Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Points Site Spy New Posts Donate Unanswered Posts Search Forum Rules


Reply
 
LinkBack Thread Tools
  #16  
Old 4th Nov 2007, 04:03 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

Yes. This happens with Casino Royal movie. We played King Kong and it does not happen. Sony flash player starts with the CR movie which Does Not happen with the King Kong movie. Plus there are 4 users. So far it Only occurs with one user. The rest seem to be ok.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #17  
Old 4th Nov 2007, 04:06 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

I will do HiJack This right now. Thank you.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #18  
Old 4th Nov 2007, 04:07 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:06:49 PM, on 11/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\PccGuide.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.investors.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\pkext.dll
O3 - Toolbar: AbsoluteShield - {EE9DD090-902D-4623-9360-FB7D8666202B} - C:\Program Files\SysShield Tools\Internet Eraser\AbsoluteBar.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: HPAiODevice(hp officejet d series) - 2.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02...s/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1112912480746
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1143419328031
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} - http://secure2.comned.com/signuptemp...ogin-devel.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6...ws-i586-jc.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
O16 - DPF: {AECD14A8-F662-11D1-A395-00805F535788} (PlotWon Control) - http://www.investors.com/member/ocx/plotwon.ocx
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://upload.mediamax.com/Upload/XUpload.ocx
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
--
End of file - 7141 bytes
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #19  
Old 4th Nov 2007, 04:11 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

Is this the way I was suppose to send HiJackThis?
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #20  
Old 4th Nov 2007, 04:23 PM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Unwanted/Unimplemented Porn site hijack?

You need to pick one antivirus and uninstall the other. Since you have the PcCillin suite I would get ri of the BitDefender. Two antivirus causes instability and conflicts.


Open HijackThis and select "Do a system scan only"
Place a check mark next to this entry
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} - http://secure2.comned.com/signuptemp...ogin-devel.cab
Close all windows except for HijackThis and click "Fix checked"

Run this program. It is a trial version but has full functions during the trial period. Have it remove anything found.

TrojanHunter

Let me know if anything was found.

Also let me know how things are now.
__________________
.
.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #21  
Old 4th Nov 2007, 10:09 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

OK! Thanks once again. I will run the program mentioned. I realize that only One Anti-Virus should run and that is the way I have it set. BitDefender is turned Off and is used only as a scanner without any real-time protection on whatsoever. This is also true for MultiVirus scanner which is also installed but is only used to scan. Your help is greatly needed and I really cannot thank you enough. I will run the Trojan scan and get back ASAP.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #22  
Old 4th Nov 2007, 11:49 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

Quarantined file C:\Program Files\K-Lite Codec Pack\filters\CoreAVCDecoder.ax This is what TH found. I am uninstalling K-Lite. Too bad since this was a way for a no cost program to watch DVD's. Thank you
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #23  
Old 4th Nov 2007, 11:50 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

Found trojan file: C:\Program Files\K-Lite Codec Pack\filters\CoreAVCDecoder.ax (Generic.TrojanDownloader.A)
Quarantined file C:\Program Files\K-Lite Codec Pack\filters\CoreAVCDecoder.ax
This is all of the report Trojan Hunter found.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #24  
Old 5th Nov 2007, 06:43 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Unwanted/Unimplemented Porn site hijack?

After uninstalling K-Lite you can reinstall a fresh version from Here

It is possible it had become infected.
__________________
.
.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #25  
Old 5th Nov 2007, 02:57 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

Not only did I uninstall K-Lite but I had to system restore several times to find the right spot for the bug to be gone. I did download from FileHippo the first time and most of the time all programs from FileHippo are clean. Still scratching my head trying to figure out how this happend since this was the first time to use it. Plus I uninstalled WMP 11 and all Codecs I could find. It is just not worth it to have this thing popping up just to watch a movie. Thanks for the help.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #26  
Old 5th Nov 2007, 03:23 PM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Unwanted/Unimplemented Porn site hijack?

OK, just a few more things,

Delete:
Combofix
Go to C:\qoovox <---Delete this whole folder
Uninstall TrojanHunter <---unless you want to keep it until the trial is over

Toggle System Restore to remove infected restore points.
System Restore
1: Right click on the My Computer icon on your desktop and select properties.
2: Click on the system restore tab.
3: Check the box that says "Turn off system restore on all drives". Click OK.
4: Click Yes when you are prompted to restart the computer
5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.

Suggested reading Keeping Yourself Safe On The Web

Let me know if there is anything else that comes up.
__________________
.
.

Last edited by evilfantasy : 5th Nov 2007 at 03:23 PM.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #27  
Old 5th Nov 2007, 08:14 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

Your help has helped greatly. I have followed the above steps. Plus I have done yet another thorough cleaning. Now I would like to check again to see if that infected site appears again. This is basically the steps that I use when trying to view the Casino Royal DVD movie. At present I have no software that I am aware of to play DVD's. That does not matter since the bug shows up with WMP. I insert or auto play the DVD. Next the Sony Flash player appears. I press play movie with Sony 's player. Then WMP starts. Then it sits there idle until I press play on WMP. Once play is clicked then a connection is made to the web. In the Now Playing section the word “trailer” appears and then the unwanted nasty commercial begins to play. Is it safe to check this without getting “bit” again? I am really timid to attempt to play a movie. I'd like to reinstall WMP 11 also. Is that something else I should tip toe with?

Last edited by silver : 5th Nov 2007 at 08:22 PM.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #28  
Old 5th Nov 2007, 08:25 PM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Unwanted/Unimplemented Porn site hijack?

It sounds like the movie has an extra bit of footage on it that you are forced to watch.

You could try to install another free player and see if it happens with that one also. If it does then I would have to say it is something installed on the CD. WMP can be difficult at times.

I use winamp http://www.winamp.com/ and it plays most everything I need it to.
__________________
.
.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #29  
Old 5th Nov 2007, 08:28 PM
No Avatar
silver  United States
New Member Group
 
silver is offline
 
Join Date: 3rd Nov 2007
Last Online: 5th Nov 2007 08:36 PM
Posts: 20
iTrader: (0)
silver is on a distinguished road
Default Unwanted/Unimplemented Porn site hijack?

Thank you, thank you, and thank you. I'll try those steps also. It's too bad I could find anyone here on this side of the world to be as helpful or as knowledgeable. God bless ya!

Last edited by silver : 5th Nov 2007 at 08:29 PM. Reason: grammer
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #30  
Old 5th Nov 2007, 08:37 PM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Unwanted/Unimplemented Porn site hijack?

No problem, glad to help.

Let me know if there is anything else and we will try to work it out.
__________________
.
.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote

Please support this forum, donate towards our running costs.
Reply

Thread Tools
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Google Webmaster Central - Site Verification (Freewebs site) jsh4 Web Design, Hosting & SEO 5 22nd Jan 2008 04:01 AM
Unwanted Tab on IE7 dfr200764 Web Browsers & FTP Clients 3 10th Dec 2007 09:51 AM
Unwanted Folders Jayu Windows Operating Systems 1 17th Aug 2007 02:17 PM
PC Porn alex CPUs, Motherboards & RAM 2 24th Jun 2007 02:00 PM
how do i get internet explorer to stop unwanted pages... sharon c Virus, Spyware & Security 2 20th Mar 2007 10:15 AM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.