<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>ID Theft Product &#187; 1342</title>
	<link>http://idtheftproduct.com</link>
	<description>Mailboxes, Shredders, Software &#38; Services</description>
	<pubDate>Fri, 21 Dec 2007 21:29:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
	<language>en</language>
			<item>
		<title>Cleaning the closet: HiPoint hijackers</title>
		<link>http://idtheftproduct.com/2007/12/09/cleaning-the-closet-hipoint-hijackers/</link>
		<comments>http://idtheftproduct.com/2007/12/09/cleaning-the-closet-hipoint-hijackers/#comments</comments>
		<pubDate>Sun, 09 Dec 2007 09:58:37 +0000</pubDate>
		<dc:creator></dc:creator>
		
		<category><![CDATA[1342]]></category>

		<guid isPermaLink="false">http://idtheftproduct.com/2007/12/09/cleaning-the-closet-hipoint-hijackers/</guid>
		<description><![CDATA[Earlier this year, I posted about my experience with 0ww and the HiPoint Ltd hijackers. 
This post has generated a few e-mails with requests for help to remove the threat. So here goes a mock-up of one of the answers:
 Steve H. sent me an email asking how to remove the HiPoint tools from his computer. [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier this year, I posted about my experience with 0ww and the <a href="/node/103">HiPoint Ltd hijackers</a>. </p>
<p>This post has generated a few e-mails with requests for help to remove the threat. So here goes a mock-up of one of the answers:</p>
<p> Steve H. sent me an email asking how to remove the HiPoint tools from his computer. This is my reply:  </p>
<p>### </p>
<p>From your message, I believe that only one computer is exploited, and that your request is not regarding a business network. Please correct me if I am wrong, as that would require a different approach.</p>
<p>What the HiPoint tools is doing to your computer, I can only guess (as I have no intention of actually trying it currently). <br />To remove it, you may want to try tools like Spybot Search and Destroy from Kolla in Germany: <a href="http://www.kolla.de/">www.kolla.de</a> - this is free tool, which I use much myself. Make sure you download from Kolla himself - as there are a few rouge versions out there. <br />There are alternatives that may or may not work better - among those Lavasoft Ad-Aware is well known. <a href="http://www.lavasoftusa.com/">http://www.lavasoftusa.com/</a><br />It is not free, however. </p>
<p>If it is not possible to remove it (either the tools do not find it, or finds it again and again), then I suggest you low-level format your hard drive, and reinstall your OS. Make sure you do have backups of your data before the formatting, though, or the data is gone. </p>
<p>The re-installation process takes a few hours, and you need to patch your OS after the installation. </p>
<p>The true challenge is in the future - to avoid these kind of attacks. They get smarter by every day, and very few, if anyone, can expect to keep their computer clean all the time. So I hope you do not feel that you have done somethings stupid by clicking the button - remember I almost did the same, and I deal with these things as my job&#8230; <img src='http://idtheftproduct.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>###</p>
<p>Steve also had some issues with the file MGRS.exe. </p>
<p>This thread gives valuable input: <a href="http://forums.techguy.org/malware-removal-hijackthis-logs/591494-solved-mgrs-exe-startup.html">http://forums.techguy.org/malware-removal-hijackthis-logs/591494-solved-mgrs-exe-startup.html</a></p>
<p>###</p>
<p>And of course - why not just use the <a href="http://onecare.live.com/site/en-US/center/howsafe.htm?s_cid=mscom_msrt">Microsoft own malware scanner</a>? After all, they made the OS, so they should be in control of what is what? Right?  One of the bonuses of using the Microsoft OneCare tools, is that they are free, and you know you can trust the publisher. </p>
<p> ### </p>
<p>To end this post, five tips on how to avoid the malware:</p>
<p>1. Keep an updated and trusted AntiVirus tool running at all times. Make sure it focuses on doing its job, and not telling you what it is about all the time. It is a generally good idea to combine it with a software firewall and antispam.  </p>
<p>2. Keep you OS updated at all times. If you run windows, make sure Windows Update is on, and configured for automatic download and update. If you run Linux, make sure you set it up to download and install updates automatically (how? depends on the distros - usually pretty simple by adding an update source and setting it to check automatically)</p>
<p>3. Use common sense when surfing, downloading and running software. Not sure? Then don&#8217;t do it!  </p>
<p>4. Learn how to deal with it - how to spot a hoax, how to recognize a bad website, and how to see the bad guys. Remember that if an offer sounds too good to be true, it is! Even on the Internet! </p>
<p>5. Have fun! After all, what is the use of computers and Internet if you cannot have some fun with it? And when you are protected, and know how to deal with the threats, you can surf in confidence!    </p>
<div>
<div>Bookmark/Search this post with: </div>
