Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-03-2005, 06:34 AM   #1
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
:mad Ban Alan Greenspan and his toolbar shit site

greenspan has shown up in a number of threads posting a link to a site that immediately tries to forcibly install a toolbar (even forcing slightly on firefox).

His intentions are clear.

Ban his ass. Report him to his ISP. FUCK HIM UP BIGTIME.

He's an asshole.

Alex
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 06:44 AM   #2
NickPapageorgio
Confirmed User
 
Join Date: Apr 2004
Location: NC
Posts: 8,323
Absofuckinglutely. He almost got me with that shit too. Fucker!!
__________________
NickPapageorgio is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 06:50 AM   #3
yuvalus
Confirmed User
 
Join Date: Oct 2003
Posts: 1,906
yes ban this fucker
__________________
Mail me: [email protected]
yuvalus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 06:51 AM   #4
chupachups
Confirmed User
 
chupachups's Avatar
 
Join Date: Dec 2002
Location: Sweden/Spain you sum bitch!
Posts: 6,576
I concur...
Ban the sleasebag homo
__________________
chupachups is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 06:58 AM   #5
chemicaleyes
UNSTOPPABLE
 
chemicaleyes's Avatar
 
Join Date: Aug 2003
Location: UK :: ICQ# 156068
Posts: 11,569
Quote:
Originally Posted by NickPapageorgio
Absofuckinglutely.
__________________
No way as way, No limitation as limitation. AmeriNOC formally PhatServers
chemicaleyes is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:00 AM   #6
polish_aristocrat
Too lazy to set a custom title
 
Join Date: Jul 2002
Posts: 40,377
I don't think he wants to install toolbars... that's just Lawrence Connor....
__________________
I don't use ICQ anymore.
polish_aristocrat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:00 AM   #7
emthree
Dialer Kingpin
 
Join Date: Jun 2003
Location: New York
Posts: 10,816
It works on firefox? Link?
That's interesting.
__________________

Sell Patches & Pills
emthree is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:03 AM   #8
yuvalus
Confirmed User
 
Join Date: Oct 2003
Posts: 1,906
example of his message

https://gfy.com/7021373-post4.html
__________________
Mail me: [email protected]
yuvalus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:03 AM   #9
Trax
[----------------------]
 
Join Date: Aug 2001
Posts: 14,486
agreed!..
Trax is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:09 AM   #10
EROTEEK
Confirmed User
 
Join Date: May 2004
Location: Transylvania...no kidding
Posts: 419
__________________
EROTEEK STUDIOS

Yahoo: Eroteek_Studios
ICQ: 346685131
CUSTOM AND EXCLUSIVE CONTENT
EROTEEK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:14 AM   #11
ssp
Confirmed User
 
Join Date: Jan 2005
Location: United Kingdom
Posts: 7,990
Lawrence Conner has been banned countless of times, he just comes back everytime. Just put him on ignore.
ssp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:14 AM   #12
feN
Confirmed User
 
Join Date: Aug 2003
Location: ger
Posts: 2,547
ban that ugly fucker gogo
__________________
feN is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:14 AM   #13
pinkhat
Registered User
 
Join Date: Dec 2004
Location: I sleep with MSNbot
Posts: 21
i got a java popup trying to install something ( on firefox ) Lucky i clicked NO.
__________________
Promote EROTICA CASH - Niche sites including Sexy Trek, Vengified, Plushie Girls and many other Unique Niche Sites!!
pinkhat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 07:16 AM   #14
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
fucking gimp he is
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 08:40 AM   #15
Barefootsies
Choice is an Illusion
 
Barefootsies's Avatar
 
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
Quote:
Originally Posted by EROTEEK


__________________
Should You Email Your Members?

Link1 | Link2 | Link3

Enough Said.

"Would you rather live like a king for a year or like a prince forever?"
Barefootsies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 08:43 AM   #16
Corleone
C.R.E.A.M
 
Industry Role:
Join Date: Apr 2003
Posts: 15,262
hios toolbar links suck - ban
Corleone is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 08:57 AM   #17
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
leave Larence alone!! Hes my hero
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 08:59 AM   #18
AlienQ - BANNED FOR LIFE
best designer on GFY
 
AlienQ - BANNED FOR LIFE's Avatar
 
Join Date: Mar 2003
Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384
Posts: 30,307
I concurr, the bitch has to go.
AlienQ - BANNED FOR LIFE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 08:59 AM   #19
Project-Shadow
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Posts: 7,340
http://www.gofuckyourself.com/profil...=block&u=23513
Project-Shadow is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 09:01 AM   #20
LadyMischief
Orgasms N Such!
 
