Some of you might not have to deal with malware on a regular basis, but this
new breed is nasty enough that it warrants mentioning to the list.  The
latest is called "Ad Destroyer" or "Virtual Bouncer".  From the research I
did over the weekend, it is capable of doing stealth "drive-by" installs and
has screenshot, key logger, remote admin functionality stay resident and
phone-home capabilities.  

It phones home after drive-by install, gives itself the right (in the EULA)
to download and install software from its servers, and you have to *pay
them* for a "subscription" with a credit card to have it removed, then opt
out of having the "subscription" automatically renewed.  Install can happen
via JavaScript, ActiveX or VBScript hijack methods.

Because you must pay to have to removed, some have dubbed this "extortion
ware".

You can somtimes remove it via add/remove.
You can also try to uninstall via:
http://www.spywarelabs.com/VirtualBouncerUninstall.exe

Some tools that supposedly can clean it:
AdAware (http://www.lavasoft.com)
SpyBot (http://www.safer-networking.org/)
X-Cleaner (http://www.xblock.com/)
RegBlock (http://www.regblock.com/)

Good luck squashing this buggar.

Eric Fretz

_________________________________________________________________
List posting FAQ:       http://www.swinc.com/resource/exch_faq.htm
Web Interface: 
http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english
To unsubscribe send a blank email to [EMAIL PROTECTED]
Exchange List admin:    [EMAIL PROTECTED]
To unsubscribe via postal mail, please contact us at:
Jupitermedia Corp.
Attn: Discussion List Management
475 Park Avenue South
New York, NY 10016

Please include the email address which you have been contacted with.

Reply via email to