|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (4 bit)
Join Date: Jul 2005
Posts: 10
|
Would like to know how to stealth the ports on my Norton Internet Security 2005 firewall?
-j |
|
|
|
|
|
#3 |
|
Member (4 bit)
Join Date: Jul 2005
Posts: 10
|
I failed the TruStealth Analysis test. Only 3 ports are stealthed. Would like to know how to stealth all the ports on my Norton Internet Security 2005.
-j |
|
|
|
|
|
#4 | |
|
Computing Professor
Staff
Premium Member
Join Date: Jun 2001
Posts: 11,941
|
Quote:
The default settings for Norton automatically stealths all ports. If you've lost the defaults read this : http://service1.symantec.com/SUPPORT...&osv=&osv_lvl=
__________________
Asus M4A77D, 64 X2 6000+, 4 GB Corsair DDR2 800 ram, Radeon 5770. |
|
|
|
|
|
|
#5 |
|
Member (4 bit)
Join Date: Jul 2005
Posts: 10
|
Reset the default settings but continue to fail the Hacker Exposure Check. Only 3 ports are stealthed. If I stealth all my ports how will this affect my internet use?
-j Last edited by jsun; 08-12-2005 at 08:59 AM. |
|
|
|
|
|
#6 |
|
Computing Professor
Staff
Premium Member
Join Date: Jun 2001
Posts: 11,941
|
Here's how Norton works : http://service1.symantec.com/SUPPORT...rc=bar_sch_nam
Since you don't want to shut off your e-mail or internet access do not go in manually and change rules. Instead go to ShieldsUp : https://www.grc.com/x/ne.dll?bh0bkyd2 and run their test. If you fail this one, all ports opened except 3, something is compromising your firewall. |
|
|
|
|
|
#7 |
|
Member (4 bit)
Join Date: Jul 2005
Posts: 10
|
Thanks for the link to symantec. Already tried ShieldsUp and got the same error. Installed Zonealarm Pro and turned off Norton Internet Security. Did the test and got the same error.
-j |
|
|
|
|
|
#8 | |
|
Computing Professor
Staff
Premium Member
Join Date: Jun 2001
Posts: 11,941
|
Quote:
Since no defaults work you're not protected when you're on-line. Follow the instructions in the forum sticky about posting a hijackthis log. Also go here : http://housecall.trendmicro.com/ and run a scan. Start another thread in this forum about firewall(s) defaults not working for you along with all the results. You may still end up having to format the computer but you'll have tried all the options. |
|
|
|
|
|
|
#9 |
|
Member (4 bit)
Join Date: Jul 2005
Posts: 10
|
Ran Ad-Aware and removed some critical objects. Tried HouseCalls but couldn't proceed after selecting type of scan. Saw only a Back button.
