Maker Pro
Maker Pro

Bogus Warning Message @DataSheetCatalog.com

  • Thread starter Watson A.Name - Watt Sun, Dark Remover
  • Start date
A

Active8

You should check your history. Sun made JAVA. Billy took it, and
changed it. Now, there are two forms.

Not. Billy changed Java but Javascript is not java. Java compiles
to a binary that you need a Virtual Machine to run. Javascript is
not compiled. It is the glue that binds the DOM and DHTML. Netscrap
has some pretty good refs on Javascript, DOM, and DHTML. But not a
word on Java. Sun has a kinda cool Java mascott, too. His name is
Duke.
Mozilla, and Netscape stayed true to the EULA of SUN and use THEIR
JAVA, the correct one.

Billy uses his, the one he screwed with such that it is incompatible
with the original author's product.

I finally got the latest Sun JVM on this box. I used to get
messages saying I needed to douwnload MS JVM (which was already
installed with XP. to run embedded applets. Clicking the OK button
would take me to a 40x page unavailable or not found deal at MS and
after closing that winder, the applet would run. So after getting
Sun JVM, evrything was cool, until I loaded a new app. The
installer needed MS JVM. AAARRRRGGGHHH!!!! back to square one, I
are. I have to keep notes on what to install first so I'm not back
and forth and formatting and reloading and hacking my registry.

Linux rules!
 
A

Active8

I may have seen that as a pat of another app, but can't remember.
It scared me though since the host file is used to redirect URLs to
IP addys. so if I have a popup ad coming from ads.craphead.com

I can redirect to 127.0.0.1 and it won't be found.
You're a good detective. You can run this by the guys at
news.grc.com and see what they know. They may have a discussion on
this already.


Thanks, I wouldn't doubt it if there is a thread already. I hope so
anyways, because another .EXE file just downloaded and executed itself![/QUOTE]

ouch!! That's worse than those friggin' pages that change your
start up or home page for you. Some of the craftier one's write the
registry to change it back on OS load.
I
have no idea what can possibly be allowing these seemingly random executable
files to be (apparently downloaded) and ran - there are no unusual
processes, scheduled tasks, registry "run" keys, nothing. I just checked
spyware again, 37 new spyware components... "NCase",

NCase... that's weird. Encase is the forensic software the FBI uses
to try to recover deleted and supposedly wiped files. I like to use
it to test my wipe utils.

"Hijacker.nCase",
"tribalfusion", "bluestreak", etc... all new.

Shit. I'd be backing up and reformatting at this point. It could
take a while for the new AdAware defs to catch up if this is new,
but GRC is usually on top of this crap.
How in the bloody hell? It's almost as if I've been "hacked," as impossible
as that sounds. Very devious, whatever is going on. I've searched and there
are no new anti-virus updates or spyware updates and no new threats listed.
I'm uber-careful about this sort of thing and always clean up all spyware
after installing anything... perhaps a legitimate program has been hijacked,
and keeps re-infecting the system? Wish I knew more about what was going on.
Thanks for the link, I'll let us know if this is just an isolated incident
or if someone has found yet another nasty backdoor in M$ winblows. :)

Please do. I'd be grateful.
P.S. I did find a nifty website for info on this sort of thing... check out
this amazing site: http://www.pestpatrol.com

Regards,
Mark

ok. as soon as I put my lead suit on :)
 
P

Paul Burridge

ok. as soon as I put my lead suit on :)

Interesting site. Is the Windows system file spoolsv.exe M$ spyware,
does anyone know? My firewall flags it up as trying to send something
out every time I connect to the Net.
 
W

Watson A.Name - Watt Sun, Dark Remover

More like a year at least.


Usually to a site where you get the hype sales letter about
WebWasher, Evidence eliminator, or maybe something like Ad-Aware
which is another good one.

Those first 2 apps *do* work BTW. You can find info on the hidden
files at www.fuckmicrosoft.com

I have the logs from the cleanup apps so I could write my own (back
burner.) You Basically have to check the registry to find the
directory the user's hidden files are in and write a batch file to
delete them after reboot so you can get them before file protection
kicks in. And you have to get the .DAT files which Microshaft uses
to reconstruct your Favorites folder, etc.

Best place to read about this and verify what I've said is
www.grc.com and his (Steve's) discussion groups at news.grc.com
Just set up a new news server in your reader.

