data Streaming explained
 
B

Boomer

Tarapia Tapioco said:
From: Spyware Weekly Newsletter > September 3, 2003

Surferbar: A Nasty New Hijacker

A nasty new browser hijacker/trojan has been discovered and is
spreading
across the web at a rapid pace. Dozens of threads have
sprung up
at the
support forums started by people infected with the
Surferbar
hijacker. [snip]

Links:

http://tomcoyote.org/hjt/ :: Download HijackThis
http://www.spywareinfo.com/forums/ :: SWI Forums
http://patriot.net/~carvdawg/docs/dark_side.html ::
Alternate
Data Streaming explained

Thanks
 
T

Tarapia Tapioco

Since you post from a fairly notorious Italian remailer site, I guess we
all should scramble to heed your advice. Not. ;)

Up to you......

I showed the source and the links so it's the readers call. If you are not
aware of "Spyware Weekly" then I'd say it's your loss.

PS: So I post via remailers, what's up with "(e-mail address removed)"
 
A

Allen_L

Thing about it is, there is no reference I read in alt.music.mp3.kazaa, or
alt.internet.p2p and I've been using the lastests versions off and on by
both different makers of the Kazaa Lite program. Seems as these above
mentioned groups are where we would see all these 'warnings' if they were
valid. Maybe a Kazaa regular version troll planted to 'knock' the lite
versions, as you can bet the Kazaa doesn't approve of the 'no spyware' - 'no
adds' versions.

....Allen
 
3

|3iff //ullins

lucat bene, der Tarapia Tapioco <[email protected]>
goh, a hunnert truxx inero, sumwit kowz n' sumwit duxx on Wed, 3 Sep
2003 21:26:37 +0200 (CEST):
A few victims are convinced they received Surferbar.a after
downloading and installing Kazaa Lite K++
sounds like anti-kazaa lite propoganda to me. i run it and have never
been infected with anything at all...
 
3

|3iff //ullins

lucat bene, der Tarapia Tapioco <[email protected]>
goh, a hunnert truxx inero, sumwit kowz n' sumwit duxx on Thu, 4 Sep
2003 12:53:23 +0200 (CEST):
Up to you......

I showed the source and the links so it's the readers call. If you are not
aware of "Spyware Weekly" then I'd say it's your loss.
i know of it, but consider it dogdy at best.
 
3

|3iff //ullins

You can say that again. Go to google and type in "kazaalite", scroll to
the bottom and click "read the DMCA complaint".
that's hilarious! i like the way google left all the links in the
complaint that kazaa's attorneys objected to. just for reference, here
they are:

(i'll bet kazaa lite can be downloaded at some of these addresses)

a. http://www.kazaagold.com
b. http://mp3download.com
c. http://www.kazaalite.tk
d. http://www.kaaza.com
e. http://doa2.host.sk
f. http://www.k-lite.tk
g. http://www.kazaa-file-sharing-downloads.com
h. http://www.kazaalite.nl
i. http://home.hccnet.nl/h.edskes/mirror.htm
j. http://www.kazaa-download.de
k. http://www.zeropaid.com
l. http://www.kazaalite.nl/downloads.htm
m. http://kazaa.infos-du-net.com
n. http://www.kazaa-lite.tk
o. http://www.kazaa-lite.info

and kazaa lite can even be gotten here, i'll wager:
http://www.freecodecs.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top