New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online.
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 19)
· Marcia's (QA2)
· Bill G's (CO5)
· Paul's (AR 5)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· Recommend Us
· RegChat
· Reviews
· Search (Topics)
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 116
Comments: 5
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Another Hijack while logged in to CCSP
Goto page Previous  1, 2, 3  Next
 
Post new topic   Reply to topic       Computer Cops Forum Index -> Site Inbox
View previous topic :: View next topic  
Author Message
IACOJ

Site Admin
Site Admin



Joined: Oct 15, 2003
Posts: 263
Location: USA

PostPosted: Mon Mar 08, 2004 10:22 am    Post subject:
Reply with quote

Hi QuietOne.

I'm helping Paul trouble shoot this, and I need some more info. Some of my questions may make you feel like you are being asked to repeat yourself, I apologize if that is the case, it is more or less for my own troubleshoot tactics, and to make sure we are infact talking about the same thing.

Quote:
I clicked on the "View last post" anchor symbol on my "Error Message when attempting to quote post" topic and got slammed with about 50-75 requests for personal info. I blocked all via Norton Personal Firewall 2004.

50 - 75 requests for personal information is quite a lot. Normally I wouldn't ask you to post a copy of your hijackthis log in this forum, but would you mind please?

How did you bring up the posts prior to clicking on the view last post icon? Was it via the forum index,forum index/site inbox, new forum posts, your posts, or your topics?

At the time when the requests came, did you have any other browser windows open? Did the alerts from your firewall specifically say it was ccsp requesting the information? Was an IP included in the alert?

Paul,

I've tried for about the last 40 minutes, being logged in and being not logged in on two different computers and haven't been able to recreate it either.
Back to top
View users profile Send private message
Paul

Admin
Admin



Joined: Feb 22, 2002
Posts: 5154
Location: USA

PostPosted: Mon Mar 08, 2004 10:32 am    Post subject:
Reply with quote

JD you have duplicated this?
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
phoenix22

Site Admin
Site Admin
Premium Member
Premium Member


Joined: Mar 08, 2002
Posts: 4503
Location: "C & C Bird"

PostPosted: Mon Mar 08, 2004 10:33 am    Post subject:
Reply with quote

sorry......to clarify....it is a valid link w/no complications
_________________
"De Oppresso Liber" (We Liberate the Oppressed) Got Cawotts?? Got Ammo?? Holy Shinola Bat Babe! ....for Buddy...who lived it!
Back to top
View users profile Send private message Visit posters website
QuietOne

Lieutenant
Lieutenant



Joined: Dec 28, 2003
Posts: 227
Location: USA

PostPosted: Mon Mar 08, 2004 12:30 pm    Post subject:
Reply with quote

IACOJ wrote:
Hi QuietOne.

I'm helping Paul trouble shoot this, and I need some more info. Some of my questions may make you feel like you are being asked to repeat yourself, I apologize if that is the case, it is more or less for my own troubleshoot tactics, and to make sure we are infact talking about the same thing.

Hi IACOJ,

Don't worry about apologizing for making me repeat myself. While it's a PITA Rolling Eyes Smile , it's a fact of life in cases like this.

IACOJ wrote:
Quote:
I clicked on the "View last post" anchor symbol on my "Error Message when attempting to quote post" topic and got slammed with about 50-75 requests for personal info. I blocked all via Norton Personal Firewall 2004.

50 - 75 requests for personal information is quite a lot. Normally I wouldn't ask you to post a copy of your hijackthis log in this forum, but would you mind please?

Yea, you're right it is a lot. But that's part of the reason it's so $*&#& aggravating! As for posting my hijackthis log - sorry 'bout that but "No such animule on this here machine". Have searched all over, no joy. Will be happy to email you a copy of my NPF Alerts log which I exported, but won't post it on the web for security reasons. I don't have time right now to sanitize it soooooo, that's why I won't post it. If you don't mind, send me a PM with your email address in it and I'll email it to you direct. Have already tried attaching it to an email via CCSP: You don't have an email address and CCSP email doesn't have an attachment capability.

IACOJ wrote:
How did you bring up the posts prior to clicking on the view last post icon? Was it via the forum index,forum index/site inbox, new forum posts, your posts, or your topics?

The only time I've experienced this problem is by clickiing on the anchor symbol (preceded by the arrow) that comes up when there is a new UNREAD post attached to a topic. When I've clicked on the topic title, I've not experienced the problem. At least not yet. Rolling Eyes

IACOJ wrote:
At the time when the requests came, did you have any other browser windows open? Did the alerts from your firewall specifically say it was ccsp requesting the information? Was an IP included in the alert?

