| |
|
|
Limited Time!
Parasite: FreeScratchAndWinThis record last updated Tue Sep 20 2005 00:34:15 PLEASE NOTE: Due to the overwhelming extent of this problem and the unbelievable volume of email we have received, we regret that we cannot respond to questions about browser parasites at this time. If you have attempted to contact us about this parasite please accept our apology for not responding. "Thank you's" are always appreciated ;-) DescriptionFreeScratchAndWin is an IE Browser Helper Object that comes with a web-based ‘scratchcards’ game. (What exactly is available to be won, and whether anybody has ever won it, remains unclear.) VariantsFreeScratchAndWin/Beta: a version of the software that didn’t seem to work fully, but was distributed anyway. FreeScratchAndWin/v5: most common variant of the software. Includes a homepage- and search-hijacker pointed at xzoomy.com. FreeScratchAndWin/v6: now renamed ‘Free Scratch Cards’. Instead of the xzoomy hijack this now bundles lop/Rnd. Like lop/Rnd, it uses random filenames for its files, and cannot be detected by the script at this site. Also known asFSW, FSC (v6 variant). CPM Media, after the company name used to sign the software. DistributionInstalled by ActiveX drive-by download in affiliate pages which are redirected to by AdsCPM, the advertising network company who run FreeScratchAndWin. What it doesAdvertisingYes. Connects to its controlling servers and downloads and opens pop-up adverts every few minutes. Privacy violationSuspected. The software’s terms of use advises that the software can track users’ web usage. However this behaviour has not actually been observed. Security issuesYes. Downloads and installs arbitrary unsigned code as part of an update feature; it claims that it will prompt you before installing extra third-party software. Stability problemsNone known. Although it sometimes seems to go crazy and start connecting to its controlling servers every couple of seconds, which generates an annoying amount of traffic. RemovalThere are uninstallers available for v5 and v6 from the manufacturers (not tested, may or may not work). Spybot update 2002-11-30 can also remove FreeScratchAndWin/v5. Spybot update 2003-03-27 can also remove FreeScratchAndWin/v6. Manual RemovalBeta variantOpen the registry (Start, Run, regedit) and delete the following keys: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\FSW Reboot Windows and delete the ‘FSW’ folder inside ‘Program Files’. You can also remove a leftover installer file from a DOS command prompt window (Start->Programs->Accessories): cd "%WinDir%\Downloaded Program Files" v5 variantOpen the registry (Start, Run, regedit) and delete the following keys: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\FSW Reboot Windows and delete the ‘FSW’ folder inside ‘Program Files’, along with the files ‘support.exe’ and ‘IdleUI.dll’ in the System folder (inside ‘Windows’, called ‘System32’ under Windows NT/2000/XP). You can also remove a leftover installer file from a DOS command prompt window (Start->Programs->Accessories): cd "%WinDir%\Downloaded Program Files" Finally, go to Internet Options and reset your home page. v6 variantThe v6 variant (Free Scratch Cards) uses random eight-letter filenames in the System folder (in ‘Windows’, called ‘System32’ under Windows NT/2000/XP). Find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run and delete the random-looking eight-letter value pointing to a similarly named EXE in the System folder. (eg. bprplgqf). This should Restart the computer and open the System folder. Delete the file with the same name as you saw in the Run registry entry along with ‘fsc.ini’. There should be some other eight-letter random files you can delete to clean up if you like:
Make sure you have removed lop as well; unfortunately this means more random filename finding. LinksFreeScratchAndWin and Free Scratch Cards sites. * Parasite information and detection script by Andrew Clover - www.doxdesk.com, used with permission. For more information about Scumware, Spyware and Parasites, their sources and their cure, visit our About Parasites page and related Tech Links. Visit our new services portal at Allen One for a completely new parasite database format, comming November 2005! |