Acura Legend Forum Acura Legend Forum
Go Back   The Acura Legend & Acura RL Forum > Off Topic > The Lounge > Computers
Register Home Forum Active Topics Photo Gallery Wiki AIM Chat DIY Search Today's Posts Mark Forums Read

Computers Computer acting up? Have software questions? Post them in here!


       

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old 11-25-05, 11:15 PM   #1 (permalink)
I like shiny
 
91LSMAN's Avatar
 
Join Date: Jan 2002
Location: Puyallup, WA
Posts: 14,892


Car 1: 91 LS Coupe (GONE)
Car 2: Current-02 Corvette
Car 3: 94 LS Coupe (Bro's)



iTrader: (4)
Weird Problem: Redirecting Web Pages... Possibly a Trojin/Virus...

Ok, here is the thing: for the longest time I didn't have any virus software installed on my computer, because I was not opening any e-mail attachments and I was not downloading many files. I started getting ads and pop-ups, sometimes my web pages would re-direct to other things. So I installed Spy-bot and Ad-aware and used those a lot. I also installed Microsofts new Spyware program. I also have Mcaffee virus detection software due to the fact that I have Comcast (It's free with their internet service). All the problems are taken care of, but ONE. It's very weird, every once in a while I would get re-directed to a "naughty" web page. Then I stopped that from happening by getting some updates on the software, etc. Then I went to HondaFloormats.com and got redirected, and being that was the only website it happened on, I stopped going to that website. A few minutes ago I was looking for webistes that offered custom floormats, clicked on one and was re-directed to the same naughty stuff as when I would go to Hondafloormats.com.

Also, every once in a while Mcaffee pops up a little window that say "trojen detected" and it delets it. How are these trojens popping up with all the protection software I have? My thought is there is a file on my computer from before I was running the protection software that keeps re-creating the trojen file, which file, I have no idea.

Any suggestions?
__________________
91LSMAN is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Advertisement
 
Old 11-26-05, 12:01 AM   #2 (permalink)
TSX pupils
 
Join Date: Jun 2003
Location: Hillside, NJ
Posts: 9,528


Car 1: 1995 Legend GS



iTrader: (4)
Send a message via AIM to Daddymac117 Send a message via Yahoo to Daddymac117
does it always redirect to the same site everytime, or does it alternate between a few different ones?
__________________

FS: Weapon R Secret Weapon intake (NON TCS/Type I) in box, never used. $140 shipped.
I'll make a thread once i figure out the best way to ship it, but PM if interested.
Daddymac117 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 12:05 AM   #3 (permalink)
Victory is fleeting...
 
duck's Avatar
 
Join Date: Mar 2004
Location: Duck!
Posts: 6,125


Car 1: 2007 Honda Ridgeline



iTrader: (1)
What's the website?

Let me check out hondafloormats.com...
__________________



Rythmic, systemic and world control Magnetic, genetic, dement your sou...
duck is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 12:06 AM   #4 (permalink)
Victory is fleeting...
 
duck's Avatar
 
Join Date: Mar 2004
Location: Duck!
Posts: 6,125


Car 1: 2007 Honda Ridgeline



iTrader: (1)
hondafloormats.com works for me. Post the re-directed site, if you have Coolweb, you'll get redirected to coolwebsearch.com. And if you have coolweb, you're hosed.
__________________



Rythmic, systemic and world control Magnetic, genetic, dement your sou...
duck is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 01:35 AM   #5 (permalink)
I like shiny
 
91LSMAN's Avatar
 
Join Date: Jan 2002
Location: Puyallup, WA
Posts: 14,892


Car 1: 91 LS Coupe (GONE)
Car 2: Current-02 Corvette
Car 3: 94 LS Coupe (Bro's)



iTrader: (4)
It's a little different each time. There are different pictures of "ladies" and a link or two. I'd try it right now to see exactly what it is, but my little brother is right behind me watching TV. Once he goes to bed, I'll try and see if I can copy it. I think part of it is coming from my computer, it's actually a slightly different URL each time.
__________________
91LSMAN is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 01:54 AM   #6 (permalink)
Victory is fleeting...
 