There's your security/privacy tip for the day :)

Here's another bit of info I ran across today, in the same vein. This
tells you how to recover from a corrupt registry file in XP.
Something about executing some batch files. I've just looked over it
briefly, mainly because I don't have a XP machine to play around with
yet. But that'll be coming this year, when we u/g. Anyway, it's some
useful info, but like it says, after your XP machine has crashed, it's
too late to look at this file, unless you have it on another machine.
http://www.aade.com/XPhint/XPrecovery.htm


--
@@F@r@o@m@@O@r@a@n@g@e@@C@o@u@n@t@y@,@@C@a@l@,@@w@h@e@r@e@@
###Got a Question about ELECTRONICS? Check HERE First:###
http://users.pandora.be/educypedia/electronics/databank.htm
My email address is whitelisted. *All* email sent to it
goes directly to the trash unless you add NOSPAM in the
Subject: line with other stuff. alondra101 <at> hotmail.com
Don't be ripped off by the big book dealers. Go to the URL
that will give you a choice and save you money(up to half).
http://www.everybookstore.com You'll be glad you did!
Just when you thought you had all this figured out, the gov't
changed it: http://physics.nist.gov/cuu/Units/binary.html
@@t@h@e@@a@f@f@l@u@e@n@t@@m@e@e@t@@t@h@e@@E@f@f@l@u@e@n@t@@
 
W

Watson A.Name - Watt Sun, Dark Remover

On Fri, 2 Jan 2004 20:27:24 -0800, Watson A.Name - "Watt Sun, Dark



http://poxomitron.cjb.net a proxy filter is what I use, but someone
last month posted

I think you missed that, it should be proximitron.



--
@@F@r@o@m@@O@r@a@n@g@e@@C@o@u@n@t@y@,@@C@a@l@,@@w@h@e@r@e@@
###Got a Question about ELECTRONICS? Check HERE First:###
http://users.pandora.be/educypedia/electronics/databank.htm
My email address is whitelisted. *All* email sent to it
goes directly to the trash unless you add NOSPAM in the
Subject: line with other stuff. alondra101 <at> hotmail.com
Don't be ripped off by the big book dealers. Go to the URL
that will give you a choice and save you money(up to half).
http://www.everybookstore.com You'll be glad you did!
Just when you thought you had all this figured out, the gov't
changed it: http://physics.nist.gov/cuu/Units/binary.html
@@t@h@e@@a@f@f@l@u@e@n@t@@m@e@e@t@@t@h@e@@E@f@f@l@u@e@n@t@@
 
D

DarkMatter

I finally got the latest Sun JVM on this box. I used to get
messages saying I needed to douwnload MS JVM (which was already
installed with XP. to run embedded applets. Clicking the OK button
would take me to a 40x page unavailable or not found deal at MS and
after closing that winder, the applet would run. So after getting
Sun JVM, evrything was cool, until I loaded a new app. The
installer needed MS JVM. AAARRRRGGGHHH!!!! back to square one, I
are. I have to keep notes on what to install first so I'm not back
and forth and formatting and reloading and hacking my registry.
Cool.

Linux rules!

For sure.
 
J

John Woodgate

I read in alt.binaries.schematics.electronic that Watson A. Name - Watt
[email protected]>) about 'Bogus Warning Message
@DataSheetCatalog.com', on Sun, 4 Jan 2004:
I think you missed that, it should be proximitron.

Or even Proxomitron.

It's not a good brand name if people can't spell it. 'Oxo' is good, so
is 'Proxo'. It's the mitron (head nurse in an Aussie hospital) that
causes the problem.(;-)
 
M

Mark Jones

In news:[email protected] (Active8):
Thanks, I wouldn't doubt it if there is a thread already. I hope so
anyways, because another .EXE file just downloaded and executed itself!

ouch!! That's worse than those friggin' pages that change your
start up or home page for you. Some of the craftier one's write the
registry to change it back on OS load.
I
have no idea what can possibly be allowing these seemingly random
executable files to be (apparently downloaded) and ran - there are no
unusual processes, scheduled tasks, registry "run" keys, nothing. I
just checked spyware again, 37 new spyware components... "NCase",

NCase... that's weird. Encase is the forensic software the FBI uses
to try to recover deleted and supposedly wiped files. I like to use
it to test my wipe utils.