This is the HijackThis log: Logfile of HijackThis v1.99.1 Scan saved at 11:28:08 PM, on 8/20/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINNT\System32\CTsvcCDA.EXE C:\WINNT\System32\svchost.exe C:\Program Files\Roxio\GoBack\GBPoll.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\Dantz\Retrospect\retrorun.exe C:\WINNT\system32\MSTask.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\MsPMSPSv.exe C:\WINNT\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINNT\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINNT\system32\atiptaxx.exe C:\WINNT\system32\desk95.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Creative\ShareDLL\CtNotify.exe C:\Program Files\ahead\InCD\InCD.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Creative\ShareDLL\MediaDet.Exe C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Creative\SBAudigy\Taskbar\CTLTray.exe C:\Program Files\Creative\SBAudigy\Taskbar\CTLTask.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Roxio\GoBack\GBTray.exe C:\Program Files\HotKey\HotKey.exe C:\Program Files\iM Networks\iM Radio Tuner\iM_Tray.exe C:\Program Files\Plextor\PlexTool.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\Administrator\My Documents\HijackThis\HijackThis.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe O4 - HKLM\..\Run: [HydarVisionDesktopManager] desk95.exe O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [CTRegRun] C:\WINNT\CTRegRun.EXE O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe O4 - HKLM\..\Run: [UpdReg] C:\WINNT\Updreg.exe O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" O4 - HKLM\..\Run: [RemoteControl] C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKCU\..\Run: [ATI Launchpad] "F:\Program Files\ATI Multimedia\main\LaunchPd.exe" O4 - HKCU\..\Run: [TaskTray] C:\Program Files\Creative\SBAudigy\Taskbar\CTLTray.exe O4 - HKCU\..\Run: [Taskbar] C:\Program Files\Creative\SBAudigy\Taskbar\CTLTask.exe O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe O4 - Global Startup: HotKey Driver.lnk = C:\Program Files\HotKey\HotKey.exe O4 - Global Startup: iM StartCenter.lnk = C:\Program Files\iM Networks\iM Radio Tuner\iM_Tray.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: PlexTools Professional.lnk = C:\Program Files\Plextor\PlexTool.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...a/LSSupCtl.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1123012758015 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ....................................................... Spybot log: (wasn't sure what to remove so didn't remove anything) BackWeb lite: Executable (File, nothing done) C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe BackWeb lite: File extension (Registry key, nothing done) HKEY_CLASSES_ROOT\bwpfile BackWeb lite: File extension (Registry key, nothing done) HKEY_CLASSES_ROOT\.bwp BackWeb lite: Global settings (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\BackWeb DSO Exploit: Data source object exploit (Registry change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3 DSO Exploit: Data source object exploit (Registry change, nothing done) HKEY_USERS\S-1-5-21-1757981266-261478967-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3 Windows Security Center.SP2Update: Settings (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dword:0 Windows Security Center.AntiVirusOverride: Settings (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride!=dword:0 Windows Security Center.FirewallOverride: Settings (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride!=dword:0 Windows Security Center.FirewallDisableNotify: Settings (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0 Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0 Windows Security Center.UpdateDisableNotify: Settings (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify!=dword:0 Alexa Related: Link (Replace file, nothing done) C:\WINNT\Web\RELATED.HTM NewsUpdate: Settings (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Creative Tech\Software Installed\News NewsUpdate: Program directory (Directory, nothing done) C:\Program Files\Creative\News\ NewsUpdate: Root class (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\CTMARQ.CTMarqCtrl.1 NewsUpdate: Class ID (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C1B43B81-8B3C-11D4-B615-00A0C98E9F5B} NewsUpdate: Class ID (CTMarq Property Page) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C1B43B82-8B3C-11D4-B615-00A0C98E9F5B} BackWeb lite: Interface (IBackWebDisplaySettings4_2) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{001B3F20-D866-11D1-8B4C-00609761C47A} BackWeb lite: Interface (IBackWebChannel4_2) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{025632A0-BCEC-11D1-8B35-00609761C47A} BackWeb lite: Interface (IBackWebDirectoryEntry) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{0C6E0440-0B50-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebDownloadTimeConstraint) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{0D1F7C83-8123-11D0-B5CA-0000B43698D6} BackWeb