duck's Avatar
 
Join Date: Mar 2004
Location: Duck!
Posts: 6,125


Car 1: 2007 Honda Ridgeline



iTrader: (1)
Get those two spyware programs, ad-aware and spybot now and run them. You could also have an entry in your hosts file that is redirecting you. The hosts file is a vestige from pre-DNS days, and is actually a lot of fun when you want to muck around with someone, but a pain also if it gets written to for hijacking purposes. But we'll burn that bridge after you run your spyware sweep.
__________________



Rythmic, systemic and world control Magnetic, genetic, dement your sou...
duck is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 02:04 AM   #7 (permalink)
Registered User
 
MagicMikey's Avatar
 
Join Date: Jun 2004
Location: Montreal, Canada
Posts: 839


Car 1: '91 LS Sedan



iTrader: (3)
Send a message via MSN to MagicMikey
What browser are you using? IE? switch to mozilla or something similar if so.

Try scanning with Spybot because this is def. a spyware problem.
MagicMikey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 02:09 AM   #8 (permalink)
I like shiny
 
91LSMAN's Avatar
 
Join Date: Jan 2002
Location: Puyallup, WA
Posts: 14,892


Car 1: 91 LS Coupe (GONE)
Car 2: Current-02 Corvette
Car 3: 94 LS Coupe (Bro's)



iTrader: (4)
Ok, the thing is, it's been doing it for a long time. And I'm using IE.

Now the crazy thing. Hondafloormats.com has been re-designed since the last time I went there. And now it's not happening. I'm going to try and find a website that it'll r-direct.

Oh and when I run different spyware programs it usually wont find anything. This is actually something that's been happening for a while, I'm just getting tired of it.
__________________
91LSMAN is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 02:15 AM   #9 (permalink)
I like shiny
 
91LSMAN's Avatar
 
Join Date: Jan 2002
Location: Puyallup, WA
Posts: 14,892


Car 1: 91 LS Coupe (GONE)
Car 2: Current-02 Corvette
Car 3: 94 LS Coupe (Bro's)



iTrader: (4)
Do not click any links in this post. I don't want anyone to "get" or see anything they shouldn't (disclaimer)


Ok, just got it to happen-this website: http://www.ggbailey.com/escalate/sto...iley&page=Main

This is what it re-directed to: http://www.marketrealsearch.com/dein.php?id=dname

2nd time: http://www.findsap.org/dein.php?id=dname

3rd time: http://www.searchregister.org/dein.php?id=dname

other time:http://searchengineand.biz/search.php?q=allstate


There is something on my computer doing this and when I run a spyware program (I'll do it right now) it'll find something, sometimes, and then it'll come back, like my computer is creating it.
__________________
91LSMAN is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 02:19 AM   #10 (permalink)
TSX pupils
 
Join Date: Jun 2003
Location: Hillside, NJ
Posts: 9,528


Car 1: 1995 Legend GS



iTrader: (4)
Send a message via AIM to Daddymac117 Send a message via Yahoo to Daddymac117
hmm...the "other time" link, was that the 4th time, or that was literally a diff time all together?

i noticed the first 3 all link to the same site, just has a diff url.

its definately a spyware problem...make sure those programs youre using are fully updated before you scan, just incase its something relatively new.
__________________

FS: Weapon R Secret Weapon intake (NON TCS/Type I) in box, never used. $140 shipped.
I'll make a thread once i figure out the best way to ship it, but PM if interested.
Daddymac117 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 02:24 AM   #11 (permalink)
Victory is fleeting...
 