Can't say for absolutely positive about the first occurrence, but for the last (second) occurrence the answer is absolutely NOT! IF I did have another one open during the first occurrence (which is doubtful due to what I was doing at the time - I wasn't writing a post myself, I was simply attempting to view one), it would have been open to another page/view of somewhere at CCSP (i.e. viewing a different post for reference purposes while writing a post of my own).

IACOJ wrote:
Paul,

I've tried for about the last 40 minutes, being logged in and being not logged in on two different computers and haven't been able to recreate it either.

IACOJ,

Be sure to get a copy of the PM I sent Paul. It contains the text of the two messages I sent rusticdog about the first occurrence I had with this little nasty! Let me know if I can help any other way.

_________________
Stealth is the best weapon
Back to top
View users profile Send private message Send email
Paul

Admin
Admin



Joined: Feb 22, 2002
Posts: 5154
Location: USA

PostPosted: Mon Mar 08, 2004 3:42 pm    Post subject:
Reply with quote

You don't have HijackThis installed? Grab it from here and post your logfile.

http://computercops.biz/downloads-file-...11.03.html

_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
QuietOne

Lieutenant
Lieutenant



Joined: Dec 28, 2003
Posts: 227
Location: USA

PostPosted: Mon Mar 08, 2004 10:12 pm    Post subject:
Reply with quote

OK, HiJackThis dnld'd. Will be installed ASAP.

Here's the alerts file too.

Edited topic and deleted alerts file 3/9/04-0727

_________________
Stealth is the best weapon


Last edited by QuietOne on Tue Mar 09, 2004 8:29 am, edited 1 time in total
Back to top
View users profile Send private message Send email
Paul

Admin
Admin



Joined: Feb 22, 2002
Posts: 5154
Location: USA

PostPosted: Mon Mar 08, 2004 10:18 pm    Post subject:
Reply with quote

I checked your alerts and searched on:
  • cops
  • 67.227.
Nothing was found.
Back to top
View users profile Send private message Send email Visit posters website
QuietOne

Lieutenant
Lieutenant



Joined: Dec 28, 2003
Posts: 227
Location: USA

PostPosted: Mon Mar 08, 2004 10:49 pm    Post subject:
Reply with quote

Paul wrote:
I checked your alerts and searched on:
  • cops
  • 67.227.
Nothing was found.


I'll take your word for it Paul. But it's more than a little confusing to me about nothing found because of the way it happens. Well, maybe with hijackthis installed from now on I'll be able to part the fog! Wink

As I said a minute ago -- LATER, and I'm really outta here this time!

_________________
Stealth is the best weapon
Back to top
View users profile Send private message Send email
Paul

Admin
Admin



Joined: Feb 22, 2002
Posts: 5154
Location: USA

PostPosted: Mon Mar 08, 2004 11:10 pm    Post subject:
Reply with quote

Actually you can search that text file too without taking my word. If you resolve computercops.biz via nslookup and search on that IP you won't find it in the list. Neither will you find computercops.biz in it.
_________________
http://computercops.biz/
Back to top
View users profile Send private message Send email Visit posters website
QuietOne

Lieutenant
Lieutenant



Joined: Dec 28, 2003
Posts: 227
Location: USA

PostPosted: Mon Mar 08, 2004 11:16 pm    Post subject:
Reply with quote

Here's the hijackthis log. After I logged off and got it installed I realized what kind of software it was and so, decided not to make you wait till tomorrow. Had to change the name to hijackrthis.log.txt since CCSP won't accept .log extensions.

Anyway, here it is.



hijackthis.log.txt
 Description:

Download
 Filename:  hijackthis.log.txt
 Filesize:  10.8 KB
 Downloaded:  13 Time(s)


_________________
Stealth is the best weapon
Back to top
View users profile Send private message Send email
QuietOne

Lieutenant
Lieutenant



Joined: Dec 28, 2003
Posts: 227
Location: USA

PostPosted: Mon Mar 08, 2004 11:20 pm    Post subject:
Reply with quote

That's not what I'm confused about. I'm confused about the fact that this is happening while I'm browsing CCSP but there are no links or other indicators of it happening associated with CCSP. I'm glad it's that way, but still confused as to why things are happening the way they are. That's all.
_________________
Stealth is the best weapon
Back to top
View users profile Send private message Send email
QuietOne

Lieutenant
Lieutenant



Joined: Dec 28, 2003
Posts: 227
Location: USA

PostPosted: Tue Mar 23, 2004 12:01 pm    Post subject:
Reply with quote

Here's an updated copy of the HiJackThis.log file from my computer, just in case something new has cropped up since I submitted the original.


