|
Donations |
|
|
|
|
|
If you found this site helpful, please donate to help keep it online.
|
|
|
Survey |
|
|
|
|
|
|
|
|
Translate |
|
|
|
|
|
|
|
|
|
|
View previous topic :: View next topic |
Author |
Message |
IACOJ
Site Admin
Joined: Oct 15, 2003
Posts: 263
Location: USA
|
Posted: Mon Mar 08, 2004 10:22 am Post subject: |
|
|
Hi QuietOne.
I'm helping Paul trouble shoot this, and I need some more info. Some of my questions may make you feel like you are being asked to repeat yourself, I apologize if that is the case, it is more or less for my own troubleshoot tactics, and to make sure we are infact talking about the same thing.
Quote: |
I clicked on the "View last post" anchor symbol on my "Error Message when attempting to quote post" topic and got slammed with about 50-75 requests for personal info. I blocked all via Norton Personal Firewall 2004. |
50 - 75 requests for personal information is quite a lot. Normally I wouldn't ask you to post a copy of your hijackthis log in this forum, but would you mind please?
How did you bring up the posts prior to clicking on the view last post icon? Was it via the forum index,forum index/site inbox, new forum posts, your posts, or your topics?
At the time when the requests came, did you have any other browser windows open? Did the alerts from your firewall specifically say it was ccsp requesting the information? Was an IP included in the alert?
Paul,
I've tried for about the last 40 minutes, being logged in and being not logged in on two different computers and haven't been able to recreate it either.
|
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5154
Location: USA
|
Posted: Mon Mar 08, 2004 10:32 am Post subject: |
|
|
JD you have duplicated this?
_________________
http://computercops.biz/ |
|
Back to top |
|
|
phoenix22
Site Admin
Premium Member
Joined: Mar 08, 2002
Posts: 4503
Location: "C & C Bird"
|
Posted: Mon Mar 08, 2004 10:33 am Post subject: |
|
|
sorry......to clarify....it is a valid link w/no complications
_________________
"De Oppresso Liber" (We Liberate the Oppressed) Got Cawotts?? Got Ammo?? Holy Shinola Bat Babe! ....for Buddy...who lived it! |
|
Back to top |
|
|
QuietOne
Lieutenant
Joined: Dec 28, 2003
Posts: 227
Location: USA
|
Posted: Mon Mar 08, 2004 12:30 pm Post subject: |
|
|
IACOJ wrote: |
Hi QuietOne.
I'm helping Paul trouble shoot this, and I need some more info. Some of my questions may make you feel like you are being asked to repeat yourself, I apologize if that is the case, it is more or less for my own troubleshoot tactics, and to make sure we are infact talking about the same thing. |
Hi IACOJ,
Don't worry about apologizing for making me repeat myself. While it's a PITA , it's a fact of life in cases like this.
IACOJ wrote: |
Quote: |
I clicked on the "View last post" anchor symbol on my "Error Message when attempting to quote post" topic and got slammed with about 50-75 requests for personal info. I blocked all via Norton Personal Firewall 2004. |
50 - 75 requests for personal information is quite a lot. Normally I wouldn't ask you to post a copy of your hijackthis log in this forum, but would you mind please?
|
Yea, you're right it is a lot. But that's part of the reason it's so $*& aggravating! As for posting my hijackthis log - sorry 'bout that but "No such animule on this here machine". Have searched all over, no joy. Will be happy to email you a copy of my NPF Alerts log which I exported, but won't post it on the web for security reasons. I don't have time right now to sanitize it soooooo, that's why I won't post it. If you don't mind, send me a PM with your email address in it and I'll email it to you direct. Have already tried attaching it to an email via CCSP: You don't have an email address and CCSP email doesn't have an attachment capability.
IACOJ wrote: |
How did you bring up the posts prior to clicking on the view last post icon? Was it via the forum index,forum index/site inbox, new forum posts, your posts, or your topics? |
The only time I've experienced this problem is by clickiing on the anchor symbol (preceded by the arrow) that comes up when there is a new UNREAD post attached to a topic. When I've clicked on the topic title, I've not experienced the problem. At least not yet.