duck's Avatar
 
Join Date: Mar 2004
Location: Duck!
Posts: 6,125


Car 1: 2007 Honda Ridgeline



iTrader: (1)
I fear you may have the most vile trojan out there, coolwebsearch. Go to

http://www.intermute.com/spysubtract..._download.html

and download their standalone version of cwshredder and run it. Let us know what it finds. Hopefully, I'm wrong.
__________________



Rythmic, systemic and world control Magnetic, genetic, dement your sou...
duck is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 03:17 AM   #12 (permalink)
I like shiny
 
91LSMAN's Avatar
 
Join Date: Jan 2002
Location: Puyallup, WA
Posts: 14,892


Car 1: 91 LS Coupe (GONE)
Car 2: Current-02 Corvette
Car 3: 94 LS Coupe (Bro's)



iTrader: (4)
Ok, ran spybot. Tried to update it. It didn't find any new updates. Ran very slow and I stopped it. Here is what it found.

User abort!: Scan was not completed successfully. ()

Adbureau: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@katu.adbureau[2].txt

Advertising.com: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@advertising[1].txt

Avenue A, Inc.: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@atdmt[2].txt

Commission Junction: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@qksrv[2].txt

CoolWWWSearch.CameUp: Class (Registry key, nothing done)
HKEY_CLASSES_ROOT\ToolBand.ToolBandObj

CoolWWWSearch.CameUp: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{08BEC6AA-49FC-4379-3587-4B21E286C19E}

CoreMetrics: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@twci.coremetrics[1].txt

DoubleClick: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@doubleclick[2].txt

FastClick: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@fastclick[1].txt

HitsLink: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@counter2.hitslink[2].txt

MediaPlex: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@mediaplex[1].txt

ValueClick: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@valueclick[1].txt

WebTrends live: Tracking cookie or cookie of tracking site (File, nothing done)
C:\Documents and Settings\Patrick Cain\Cookies\patrick cain@statse.webtrendslive[1].txt


--- Spybot-S&D version: 1.2 ---
2003-03-16 Includes\Temporary.sbi
2004-02-26 Includes\Cookies.sbi
2004-02-29 Includes\Dialer.sbi
2004-02-29 Includes\Hijackers.sbi
2004-02-26 Includes\Keyloggers.sbi
2004-02-29 Includes\Malware.sbi
2003-03-16 Includes\plugin-ignore.ini
2004-02-26 Includes\Security.sbi
2004-02-29 Includes\Spybots.sbi
2004-02-26 Includes\Tracks.uti
2004-02-29 Includes\Trojans.sbi
2004-03-09 Includes\Revision.sbi
__________________
91LSMAN is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 03:22 AM   #13 (permalink)
I like shiny
 
91LSMAN's Avatar
 
Join Date: Jan 2002
Location: Puyallup, WA
Posts: 14,892


Car 1: 91 LS Coupe (GONE)
Car 2: Current-02 Corvette
Car 3: 94 LS Coupe (Bro's)



iTrader: (4)
Quote:
Originally Posted by duck
I fear you may have the most vile trojan out there, coolwebsearch. Go to

http://www.intermute.com/spysubtract..._download.html

and download their standalone version of cwshredder and run it. Let us know what it finds. Hopefully, I'm wrong.
Just did it:

**** Run Keys ****

RUN: [SystemTray] SysTray.Exe
RUN: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
RUN: [nwiz] nwiz.exe /install
RUN: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
RUN: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
RUN: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
RUN: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
RUN: [iehelper] JAguAr.exe
RUN: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
RUN: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
RUN: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
RUN: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
RUN: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
RUN: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
RUN: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
RUN: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
RUN: [porka_] SysEntry.exe
RUN: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


**** Browser Helper Objects ****

BHO: [AcroIEHlprObj Class] C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
BHO: [McBrwHelper Class] c:\program files\mcafee.com\mps\mcbrhlpr.dll
BHO: [McAfee Privacy Service Popup Blocker] c:\program files\mcafee.com\mps\popupkiller.dll
BHO: [SpywareGuardDLBLOCK.CBrowserHelper] C:\Program Files\SpywareGuard\dlprotect.dll
BHO: [] C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
BHO: [PCTools Site Guard] C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
BHO: [PCTools Browser Monitor] C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll


**** IE Toolbars ****

TOOLBAR: [McAfee VirusScan] c:\progra~1\mcafee.com\vso\mcvsshl.dll


**** IE Extensions ****

IEExt: [Web Browser Applet Control] C:\WINDOWS\SYSTEM32\MSJAVA.DLL
IEExt: [Spyware Doctor] C:\WINDOWS\SYSTEM32\MSJAVA.DLL
IEExt: [Microsoft® JavaScript® Console] C:\WINDOWS\SYSTEM32\MSJAVA.DLL
IEExt: [Messenger] C:\Program Files\Messenger\msmsgs.exe


**** Hosts File Entries ****

HOSTS: 127.0.0.1 localhost
HOSTS: 127.0.0.1 localhost


**** IE Settings ****

Default Page: http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
Default Search:
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: http://www.microsoft.com/isapi/redir...ie&ar=iesearch


**** IE Context Menu (Right click) ****



**** Layered Service Providers ****

LSP: MC_LAYERED MSAFD Tcpip [TCP/IP]
LSP: MC_LAYERED MSAFD Tcpip [UDP/IP]
LSP: MC_LAYERED RSVP UDP Service Provider
LSP: MC_LAYERED RSVP TCP Service Provider
LSP: MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{03B96CD0-D033-4601-910B-57ACB202D3BA}] SEQPACKET 0
LSP: MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{03B96CD0-D033-4601-910B-57ACB202D3BA}] DATAGRAM 0
LSP: MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{837EB8E1-021C-468D-AE34-0DB44F601071}] SEQPACKET 1
LSP: MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{837EB8E1-021C-468D-AE34-0DB44F601071}] DATAGRAM 1
LSP: MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{871D0899-CBEF-4A84-88C3-11E185E57D64}] SEQPACKET 2
LSP: MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{871D0899-CBEF-4A84-88C3-11E185E57D64}] DATAGRAM 2
LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{03B96CD0-D033-4601-910B-57ACB202D3BA}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{03B96CD0-D033-4601-910B-57ACB202D3BA}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{837EB8E1-021C-468D-AE34-0DB44F601071}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{837EB8E1-021C-468D-AE34-0DB44F601071}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{871D0899-CBEF-4A84-88C3-11E185E57D64}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{871D0899-CBEF-4A84-88C3-11E185E57D64}] DATAGRAM 2


**** Blocked Control Panel Items ****

BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No
BLOCKED: [snd.cpl] no
BLOCKED: [joystick.cpl] no
BLOCKED: [midimap.drv] no


**** Downloaded Program Files ****

DirectAnimation Java Classes [file://C:\WINDOWS\SYSTEM\dajava.cab]
Microsoft XML Parser for Java [file://C:\WINDOWS\Java\classes\xmldso.cab]
Win32 Classes [file://C:\WINDOWS\Java\classes\xmldso.cab]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [http://www.apple.com/qtactivex/qtplugin.cab]
{03F998B2-0E00-11D3-A498-00104B6EB52E} [https://components.viewpoint.com/MTS...viewpoint.com]
{0713E8D2-850A-101B-AFC0-4210102A8DA7} [http://download.mcafee.com/molbin/Sh.../ComCtl32.cab]
{166B1BCA-3F9C-11CF-8075-444553540000} [http://download.macromedia.com/pub/s...rector/sw.cab]
{17492023-C23A-453E-A040-C7C580BBF700} [http://go.microsoft.com/fwlink/?linkid=39204] C:\WINDOWS\system32\GWFSPidGen.DLL C:\WINDOWS\system32\LegitCheckControl.DLL
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} [http://download.mcafee.com/molbin/sh.../mcinsctl.cab]
{6414512B-B978-451D-A0D8-FCFDF33E833C} [http://update.microsoft.com/windowsu...1129437042906]
{8AD9C840-044E-11D1-B3E9-00805F499D93} [http://java.sun.com/update/1.5.0/jin...dows-i586.cab]
{9F1C11AA-197B-4942-BA54-47A8489BB47F} [http://v4.windowsupdate.microsoft.co...07.8141782407]
{BCC0FF27-31D9-4614-A68E-C18E1ADA4389} [http://download.mcafee.com/molbin/sh...6/mcgdmgr.cab]
{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} [http://java.sun.com/update/1.5.0/jin...dows-i586.cab]
{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} [http://java.sun.com/update/1.5.0/jin...dows-i586.cab]
{D27CDB6E-AE6D-11CF-96B8-444553540000} [http://download.macromedia.com/pub/s...h/swflash.cab]
{EF791A6B-FC12-4C68-99EF-FB9E207A39E6} [http://download.mcafee.com/molbin/is...6/mcfscan.cab]


