AOA Forums AOA Forums AOA Forums Folding For Team 45 AOA Files Home Front Page Become an AOA Subscriber! UserCP Calendar Memberlist FAQ Search Forum Home


Go Back   AOA Forums > Hardware > Mobile Devices and Networking


Reply
 
LinkBack Thread Tools Rate Thread
  #1 (permalink)  
Old 30th August, 2002, 03:14 AM
WyrmMaster's Avatar
Member
 
Join Date: December 2001
Location: Columbia Falls, Montana, USA
Posts: 253

Spyware alert

I THINK i have found spyware in fraps, the FPS display program. Basically whenever it is running it tries to load fraps.dll into any program that has internet access (opera, flashget, trillian, ect). Luckily i have sygate set to tell me if any program loads an new dll, so i can deny it access. But this is something to be aware of. Just because the program does not ask for permission to access does not mean its not phoning home. I also never let any windows components (kernal, services and controlls app, ect) access the internet. Personally i think sygate is the best software firewall you can get, and i recommend it to all.
__________________

Watercooled Barton 2500+ AGOIA-Y @ 2300 (11.5x200) 1.85v
Epox 8RDA
1gb OCZ PC3200, 2-2-2-6
eVGA Geforce 4 TI4400
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 30th August, 2002, 03:41 AM
robbie's Avatar
AOA Staff
 
Join Date: November 2001
Location: Out in the desert of Ca.
Posts: 12,548
Send a message via AIM to robbie Send a message via MSN to robbie Send a message via Yahoo to robbie Send a message via Skype™ to robbie

I think most of use here use ad-ware. I like it.
Rob
__________________
Taking each day as it comes
Grow, learn and OVERCLOCK. Need help?? Ask me.
Your Mommy!! (Aug/02) Welcome to the fold.
Buy it, Sell it, or Trade it in the AoA classifieds!!
AOA Team fah
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 30th August, 2002, 04:27 AM
WyrmMaster's Avatar
Member
 
Join Date: December 2001
Location: Columbia Falls, Montana, USA
Posts: 253

I use ad-aware too, but it doesnt catch this one. The thing is ad-aware works on a database, so if somethings not in the data base then it doesnt get caught.
__________________

Watercooled Barton 2500+ AGOIA-Y @ 2300 (11.5x200) 1.85v
Epox 8RDA
1gb OCZ PC3200, 2-2-2-6
eVGA Geforce 4 TI4400
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 30th August, 2002, 09:32 AM
Chief Systems Administrator
 
Join Date: September 2001
Location: Europe
Posts: 13,075

Re: Spyware alert

Quote:
Originally posted by WyrmMaster
Basically whenever it is running it tries to load fraps.dll into any program that has internet access (opera, flashget, trillian, ect). Luckily i have sygate set to tell me if any program loads an new dll, so i can deny it access
If you find that an application is attempting to do code injection into other running processes, then I'd cease running it, full stop. Why? Any program that does code injection into other processes will only be doing it for malicious purposes, and can seriously screw up the other processes. It could be doing the same to the kernel OS as well. Either that or Sygate is getting confused.

Have done DLL injection into running processes in the past. Much more fun injecting DLLs into the W2K security system, or Win32 subsystem. Win32 subsystem is fun, as it's what all windows programs use to do everything. It's nice being able to subvert an entire machine, including it's security system.

AidanII
__________________
Any views, thoughts and opinions are entirely my own. They don't necessarily represent those of my employer (BlackBerry).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 30th August, 2002, 06:34 PM
Banned
 
Join Date: September 2001
Posts: 5,957

Zonealarm catches run.dll doing that all the time, and seems to catch these spyware buggers dead in their tracks, sygate has been improved i guess, but I used it a year ago and found it to be buggy and slow.
__________________
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 1st September, 2002, 02:48 AM
cloasters's Avatar
Asst. BBS Administrator
 
Join Date: September 2001
Location: Location, Location
Posts: 21,956

I wish I had that much faith in ZA. Its latest interface clouds WTH it's really doing. Perhaps "makes it more difficult to set up" is more accurate. Ad-Aware is great, yet its Achilles heel is that it needs to be updated. A process that Ad-Aware makes difficult. It's uninstall the old version and install the new version, at least for this dummy.

To the rescue! You might give spybotsd10.niaswiss.zip a try. It's in AOA files, it's a powerful SpyWare finder that needs to be used with care.
__________________
When the world will be better.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 1st September, 2002, 04:06 AM
WyrmMaster's Avatar
Member
 
Join Date: December 2001
Location: Columbia Falls, Montana, USA
Posts: 253

Im not sure now if its something to worry about. Kingslayer from overclockers.com said it may be that it needs to load that DLL for fps monitoring purposes, and it loads it into all running programs, not just the ones that it can monitor. I dont know if it is or not.
__________________

Watercooled Barton 2500+ AGOIA-Y @ 2300 (11.5x200) 1.85v
Epox 8RDA
1gb OCZ PC3200, 2-2-2-6
eVGA Geforce 4 TI4400
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Fah-smp Alert!!! SteveI ThunderRd's AOA FOLDING@HOME Team 25 19th July, 2007 06:20 PM
Virus Alert...my a$$ chrisbard Data Security 8 19th April, 2006 10:28 PM
Milestones alert dod ThunderRd's AOA FOLDING@HOME Team 22 9th July, 2004 10:28 AM
Virus Alert! Stepper Mookydooky's Just for laughs! 3 16th May, 2003 12:11 PM
Virus Alert!! Daniel ~ Random Nonsense! 6 2nd October, 2001 07:43 AM


All times are GMT +1. The time now is 08:56 AM.


Copyright ©2001 - 2010, AOA Forums
Don't Click Here Don't Click Here Either

Search Engine Friendly URLs by vBSEO 3.3.0