LadyMischief's Avatar
 
Industry Role:
Join Date: Sep 2002
Location: Oakville, Ontario
Posts: 18,135
I must agree, that's absolute bullshit.
__________________

ICQ 3522039
Content Manager - orgasm.com
[email protected]
LadyMischief is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 09:02 AM   #21
pornstar2pac
Omaha Hi/Lo
 
Join Date: Nov 2003
Posts: 17,380
this guy is 3 cards shy of a full deck
__________________
Trump haters gonna hate. that's all they can do
pornstar2pac is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 09:04 AM   #22
Michael O
More Cowbell
 
Industry Role:
Join Date: Jul 2001
Location: Nakhom Nowhere
Posts: 10,607
He is a idiot he proved that countless times ban the fucker.
__________________
Truth Teller
Michael O is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 09:06 AM   #23
garce
Confirmed User
 
garce's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Toronto
Posts: 7,103
Quote:
Originally Posted by Project-Shadow
That was convenient. Thanks.
garce is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 09:11 AM   #24
bly
So Fucking Banned
 
Join Date: Jul 2004
Location: pennsylvania
Posts: 850
alan posted 4-5 times straight, thats ban material too
bly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 09:39 AM   #25
r3ap3r
Confirmed User
 
Join Date: Jul 2004
Location: Canada
Posts: 3,535
Quote:
Originally Posted by Alan Greenspan
looks like I am not banned!
Asshole!!!
__________________
Fuck My Sig Good
ICQ - 203744959
r3ap3r is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 10:17 AM   #26
TexasDreams
former Miserable Admin :)
 
Join Date: Oct 2003
Location: Somewhere in Cali
Posts: 4,700


__________________
ICQ: 168-914-369 >>> sysop [at] TexasDreams [dot] com
TexasDreams is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:16 AM   #27
Bansheelinks
Confirmed User
 
Join Date: Apr 2003
Posts: 6,023
fuck you, greenspan........

you gotta go.........
Bansheelinks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:21 AM   #28
Bansheelinks
Confirmed User
 
Join Date: Apr 2003
Posts: 6,023
bump for a ban for greenspan
Bansheelinks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:23 AM   #29
CDSmith
Too lazy to set a custom title
 
CDSmith's Avatar
 
Industry Role:
Join Date: May 2001
Location: My network is hosted at TECHIEMEDIA.net ...Wait, you meant where am *I* located at? Oh... okay, I'm in Winnipeg, Canada. Oops. :)
Posts: 51,460
Quote:
Originally Posted by ssp
Lawrence Conner has been banned countless of times, he just comes back everytime. Just put him on ignore.
I can see who the real problemsolvers are here.

What he said.
__________________
Promote Wildmatch, ImLive, Sexier.com, and more!!

ALWAYS THE HIGHEST PAYOUTS: Big Bux/ImLive SIGNUP ON NOW!!!

Put some PUSSYCA$H in your pocket.
ICQ me at: 31024634
CDSmith is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:25 AM   #30
ezrydn
Confirmed User
 
Join Date: Aug 2004
Location: Guadalajara, MX
Posts: 695
I agree. Ban the fucker. Anyone who tries to install on MY machine without my permission is the lowest form of scum. And if little Allan doesn't like it, I'd be more than open to discuss it with him.......in person! PENCHE PENDEJO!
ezrydn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:30 AM   #31
Paolo Pinkas
Confirmed User
 
Join Date: Feb 2005
Posts: 345
:mad

that guy needs to get banned. posting this "fun-link" three times in a thread, without contributing in any way to the topic isn't funny at all imho
a poll if he should get banned or not would be a good idea.
Paolo Pinkas is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:32 AM   #32
fl_prn_str
Confirmed User
 
fl_prn_str's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Tampa, FL
Posts: 5,736
Quote:
Originally Posted by mrthumbs
leave Larence alone!! Hes my hero
fl_prn_str is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:33 AM   #33
Spunky
I need a beer
 
Spunky's Avatar
 
Industry Role:
Join Date: Jun 2002
Location: ♠ Toiletville ♠
Posts: 133,944
He eventually comes back under another nic anyways..
__________________
Spunky is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:36 AM   #34
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
Wandering around thread to thread posting the link shows me someone wants to get a bunch of people stuck with a crappy toolbar.