**** Windows Services ****

[Alerter] %SystemRoot%\System32\svchost.exe -k LocalService
[ALG] %SystemRoot%\System32\alg.exe
[AppMgmt] %SystemRoot%\system32\svchost.exe -k netsvcs
[AudioSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[BITS] %SystemRoot%\System32\svchost.exe -k netsvcs
[Browser] %SystemRoot%\System32\svchost.exe -k netsvcs
[CiSvc] %SystemRoot%\system32\cisvc.exe
[ClipSrv] %SystemRoot%\system32\clipsrv.exe
[COMSysApp] C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
[CryptSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[DcomLaunch] %SystemRoot%\system32\svchost -k DcomLaunch
[Dhcp] %SystemRoot%\System32\svchost.exe -k netsvcs
[dmadmin] %SystemRoot%\System32\dmadmin.exe /com
[dmserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[Dnscache] %SystemRoot%\System32\svchost.exe -k NetworkService
[ERSvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[Eventlog] %SystemRoot%\system32\services.exe
[EventSystem] C:\WINDOWS\System32\svchost.exe -k netsvcs
[FastUserSwitchingCompatibility] %SystemRoot%\System32\svchost.exe -k netsvcs
[helpsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[HidServ] %SystemRoot%\System32\svchost.exe -k netsvcs
[HTTPFilter] %SystemRoot%\System32\svchost.exe -k HTTPFilter
[IDriverT] "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
[ImapiService] C:\WINDOWS\System32\imapi.exe
[iPodService] C:\Program Files\iPod\bin\iPodService.exe
[lanmanserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[lanmanworkstation] %SystemRoot%\System32\svchost.exe -k netsvcs
[LmHosts] %SystemRoot%\System32\svchost.exe -k LocalService
[McDetect.exe] c:\program files\mcafee.com\agent\mcdetect.exe
[McShield] c:\PROGRA~1\mcafee.com\vso\mcshield.exe
[McTskshd.exe] c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
[mcupdmgr.exe] C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
[Messenger] %SystemRoot%\System32\svchost.exe -k netsvcs
[mnmsrvc] C:\WINDOWS\System32\mnmsrvc.exe
[MpfService] C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
[MSDTC] C:\WINDOWS\System32\msdtc.exe
[MSIServer] C:\WINDOWS\system32\msiexec.exe /V
[NetDDE] %SystemRoot%\system32\netdde.exe
[NetDDEdsdm] %SystemRoot%\system32\netdde.exe
[Netlogon] %SystemRoot%\System32\lsass.exe
[Netman] %SystemRoot%\System32\svchost.exe -k netsvcs
[Nla] %SystemRoot%\System32\svchost.exe -k netsvcs
[NtLmSsp] %SystemRoot%\System32\lsass.exe
[NtmsSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[NVSvc] %SystemRoot%\System32\nvsvc32.exe
