i2d_group Posted September 17, 2006 Share Posted September 17, 2006 hi.i use bitcomet 0.70 and the past few days when i log on to bit comet and downloading smthng,the browser i use (firefox latest updates) gives me some mysterious messages like: ''This IP is being shared among many domains. To view the domain you are looking for, simply enter the domain name in the location bar of your web browser.'' or ''Directory Listing Denied This Virtual Directory does not allow contents to be listed.'' or this ''This is the placeholder for domain idpserver.net. If you see this page after uploading site content you probably have not replaced the index.html file.'' or it finally takes me to conduit.com(???) i close bitcomet and there are 2 options: 1)the browser works fine 2)the browser still doesnt work, i restart my pc and everything is ok. what is going on?any help. thanks :( Link to comment Share on other sites More sharing options...
The UnUsual Suspect Posted September 17, 2006 Share Posted September 17, 2006 I'm not sure why this is happening, but have seen simular errors as a result of addware/spyware. I suggest you run the following programs Spybot Search and Destroy (freeware) Ad Aware, also free (beware of sound alike programs that will infect you rather then clean your system) Also, since this may be a browser hijacker, I would run "xoft anti spyware" (very good at removing hijack malware), not free, but worth every penny (or download a torrent with keygen if you like) Suspect Link to comment Share on other sites More sharing options...
i2d_group Posted September 17, 2006 Author Share Posted September 17, 2006 thank you for your concern. i have already done full systems scans with: 1)bitdefender antivirus plus v10 2)lavasoft ad-aware se proffesional 3)bulletproof spyware remover all full updated. only bulletproof found a trojan(i dont remember its name) which was succesfully removed. i will try those you suggested me. but why this happens only when bitcomet is online? i installed xoft antispyware(ad-aware was already installed) i updated it and i scaned my pc.some cookies were found,nothing much.but it keeps doing it :( :( i've been using bitcomet port forwarded for a long time but i have never face such problem again Link to comment Share on other sites More sharing options...
The UnUsual Suspect Posted September 17, 2006 Share Posted September 17, 2006 I would like the rest of the staff and members to review this post, as I've not seen this problem before. Feel free to send me a PM if you don't get any replys within 24hours or so. Suspect Link to comment Share on other sites More sharing options...
bitdave Posted September 17, 2006 Share Posted September 17, 2006 Have you installed any Firefox addons recently? especially any with Toolbar in the name. EffectiveBrand.com changed its name to Conduit.com and removed the "no spyware guaranteed" warnings from their homepage. Could be a problem if you have an older toolbar of theirs since they changed domains fairly recently. If you have any toolbars for Firefox I would say uninstall them and see if that helps. Otherwise I guess if you post a HiJackThis log I could take a look. Link to comment Share on other sites More sharing options...
Dark_Shroud Posted September 18, 2006 Share Posted September 18, 2006 Hmm, does this happen only with firefox, have you tried opening a page in IE? Did you use the LvlLord patch or any other mods to windows? Link to comment Share on other sites More sharing options...
i2d_group Posted September 18, 2006 Author Share Posted September 18, 2006 I would like the rest of the staff and members to review this post, as I've not seen this problem before. Feel free to send me a PM if you don't get any replys within 24hours or so. Suspect yep i have TABMIX PLUS and TORRENT SEARCH TOOLBAR installed.should i uninstall them? Have you installed any Firefox addons recently? especially any with Toolbar in the name. Could be a problem if you have an older toolbar of theirs since they changed domains fairly recently. If you have any toolbars for Firefox I would say uninstall them and see if that helps. Otherwise I guess if you post a HiJackThis log I could take a look. the same thing happens with ie.nop any mods to windows i run EWIDO antispyware scan and it found this: ewido anti-spyware - Scan Report --------------------------------------------------------- 1.txt here's a hifackthis report: 2.txt Link to comment Share on other sites More sharing options...