IACOJ wrote: |
At the time when the requests came, did you have any other browser windows open? Did the alerts from your firewall specifically say it was ccsp requesting the information? Was an IP included in the alert? |
Can't say for absolutely positive about the first occurrence, but for the last (second) occurrence the answer is absolutely NOT! IF I did have another one open during the first occurrence (which is doubtful due to what I was doing at the time - I wasn't writing a post myself, I was simply attempting to view one), it would have been open to another page/view of somewhere at CCSP (i.e. viewing a different post for reference purposes while writing a post of my own).
IACOJ wrote: |
Paul,
I've tried for about the last 40 minutes, being logged in and being not logged in on two different computers and haven't been able to recreate it either. |
IACOJ,
Be sure to get a copy of the PM I sent Paul. It contains the text of the two messages I sent rusticdog about the first occurrence I had with this little nasty! Let me know if I can help any other way.
_________________
Stealth is the best weapon
|
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5154
Location: USA
|
Posted: Mon Mar 08, 2004 3:42 pm Post subject: |
|
|
You don't have HijackThis installed? Grab it from here and post your logfile.
http://computercops.biz/downloads-file-...11.03.html
_________________
http://computercops.biz/ |
|
Back to top |
|
|
QuietOne
Lieutenant
Joined: Dec 28, 2003
Posts: 227
Location: USA
|
Posted: Mon Mar 08, 2004 10:12 pm Post subject: |
|
|
OK, HiJackThis dnld'd. Will be installed ASAP.
Here's the alerts file too.
Edited topic and deleted alerts file 3/9/04-0727
_________________
Stealth is the best weapon
Last edited by QuietOne on Tue Mar 09, 2004 8:29 am, edited 1 time in total |
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5154
Location: USA
|
Posted: Mon Mar 08, 2004 10:18 pm Post subject: |
|
|
I checked your alerts and searched on:
Nothing was found.
|
|
Back to top |
|
|
QuietOne
Lieutenant
Joined: Dec 28, 2003
Posts: 227
Location: USA
|
Posted: Mon Mar 08, 2004 10:49 pm Post subject: |
|
|
Paul wrote: |
I checked your alerts and searched on:
Nothing was found.
|
I'll take your word for it Paul. But it's more than a little confusing to me about nothing found because of the way it happens. Well, maybe with hijackthis installed from now on I'll be able to part the fog!
As I said a minute ago -- LATER, and I'm really outta here this time!
_________________
Stealth is the best weapon
|
|
Back to top |
|
|
Paul
Admin
Joined: Feb 22, 2002
Posts: 5154
Location: USA
|
Posted: Mon Mar 08, 2004 11:10 pm Post subject: |
|
|
Actually you can search that text file too without taking my word. If you resolve computercops.biz via nslookup and search on that IP you won't find it in the list. Neither will you find computercops.biz in it.
_________________
http://computercops.biz/ |
|
Back to top |
|
|
QuietOne
Lieutenant
Joined: Dec 28, 2003
Posts: 227
Location: USA
|
Posted: Mon Mar 08, 2004 11:16 pm Post subject: |
|
|
Here's the hijackthis log. After I logged off and got it installed I realized what kind of software it was and so, decided not to make you wait till tomorrow. Had to change the name to hijackrthis.log.txt since CCSP won't accept .log extensions.
Anyway, here it is.
Description: |
|
Download |
Filename: |
hijackthis.log.txt |
Filesize: |
10.8 KB |
Downloaded: |
13 Time(s) |
_________________
Stealth is the best weapon
|
|
Back to top |
|
|
QuietOne
Lieutenant
Joined: Dec 28, 2003
Posts: 227
Location: USA
|
Posted: Mon Mar 08, 2004 11:20 pm Post subject: |
|
|
That's not what I'm confused about. I'm confused about the fact that this is happening while I'm browsing CCSP but there are no links or other indicators of it happening associated with CCSP. I'm glad it's that way, but still confused as to why things are happening the way they are. That's all.
_________________
Stealth is the best weapon |
|
Back to top |
|
|
QuietOne
Lieutenant
Joined: Dec 28, 2003
Posts: 227
Location: USA
|
Posted: Tue Mar 23, 2004 12:01 pm Post subject: |
|
|
Here's an updated copy of the HiJackThis.log file from my computer, just in case something new has cropped up since I submitted the original.
Description: |
|
Download |
Filename: |
HiJackThis3-23-2004.log.txt |
Filesize: |
11.72 KB |
Downloaded: |
10 Time(s) |
_________________
Stealth is the best weapon
|
|
Back to top |
|
|
IACOJ
Site Admin
Joined: Oct 15, 2003
Posts: 263
Location: USA
|
Posted: Sat Mar 27, 2004 10:52 am Post subject: |
|
|
Hi Quietone,
Sorry for the delay. I was asking for some additional input on a couple things in your first hijacklog, and ended up getting busy and neglected to get back to you. I apologize. I have asked for some assistance on a few things from your second hijacklog because there are a few things that aren't showing up on any reference. I'll get back to you with that information as soon as I have it.
Until then have hijackthis fix the following, and please post another hijacklog after it's done:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ceoexpress.com/personal.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O15 - Trusted Zone: www.ad-aware.nu
O15 - Trusted Zone: www.ceoexpress.com
O16 - DPF: {511073AD-BE56-4D43-AE68-93390514385E} (TechToolsActivex.TechTools) - hcp://system/TechTools.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
The reason I'm suggesting you remove ceoexpress from both startup and from trusted zone is because they are affiliated with TribalFusion and have been known to dump zedo.com tracking cookies on people machines. Ad-aware.nu is a dead link which is why I'm saying to remove it from trusted zone.
You have many things running on startup which don't need to be there. Most of them are related to special characters, it is entirely up to you whether you want them changed or not. If you want the unnecessary things removed, because they will simply work when required to work, please advise and I'll give you a list. |
|
Back to top |
|
|
IACOJ
Site Admin
Joined: Oct 15, 2003
Posts: 263
Location: USA
|
Posted: Sat Mar 27, 2004 11:26 am Post subject: |
|
|
Hi Quietone,
Please also have hjackthis fix the following before reposting your log.
O2 - BHO: (no name) - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll |
|
Back to top |
|
|
QuietOne
Lieutenant
Joined: Dec 28, 2003
Posts: 227
Location: USA
|
Posted: Sat Mar 27, 2004 3:33 pm Post subject: |
|
|
Hi IACOJ,
Have had HiJackThis fix all entries you requested EXCEPT for the two listed immediately below.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ceoexpress.com/personal.asp
O15 - Trusted Zone: www.ceoexpress.com
These entries (ceoexpress) are references to my home page and I don't wish to change that page as I have used it for more than seven years. I'll contact ceoexpress and see what they say about the Tribalfusion cookies. In the meantime, I'm running, and have been running for some time, Ad-Aware Pro each time I quit an Inet session and deleting any spyware (tracking) cookies, but as mentioned this is not a new routine for me. Additionally I've just recently decided to switch browsers to Opera in the last few days and currently have it set up to block 3rd party cookies, so hope that will help. Your comments appreciated.
With respect to the special chars issue, the three entries below are related to MS's Input Method Editors and I use them quite a bit in creating some of the docs I'm writing (WW2 stuff). They make extended access to Eurpopean language chars much quicker and easier for me, vice repeatedly going for the MS Char Map or some other mini-app. On the other hand, if the entries don't need to be loaded in order to access the IME's I'll be happy to delete them. Again, your comments appreciated.
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINNT\System32\IME\PINTLGNT\ImScInst.exe /SYNC
I'd like to get rid of the two entries immediately below, but don't see any entries in either Add/Remove Programs for related apps or in any of the registry keys to identify what apps they are related to. Both are web page entries but I'm unsure when/where they came from and whether they can be safely removed.
O16 - DPF: {3EB4F9EA-51A6-48DA-846A-0D69DCBA39EF} (DownloadManager Control) - http://download.akamaitools.com.edgesui...anager.ocx
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://content.kontiki.com/kdx/v2.11/ko...nt/kdx.cab
Have uninstalled several apps I had installed a long time ago and that were loading stuff on startup because I now no longer need them. Should have done it a long time ago but ...
Attached is the updated run of HiJackThis you requested.
As for the unnecessary things being removed that you mentioned, sure! Let me have a list and I'll sure dump as much as I can. It never hurts to clean house now and then.
Thanks again and I look forward to hearing back from you.
Description: |
|
Download |
Filename: |
HiJackThis3-27-2004.log.txt |
Filesize: |
9.32 KB |
Downloaded: |
1 Time(s) |
_________________
Stealth is the best weapon
|
|
Back to top |
|
|
|
|
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
|
Powered by phpBB 2.0.8a © 2001 phpBB Group
Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops
|