lite: Interface (IBackWebDownloadTimeConstraintCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{0D1F7C84-8123-11D0-B5CA-0000B43698D6} BackWeb lite: Interface (IBackWebExtension) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{0F4FE440-983F-11D0-9B9C-444553540000} BackWeb lite: Interface (IBackWebGeneralSettings) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{12473FC3-61A7-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebDialerSettings) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{12473FC4-61A7-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebCommSettings) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{12473FC5-61A7-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebDisplaySettings) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{12473FC6-61A7-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebSetup) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{12473FC7-61A7-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebDirectory) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{15030BC0-0B52-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebStoryFieldCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{1D91D9E0-004B-11D1-9951-444553540000} BackWeb lite: Interface (IBackWeb2) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{23F43240-F78D-11D0-9A50-00AA004812C2} BackWeb lite: Interface (IBackWebInfoPakDownloadServices) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{2DE07D90-DC04-11D0-A875-0000B43699FC} BackWeb lite: Interface (IBackWebSetupNotifications) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{2F099AF0-6329-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebChannelTableNotifications) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{2F523082-5A0B-11D0-9B9C-444553540000} BackWeb lite: Interface (IBackWebSetup4) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{3667E7B0-4F28-11D1-8ADB-00609761C47A} BackWeb lite: Interface (IBackWebFileAccess) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{3AF78A6E-6F14-11D1-A884-0000B43699FC} BackWeb lite: Interface (IBackWebInfoPakFilesCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{3AF78A71-6F14-11D1-A884-0000B43699FC} BackWeb lite: Interface (IBackWebInfoPakFile) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{3AF78A74-6F14-11D1-A884-0000B43699FC} BackWeb lite: Interface (IBackWebOpenInfoPakFile) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{3AF78A77-6F14-11D1-A884-0000B43699FC} BackWeb lite: Interface (IBackWebDirectoryNotifications) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{41CEBDC0-32C1-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebStoryTableNotifications) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{44230BC0-3105-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebInfoPakNotifications) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{4A3666F3-5F2D-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWeb) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{53FCF355-5323-11D0-A864-0000B43699FC} BackWeb lite: Interface (IBackWebChannelCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{53FCF35A-5323-11D0-A864-0000B43699FC} BackWeb lite: Interface (IBackWebChannel) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{53FCF35B-5323-11D0-A864-0000B43699FC} BackWeb lite: Interface (IBackWebStoryField) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{5B1E13A0-004B-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebDirectoryEntryCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{5DF6CE40-0B50-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebFileAccessViaDir) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{608FE360-6FB2-11D1-A885-0000B43699FC} BackWeb lite: Interface (IBackWebInfoPak4_2) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{610141C2-7701-11D1-B042-004095903824} BackWeb lite: Interface (IBackWebAlertSettings) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{72B62B40-17D1-11D1-96A7-F8E906C10000} BackWeb lite: Interface (IBackWeb4) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{740904E0-0BFB-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebPlayer) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{8028B940-4932-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebAllInfoPakCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{8131F530-649E-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebChannelDownloadServices) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{9132E380-DC21-11D0-A875-0000B43699FC} BackWeb lite: Interface (IBackWebItemDownloadServices) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{93BF8F00-DBE8-11D0-A875-0000B43699FC} BackWeb lite: Interface (IBackWebChannel2) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{9647FB70-DC0F-11D0-A875-0000B43699FC} BackWeb lite: Interface (IBackWebStoryCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{9DB46422-FF61-11D0-9951-444553540000} BackWeb