The UnUsual Suspect Posted September 18, 2006 Share Posted September 18, 2006 I would remove the toolbars (most are a drain on resources), and you can always reinstall them if you like their function. Suspect ps. I removed your logs from the post and added them as attachments. Please use the attach file option to post this type of data. Link to comment Share on other sites More sharing options...
i2d_group Posted September 18, 2006 Author Share Posted September 18, 2006 I would remove the toolbars (most are a drain on resources), and you can always reinstall them if you like their function. Suspect ps. I removed your logs from the post and added them as attachments. Please use the attach file option to post this type of data. i moved it and i killed commserve.exe.but i still get(more) wird messages when i run both bitcomet and firefox.like ''the pafe is under construction'' or a fake (i think from the logo design) google error(??????) i have already run:bitdefender pro v10 ad aware se pro bullet proof spyware remover spybot search and destroy xoftspy se ewido antispyware 4 all full updated.i fixed every problem they suggested.but nothing... ps.sorry about that :) Link to comment Share on other sites More sharing options...
bitdave Posted September 18, 2006 Share Posted September 18, 2006 It appears that your security software didnt keep you very secure. Your computer has been compromised by a trojan as Im sure your aware, and Ewido even saw it but apparently did nothing about it C:\WINDOWS\system32\commserv.exe -> Trojan.Agent.ye : No action taken. It probably came in that keygen you downloaded or possibly in a toolbar you downloaded. Also it may have installed some things that you dont want or need, like: C:\WINDOWS\system32\spnpinst.exe (See here) This program itself isnt necessarily bad but it can be used for bad purposes. This thread should help you getting things cleaned up. Just worry about the things that apply to you and it is very important that your computer is in Safe Mode when cleaning up. Also you may want to disable System Restore while cleaning so that the trojan cant hide in there. Link to comment Share on other sites More sharing options...
i2d_group Posted September 18, 2006 Author Share Posted September 18, 2006 ''.......no action taken''---->>i didnt tell it to do smth cos i was waiting for an answer here first. B) i eerased it a few moments later the strange thing is that this happens only when i run bitcomet and after that. i have scanned my pc with so many antispywares and antiviruses,i dont even remember them... :( Link to comment Share on other sites More sharing options...
Dark_Shroud Posted September 23, 2006 Share Posted September 23, 2006 i2d, how are you doing on this? Link to comment Share on other sites More sharing options...
trueblu8 Posted October 13, 2006 Share Posted October 13, 2006 It appears that your security software didnt keep you very secure. Your computer has been compromised by a trojan as Im sure your aware, and Ewido even saw it but apparently did nothing about it C:\WINDOWS\system32\commserv.exe -> Trojan.Agent.ye : No action taken. It probably came in that keygen you downloaded or possibly in a toolbar you downloaded. Also it may have installed some things that you dont want or need, like: C:\WINDOWS\system32\spnpinst.exe (See here) This program itself isnt necessarily bad but it can be used for bad purposes. This thread should help you getting things cleaned up. Just worry about the things that apply to you and it is very important that your computer is in Safe Mode when cleaning up. Also you may want to disable System Restore while cleaning so that the trojan cant hide in there. "commserv.exe -> Trojan.Agent.ye" Dude, I have this same virus. You were absolutely right, it came as a keygen for BitDefender v.10. BitDefender was able to quarantine it, but for some reason I cannot delete it. Do I need to be in safe mode to do this? Were you ever able to remove it, and if so, how did you do it? Any help is appreciated, thanks. Link to comment Share on other sites More sharing options...
Dark_Shroud Posted October 13, 2006 Share Posted October 13, 2006 The two of you should try Avast! free version and set it to scan at start up. It will run the scan and then load the OS so it should be able to get everything. Link to comment Share on other sites More sharing options...
Recommended Posts
Please sign in to comment
You will be able to leave a comment after signing in
Sign In Now