Help - Search - Members - Calendar
Full Version: Malicious Banner Ads
B.I.S.S. Forums > Malware Research Forum > Malware Playground
Kimberly
Please help us with the removal of malicious banner ads. If you find a web site that is the victim of a redirecting Flash advert, if you have been a victim of a redirect, please perform the steps below before returning to the website.
If you feel uncomfortable going back to the website, please take a few minutes to report it here. Give us as much details as possible.

Cleanup of cookies and temporary files can be done either manually or with the help of a program. You can choose any of the methods listed below as long as it cleans out your flash cookies also.

<h4>
Manual cleanup
</h4>
Clean out your Temporary Internet files. Proceed like this:

Quit Internet Explorer, all browsers and quit any instances of Windows Explorer.

For Internet Explorer 7
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete... under Browsing History.
  • Next to Temporary Internet Files, click Delete files, and then click OK.
  • Next to Cookies, click Delete cookies, and then click OK.
  • Next to History, click Delete history, and then click OK.
  • Click the Close button.
  • Click OK.
For Internet Explorer 4.x - 6.x
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box, and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
For Netscape 4.x and Up
  • Click Edit from the Netscape menubar.
  • Click Preferences... from the Edit menu.
  • Expand the Advanced menu by clicking the triangle sign.
  • Click Cache.
  • Click both the Clear Memory Cache and the Clear Disk Cache buttons.
For Mozilla 1.x and Up
  • Click Edit from the Mozilla menubar.
  • Click Preferences... from the Edit menu.
  • Expand the Advanced menu by clicking the plus sign.
  • Click Cache.
  • Click the Clear Cache button.
For Opera
  • Click File from the Opera menubar.
  • Click Preferences... from the File menu.
  • Click the History and Cache menu.
  • Click the two Clear buttons next to Typed in addresses and Visited addresses (history) and click the Empty now button to clear the Disk cache.
  • Click Ok to close the Preferences menu.
______________________________

Clean out your Flash Cookies by using one of the methods below.
  1. Manually.
    First make sure that you can see hidden files.
    • Click Start.
    • Click My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Show hidden files and folders.
    • Uncheck the Hide protected operating system files (recommended) option.
    • Click Yes to confirm.
    • Uncheck the Hide file extensions for known file types.
    • Click OK.
    Using Windows Explorer navigate to C:\Documents and Settings\[Your username]\Application Data\Macromedia\Flash Player. Delete all files and sub folders.
  2. Using the Flash Settings Manager.
    • Navigate to the Flash help site.
    • You will see your proper settings as shown below.
      IPB Image
    • Click Delete all sites.
    • Confirm your action.
    Note: This method will leave behind all empty folders and the Macromedia cookie. (C:\Documents and Settings\[Your username]\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol)
<h4>
Cleanup using a program
</h4>
Use CCleaner for example. Select the slim build without toolbar. Save to your desktop and install the application.
Make sure that at least the following items are checked under the Windows tab for your browser(s).
  • Temporary Internet files.
  • Cookies.
  • History.
  • Recently Typed URLS
Click on the Applications tab. Under Multimedia make sur that Adobe Flash Player is selected.
Click Analyse, check that you don't delete anything by mistake and click Run Cleaner.
Flash cookies are correctly cleaned out with CCleaner.

Note: Unless you are a experienced user, don't use the Registry options.

<h4>
Record your visit
</h4>
Download FiddlerCap to your desktop.
  1. Close all instances of Internet Explorer.
  2. Install the program by running FiddlerCapSetup.exe.
  3. After a succesfull install, FiddlerCap should start automatically. If it doesn't, you can start it from the START menu.
  4. Click the Start Capture button.
    IPB Image
  5. A new Internet Explorer window will appear. Type in the website address and try to reproduce the redirect.
  6. Verify that new lines are showing up in the FiddlerCap window.
    IPB Image
  7. When done, click the Stop Capture button.
    IPB Image
  8. Click the Save Capture button. Save the .SAZ file to your desktop.
    IPB Image
  9. Upload your .SAZ file to my channel at Bleeping Computer.
Note: FiddlerCap needs Microsoft .NET Framework Version 2.0 to work. If .NET is missing, you will be invited to install it.

Thanks.
Kimberly
<h4>
URL Snooper
</h4>
I found another tool able to capture network packets and it doesn't need the Microsoft .NET Framework to work. It's also able to capture traffic when you are on dial-up (needs a few extra steps - see URL Snooper homepage). The program is based on the free WinPcap network sniffing driver.

Download URL Snooper to your desktop.

Run the installer. If wincap is detected you will be prompted to install a more recent version.
  1. Start the program and switch to the Advanced Mode.
    IPB Image
  2. Make sure that the Protocol Filter is set to Show All instead of Multimedia URLs.
    IPB Image
  3. If not active, hit the button Sniff Network.
  4. It starts recording URLs.
  5. If you manage to catch the popup while sniffing, hit Stop Search to stop the recording process.
  6. Click File -> Save all URLs to a file.
  7. Upload your .txt file to my channel at Bleeping Computer.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.