Some of you might not have to deal with malware on a regular basis, but this new breed is nasty enough that it warrants mentioning to the list. The latest is called "Ad Destroyer" or "Virtual Bouncer". From the research I did over the weekend, it is capable of doing stealth "drive-by" installs and has screenshot, key logger, remote admin functionality stay resident and phone-home capabilities.
It phones home after drive-by install, gives itself the right (in the EULA) to download and install software from its servers, and you have to *pay them* for a "subscription" with a credit card to have it removed, then opt out of having the "subscription" automatically renewed. Install can happen via JavaScript, ActiveX or VBScript hijack methods. Because you must pay to have to removed, some have dubbed this "extortion ware". You can somtimes remove it via add/remove. You can also try to uninstall via: http://www.spywarelabs.com/VirtualBouncerUninstall.exe Some tools that supposedly can clean it: AdAware (http://www.lavasoft.com) SpyBot (http://www.safer-networking.org/) X-Cleaner (http://www.xblock.com/) RegBlock (http://www.regblock.com/) Good luck squashing this buggar. Eric Fretz _________________________________________________________________ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe send a blank email to [EMAIL PROTECTED] Exchange List admin: [EMAIL PROTECTED] To unsubscribe via postal mail, please contact us at: Jupitermedia Corp. Attn: Discussion List Management 475 Park Avenue South New York, NY 10016 Please include the email address which you have been contacted with.