[Pctspk] %SystemRoot%\system32\pctspk.exe
[PlugPlay] %SystemRoot%\system32\services.exe
[Pml Driver HPH11] C:\WINDOWS\system32\HPHipm11.exe
[PolicyAgent] %SystemRoot%\System32\lsass.exe
[ProtectedStorage] %SystemRoot%\system32\lsass.exe
[PurgProService] C:\Program Files\PurgeIE\PurgPro_Service.exe
[RasAuto] %SystemRoot%\System32\svchost.exe -k netsvcs
[RasMan] %SystemRoot%\System32\svchost.exe -k netsvcs
[RDSessMgr] C:\WINDOWS\system32\sessmgr.exe
[RemoteAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
[RpcLocator] %SystemRoot%\System32\locator.exe
[RpcSs] %SystemRoot%\system32\svchost -k rpcss
[RSVP] %SystemRoot%\System32\rsvp.exe
[SamSs] %SystemRoot%\system32\lsass.exe
[SCardSvr] %SystemRoot%\System32\SCardSvr.exe
[Schedule] %SystemRoot%\System32\svchost.exe -k netsvcs
[seclogon] %SystemRoot%\System32\svchost.exe -k netsvcs
[SENS] %SystemRoot%\system32\svchost.exe -k netsvcs
[ShellHWDetection] %SystemRoot%\System32\svchost.exe -k netsvcs
[Spooler] %SystemRoot%\system32\spoolsv.exe
[srservice] %SystemRoot%\System32\svchost.exe -k netsvcs
[SSDPSRV] %SystemRoot%\System32\svchost.exe -k LocalService
[stisvc] %SystemRoot%\System32\svchost.exe -k imgsvc
[SwPrv] C:\WINDOWS\System32\dllhost.exe /Processid:{931D2B8E-D66E-4BE3-A26E-C8647BE83612}
[SysmonLog] %SystemRoot%\system32\smlogsvc.exe
[TapiSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[TermService] %SystemRoot%\System32\svchost -k DComLaunch
[Themes] %SystemRoot%\System32\svchost.exe -k netsvcs
[TrkWks] %SystemRoot%\system32\svchost.exe -k netsvcs
[UMWdf] C:\WINDOWS\system32\wdfmgr.exe
[upnphost] %SystemRoot%\System32\svchost.exe -k LocalService
[UPS] %SystemRoot%\System32\ups.exe
[VSS] %SystemRoot%\System32\vssvc.exe
[W32Time] %SystemRoot%\System32\svchost.exe -k netsvcs
[WebClient] %SystemRoot%\System32\svchost.exe -k LocalService
[winmgmt] %systemroot%\system32\svchost.exe -k netsvcs
[WmdmPmSN] %SystemRoot%\System32\svchost.exe -k netsvcs
[WmiApSrv] C:\WINDOWS\System32\wbem\wmiapsrv.exe
[wscsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[wuauserv] %systemroot%\system32\svchost.exe -k netsvcs
[WZCSVC] %SystemRoot%\System32\svchost.exe -k netsvcs
[xmlprov] %SystemRoot%\System32\svchost.exe -k netsvcs


**** Custom IE Search Items ****

SEARCH: [SearchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
SEARCH: [SearchAssistant_bak] http://www.xxxtoolbar.com/ist/script...es_manager.php
SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
SEARCH: [Default_Search_URL] about:blank