Fuck him. Ban him. Burn him. Block his IP.
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:36 AM   #35
Manowar
jellyfish  
 
Join Date: Dec 2003
Posts: 71,528
hes such a lamer.
Manowar is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 11:58 AM   #36
lazycash
Troll Patrol
 
Industry Role:
Join Date: Aug 2002
Location: Local Socal
Posts: 15,214
Quote:
Originally Posted by Alan Greenspan
the page I have been linking to
was purely for the joke of what is displayed
ON the page, not the toolbar that I am pretty
sure only goes with that site (pornstarguru)
and that you can either click off, or click no
to it before it installs anything, so its not
this terrible spyware its been called, its
fairly lame stuff, and not the point of the page
linked to, thats not the point of that page or site,
what it is is a joke page that shows a cartoon like
illustration of a guy cumming on you, its whoever
made a pornstarguru character, and anyone can join that
site and make a pornstarguru character too,
so my character's name is Lawrence_Connor
and that's the idea of that page linked to,
just that joke, not the toolbar which is always
a part of that site, and not my choice to have it
there and not in my control, it is also not my site.

It is just a harmless joke, the toolbar even,
which again, you can either click no to it, or click it off.

it's a game too, when more people click to your page
you earn more money in the game and stuff like that
If the toolbar is so harmless, go ahead and ok it for your pc. I've had that one before and its a pain in the ass to uninstall its adware.
__________________
"WTF, on google you can find the answer to every question in human history, EXCEPT how to convert cams..

Its crazy..."

VenusBlogger
lazycash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 12:22 PM   #37
CybermedAndy
Confirmed User
 
CybermedAndy's Avatar
 
Join Date: Jul 2004
Location: Vancouver
Posts: 4,170
Quote:
Originally Posted by Keyser Soze
He is a idiot he proved that countless times ban the fucker.
What he said
CybermedAndy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 02:41 PM   #38
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
Nobody wants your toolbar piece of shit. FUCK OFF AND GO AWAY!
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 03:51 PM   #39
NoCarrier
We need more free porn
 
Join Date: Mar 2002
Location: Montreal
Posts: 16,356
__________________
NoCarrier is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 03:53 PM   #40
KRosh
So Fucking Outlawed
 
KRosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Posts: 5,114
I had hoped that Lawrence died in a car accident.. One can only wish !
KRosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 03:56 PM   #41
Marcus Aurelius
No Refunds Issued.
 
Marcus Aurelius's Avatar
 
Industry Role:
Join Date: Apr 2003
Posts: 14,809
This message is hidden because Alan Greenspan is on your ignore list.
Marcus Aurelius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 08:35 PM   #42
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
Ignoring him isn't enough! Ban his ass.
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 08:39 PM   #43
Spunky
I need a beer
 
Spunky's Avatar
 
Industry Role:
Join Date: Jun 2002
Location: ♠ Toiletville ♠
Posts: 133,944
Quote:
Originally Posted by NoCarrier
That pic rocks..right click and save
__________________
Spunky is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 09:02 PM   #44
KRosh
So Fucking Outlawed
 
KRosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Posts: 5,114
BAN this idiot

oh yeah .. 50 banned FUCKHEADS
KRosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 10:22 PM   #45
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
i was skeptical of this thread up until about 10 minutes ago

now that I accidentaly clicked his link without thinking, i totally agree with you all now

between spybot and microsoft spyware, i had over 50 FUCKING WARNINGS from that one page lawrence had linked on here

my system was totally clean, and now with running MSW for only 5 minutes so far it has picked up 39 items and more as I type this

fuck you lawrence, you are now on my permanent shit list and I will be coming after you in the same way
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 10:25 PM   #46
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
want to know what happend on my machine from that one link...here ya go