lite: Interface (IBackWebAllStoryCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{9DB46423-FF61-11D0-9951-444553540000} BackWeb lite: Interface (IBackWebStory) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{9DB46424-FF61-11D0-9951-444553540000} BackWeb lite: Interface (IBackWebChannelVariableCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{A4BC67F0-6C90-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebChannel4) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{AEE96320-2131-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebCommunications) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{BAD37BC0-2231-11D1-9951-444553540000} BackWeb lite: Interface (IBackWebChannelCollection4) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{BCD0C200-69C1-11D1-8AF8-00609761C47A} NewsUpdate: Interface (_DCTMarq) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{C1B43B7F-8B3C-11D4-B615-00A0C98E9F5B} NewsUpdate: Interface (_DCTMarqEvents) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{C1B43B80-8B3C-11D4-B615-00A0C98E9F5B} BackWeb lite: Interface (IBackWebFilterSettings) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{C8CEEEE0-17D6-11D1-96A7-F8E906C10000} BackWeb lite: Interface (IBackWebApplicationNotifications) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{D0894D60-6C6C-11D0-A866-0000B43699FC} BackWeb lite: Interface (IBackWebGeneralSettings2) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{E01AD640-F87D-11D0-9A50-00AA004812C2} BackWeb lite: Interface (IBackWebInfoPakCollection) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{EB1FFFC1-5688-11D0-A865-0000B43699FC} BackWeb lite: Interface (IBackWebInfoPak) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{EB1FFFC2-5688-11D0-A865-0000B43699FC} BackWeb lite: Interface (IBackWebChannelVariable) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\Interface\{FEFCA7F0-6C8E-11D0-A866-0000B43699FC} NewsUpdate: Type library (CTMarq ActiveX Control module) (Registry key, nothing done) HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{C1B43B7E-8B3C-11D4-B615-00A0C98E9F5B} Avenue A, Inc.: Tracking cookie (Internet Explorer: Administrator) (Cookie, nothing done) XXXToolbar: Tracking cookie (Internet Explorer: Administrator) (Cookie, nothing done) LinkSynergy: Tracking cookie (Internet Explorer: Administrator) (Cookie, nothing done) Advertising.com: Tracking cookie (Internet Explorer: Administrator) (Cookie, nothing done) MediaPlex: Tracking cookie (Internet Explorer: Administrator) (Cookie, nothing done) Advertising.com: Tracking cookie (Internet Explorer: Administrator) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Avenue A, Inc.: Tracking cookie (Firefox: default) (Cookie, nothing done) DoubleClick: Tracking cookie (Firefox: default) (Cookie, nothing done) HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done) FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done) FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done) HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done) HitBox: Tracking cookie (Firefox: default) (Cookie, nothing done) MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done) MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) Advertising.com: Tracking cookie (Firefox: default) (Cookie, nothing done) CoreMetrics: Tracking cookie (Firefox: default) (Cookie, nothing done) WebTrends live: Tracking cookie (Firefox: default) (Cookie, nothing done) WebTrends live: Tracking cookie (Firefox: default) (Cookie, nothing done) --- Spybot - Search & Destroy version: 1.4 (build: 20050523) --- 2005-05-31 blindman.exe (1.0.0.1) 2005-05-31 SpybotSD.exe (1.4.0.3) 2005-05-31 TeaTimer.exe (1.4.0.2) 2005-08-02 unins000.exe (51.41.0.0) 2005-05-31 Update.exe (1.4.0.0) 2005-05-31 advcheck.dll (1.0.2.0) 2005-05-31 aports.dll (2.1.0.0) 2005-05-31 borlndmm.dll (7.0.4.453) 2005-05-31 delphimm.dll (7.0.4.453) 2005-05-31 SDHelper.dll (1.4.0.0) 2005-05-31 Tools.dll (2.0.0.2) 2005-05-31 UnzDll.dll (1.73.1.1) 2005-05-31 ZipDll.dll (1.73.2.0) 2005-04-26 Includes\Cookies.sbi (*) 2005-08-19 Includes\Dialer.sbi (*) 2005-08-19 Includes\Hijackers.sbi (*) 2005-08-16 Includes\Keyloggers.sbi (*) 2005-08-19 Includes\Malware.sbi (*) 2005-08-12 Includes\PUPS.sbi (*) 2005-04-27 Includes\Revision.sbi (*) 2005-08-19 Includes\Security.sbi (*) 2005-08-16 Includes\Spybots.sbi (*) 2005-02-17 Includes\Tracks.uti 2005-08-19 Includes\Trojans.sbi (*) -j |
|
|
|
|
|
#10 |
|
Computing Professor
Staff
Premium Member
Join Date: Jun 2001
Posts: 11,941
|
I just went and googled IBackWebCommunications and found lots of people with a log in Spybot Search&Destroy that looks just like yours.
It's spyware and in order to do it's job it needs, you guessed it, open ports. Security risk doesn't even begin to describe it. Get rid of it. As a rule you can, and should, delete anything Spybot finds. When in doubt make sure you have enabled Recovery. |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|