"Hijacker.nCase",
"tribalfusion", "bluestreak", etc... all new.

Shit. I'd be backing up and reformatting at this point. It could
take a while for the new AdAware defs to catch up if this is new,
but GRC is usually on top of this crap.
How in the bloody hell? It's almost as if I've been "hacked," as
impossible as that sounds. Very devious, whatever is going on. I've
searched and there are no new anti-virus updates or spyware updates
and no new threats listed. I'm uber-careful about this sort of thing
and always clean up all spyware after installing anything... perhaps a
legitimate program has been hijacked, and keeps re-infecting the
system? Wish I knew more about what was going on. Thanks for the link,
I'll let us know if this is just an isolated incident or if someone
has found yet another nasty backdoor in M$ winblows. :)

Please do. I'd be grateful.
P.S. I did find a nifty website for info on this sort of thing...
check out this amazing site: http://www.pestpatrol.com

Regards,
Mark

ok. as soon as I put my lead suit on :)[/QUOTE]


Hehe :)

I do have some news, with a lot of tweaking and an oogle of reboots I've
gotten the "lead" out. :)

What happened is the "nCase" trojan/malware was silently installed when
(most likely Nero Burning ROM) was upgraded. This malware took over the
default browser search and homepage functions and installed a flurry of
"nCase" protection files and registry entries, specifically designed to make
it nearly impossible to remove. The nCase bug is designed to FORWARD all
surfing to the ncase website, which I denied when ZoneAlarm said a new file
wanted access to the net. (The site would have recorded potentially all web
surfing and reported it to them, email addresses, passwords, credit card
numbers, etc...)

When I originally tried removing some of the nCase components, as a
self-defense mechanism or perhaps normal action it started downloading and
installing other malware. This is where these EXE files kept popping up
from. I removed one yet unknown mailware and an XXX dialer, which could have
racked up hundreds of dollars in phone bills had it tried to actually dial
some 900 number without me even knowing about it...

The interesting thing was that it kept spawning new malware and there were
zero unusual running processes. What this means is that somewhere in one of
the existing running tasks, it had imbedded itself and was occasionally
executing. A simple reboot (and making sure there were no bad "run" keys or
shortcuts) cleared the memory and presto, no more spawning malware or xxx
dialers. Using the PestPatrol scanner I was then able to find the remnants
of the infections and nullify them. Norton Anti-Virus found nothing of this
at all. :\

Whew! There's some really bad software out there folks, being installed
silently by some pretty mainstream vendors... be careful!

Regards,
Mark
 
A

Active8

ouch!! That's worse than those friggin' pages that change your
start up or home page for you. Some of the craftier one's write the
registry to change it back on OS load.


NCase... that's weird. Encase is the forensic software the FBI uses
to try to recover deleted and supposedly wiped files. I like to use
it to test my wipe utils.



Shit. I'd be backing up and reformatting at this point. It could
take a while for the new AdAware defs to catch up if this is new,
but GRC is usually on top of this crap.

Please do. I'd be grateful.

ok. as soon as I put my lead suit on :)


Hehe :)
[/QUOTE]

You might want to check for the presence of wininit.ini from time
to time. If it's there, it runs. It's normally used for renames,
moves and deletes of protected system files like winders hidden
files, but you can probably run a .reg file with it (?) which would
import registry keys.

Mike
 
A

Active8

I read in alt.binaries.schematics.electronic that Watson A. Name - Watt
[email protected]>) about 'Bogus Warning Message
@DataSheetCatalog.com', on Sun, 4 Jan 2004:

should be but it's what John said.
Or even Proxomitron.

It's not a good brand name if people can't spell it. 'Oxo' is good, so
is 'Proxo'. It's the mitron (head nurse in an Aussie hospital) that
causes the problem.(;-)

Luckily google will ask if you meant... :)
 
A

Active8

On Sun, 4 Jan 2004 08:35:01 -0800, Watson A.Name - "Watt Sun, Dark
Remover said:
Here's another bit of info I ran across today, in the same vein. This
tells you how to recover from a corrupt registry file in XP.
Something about executing some batch files. I've just looked over it
briefly, mainly because I don't have a XP machine to play around with
yet.