Spyware Scan Details
Start Date: 4/4/2005 1:15:54 AM
End Date: 4/4/2005 1:22:35 AM
Total Time: 6 mins 41 secs

Detected Threats

ShopAtHome Spyware more information...
Details: ShopAtHome installs itself in the Winsock layer of your system and redirects your browser to merchant sites to take advantage of the affiliate fees.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\software\winsock2\layered provider sample


Xrenoder Browser Plug-in more information...
Details: Xrenoder is a Trojan that resets your browsers home page and search settings redirecting it to affiliate sites. Xrenoder also displays adult content pop-up advertisements.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\software\istsvc
HKEY_LOCAL_MACHINE\software\istsvc popup_day_limit 3
HKEY_LOCAL_MACHINE\software\istsvc update_count 0
HKEY_LOCAL_MACHINE\software\istsvc update_version 1020
HKEY_LOCAL_MACHINE\software\istsvc config_count 1
HKEY_LOCAL_MACHINE\software\istsvc account_id 138175
HKEY_LOCAL_MACHINE\software\istsvc app_date
HKEY_LOCAL_MACHINE\software\istsvc popup_interval 43200
HKEY_LOCAL_MACHINE\software\istsvc popup_last
HKEY_LOCAL_MACHINE\software\istsvc update_interval 86400
HKEY_LOCAL_MACHINE\software\istsvc update_last
HKEY_LOCAL_MACHINE\software\istsvc version 1022
HKEY_LOCAL_MACHINE\software\istsvc config_interval 86400
HKEY_LOCAL_MACHINE\software\istsvc config_last
HKEY_LOCAL_MACHINE\software\istsvc app_name istsvc.exe
HKEY_LOCAL_MACHINE\software\istsvc popup_url http://www.ysbweb.com/ist/scripts/istsvc_ads_data.php
HKEY_LOCAL_MACHINE\software\istsvc update_url http://www.ysbweb.com/ist/scripts/istsvc_update.php
HKEY_LOCAL_MACHINE\software\istsvc config_url http://www.ysbweb.com/ist/scripts/istsvc_config.php
HKEY_LOCAL_MACHINE\software\istsvc popup_initial_delay 600
HKEY_LOCAL_MACHINE\software\istsvc popup_count 0
HKEY_LOCAL_MACHINE\software\istsvc popup_day_count 0


AproposMedia Browser Modifier more information...
Details: AproposMedia is a component of PeopleOnPage, sometimes found on computers without the commonly visible portion of the application . AproposMedia displays pop-up advertisements, and changes browser settings.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
C:\Documents and Settings\Jace\Local Settings\Temp\AutoUpdate0\auto_update_install.exe
c:\program files\cxtpls\ace.dll
c:\program files\cxtpls\ai_04-04-2005.log
c:\program files\cxtpls\atl.dll
c:\program files\cxtpls\data.bin
c:\program files\cxtpls\libexpat.dll
c:\program files\cxtpls\uninstaller.exe
c:\program files\cxtpls\cxtpls.dll
c:\program files\autoupdate\autoupdate.exe
C:\Documents and Settings\Jace\Local Settings\Temp\auf0.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\Program Files\CxtPls\ProxyStub.dll
C:\Program Files\CxtPls\WinGenerics.dll
c:\windows\system32\dgsrtp.exe
c:\windows\system32\dllcert.exe

Infected folders detected
c:\program files\cxtpls

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{016235B E-59D4-4CEB-ADD5-E2378282A1D9}
HKEY_CLASSES_ROOT\clsid\{016235BE-59D4-4CEB-ADD5-E2378282A1D9}\InprocServer32 ThreadingModel Both
HKEY_CLASSES_ROOT\clsid\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}
HKEY_CLASSES_ROOT\clsid\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\LocalServer32 C:\Program Files\CxtPls\CxtPls.exe
HKEY_CLASSES_ROOT\clsid\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\ProgID
HKEY_CLASSES_ROOT\clsid\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\VersionIndependentProgID
HKEY_CLASSES_ROOT\clsid\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}
HKEY_CLASSES_ROOT\clsid\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}
HKEY_CLASSES_ROOT\clsid\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\InProcServer32 C:\Program Files\CxtPls\proxystub.dll
HKEY_CLASSES_ROOT\clsid\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\InProcServer32 ThreadingModel Both
HKEY_CLASSES_ROOT\clsid\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} PSFactoryBuffer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{016235BE-59D4-4CEB-ADD5-E2378282A1D9}
HKEY_LOCAL_MACHINE\software\apropos
HKEY_LOCAL_MACHINE\software\apropos\Client ProxyStub C:\Program Files\CxtPls\proxystub.dll
HKEY_LOCAL_MACHINE\software\apropos\Client Plugin C:\Program Files\CxtPls\cxtpls.dll
HKEY_LOCAL_MACHINE\software\apropos\Client ClientName C:\Program Files\CxtPls\CxtPls.exe
HKEY_LOCAL_MACHINE\software\apropos\Client LegalNote nonbranded
HKEY_LOCAL_MACHINE\software\apropos\Client InstallationId {H4063360-819c-7269-0b4d-9c8ba370ddbd}
HKEY_LOCAL_MACHINE\software\apropos\Client PartnerId CP.IST
HKEY_LOCAL_MACHINE\software\apropos\Client ServerAddress adchannel.contextplus.net
HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClie nt
HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClie nt LoadUrl http://download.contextplus.net/apropos/client/<>/CP.IST/<>/AproposClientInstaller.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run AutoUpdater
HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClie nt TempFile C:\DOCUME~1\Jace\LOCALS~1\Temp\auf0.exe
HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClie nt Parameters /PC=CP.IST /ForSupportedBrowsers /ShowLegalNote=nonbranded
HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClie nt Attempts 2
HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClie nt Trust 1
HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClie nt Total 2
HKEY_LOCAL_MACHINE\SOFTWARE\AutoLoader\AproposClie nt Downloaded 1
HKEY_LOCAL_MACHINE\SOFTWARE\Envolo\AutoUpdate\Stat e
HKEY_LOCAL_MACHINE\SOFTWARE\Envolo\AutoUpdate\Stat e AM_version 1.0.174
HKEY_LOCAL_MACHINE\SOFTWARE\Envolo\AutoUpdate\Stat e EnvoloAutoUpdater_version 1.0.24
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run AutoUpdater "C:\Program Files\AutoUpdate\AutoUpdate.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{016235B E-59D4-4CEB-ADD5-E2378282A1D9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC33311 6-6EA1-40A1-9D07-ECB192DB8CEA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{016235B E-59D4-4CEB-ADD5-E2378282A1D9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC33311 6-6EA1-40A1-9D07-ECB192DB8CEA}
HKEY_CLASSES_ROOT\clsid\{016235BE-59D4-4CEB-ADD5-E2378282A1D9}
HKEY_CLASSES_ROOT\clsid\{016235BE-59D4-4CEB-ADD5-E2378282A1D9}\InprocServer32 C:\Program Files\CxtPls\cxtpls.dll
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 10:25 PM   #47
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
IST.ISTbar Browser Modifier more information...
Details: ISTbar is an Internet Explorer redirector that modifies your homepage and searches without your consent using an Internet Explorer toolbar.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
C:\Program Files\ISTsvc\istsvc.exe
c:\windows\downloaded program files\istactivex.dll

