| |
Antivirus World Forum
Re: SOLUTION
Posted By: Frank In Response To: SOLUTION (cptcheerios)
Date: Monday, 16 May 2005, at 1:39 a.m.
CPTCHEERIOS Solution is correct. McAfee handled the trojan Downloader-YH. While there may be a number of ways to get this trojan, I know how I got it - in a drive-by download of AdController by Unicast/Viewpoint. See the correspondence which follows.
Greetings once again Anna.
I apologize for taking so long to get back to you but other priorities have taken my time. Thank you for your note but I must tell you that it sounds somewhat scripted. "Graphically enhance your Internet experience" may well have different meanings to different people. In the pursuit of Downloader-YH, I have found many interesting articles about graphically enhancing ones experience. The latest is ZDNet's article on Ben Endelman, http://news.zdnet.com/2100-1009-5694727-2.html and from there to Endelman's website http://www.benedelman.org/spyware/.
Enough of that. I do not believe that I have made a mistake in contacting you. I definitely recall Unicast as the company that asked permission to download the plug-in, the action that led to the downloading of many advertising programs, and various spyware and malware programs. See my comments again in the virus forum http://www.antivirusworld.com/cgi-bin/webbbs/webbbs_config.pl/noframes/read/320. In particular, "In searching for the Downloader-YH file, came across an association with a program called adcontroller. That lead me to a folder deep inside Java with all sorts of files and folders coming from Unicast. The path was C:\Documents and Settings\Admins folder name\Application Data\Sun\Java\Deployment\Cache\Javapi\v1.0\Jar\Adco\com\Unicast\Adcontroller\Core. Windows Explorer only showed through \Jar. The remainder of the path came from working backward from the Adcontroller files found in searching for Adcontroller."
You can see clearly that Unicast is the problem. Searching the Internet for AdController leads directly to Unicast, http://www.x-summary.com/tools/980609.phtml. Using the address shown in several websites, www.unicast.com, one is automatically redirected to your website, http://www.viewpoint.com/pub/index.html. On your website is a Unicast tab http://www.viewpoint.com/pub/advertising/. I believe that I am at the correct place. I have also looked for other Unicast companies. Found a few but they do business with concrete and other materials. They are fairly far away from the spyware business. This leaves Unicast, now Viewpoint.My request had been simple. As I directly placed the blame for the subject trojan on the Unicast misrepresentation, and you are the Unicast involved, my request was that you provide me with a technically correct methodology and appropriate references to eliminate Downloader-YH. Since that time McAfee has come up with a procedure to eliminate. Had you provided me with the technically correct fix, I was prepared to post the fix on the Internet and let it go at that. Now I am at a crossroad as to how to proceed. After some thought, and allowing my anger and frustration to subside, (my immediate thought was to do great bodily harm to the miscreant who was responsible for what had transpired on my computer), I think that the best course of action is to send a copy of this note to the Attorney General of Ohio, http://www.ag.state.oh.us/index.asp, to the Attorney General of New York, http://www.oag.state.ny.us/, who has a particular interest in this sort of activity, to the FCC via their solicitation on this sort of activity, http://www.ftc.gov/bcp/workshops/spyware/ and to Mr Endelman, http://www.benedelman.org/mail/ who may wish to pursue additional companies of the Gator caliber.
Thank you.
Frank W Stuchal
In a message dated 5/2/2005 1:07:02 PM Eastern Standard Time, support@viewpoint.com writes:
Hi FStuchal@aol.com,
We at Viewpoint develop a 3D rendering technology for the web (http://www.viewpoint.com/) as well as a search technology to graphically enhance your Internet experience (http://search.viewpoint.com). Was this email intended for Viewpoint? If so, could you please clarify what issues you are experiencing with any of our products and we would be more then happy to help remedy the situation.
At no time whatsoever does the Viewpoint Media Player, Manager, or Toolbar collect ANY personal data about you or your usage patterns, nor do we install third-party software or access information on your hard drive. The auto-update process happens totally anonymously and happens solely to ensure that your player is up-to-date. Since we do not collect personal data, there is no way - as in the case of 'spyware' - to "traffic" or sell your personal information. We as a company find spyware to be reprehensible and we are committed to protecting the privacy of all of our users.
Please feel free to contact us if you have any additional questions.
Best Regards,
AnnaOn Sun, 1 May 2005 21:27:42 -0400, FStuchal@aol.com wrote:
> Folks, I need your help. Please see the link below. As a result of a plugin
> download for specific music (the Cisco Kid 1950s TV show music), you folks
> downloaded a host a malware, spyware and assorted ad type programs. None of
> this was expected or appreciated. You also downloaded a trojan called
> Downloader-YH. Since then, after much effort, I have eliminated, I think, most if not
> all of your downloaded material - with one exception, the trojan
> Downloader-YH. McAfee has him contained but he is not dead. Periodically he spews off a
> few files which McAfee can handle. I have spent countless hours working on
> eliminating this critter to no avail. I now need your help in a serious way.
> Please advise how specifically I can track down and kill this trojan.
>
> Thank you.
>
> Frank Stuchal
>
> _http://www.antivirusworld.com/cgi-bin/webbbs/webbbs_config.pl/noframes/read/3
> 20_
> (http://www.antivirusworld.com/cgi-bin/webbbs/webbbs_config.pl/noframes/read/320)
| |
Antivirus World Forum is maintained by Administrator with WebBBS 5.12.