republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Spybot bringing up a lot of popups
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Please review this hijack log.. »
« Found New Security Flaw in Cingular VM  
AuthorAll Replies


CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL


1 edit
reply to bladerider
Re: Spybot bringing up a lot of popups

bladerider, can you rightclick on the file that is unknown:
C:\WINDOWS\vsnpstd3.exe
Choose "Properties" from the dropdown menu and look at the tabs at the top for additional information on the file. Does it belong to Sonix?

»www.exedb.com/vsnpstd3.html
vsnpstd3.exe vsnpstd3 Process Information
File Name: vsnpstd3.exe
Process Name: Camera Monitor Application
Description: vsnpstd3.exe PC Camera Monitor MFC Application. This program is not important for your system process, but should not be terminated unless suspected to be causing problems.
Author: Sonix
Part of: Camera Monitor Application
Virus: No
Trojan: No
Spyware: No
Security Risk: 0
................
Can you post the Spybot logs or more info about the registry changes Spybot is alerting you about? It might be something quite legit and only the detailed information regarding what is trying to change and change to what will help determine if it is a problem or not.
--
It takes a disaster to make a woman out of a female

Microsoft MVP/Windows Security 2003-2006


Proud Member of ASAP (Alliance of Security Analysis Professionals)

bladerider

join:2005-10-22
netherlands

Calamity Jane, first of all thanks for your help

The properties of the file do not show a lot of information other than the original name of the file: Fileversion: 1.0.1.2,Internal Name:CameraMonitor,Original File:CameraMonitor.exe,ProductName: CameraMonitor Application,Language: English.

For better readability I will post a part of the resident log . The same line appears over and over again :

23-10-2005 15:17:43 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:43 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:44 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:44 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:45 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:46 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:47 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:47 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:48 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:48 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:49 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:49 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:50 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:50 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:51 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:51 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:52 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:52 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:53 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:54 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:55 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:55 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:56 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:56 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:57 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:57 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:58 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:58 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:59 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:17:59 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:18:01 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:18:01 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:18:02 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:18:02 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:18:03 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:18:03 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:18:04 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
23-10-2005 15:18:04 Denied value "ITBarLayout" (new data: "") deleted in User-specific browser toolbar!


CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL

said by bladerider See Profile :

The properties of the file do not show a lot of information other than the original name of the file: Fileversion: 1.0.1.2,Internal Name:CameraMonitor,Original File:CameraMonitor.exe,ProductName: CameraMonitor Application,Language: English.
Ok, that is the Camera Monitor mentioned in my previous post. So not a problem file.

quote:
For better readability I will post a part of the resident log . The same line appears over and over again :

23-10-2005 15:17:43 Denied value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") deleted in User-specific browser toolbar!
That CSLID (the number that appears in brackets) belongs to the Adobe Toolbar which is legitimate. Were you trying to delete the toolbar or doing something with Adobe?
--
It takes a disaster to make a woman out of a female
Microsoft MVP/Windows Security 2003-2006
Proud Member of ASAP (Alliance of Security Analysis Professionals)

bladerider

join:2005-10-22
netherlands
Adobe is installed on my system,but I do not recall that I was trying to change anything in it. If I would reinstall the program, would that solve this issue?


CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL

Let me see if I can find a TeamSpybot or other SB expert, perhaps we can get a better explanation of what that message is telling you. It looks like it is changing the data, but I'm not sure what is causing it or why.
--
It takes a disaster to make a woman out of a female
Microsoft MVP/Windows Security 2003-2006
Proud Member of ASAP (Alliance of Security Analysis Professionals)


Rusty Dusty

join:2002-11-23
reply to bladerider
Just wondering... Is Adobe updater turned on, or
is it in 'Manual' mode?

bladerider

join:2005-10-22
netherlands
Rusty,

the updates is set on automatic


Rusty Dusty

join:2002-11-23

Well, I do not want to interfere with CJ's process,
but I'd try changing the updates to manual, reboot
and see if you still have the problem! Adobe update may be trying to change something in the browser helper....
--
SRS 4000 CE, 4.2.1.10, G4R, 1250, W2K@all updates, IE6@all updates, ICS, 5 Clients (one wireless, one Linux) RSL 83.
Forums » Up and Running » Security » SecurityPlease review this hijack log.. »
« Found New Security Flaw in Cingular VM  


Friday, 27-Nov 20:18:23 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [120] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [68] In-Flight Internet Headed For Bumpy Landing?
· [61] Verizon CEO: Hulu Will Be Dead Soon
· [60] Thanksgiving Open Thread
· [38] EFF Wages War On Fine Print
· [38] ICANN Slams DNS Redirection
Most people now reading
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Leveling to 85 [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· [Vista] Why is HD So Full? [Microsoft Help]
· [Newsgroups] Newzleech down? [Filesharing Software]
· 5 hour energy for diabetic [General Questions]
· Not strictly "Home" related - but WOW anyways... [Home Repair & Improvement]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· Only firefox accesses Internet? [Security]