Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Spyware targeting Randi Rhodes ?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
freeminder Donating Member (407 posts) Send PM | Profile | Ignore Fri Jul-30-04 06:34 AM
Original message
Spyware targeting Randi Rhodes ?
I've got my computer infected with some spyware that keeps replacing my homepage in IE with an address called "about:blank".

Asides of that, it also replaces some adresses I go to, like the randi rhodes site, the archive site, and whiterosesociety.

It doesn't do this with any other sites.

Can this be partisan spyware ?

:tinfoilhat:

Blanketing the free speech on the internet is what I believe to be a logical first strike should the masks come off.
Printer Friendly | Permalink |  | Top
TheWatcher Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 06:38 AM
Response to Original message
1. It's probably a CoolWeb Trojan
You can get rid of it with a Program called CWShredder.

Get it here:

http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
Printer Friendly | Permalink |  | Top
 
Bowline Donating Member (670 posts) Send PM | Profile | Ignore Fri Jul-30-04 07:41 AM
Response to Reply #1
14. Cool Web is a real bitch of a program to get rid of.
Once you get rid of it make sure you have the latest update to your anti-virus and your firewall. (You ARE running anti-virus and firewall protection, aren't you?)
Printer Friendly | Permalink |  | Top
 
freeminder Donating Member (407 posts) Send PM | Profile | Ignore Fri Jul-30-04 07:48 AM
Response to Reply #14
16. yes I am - but free ones
looks like I'll need to rake out some cash :-)
Printer Friendly | Permalink |  | Top
 
Bowline Donating Member (670 posts) Send PM | Profile | Ignore Fri Jul-30-04 07:56 AM
Response to Reply #16
17. It's worth your money.
Either Norton or McAfee will suit your anti-virus purposes. I also run the Zone Alarm firewall and have never had any problems with it. Again, both are worthwhile investments from a security standpoint.
Printer Friendly | Permalink |  | Top
 
WillyT Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 06:38 AM
Response to Original message
2. Interesting... You Running Anything To Deal With It ???
:shrug:
Printer Friendly | Permalink |  | Top
 
TheWatcher Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 06:42 AM
Response to Reply #2
4. I've had the about:blank problem before.
Seriously, use CWShredder or HiJack This! to get rid of it.

The CoolWeb Trojans are very annoying, and depending on which one you got, they sometimes require require modifying your registry ti get rid of completely.

If one of those two Programs don't help, Google about:blank Trojan or CoolWeb Trojan and you will find links to several Message Boards that can help solve the problem.
Printer Friendly | Permalink |  | Top
 
ObaMania Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 07:02 AM
Response to Reply #4
9. Ad Aware should help get rid of it too!
Printer Friendly | Permalink |  | Top
 
Lerkfish Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 06:41 AM
Response to Original message
3. could be...
your first problem indicates you just need to reset you home page.
the second problem could be an autofill issue: does your browser try to send you to an url that starts the same in the beginning?
Printer Friendly | Permalink |  | Top
 
ET Awful Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 06:44 AM
Response to Reply #3
6. Actually the second isssue indicates a modified hosts file. . .
that is redirecting certain domain names to other IP addresses.

CW Shredder is a good start.

Making the "hosts" file read-only is also a good thing to do. This file is in (usually) c:\windows\system32\drivers\etc

Also running Spybot Search&Destroy's immunize feature is helpful.
Printer Friendly | Permalink |  | Top
 
Media_Lies_Daily Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 06:44 AM
Response to Original message
5. Sounds like you have a variant of "CoolWebSearch", a hijacker that...
...essentially blocks your ability to bring up certain webpages.

Go to the following site and download a free anti-trojan software tool known as "CWShredder".

<http://www.softpedia.com/public/cat/10/17/10-17-150.shtml>

Install it, and run it. Make sure you check for updates. That should eliminate your problem.
Printer Friendly | Permalink |  | Top
 
ET Awful Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 06:45 AM
Response to Reply #5
7. Unfortunately CWShredders author quit updating it last I heard :(
Hopefully the version in question was included in the last update.
Printer Friendly | Permalink |  | Top
 
freeminder Donating Member (407 posts) Send PM | Profile | Ignore Fri Jul-30-04 07:18 AM
Response to Reply #5
11. actually, that site gets about:blanked too
I feel owned
Printer Friendly | Permalink |  | Top
 
freeminder Donating Member (407 posts) Send PM | Profile | Ignore Fri Jul-30-04 07:23 AM
Response to Reply #11
12. but I did get CWShredder
Printer Friendly | Permalink |  | Top
 
rooboy Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 06:45 AM
Response to Original message
8. Sounds like the CoolWeb trojan to me...
won't be anything to do specifically with Randi Rhodes, probably. These trojans are normally designed to increase traffic to sites who earn their income by the number of visitors.
Printer Friendly | Permalink |  | Top
 
freeminder Donating Member (407 posts) Send PM | Profile | Ignore Fri Jul-30-04 07:16 AM
Response to Original message
10. big thanks to all for helping me out!!
And no, I didn't abandon my own thread - baby intervention :-)


I'm quite happy it is something general evil and not partisan evil

*sigh*
Printer Friendly | Permalink |  | Top
 
ellie Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jul-30-04 07:38 AM
Response to Original message
13. That is awful!
I had that about:blank trojan for two months, I couldn't get rid of it! It was redirecting websites to the homepage; I would type in, for example, www.salon.com, and it would go back to about:blank. I could barely get on my computer. I just got rid of it yesterday. I went to computercops.biz and asked for help on their forum boards and someone helped me. The offending file is hidden and you have to find it and delete it. I was unable to fix it by just running CWShredder.

Someone should e-mail Randi and tell her that her site is causing these problems. My computer was infected from my DH who was "just checking his e-mail." (Code for visiting porn sites.)
Printer Friendly | Permalink |  | Top
 
freeminder Donating Member (407 posts) Send PM | Profile | Ignore Fri Jul-30-04 07:44 AM
Response to Reply #13
15. I just noticed
CWShredder and read-only "hosts" isn't gonna solve the issue.

Apparently, it's not Randi's site that is causing this, it's only a victim...

So thanks a lot for sharing your experience, I'll check out computercops.biz.
Printer Friendly | Permalink |  | Top
 
Torgo Johnson Donating Member (797 posts) Send PM | Profile | Ignore Fri Jul-30-04 03:39 PM
Response to Original message
18. That explains why Ad-Aware always detects...
the about:blank for my start page every time I run it. I don't have a Trojan. I prefer to start my browser with a blank page. I tried to have Ad-Aware ignore it but it doesn't seem to.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 25th 2024, 08:01 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC