Ants

Discussion in 'malware problems & news' started by ljc1174, Aug 29, 2002.

Thread Status:
Not open for further replies.
  1. ljc1174

    ljc1174 Registered Member

    Joined:
    Aug 15, 2002
    Posts:
    276
    Location:
    Cleveland, Ohio USA
    Jooske, you are TEXT (this was supposed to say)

    Jooske, you are [glow=red,2,300]AWESOME[/glow]
    (i was excited and forgot to put it in there!)
     
  2. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    <<Tee-Hee>>
    Thanks. :cool:
    Think Jan is the "hosts" specialist here, although there are several others who can tell exactly what to do with the hosts files and what not, and what exactly to look for or how to edit some lines in them.
    It could be somewhere in that part, good find (i think)
    And Lori, even after posting you can "modify" your posting to change what you want to change !
    <another Tee-Hee!>

    Your starting to know your system much better this way eh? Education on stage. And several walk with you and the nice advices to try for ourselves as well, sometimes trying out something which we might have half forgotten before posting them here, so that's great.

    Hope your date was more interesting then hunting for d/l and illegal start pages and all that. :D
    I "enjoyed" myself trying to clean out some newsgroups thanks to one and the same infected user (Klez.h). I really should go commercial and clean them out myself in distance <grin>

    I'll google for the words/links you provided.
     
  3. ljc1174

    ljc1174 Registered Member

    Joined:
    Aug 15, 2002
    Posts:
    276
    Location:
    Cleveland, Ohio USA
    Thank you much Jooske!

    Were you meaning Fan J as in Jan to help with the hosts stuff?

    How do you modify your post after it's posted?

    ~Lori
     
  4. FanJ

    FanJ Guest

    Yep, that's me, Lori ;)

    At the moment I haven't read all the latest postings in this thread, but I will do soon.
    As a side-note: maybe a good suggestion is the post different questions (if they don't depend on each other) in new threads; this thread is now getting soooo long; it's a bit hard to keep on track what one already has read and what not ;)

    Cheers, Jan.
     
  5. FanJ

    FanJ Guest

    Hi Lori,

    About HOSTS:

    You can read about it here:
    http://www.smartin-designs.com/
    It will tell you how to use HOSTS and how to install it.

    In short:
    HOSTS is a file without an extension (with extension I mean for example .txt for a textfile).
    By using HOSTS your computer is simply forbidden to make any connection (inbound or outbound) to the sites that are mentioned in HOSTS.
    You can make your own HOSTS, you can download/install one, and you can add or delete sites to/from HOSTS.
    The most used example of an HOSTS file is the one from S.Martin, which you will find on the above mentioned site.
    From time to time S.Martin will publish an updated HOSTS file.
    The way it works is:
    in HOSTS there are a lot of lines like for example:
    127.0.0.1 view.atdmt.com
    all those lines begin with 127.0.0.1
    that is your own computer, so every site, that is named in such a line, is forced to connect to your own PC instead of the internet. So no cookie from that site can be placed on your PC, neither can such a site do any harm to you cause there will be no connection made.

    There is also a nice free program called HOSTESS by which you can easily add or move sites to your HOSTS file, or by which you can easily temporarily disable HOSTS.

    BTW: you can also use HOSTS for other things, but at the moment that is not important here.

    S.Martin has divided his HOSTS file in several groups of sites.
    There is one group called "Not for everyone".
    In that group are sites mentioned which some people has to use and others not.
    S.Martin gives you the possibility to download his HOSTS file with or without that group "Not for everyone". Maybe it's better for you to start without that group.

    I myself have installed his HOSTS file, and I have added some more sites myself which for some reason I want to block.

    I did a search on my HOSTS file.
    But first of all I have to say that I found a little bit strange thing in your posting:
    you talked about a site with atdmt in it and a site with adtmt in it. Which one is causing you trouble (sorry, it was not quite clear to me)?
    OK, I found this:
    view.atdmt.com in the group Avenue [iballs]
    arc5.msn.com in the group Not-for-everyone
    and there is no site mentioned in my HOSTS with adtmt in it.


    At last:
    Instead of using HOSTS, there are also other programs by which you can stop "nasty" things that some sites might want to do.
    I name some of them: SpyBlocker, Proxomitron, WebWasher.
    And if you use InternetExplorer, it could also help to use the free utility IE-SPYAD in combination with restricting every thing to the highest secure level in your Internet Restricted Zone. IE-SPYAD is partly based on S.Martins's HOSTS list, but it uses another way to secure your connections. You can use both HOSTS and IE-SPYAD at the same time (which I do myself).

    OK, that's it for the moment ;)

    O, BTW: HOSTS contains thousands and thousands of sites....
     
  6. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Wonderful explanation Jan, thanks a lot!
    Would there be any recommendation to add lines in one of the hostfiles manually to start with to get rid of that d/lalot?

    I saw Lori's other discussions on the microsofts newsgroups, and as they offer a couple of very helpful URLs, i give one of those here:
    http://www.mvps.org/inetexplorer/Darnit.htm#hijackings
    I think tehre's a wealth of info on that page to get rid of all kinds of nasties.
    The URL to MS patch against hijackings is given there too.

    I was just thinking, where did you get the IE download Lori, as it's not clear to me how you got involved with d/lalot?
    I never before your postings here was there and (i hope) i'm still free of them.
    There are many sites really happy to integrate their links and customize their d/l versions with them; this is allowed by the original IE and NS owners, till a certain degree.
    So if Wilderssecurity would make a Wilders version you would have a wilders startpage and further be free to use the whole of internet, while commercial d/l places might include more like spyware. Or they might add some extra menu options, all for their site/products.
    So if your IE version is not original from MS ...........
    This SHOULD be solved (i hope) after an update and re-install via the MS/windows update site.
    And the recommended patches as described on that site or that might be included in the last cumulative security patch.

    Saw at the bottom of that "searchalot" page a line "make your homepage" so if you clicked that, you set your startpage to them ... and they seem involved with downloadalot, did not see so quick a "make your homepage" on that d/lalot page, but who knows it might be there.


    If you tried all recommended in this thread, i did not see nobody posting about PestPatrol, which is especially for detecting all kinds of nasties, which might not be seen with other products, although for spyware i think you have two very good detectors already.


    Further i think Jan is right:
    we are off the original name of the first posting, which was about trying ANTS to get rid of possible infections/spyware, and now we are talking about several products for IE in general.
     
  7. ljc1174

    ljc1174 Registered Member

    Joined:
    Aug 15, 2002
    Posts:
    276
    Location:
    Cleveland, Ohio USA
    :D
    I'll start a new post in privacy problems, I had been thinking the same thing!

    ~Lori
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.