**** Complete IE Options ****

IEOPT: [Anchor Underline] yes
IEOPT: [Cache_Update_Frequency] Once_Per_Session
IEOPT: [Display Inline Images] yes
IEOPT: [Do404Search]
IEOPT: [Local Page] C:\WINDOWS\system32\blank.htm
IEOPT: [Save_Session_History_On_Exit] no
IEOPT: [Show_FullURL] no
IEOPT: [Show_StatusBar] yes
IEOPT: [Show_ToolBar] yes
IEOPT: [Show_URLinStatusBar] yes
IEOPT: [Show_URLToolBar] yes
IEOPT: [Start Page] http://www.comcast.net/home.html
IEOPT: [Use_DlgBox_Colors] yes
IEOPT: [Search Page] http://www.microsoft.com/isapi/redir...ie&ar=iesearch
IEOPT: [NotifyDownloadComplete] yes
IEOPT: [LastCheckedHi]
IEOPT: [FullScreen] no
IEOPT: [Window_Placement] ,
IEOPT: [Check_Associations] No
IEOPT: [Use FormSuggest] no
IEOPT: [AddToFavoritesExpanded]
IEOPT: [FormSuggest PW Ask] no
IEOPT: [ShowGoButton] no
IEOPT: [Error Dlg Displayed On Every Error] no
IEOPT: [Error Dlg Details Pane Open] yes
IEOPT: [Use Search Assistant] no
IEOPT: [Window Title] Microsoft Internet Explorer provided by Comcast High-Speed Internet
IEOPT: [User Search Asst] no
IEOPT: [Default_Search_URL] http://home.microsoft.com/search/search.asp
IEOPT: [SearchURL] http://www.google.com
IEOPT: [Use Search Asst] yes
IEOPT: [WindowPosition]
IEOPT: [Use Custom Search URL]
IEOPT: [NoUpdateCheck]
IEOPT: [NoJITSetup]
IEOPT: [Disable Script Debugger] yes
IEOPT: [Show_ChannelBand] No
IEOPT: [AutoSearch]
IEOPT: [Default_Page_URL] http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
IEOPT: [ShowedCheckBrowser] Yes
IEOPT: [StatusBarWeb]
IEOPT: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IEOPT: [SearchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IEOPT: [DisableScriptDebuggerIE] yes
IEOPT: [Default_Page_URL] http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
IEOPT: [Default_Search_URL]
IEOPT: [Search Page] http://www.microsoft.com/isapi/redir...ie&ar=iesearch
IEOPT: [Enable_Disk_Cache] yes
IEOPT: [Cache_Percent_of_Disk]
IEOPT: [Delete_Temp_Files_On_Exit] yes
IEOPT: [Local Page] C:\WINDOWS\system32\blank.htm
IEOPT: [Anchor_Visitation_Horizon]
IEOPT: [Use_Async_DNS] yes
IEOPT: [Placeholder_Width]
IEOPT: [Placeholder_Height]
IEOPT: [Start Page] http://www.msn.com
IEOPT: [Wizard_Version] 6.0.2600.0000
IEOPT: [FullScreen] no
IEOPT: [Check_Associations] yes
IEOPT: [Window Title] Microsoft Internet Explorer provided by Comcast High-Speed Internet
IEOPT: [Search Bar]
IEOPT: [Use Search Asst] no
IEOPT: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IEOPT: [SearchAssistant]
IEOPT: [CompanyName] Microsoft Corporation
IEOPT: [Custom_Key] MICROSO
__________________
91LSMAN is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 03:35 AM   #14 (permalink)
I like shiny
 
91LSMAN's Avatar
 
Join Date: Jan 2002
Location: Puyallup, WA
Posts: 14,892


Car 1: 91 LS Coupe (GONE)
Car 2: Current-02 Corvette
Car 3: 94 LS Coupe (Bro's)



iTrader: (4)
Quote:
Originally Posted by duck
I fear you may have the most vile trojan out there, coolwebsearch. Go to

http://www.intermute.com/spysubtract..._download.html

and download their standalone version of cwshredder and run it. Let us know what it finds. Hopefully, I'm wrong.
Just ran their spyware finder and it found a bunch more stuff on my computer that other programs have not.

Gotta go surf the net now.
__________________
91LSMAN is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-26-05, 03:36 AM   #15 (permalink)
I like shiny
 
91LSMAN's Avatar
 
Join Date: Jan 2002
Location: Puyallup, WA
Posts: 14,892


Car 1: 91 LS Coupe (GONE)
Car 2: Current-02 Corvette
Car 3: 94 LS Coupe (Bro's)



iTrader: (