HiJackThis3-23-2004.log.txt
 Description:
MRV of HiJackThis

Download
 Filename:  HiJackThis3-23-2004.log.txt
 Filesize:  11.72 KB
 Downloaded:  10 Time(s)


_________________
Stealth is the best weapon
Back to top
View users profile Send private message Send email
IACOJ

Site Admin
Site Admin



Joined: Oct 15, 2003
Posts: 263
Location: USA

PostPosted: Sat Mar 27, 2004 10:52 am    Post subject:
Reply with quote

Hi Quietone,

Sorry for the delay. I was asking for some additional input on a couple things in your first hijacklog, and ended up getting busy and neglected to get back to you. I apologize. I have asked for some assistance on a few things from your second hijacklog because there are a few things that aren't showing up on any reference. I'll get back to you with that information as soon as I have it.

Until then have hijackthis fix the following, and please post another hijacklog after it's done:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ceoexpress.com/personal.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

O15 - Trusted Zone: www.ad-aware.nu
O15 - Trusted Zone: www.ceoexpress.com

O16 - DPF: {511073AD-BE56-4D43-AE68-93390514385E} (TechToolsActivex.TechTools) - hcp://system/TechTools.CAB

O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB


The reason I'm suggesting you remove ceoexpress from both startup and from trusted zone is because they are affiliated with TribalFusion and have been known to dump zedo.com tracking cookies on people machines. Ad-aware.nu is a dead link which is why I'm saying to remove it from trusted zone.

You have many things running on startup which don't need to be there. Most of them are related to special characters, it is entirely up to you whether you want them changed or not. If you want the unnecessary things removed, because they will simply work when required to work, please advise and I'll give you a list.
Back to top
View users profile Send private message
IACOJ

Site Admin
Site Admin



Joined: Oct 15, 2003
Posts: 263
Location: USA

PostPosted: Sat Mar 27, 2004 11:26 am    Post subject:
Reply with quote

Hi Quietone,

Please also have hjackthis fix the following before reposting your log.

O2 - BHO: (no name) - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll

O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
Back to top
View users profile Send private message
QuietOne

Lieutenant
Lieutenant



Joined: Dec 28, 2003
Posts: 227
Location: USA

PostPosted: Sat Mar 27, 2004 3:33 pm    Post subject:
Reply with quote

Hi IACOJ,

Have had HiJackThis fix all entries you requested EXCEPT for the two listed immediately below.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ceoexpress.com/personal.asp
O15 - Trusted Zone: www.ceoexpress.com

These entries (ceoexpress) are references to my home page and I don't wish to change that page as I have used it for more than seven years. I'll contact ceoexpress and see what they say about the Tribalfusion cookies. In the meantime, I'm running, and have been running for some time, Ad-Aware Pro each time I quit an Inet session and deleting any spyware (tracking) cookies, but as mentioned this is not a new routine for me. Additionally I've just recently decided to switch browsers to Opera in the last few days and currently have it set up to block 3rd party cookies, so hope that will help. Your comments appreciated.

With respect to the special chars issue, the three entries below are related to MS's Input Method Editors and I use them quite a bit in creating some of the docs I'm writing (WW2 stuff). They make extended access to Eurpopean language chars much quicker and easier for me, vice repeatedly going for the MS Char Map or some other mini-app. On the other hand, if the entries don't need to be loaded in order to access the IME's I'll be happy to delete them. Again, your comments appreciated.

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINNT\System32\IME\PINTLGNT\ImScInst.exe /SYNC

I'd like to get rid of the two entries immediately below, but don't see any entries in either Add/Remove Programs for related apps or in any of the registry keys to identify what apps they are related to. Both are web page entries but I'm unsure when/where they came from and whether they can be safely removed.

O16 - DPF: {3EB4F9EA-51A6-48DA-846A-0D69DCBA39EF} (DownloadManager Control) - http://download.akamaitools.com.edgesui...anager.ocx
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://content.kontiki.com/kdx/v2.11/ko...nt/kdx.cab

Have uninstalled several apps I had installed a long time ago and that were loading stuff on startup because I now no longer need them. Should have done it a long time ago but ...

Attached is the updated run of HiJackThis you requested.

As for the unnecessary things being removed that you mentioned, sure! Let me have a list and I'll sure dump as much as I can. It never hurts to clean house now and then.

Thanks again and I look forward to hearing back from you.



HiJackThis3-27-2004.log.txt
 Description:
MRV of HiJackThis

Download
 Filename:  HiJackThis3-27-2004.log.txt
 Filesize:  9.32 KB
 Downloaded:  1 Time(s)


_________________
Stealth is the best weapon
Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Site Inbox All times are GMT - 5 Hours
Goto page Previous  1, 2, 3  Next
Page 2 of 3

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops