Another Hack!

Chat about anything and everything... (well almost anything) Whether it be the front porch or the pot belly stove or news of interest or a topic of your liking, this is the place to post it.

Moderator: S2k Moderators

Message
Author
User avatar
mf_dolphin
Category 5
Category 5
Posts: 17758
Age: 68
Joined: Tue Oct 08, 2002 2:05 pm
Location: St Petersburg, FL
Contact:

#21 Postby mf_dolphin » Thu Mar 25, 2004 3:13 pm

Ducky, the Incredifind is definitely adware. Here's the instructions on removing it.

Detection
Bazooka Adware and Spyware Scanner detects IncrediFind. Bazooka is freeware and detects spyware, adware, foistware, trojan horses, viruses, worms, etc. Read more »

Uninstall procedure
Uninstall IncrediFind from "Add/Remove Programs" in the Windows® Control Panel.

Manual removal
Please follow the instructions below if you would like to remove IncrediFind manually. Please notice that you must follow the instructions very carefully and delete everything that is mentioned. In most cases the removal will fail if one single item is not deleted. If Bazooka still detects IncrediFind after stepping through the removal instructions, please double-check by stepping through them again.
Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type regedit and click OK. (The registry editor will open.)
Delete 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ {5D60FF48-95BE-4956-B4C6-6BB168A70310}', if it exists.
Delete 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Browser Helper Objects \ {5D60FF48-95BE-4956-B4C6-6BB168A70310}', if it exists.
Exit the registry editor.
Restart your computer.
Start Windows Explorer and delete:
%ProgramsDir%\IncrediFind\BHO\incfindbho.dll
Note: %ProgramsDir% is a variable (?). By default, this is C:\Program Files.
Start Microsoft Internet Explorer.
In Internet Explorer, click Tools -> Internet Options.
Click the Programs tab -> Reset Web Settings.

0 likes   

GalvestonDuck
Category 5
Category 5
Posts: 15941
Age: 57
Joined: Fri Oct 11, 2002 8:11 am
Location: Galveston, oh Galveston (And yeah, it's a barrier island. Wanna make something of it?)

#22 Postby GalvestonDuck » Thu Mar 25, 2004 3:32 pm

Thanks, Marshall! :)
0 likes   

User avatar
mf_dolphin
Category 5
Category 5
Posts: 17758
Age: 68
Joined: Tue Oct 08, 2002 2:05 pm
Location: St Petersburg, FL
Contact:

#23 Postby mf_dolphin » Thu Mar 25, 2004 3:33 pm

Duck this is a real pain to get rid of. These people should be shot on sight!
0 likes   

User avatar
Lindaloo
Category 5
Category 5
Posts: 22658
Joined: Sat Mar 29, 2003 10:06 am
Location: Pascagoula, MS

#24 Postby Lindaloo » Thu Mar 25, 2004 3:37 pm

Poor Duckie!! Sorry you got that mess. I did not get anything on my computer when visiting S2K.
0 likes   

User avatar
vbhoutex
Storm2k Executive
Storm2k Executive
Posts: 29113
Age: 73
Joined: Wed Oct 09, 2002 11:31 pm
Location: Cypress, TX
Contact:

#25 Postby vbhoutex » Thu Mar 25, 2004 3:56 pm

This may be a stupid question Steve, but I am going to ask it.

Is there not a way that our server can be locked down against more hacks? I think I am going to answer my own question here though. Since these are obviously not some kids fooling around they can get through anything they want I guess??? :?: :roll:
0 likes   
Skywarn, C.E.R.T.
Please click below to donate to STORM2K to help with the expenses of keeping the site going:
Image

Rainband

#26 Postby Rainband » Thu Mar 25, 2004 3:57 pm

Thanks Steve ,Marshall and John. We all appreciate your efforts :) Keep up the Great JOB. :wink:
0 likes   

DROliver

#27 Postby DROliver » Thu Mar 25, 2004 4:00 pm

vbhoutex
The only way is to take the server offline.But every minute that goes by the doors are being locked!

Steve O.
0 likes   

User avatar
therock1811
Category 5
Category 5
Posts: 5163
Age: 40
Joined: Thu May 15, 2003 2:15 pm
Location: Kentucky
Contact:

#28 Postby therock1811 » Thu Mar 25, 2004 4:04 pm

These SOB's need to be caught and QUICKLY!!! :grr: Thanks Steve and the rest of the team!
0 likes   

weatherlover427

#29 Postby weatherlover427 » Thu Mar 25, 2004 4:33 pm

Grrrrr what idiots :mad: Hope they can be caught quickly and punished severely!
0 likes   

User avatar
Aslkahuna
Professional-Met
Professional-Met
Posts: 4550
Joined: Thu Feb 06, 2003 5:00 pm
Location: Tucson, AZ
Contact:

It Will Not Be Easy

#30 Postby Aslkahuna » Thu Mar 25, 2004 7:38 pm

to catch the hackers because in most cases they use a surogate computer that they have hacked into earlier to launch the attack. This second system may be a completely innocent one except that it is being used unknowingly to launch the attack.

Steve
0 likes   

BocaGirl
S2K Supporter
S2K Supporter
Posts: 279
Joined: Thu Oct 10, 2002 5:17 am
Location: Boca Raton, FL

#31 Postby BocaGirl » Thu Mar 25, 2004 8:16 pm

GalvestonDuck wrote:Is there any chance this hacker did something so that we would get spyware on our computers when we access Storm2K?

I had a bear of a time with my home computer the other day and kept getting linked to "www.incredifind.com" whenever I tried to first log in to my primary DSL page. Other regular pages wouldn't load. The SBC guys had me uninstall and re-install my software for my DSL and then ran a couple of other things. Haven't had any problems yet, but then again, I've only logged in at home once since the 3 AM attack and have yet to really give it a look to see if "incredifind.com" is going to visit my webpages again.

And now, here at work a couple of times, the same thing is happening. I ran Ad-Aware and cleaned everything but I still got it (incredifind.com) about a half hour ago.

Since Yahoo, FoxNews, MSNBC, Ebay, and Storm2K are the basic sites I surf and since S2K is the one being subjected to these idiotic attacks, I just had to ask.

Anyone else getting re-directed to incredifind.com when you try to visit a webpage?

(And darn it, if it didn't just happen again when I tried to hit submit. Closed my browser and got back here...but I'm wondering what the heck?)


Duck,

I manage a computer network (my day job!!!) and Spyware is one of my biggest headaches. Try fighting fire with fire.....go to http://www.incredifind.com and then scroll to the bottom of the page. There's a link that says Remove. Click the link and follow the directions to get rid of the software.

I have found that croaking the pests this way works better sometimes than using third party software.

BocaGirl
0 likes   

chadtm80

#32 Postby chadtm80 » Thu Mar 25, 2004 8:17 pm

http://www.lavasoft.com <---- Duck get ad aware
0 likes   

ColdFront77

#33 Postby ColdFront77 » Thu Mar 25, 2004 8:48 pm

Is it possible someone from another message board is hacking us here?
0 likes   

User avatar
mf_dolphin
Category 5
Category 5
Posts: 17758
Age: 68
Joined: Tue Oct 08, 2002 2:05 pm
Location: St Petersburg, FL
Contact:

#34 Postby mf_dolphin » Thu Mar 25, 2004 8:56 pm

All it takes to be a hacker is internet access and knowledge. It's a lot easier for some to tear down what others have built instead of building something themselves....
0 likes   

User avatar
breeze
Category 5
Category 5
Posts: 9110
Age: 63
Joined: Sat Feb 08, 2003 4:55 pm
Location: Lawrenceburg, TN

#35 Postby breeze » Thu Mar 25, 2004 9:16 pm

If downtime is what it takes to get the server back up
and running, then, that's what it takes. I suppose old
e-mail pals will be saying, "Hey - why are you suddenly
talking so much?" :wink:

Steve, 'ya gotta do what 'ya gotta do. I hate it that
SOMEONE NEEDS A REAL JOB,
but, we're hanging in there!
0 likes   

VanceWxMan

#36 Postby VanceWxMan » Thu Mar 25, 2004 9:23 pm

I am sorry to hear of the hack job that you have encountered :( This is a GREAT site with great peeps and to see you attacked like this really gets under my skin!

While you are down You are more than welcome to post at WxChat.com. I have guest posting allowed in the Lounge for those that are not members or do now wish to join.

Aaron
0 likes   

rainstorm

#37 Postby rainstorm » Thu Mar 25, 2004 9:40 pm

how do you know if you have this "incredifind" in your add/remove programs? i dont think i have it, but how do you know? thanks
0 likes   

GalvestonDuck
Category 5
Category 5
Posts: 15941
Age: 57
Joined: Fri Oct 11, 2002 8:11 am
Location: Galveston, oh Galveston (And yeah, it's a barrier island. Wanna make something of it?)

#38 Postby GalvestonDuck » Thu Mar 25, 2004 10:21 pm

Chad...Already have it and ran it...to no avail.

Helen...trust me, you'll know. It will irritate the heck outta ya!

Barbara...thanks! I'm going there now. :)
0 likes   

User avatar
wx247
S2K Supporter
S2K Supporter
Posts: 14279
Age: 42
Joined: Wed Feb 05, 2003 10:35 pm
Location: Monett, Missouri
Contact:

#39 Postby wx247 » Fri Mar 26, 2004 9:00 am

How sad... :( But we will not bend to the wills of the hacker(s). This will Storm2K stronger... in the end.
0 likes   
Personal Forecast Disclaimer:
The posts in this forum are NOT official forecast and should not be used as such. They are just the opinion of the poster and may or may not be backed by sound meteorological data. They are NOT endorsed by any professional institution or storm2k.org. For official information, please refer to the NHC and NWS products.


Return to “Off Topic”

Who is online

Users browsing this forum: No registered users and 7 guests