"Play" is the operative word. I don't like it. As soon as I get
time, now that I've gotten my 2 main devel suites stop fighting
over who owns winders html help, I'm pulling XP off the 1st
partition and putting w2k back on. Saving the 2nd XP part for
testing. What I'm really looking forward to is making room for
Linux now that I've got the Video to handle XFree86. All I can do
now is SSH into a Linux box. Can't use it with a monitor 'cause the
built in AMD LAN throws eth0 errors, not worth fixing since it
doesn't do X. It's just a server.

The articles I've read in the E Week type mags basically said that
Vendors aren't making much revenue from XP sales because there's no
real reason for w2k customers to upgrade the whole enterprise. They
just put it on new installs.
 
B

Bryan Swadener

Watson A.Name - Watt Sun said:
Here's another bit of info I ran across today, in the same vein. This
tells you how to recover from a corrupt registry file in XP.
Something about executing some batch files. I've just looked over it
briefly, mainly because I don't have a XP machine to play around with
yet. But that'll be coming this year, when we u/g. Anyway, it's some
useful info, but like it says, after your XP machine has crashed, it's
too late to look at this file, unless you have it on another machine.
http://www.aade.com/XPhint/XPrecovery.htm

A batch file... hmm.. I wonder if all it does is copy the registry file to a
backup copy. Might it be worth running a batch file at startup (giving the
"CHOICE" to make a backup copy), and the choice to copy the back up to the
"live" file? Like you, I'm using Windoughs 98 so I dunno if that's possible
in WinXP.
Bryan
 
F

folgertemp

To all;
I was reading about Mark's little escapade with the drive-by installers.
I had a win2k laptop that loaded a bunch of garbage on it like Xupiter,
nCase, tribalfusion, and bluestreak. I found this site very helpful as a
reference on the how's and why's....
http://www.doxdesk.com/parasite/

They seem to list them all there.

Good luck Mark. It took me 4½ hours to get rid of everything.
Hint: reboot in safe mode and uninstall as much as you can and
make sure you back up the registry B4 you tinker with it.
--
+-+-+-+-+-+-+-+-+-+-+-+
If all the world's a stage,
I wanna operate the trap door.
*********
JimboR
 
W

Watson A.Name \Watt Sun - the Dark Remover\

folgertemp said:
To all;
I was reading about Mark's little escapade with the drive-by installers.
I had a win2k laptop that loaded a bunch of garbage on it like Xupiter,
nCase, tribalfusion, and bluestreak. I found this site very helpful as a
reference on the how's and why's....
http://www.doxdesk.com/parasite/

They seem to list them all there.

Good luck Mark. It took me 4½ hours to get rid of everything.
Hint: reboot in safe mode and uninstall as much as you can and
make sure you back up the registry B4 you tinker with it.

Or just let Spybot Search and Destroy do all that for you.


--
@@F@r@o@m@@O@r@a@n@g@e@@C@o@u@n@t@y@,@@C@a@l@,@@w@h@e@r@e@@
###Got a Question about ELECTRONICS? Check HERE First:###
http://users.pandora.be/educypedia/electronics/databank.htm
My email address is whitelisted. *All* email sent to it
goes directly to the trash unless you add NOSPAM in the
Subject: line with other stuff. alondra101 <at> hotmail.com
Don't be ripped off by the big book dealers. Go to the URL
that will give you a choice and save you money(up to half).
http://www.everybookstore.com You'll be glad you did!
Just when you thought you had all this figured out, the gov't
changed it: http://physics.nist.gov/cuu/Units/binary.html
@@t@h@e@@a@f@f@l@u@e@n@t@@m@e@e@t@@t@h@e@@E@f@f@l@u@e@n@t@@
F
o
d
d
e
r

f
o
r

s
t
u
p
i
d

n
o
t

e
n
o
u
g
h

i
n
c
l
u
d
e
d

t
e
x
t

m
s
g
 
M

Mark Jones

In (Watson A.Name "Watt Sun - the Dark
Remover"):
Or just let Spybot Search and Destroy do all that for you.


I found a great, free, Active-X based scanner online. I've been telling my
customers to go here to get rid of their spyware. Check it out (no
affiliation):

http://pestscan.com/
 

Similar threads

M
Replies
1
Views
979
Robert Baer
R
D
Replies
17
Views
1K
Paul Hovnanian P.E.
P
D
Replies
11
Views
1K
Scott Stephens
S
M
Replies
0
Views
872
Mark Leuck
M
Top