New crapware / Spyware RapidBlaster

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

New crapware / Spyware RapidBlaster

Post by Faram »

Scumware of the highest order.
General Info: RapidBlaster runs as a task at Windows startup. It downloads advertising from the Internet and displays it periodically.


ALERT REGARDING THE NEWEST VARIANT(S) OF RAPIDBLASTER

The most recent variants of RapidBlaster will "morph" themselves to evade detection. Periodically, RapidBlaster will download data from its controlling server that contains a new folder and filename. It will then copy itself to that folder, terminate the original process, delete the original file, and run the new file in the new location.

Since the folder and filenames that RapidBlaster uses are randomly sent from the server, and are not contained within the executable itself, it is very easy for the makers of RapidBlaster to simply update the list of folders/filenames that RapidBlaster uses. Thus, looking for the following folders/filenames should not be the only method of detection, and will not guarantee a RapidBlaster-free system.
Wilderssecurity.net

Protect yourself ;)

If you do porn surfing and use IE check out the site in the link provided.

Some of my co workers hawe this shit....
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Yuri Prime
Padawan Learner
Posts: 334
Joined: 2003-03-31 10:55am
Location: Arizona
Contact:

Post by Yuri Prime »

This is also why everyone should have a firewall.
I don't go to mythical places with strange men.
-Douglas Adams

Evil Liberal Conspiracy. Taking away your guns since 1987.
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Yuri Prime wrote:This is also why everyone should have a firewall.
A firewall don't help you in this instanse. If you allow IE to access the web = compromise in 99.9% of all home systems. Because it is the active-x sub component in IE that has to low default settings.

The safe way is to block active-x from the web or use an other browser.

Try Opera or Mozilla
Last edited by Faram on 2003-06-11 04:10am, edited 1 time in total.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Brother-Captain Gaius
Emperor's Hand
Posts: 6859
Joined: 2002-10-22 12:00am
Location: \m/

Post by Brother-Captain Gaius »

Goddamn those fuckheads. This shit has got to be stopped.
Agitated asshole | (Ex)40K Nut | Metalhead
The vision never dies; life's a never-ending wheel
1337 posts as of 16:34 GMT-7 June 2nd, 2003

"'He or she' is an agenderphobic microaggression, Sharon. You are a bigot." ― Randy Marsh
User avatar
Yuri Prime
Padawan Learner
Posts: 334
Joined: 2003-03-31 10:55am
Location: Arizona
Contact:

Post by Yuri Prime »

Faram wrote:
Yuri Prime wrote:This is also why everyone should have a firewall.
A firewall don't help you in this instanse. If you allow IE to access the web = compromise in 99.9% of all home systems. Because it is the active-x sub component in IE that has to low default settings.

The safe way is to block active-x from the web or use an other browser.

Try Opera or Mozilla
I am using Mozilla, actually. I love it.
I don't go to mythical places with strange men.
-Douglas Adams

Evil Liberal Conspiracy. Taking away your guns since 1987.
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

You should be blocking ActiveX from automatically installing anyways, anyone who doesn't do that is foolish.
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Only problem with completely turning RadioActiveHaX completely off is that Micro$uck decided to hard-code a warning box that comes up _EVERY_ time you do anything on a website with the slightest bit of the shit on the website. Basically it's M$'s way of saying 'You're gonna leave ActiveX ON or to hell with you!!'

Keine Mitleid fur Micro$oft!
Image Image
User avatar
Vympel
Spetsnaz
Spetsnaz
Posts: 29312
Joined: 2002-07-19 01:08am
Location: Sydney Australia

Post by Vympel »

I must have it off, I always get that Active shit.

I really need to get a better browser.
Like Legend of Galactic Heroes? Please contribute to http://gineipaedia.com/
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Einhander Sn0m4n wrote:Only problem with completely turning RadioActiveHaX completely off is that Micro$uck decided to hard-code a warning box that comes up _EVERY_ time you do anything on a website with the slightest bit of the shit on the website. Basically it's M$'s way of saying 'You're gonna leave ActiveX ON or to hell with you!!'
That has not occured to me since IE3 and I keep the security settings on rather high. For that matter, I've never been hit by an ActiveX attack, either.

If something attempts to install, the system prompts me. If an ActiveX control plays (e.g. Flash or whatever), I get no problem.
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

phongn wrote:
Einhander Sn0m4n wrote:Only problem with completely turning RadioActiveHaX completely off is that Micro$uck decided to hard-code a warning box that comes up _EVERY_ time you do anything on a website with the slightest bit of the shit on the website. Basically it's M$'s way of saying 'You're gonna leave ActiveX ON or to hell with you!!'
That has not occured to me since IE3 and I keep the security settings on rather high. For that matter, I've never been hit by an ActiveX attack, either.

If something attempts to install, the system prompts me. If an ActiveX control plays (e.g. Flash or whatever), I get no problem.
I prefer the option of not having activex on at all. Couple that with a popup blocker that works practically as good as Proxomitron minus the craptacular side effects, and Mozilla is the best browser for me. :)
Image Image
Post Reply