{"id":132,"date":"2007-01-23T05:12:01","date_gmt":"2007-01-23T13:12:01","guid":{"rendered":"http:\/\/37prime.wordpress.com\/2007\/01\/23\/spyware-drive-by-on-myspace\/"},"modified":"2007-01-23T05:12:01","modified_gmt":"2007-01-23T13:12:01","slug":"spyware-drive-by-on-myspace","status":"publish","type":"post","link":"https:\/\/37prime.com\/news\/2007\/01\/23\/spyware-drive-by-on-myspace\/","title":{"rendered":"Spyware Drive-By on MySpace"},"content":{"rendered":"<p>A friend of mine was reinstalling one of his Windows machine just for the heck of it. For some reason, &#8220;Lord Ahriman&#8221; from the band &#8220;Dark Funeral&#8221; came up in our conversations. Google pointed us to &#8220;Lord Ahriman&#8221; MySpace page and both of us were looking at the page on our own computers. I was using my PowerBook G4 and he was using Internet Explorer on his newly installed Windows OS.<\/p>\n<p>After a while Internet Explorer quit unexpectedly in the middle of Microsoft Update. Naturally, he restarted the computer. Right after that the Windows started acting weird. The &#8220;Start Menu&#8221; no longer functional, and we couldn&#8217;t go to Mozilla homepage.<\/p>\n<p>Upon a brief inspection, we found a suspicious process named &#8220;<a href=\"http:\/\/www.google.com\/search?rls=en&amp;q=ntsock.exe&amp;ie=UTF-8&amp;oe=UTF-8\" target=\"_blank\">ntsock.exe<\/a>&#8221; running on his system. It turned out to be a spyware. He quickly downloaded <a href=\"http:\/\/free.grisoft.com\/\" target=\"_blank\">AVG Anti-Spyware<\/a> and managed to remove the spyware. The &#8220;Start Menu&#8221; finally worked normally, but the system was still unstable. Upon further inspections, we found yet another suspicious process named &#8220;<a href=\"http:\/\/www.google.com\/search?hl=en&amp;lr=&amp;safe=off&amp;rls=en&amp;q=username.exe&amp;btnG=Search\" target=\"_blank\">username.exe<\/a>&#8220;. It seems to be another piece of spyware.<\/p>\n<p>We&#8217;re not really sure how we got the spywares in the first place. By the process of elimination, we concluded that the spywares were delivered through MySpace. It was a spyware drive-by on MySpace.<\/p>\n<p>Anti-Spywares (free versions) for Windows<br \/>\n<a href=\"http:\/\/www.safer-networking.org\/\" target=\"_blank\"> Spybot: Search &amp; Destroy<\/a> &#8211; <a href=\"http:\/\/spybot.info\/\" target=\"_blank\">http:\/\/spybot.info\/<\/a><br \/>\n<a href=\"http:\/\/www.lavasoft.com\/\" target=\"_blank\">Lavasoft: Ad-Aware Personal Edition SE<\/a>\t&#8211; <a href=\"http:\/\/www.lavasoft.com\/\" target=\"_blank\">http:\/\/www.lavasoft.com\/<\/a><br \/>\n<a href=\"http:\/\/www.javacoolsoftware.com\/\" target=\"_blank\"> SpywareBlaster<\/a>\t&#8211; <a href=\"http:\/\/spywareblaster.info\/ \" target=\"_blank\">http:\/\/spywareblaster.info\/<\/a><br \/>\n<a href=\"http:\/\/www.microsoft.com\/defender\/\" target=\"_blank\"> Microsoft Defender<\/a> &#8211;\t<a href=\"http:\/\/www.microsoft.com\/defender\/\" target=\"_blank\">http:\/\/www.microsoft.com\/defender\/<\/a><br \/>\n<a href=\"http:\/\/free.grisoft.com\/\" target=\"_blank\"> AVG Anti-Spyware Free<\/a> &#8211;\t<a href=\"http:\/\/free.grisoft.com\/\" target=\"_blank\">http:\/\/free.grisoft.com\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A friend of mine was reinstalling one of his Windows machine just for the heck of it. For some reason, &#8220;Lord Ahriman&#8221; from the band &#8220;Dark Funeral&#8221; came up in our conversations. Google pointed us to &#8220;Lord Ahriman&#8221; MySpace page and both of us were looking at the page on our own computers. I was &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/37prime.com\/news\/2007\/01\/23\/spyware-drive-by-on-myspace\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Spyware Drive-By on MySpace&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[946],"tags":[403,1931,934,2511,2648,936,3216],"class_list":["post-132","post","type-post","status-publish","format-standard","hentry","category-announcements","tag-applications","tag-mac-os-x","tag-microsoft","tag-resources","tag-security","tag-tech","tag-windows"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pcNtU-28","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts\/132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/comments?post=132"}],"version-history":[{"count":0,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/posts\/132\/revisions"}],"wp:attachment":[{"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/media?parent=132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/categories?post=132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/37prime.com\/news\/wp-json\/wp\/v2\/tags?post=132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}