AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 02, 2008, 10:29:02 AM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4756 Members
Latest Member: Uobeley
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Spyware Alerts  |  Topic: Spyware.SafeSurfing 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Spyware.SafeSurfing  (Read 846 times)
Brad
SysAdmin
Tech Team
Hero Member
********
Offline Offline

Posts: 391



View Profile
Spyware.SafeSurfing
« on: June 06, 2005, 01:21:16 AM »

Behavior
Spyware.SafeSurfing monitors browsing habits.

Symptoms
The files are detected as Spyware.SafeSurfing.

Transmission
Spyware.SafeSurfing must be manually installed.

technical details
File names: netsync.exe; rsyncmon.dll

When the installer for Spyware.SafeSurfing is run, it does the following:

   1. Downloads and creates the following files from www.pops-stop.com:

          * %Windir%\netsync.exe
          * %Windir%\rsyncmon.dll

            Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.

   2. Creates the following registry keys:

      HKEY_CLASSES_ROOT\CLSID\{16B238D5-80DE-47CE-8F17-B3ECE2C2248D} HKEY_CLASSES_ROOT\Interface\{57CB9B97-9FF9-4C87-88A4-56A867FFC95E}
      HKEY_CLASSES_ROOT\TypeLib\{227D1E33-EAD4-4ACE-BE32-4ACFAAD072DD}
      HKEY_CLASSES_ROOT\Var3.RsyncHlpr.1
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Netsync
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\RsyncMon
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{16B238D5-80DE-47CE-8F17-B3ECE2C2248D}
      HKEY_LOCAL_MACHINE\Software\RSyncMon
      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\RSyncMon
      HKEY_LOCAL_MACHINE\Software\SafeSurfing

   3. Adds the value:

      "RSync" = "%WINDOWS%\netsync.exe"

      to the registry key:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

      so that the Spyware runs when you start Windows.

   4. Adds the registry key:

      HKEY_LOCAL_MACHINE\System\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\netsync.exe

      so that the Spyware bypasses Microsoft Windows firewall.

   5. Sends browsing habit and system information to www.pops-stop.com.

REMOVAL INSTRUCTIONS
See: [url]http://securityresponse.symantec.com/avcenter/venc/data/spyware.safesurfing.html[/url]
Logged

Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Spyware Alerts  |  Topic: Spyware.SafeSurfing « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!