Welcome, Guest

Go Back   TechieHQ - Computer Help Forum · » Operating Systems · System Security
Reload this Page question on security

question on security

System Security File System security, OS Security, software firewalls and any other type of security topics reside here.

Reply
 
Thread Tools Display Modes
  #1  
Old Jul 25th, 05, 10:17 PM
theprofessor
Jr. THQ member
Posts: 95
Status: Offline
 
From: All Over
Joined: Feb 2005
Rep: theprofessor is on a distinguished road to becoming a computer geek
question on security

cb1.msn.com? is this legit. recently out of nowhere im getting this examine certificate box for my homepage set as my email. Ive never had this happen before. Is this bad news or what?
Reply With Quote
Advertisement
  #2  
Old Jul 25th, 05, 10:29 PM
Cryptoboats's Avatar
Cryptoboats
Ban Stick
Posts: 1,325
Status: Offline
shield_mod.giftechie.gif
 
From: Norfolk, VA
Joined: Jun 2005
Rep: Cryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geekness
I'm not sure. Probably a spyware issue. If you post your HijackThis log, I'll take a look and see if I see anything



__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee
Reply With Quote
  #3  
Old Jul 26th, 05, 2:51 PM
theprofessor
Jr. THQ member
Posts: 95
Status: Offline
 
From: All Over
Joined: Feb 2005
Rep: theprofessor is on a distinguished road to becoming a computer geek
Logfile of HijackThis v1.99.1
Scan saved at 10:47:30 PM, on 7/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\sony\usbsircs\usbsircs.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Sony\Giga Pocket\shwserv.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\DOCUME~1\LEIFWE~1\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f421.mail.yahoo.com/ym/log...=1plbf483ngi8m
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir..._PVER}&ar=home
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Remocon Driver.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http://forums.binarydreams.us
O15 - Trusted Zone: http://www.hotmail.com
O15 - Trusted Zone: http://www.hotornot.com
O15 - Trusted Zone: http://www.ironmagazineforums.com
O15 - Trusted Zone: http://www.msn.com
O15 - Trusted Zone: http://www.yahoo.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2918.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing)
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
Reply With Quote
  #4  
Old Jul 27th, 05, 12:00 AM
Cryptoboats's Avatar
Cryptoboats
Ban Stick
Posts: 1,325
Status: Offline
shield_mod.giftechie.gif
 
From: Norfolk, VA
Joined: Jun 2005
Rep: Cryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geekness
What kind of antivirus software are you running? Normally defwatch.exe is running out of the symantec folder. The folder it is coming out of (NavNT) is norton antivirus. Same company, so if you are running Norton then I don't think this is a problem.

Well, this doesn't show the problem, but here are a couple of things that need to be fixed:

O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)

The path is there, but the file is not. This can be fixed. The same goes for:

O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)


O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)

AND

O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing)


That's all I gather from this.



__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee
Reply With Quote
  #5  
Old Jul 28th, 05, 10:49 PM
theprofessor
Jr. THQ member
Posts: 95
Status: Offline
 
From: All Over
Joined: Feb 2005
Rep: theprofessor is on a distinguished road to becoming a computer geek
I got the Norton Corporate Edition from the Government. I had problems a little while back and I posted a HiJack this log and the other guys said to delete the same things with the Vaio Media Server. But they wont remove. I run a Vaio PC. I dont think those are made to be removed and not only that but I dont think those are whats causing my problem. But Im asking you so i appreciate your help. I guess if you dont find anything else then I dont have any problems.

Thanks Again.

I dont know what that certificate verification is. Ive bever seen it before and I think its kind of odd.
Reply With Quote
  #6  
Old Jul 28th, 05, 11:28 PM
Cryptoboats's Avatar
Cryptoboats
Ban Stick
Posts: 1,325
Status: Offline
shield_mod.giftechie.gif
 
From: Norfolk, VA
Joined: Jun 2005
Rep: Cryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geekness
When a site wants to prove to you that they are who they say they are, each site gets a certificate from a certified certificate authority (i don't know what their title is, but for explaining purposes they are a CCA). This prevents some punk kid from mirrorring(sp?) their site and pretending to be them. When you get an error about the certificate, that means it is expired, and it will tell you it is expired, or it has been tampered with, or it is not there, and it will tell you it isn't there. In any case, with an error you can not be 100% sure that you are on the web page that you think you are. Unless you do have some sort of spyware / malware that wasn't in your hijack this log, I'm not sure what your problem might be. Check to make sure your anit-virus is up to date, and run a scan to see if you have something. I doubt it, but better to err on the side of caution. I would also check that your IE and windows is updated.



__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee
Reply With Quote
  #7  
Old Jul 29th, 05, 10:11 PM
theprofessor
Jr. THQ member
Posts: 95
Status: Offline
 
From: All Over
Joined: Feb 2005
Rep: theprofessor is on a distinguished road to becoming a computer geek
Yeah but what is cb1.msn.com? Everything on it says its unknown authority or whatever. but see ive had this same email link set as my homepage for years on the same computer and never seen this before. all of a sudden it starts to appear alot. makes me think if it is someone trying to jack with my stuff. i say this also cause i had a couple of scammers sending me emails trying to get bank information from me. they knew some of my personal information too as far as my name etc but i figured that cant be too hard to get. but for this certificate to come up at the same time makes me wonder. you know what i mean?
Reply With Quote
  #8  
Old Jul 30th, 05, 3:02 AM
Cryptoboats's Avatar
Cryptoboats
Ban Stick
Posts: 1,325
Status: Offline
shield_mod.giftechie.gif
 
From: Norfolk, VA
Joined: Jun 2005
Rep: Cryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geekness
What is your home page?



__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee
Reply With Quote
  #9  
Old Jul 30th, 05, 10:18 PM
theprofessor
Jr. THQ member
Posts: 95
Status: Offline
 
From: All Over
Joined: Feb 2005
Rep: theprofessor is on a distinguished road to becoming a computer geek
my homepage to my hotmail account.
Reply With Quote
  #10  
Old Jul 31st, 05, 5:40 AM
Cryptoboats's Avatar
Cryptoboats
Ban Stick
Posts: 1,325
Status: Offline
shield_mod.giftechie.gif
 
From: Norfolk, VA
Joined: Jun 2005
Rep: Cryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geekness
Don't worry about it. cb1.msn.com is in the source code of the page, so it is legit.



__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee
Reply With Quote
Reply

Tags
question, security


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
College Security Goober System Security 8 Aug 23rd, 06 7:33 PM
AVG Security error Goober System Security 2 Dec 30th, 05 7:43 AM
How to get the security tab? Goober Windows XP 2 Jul 20th, 05 6:39 PM
security help weman4u System Security 6 Oct 28th, 04 1:51 AM


All times are GMT +1. The time now is 4:01 PM.