Jump to content
To block spammers, this forum has suspended new user registration ×
Comet Forums
To block spammers, this forum has suspended new user registration

strange things happen lately


i2d_group

Recommended Posts

hi.i use bitcomet 0.70 and the past few days when i log on to bit comet and downloading smthng,the browser i use (firefox latest updates) gives me some mysterious messages like:

''This IP is being shared among many domains.

To view the domain you are looking for, simply enter the domain name in the location bar of your web browser.''

or

''Directory Listing Denied

This Virtual Directory does not allow contents to be listed.''

or this

''This is the placeholder for domain idpserver.net. If you see this page after uploading site content you probably have not replaced the index.html file.''

or it finally takes me to conduit.com(???)

i close bitcomet and there are 2 options:

1)the browser works fine

2)the browser still doesnt work, i restart my pc and everything is ok.

what is going on?any help.

thanks :(

Link to comment
Share on other sites

I'm not sure why this is happening, but have seen simular errors as a result of addware/spyware.

I suggest you run the following programs

Spybot Search and Destroy (freeware)

Ad Aware, also free (beware of sound alike programs that will infect you rather then clean your system)

Also, since this may be a browser hijacker, I would run "xoft anti spyware" (very good at removing hijack malware), not free, but worth every penny (or download a torrent with keygen if you like)

Suspect

Link to comment
Share on other sites

thank you for your concern.

i have already done full systems scans with:

1)bitdefender antivirus plus v10

2)lavasoft ad-aware se proffesional

3)bulletproof spyware remover

all full updated.

only bulletproof found a trojan(i dont remember its name) which was succesfully removed.

i will try those you suggested me.

but why this happens only when bitcomet is online?

i installed xoft antispyware(ad-aware was already installed) i updated it and i scaned my pc.some cookies were found,nothing much.but it keeps doing it :( :(

i've been using bitcomet port forwarded for a long time but i have never face such problem again

Link to comment
Share on other sites

Have you installed any Firefox addons recently? especially any with Toolbar in the name.

EffectiveBrand.com changed its name to Conduit.com and removed the "no spyware guaranteed" warnings from their homepage.

Could be a problem if you have an older toolbar of theirs since they changed domains fairly recently. If you have any toolbars for Firefox I would say uninstall them and see if that helps. Otherwise I guess if you post a HiJackThis log I could take a look.

Link to comment
Share on other sites

I would like the rest of the staff and members to review this post, as I've not seen this problem before.

Feel free to send me a PM if you don't get any replys within 24hours or so.

Suspect

yep i have TABMIX PLUS and TORRENT SEARCH TOOLBAR installed.should i uninstall them?

Have you installed any Firefox addons recently? especially any with Toolbar in the name.

Could be a problem if you have an older toolbar of theirs since they changed domains fairly recently. If you have any toolbars for Firefox I would say uninstall them and see if that helps. Otherwise I guess if you post a HiJackThis log I could take a look.

the same thing happens with ie.nop any mods to windows

i run EWIDO antispyware scan and it found this:

ewido anti-spyware - Scan Report

---------------------------------------------------------

1.txt

here's a hifackthis report:

2.txt

Link to comment
Share on other sites

I would remove the toolbars (most are a drain on resources), and you can always reinstall them if you like their function.

Suspect

ps. I removed your logs from the post and added them as attachments. Please use the attach file option to post this type of data.

Link to comment
Share on other sites

I would remove the toolbars (most are a drain on resources), and you can always reinstall them if you like their function.

Suspect

ps. I removed your logs from the post and added them as attachments. Please use the attach file option to post this type of data.

i moved it and i killed commserve.exe.but i still get(more) wird messages when i run both bitcomet and firefox.like ''the pafe is under construction'' or a fake (i think from the logo design) google error(??????)

i have already run:bitdefender pro v10

ad aware se pro

bullet proof spyware remover

spybot search and destroy

xoftspy se

ewido antispyware 4

all full updated.i fixed every problem they suggested.but nothing...

ps.sorry about that :)

Link to comment
Share on other sites

It appears that your security software didnt keep you very secure.

Your computer has been compromised by a trojan as Im sure your aware, and Ewido even saw it but apparently did nothing about it

C:\WINDOWS\system32\commserv.exe -> Trojan.Agent.ye : No action taken.

It probably came in that keygen you downloaded or possibly in a toolbar you downloaded.

Also it may have installed some things that you dont want or need, like:

C:\WINDOWS\system32\spnpinst.exe (See here)

This program itself isnt necessarily bad but it can be used for bad purposes.

This thread should help you getting things cleaned up. Just worry about the things that apply to you and it is very important that your computer is in Safe Mode when cleaning up. Also you may want to disable System Restore while cleaning so that the trojan cant hide in there.

Link to comment
Share on other sites

''.......no action taken''---->>i didnt tell it to do smth cos i was waiting for an answer here first. B) i eerased it a few moments later

the strange thing is that this happens only when i run bitcomet and after that.

i have scanned my pc with so many antispywares and antiviruses,i dont even remember them... :(

Link to comment
Share on other sites

  • 3 weeks later...

It appears that your security software didnt keep you very secure.

Your computer has been compromised by a trojan as Im sure your aware, and Ewido even saw it but apparently did nothing about it

C:\WINDOWS\system32\commserv.exe -> Trojan.Agent.ye : No action taken.

It probably came in that keygen you downloaded or possibly in a toolbar you downloaded.

Also it may have installed some things that you dont want or need, like:

C:\WINDOWS\system32\spnpinst.exe (See here)

This program itself isnt necessarily bad but it can be used for bad purposes.

This thread should help you getting things cleaned up. Just worry about the things that apply to you and it is very important that your computer is in Safe Mode when cleaning up. Also you may want to disable System Restore while cleaning so that the trojan cant hide in there.

"commserv.exe -> Trojan.Agent.ye" Dude, I have this same virus. You were absolutely right, it came as a keygen for BitDefender v.10. BitDefender was able to quarantine it, but for some reason I cannot delete it. Do I need to be in safe mode to do this? Were you ever able to remove it, and if so, how did you do it? Any help is appreciated, thanks.

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
×
×
  • Create New...