The Mudcat Café TM
Thread #68739   Message #1161490
Posted By: Stilly River Sage
14-Apr-04 - 11:36 AM
Thread Name: Tech: spyware-etc..how it happens -what to do
Subject: RE: Tech: spyware-etc..how it happens -what to do
I went in this morning again to see what popped up after I'd removed stuff yesterday. I did another deep scan, sending it into Windows to look for stuff lodged in there. I came up with one more malware, a parasite called "e2give" that has a couple of variants. It's loaded by (drum roll, please) an ActiveX drive-by. I set the IE browser to ask me if it may run ActiveX scripts and so far it only comes up with places it should be--like on banking and such. But I'll be curious to see who else tries to run them.

http://www.doxdesk.com/parasite/E2Give.html has some interesting information about e2give.

Description
E2Give is an Internet Explorer Browser Helper Object that redirects accesses to web merchants in order to claim their affiliate fees.

Distribution
Installed by ActiveX drive-by download, believed to be used in pop-up advertisements.

What it does

Advertising
No.

Privacy violation
Not known.

Security issues
Not known.

Stability problems
No, though it can make opening new Windows Explorer windows very slow.

Removal
The E2GBHO variant has an entry in the Control Panel's Add/Remove Programs feature — choose 'E2Give Browser Add On'

Oh, by the way. Windows has more important security updates they released yesterday. Go ahead and visit Windows Update and get them installed.

SRS