<p><a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2Fcleaning_the_closet_removing_HiPoint&amp;title=Cleaning+the+closet%3A+HiPoint+hijackers" title="Bookmark this post on del.icio.us." rel="nofollow"><img src="/modules/service_links/delicious.png" alt="delicious" /></a> | <a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2Fcleaning_the_closet_removing_HiPoint&amp;title=Cleaning+the+closet%3A+HiPoint+hijackers" title="Digg this post on digg.com." rel="nofollow"><img src="/modules/service_links/digg.png" alt="digg" /></a> | <a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2Fcleaning_the_closet_removing_HiPoint&amp;title=Cleaning+the+closet%3A+HiPoint+hijackers" title="Submit this post on reddit.com." rel="nofollow"><img src="/modules/service_links/reddit.png" alt="reddit" /></a> | <a href="http://ma.gnolia.com/bookmarklet/add?url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2Fcleaning_the_closet_removing_HiPoint&amp;title=Cleaning+the+closet%3A+HiPoint+hijackers" title="Submit this post on ma.gnolia.com." rel="nofollow"><img src="/modules/service_links/magnoliacom.png" alt="magnoliacom" /></a> | <a href="http://www.newsvine.com/_tools/seed&amp;save?u=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2Fcleaning_the_closet_removing_HiPoint&amp;h=Cleaning+the+closet%3A+HiPoint+hijackers" title="Submit this post on newsvine.com." rel="nofollow"><img src="/modules/service_links/newsvine.png" alt="newsvine" /></a> | <a href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2Fcleaning_the_closet_removing_HiPoint&amp;t=Cleaning+the+closet%3A+HiPoint+hijackers" title="Submit this post on furl.net." rel="nofollow"><img src="/modules/service_links/furl.png" alt="furl" /></a> | <a href="http://technorati.com/cosmos/search.html?url=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2Fcleaning_the_closet_removing_HiPoint" title="Search Technorati for links to this post." rel="nofollow"><img src="/modules/service_links/technorati.png" alt="technorati" /></a> | <a href="http://blogs.icerocket.com/search?q=http%3A%2F%2Fwww.roer.com%2Fsecurity%2Farchive%2F2007%2Fdecember%2Fcleaning_the_closet_removing_HiPoint" title="Search IceRocket for links to this post." rel="nofollow"><img src="/modules/service_links/icerocket.png" alt="icerocket" /></a></div>
<p><a href="http://feeds.feedburner.com/~a/kairoer?a=crIeyF"><img src="http://feeds.feedburner.com/~a/kairoer?i=crIeyF" border="0"></img></a></p>
<div>
<a href="http://feeds.feedburner.com/~f/kairoer?a=z9CnfyC"><img src="http://feeds.feedburner.com/~f/kairoer?i=z9CnfyC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=2r9FNlC"><img src="http://feeds.feedburner.com/~f/kairoer?i=2r9FNlC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=ZRVT9Kc"><img src="http://feeds.feedburner.com/~f/kairoer?i=ZRVT9Kc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=q2OWAcc"><img src="http://feeds.feedburner.com/~f/kairoer?i=q2OWAcc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=yXxyYfc"><img src="http://feeds.feedburner.com/~f/kairoer?i=yXxyYfc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/kairoer?a=8KGE6JC"><img src="http://feeds.feedburner.com/~f/kairoer?i=8KGE6JC" border="0"></img></a><br />
 <a href="http://feeds.feedburner.com/~f/AmbersailSecNews?a=rQdlxyC"><img src="http://feeds.feedburner.com/~f/AmbersailSecNews?i=rQdlxyC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AmbersailSecNews?a=302s9FC"><img src="http://feeds.feedburner.com/~f/AmbersailSecNews?i=302s9FC" border="0"></img></a> </div>
<p><img src="http://feeds.feedburner.com/~r/kairoer/~4/197495531" height="1">
<p>Original post by <em><a href="http://feeds.feedburner.com/~r/kairoer/~3/197495531/cleaning_the_closet_removing_HiPoint" title="">Yahoo! News Search Results for identity theft</a></em></p>
<h3>Additional Reading</h3><ul class="related_post"><li><a href="http://idtheftproduct.com/2007/11/11/nbc-direct-launched-download-shows-for-free/" title="NBC Direct launched, download shows for free">NBC Direct launched, download shows for free</a></li><li><a href="http://idtheftproduct.com/2007/12/18/opinion-mixing-open-and-closed-source-managing-risk/" title="Opinion: Mixing open- and closed-source, managing risk">Opinion: Mixing open- and closed-source, managing risk</a></li><li><a href="http://idtheftproduct.com/2007/12/03/identity-thief-snatches-insurance-data-upi/" title="Identity thief snatches insurance data (UPI)">Identity thief snatches insurance data (UPI)</a></li><li><a href="http://idtheftproduct.com/2007/12/18/session-hijacking-in-wireless-networks/" title="Session Hijacking in Wireless Networks">Session Hijacking in Wireless Networks</a></li><li><a href="http://idtheftproduct.com/2007/12/14/botnets-threaten-online-security/" title="&#8216;Botnets&#8217; threaten online security">&#8216;Botnets&#8217; threaten online security</a></li><li><a href="http://idtheftproduct.com/2007/12/20/tiger-team-brings-haxploitation-to-tv/" title="Tiger Team brings haxploitation to TV">Tiger Team brings haxploitation to TV</a></li><li><a href="http://idtheftproduct.com/2007/11/30/conflicting-reports-about-identity-theft-krem-spokane/" title="Conflicting reports about identity theft (KREM Spokane)">Conflicting reports about identity theft (KREM Spokane)</a></li><li><a href="http://idtheftproduct.com/2007/12/13/notable-security-breeches-in-2007/" title="Notable Security Breeches in 2007">Notable Security Breeches in 2007</a></li><li><a href="http://idtheftproduct.com/2007/12/12/army-sets-up-new-office-of-videogames/" title="Army Sets Up New Office of Videogames">Army Sets Up New Office of Videogames</a></li><li><a href="http://idtheftproduct.com/2007/12/13/collaborative-systems-and-ajaxria-security/" title="Collaborative systems and Ajax/RIA security">Collaborative systems and Ajax/RIA security</a></li></ul><!-- Created with WP-Autoblog (http://elliottback.com) -->]]></content:encoded>
			<wfw:commentRss>http://idtheftproduct.com/2007/12/09/cleaning-the-closet-hipoint-hijackers/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.213 seconds -->