Infected folders detected
c:\program files\istsvc

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run IST Service
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C55910 5-9ECF-42b8-B3F7-832E75EDD959}
HKEY_CLASSES_ROOT\ISTx.Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ISTx.Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run IST Service
HKEY_CURRENT_USER\software\ist
HKEY_CURRENT_USER\software\ist InstallDate 2005-04-04 05:15:08
HKEY_CURRENT_USER\software\ist account_id 138175
HKEY_CURRENT_USER\software\ist config mtb
HKEY_CURRENT_USER\software\ist Recover !ZpHc1YǍQ%? je? s?M?5?,J??L9
HKEY_LOCAL_MACHINE\Software\ISTbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run IST Service
HKEY_LOCAL_MACHINE\Software\ISTbar\Historyfiles C:\Program Files\ISTbar\xml_istbar.xml 1
HKEY_LOCAL_MACHINE\Software\ISTbar\Historyfiles C:\Program Files\ISTbar\imagemap_normal.bmp 1
HKEY_LOCAL_MACHINE\Software\ISTbar\Historyfiles C:\Program Files\ISTbar\version.txt 1
HKEY_LOCAL_MACHINE\Software\ISTbar installTitle SlotchBar
HKEY_LOCAL_MACHINE\Software\ISTbar barTitle SlotchBar
HKEY_LOCAL_MACHINE\Software\ISTbar serverpath http://www.slotch.com/ist/bars/istbar_cm/
HKEY_LOCAL_MACHINE\Software\ISTbar urlAfterInstall http://www.ysbweb.com/install/welcome.html
HKEY_LOCAL_MACHINE\Software\ISTbar gUpdate 0
HKEY_LOCAL_MACHINE\Software\ISTbar TBRowMode 0
HKEY_LOCAL_MACHINE\Software\ISTbar xml_istbar.xml -201558575
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C55910 5-9ECF-42b8-B3F7-832E75EDD959}
HKEY_LOCAL_MACHINE\Software\ISTbar imagemap_normal.bmp -924152405
HKEY_LOCAL_MACHINE\Software\ISTbar showcorrupted 1
HKEY_LOCAL_MACHINE\Software\ISTbar updatever
HKEY_LOCAL_MACHINE\Software\ISTbar refreshscope 1440
HKEY_LOCAL_MACHINE\Software\ISTbar allowupdate 0
HKEY_LOCAL_MACHINE\Software\ISTbar LastCheckTime 1112591777
HKEY_LOCAL_MACHINE\Software\ISTbar version.txt -186917087
HKEY_LOCAL_MACHINE\Software\ISTbar UpdateBegin 0
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\autoupdate
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\autoupdate UninstallString C:\WINDOWS\System32\auto_update_uninstall.exe C:\WINDOWS\System32\auto_update_uninstall.log
HKEY_CLASSES_ROOT\ISTx.Installer
HKEY_LOCAL_MACHINE\Software\microsoft\windows\curr entversion\uninstall\ISTbar
HKEY_LOCAL_MACHINE\Software\microsoft\windows\curr entversion\uninstall\ISTbar DisplayName SlotchBar
HKEY_LOCAL_MACHINE\Software\microsoft\windows\curr entversion\uninstall\ISTbar UninstallString regsvr32 /u /s "C:\Program Files\ISTbar\istbarcm.dll"
HKEY_LOCAL_MACHINE\Software\microsoft\windows\curr entversion\uninstall\ISTbar Publisher Integrated Seach Technologies
HKEY_LOCAL_MACHINE\Software\microsoft\windows\curr entversion\uninstall\ISTbar URLInfoAbout http://www.slotch.com
HKEY_LOCAL_MACHINE\Software\microsoft\windows\curr entversion\uninstall\ISTbar HelpLink http://www.slotch.com
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\istsvc
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\istsvc DisplayName ISTsvc
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\istsvc UninstallString C:\PROGRAM FILES\ISTSVC\ISTSVC.EXE /remove
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\istsvc NoModify 1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ISTx.Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C55910 5-9ECF-42b8-B3F7-832E75EDD959}
HKEY_CLASSES_ROOT\ISTx.Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ISTx.Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run IST Service


MoneyTree Dialer more information...
Details: MoneyTree is an ActiveX installer control that downloads premium-rate dialers, primarily for adult content sites. On system startup MoneyTree attempts to connect to an adult content site.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_CLASSES_ROOT\clsid\{00000010-6F7D-442C-93E3-4A4827C2E4C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000001 0-6F7D-442C-93E3-4A4827C2E4C8}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000001 0-6F7D-442C-93E3-4A4827C2E4C8}\ProgID DyFuCA_BH.BHObj.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000001 0-6F7D-442C-93E3-4A4827C2E4C8}\TypeLib {40B1D454-9CA4-43CC-86AA-CB175EAC52FB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000001 0-6F7D-442C-93E3-4A4827C2E4C8}\VersionIndependentProgID DyFuCA_BH.BHObj
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000001 0-6F7D-442C-93E3-4A4827C2E4C8} BHObj Class
HKEY_CLASSES_ROOT\clsid\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\InprocServer32 C:\WINDOWS\nem220.dll
HKEY_CLASSES_ROOT\clsid\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\ProgID DyFuCA_BH.BHObj.1
HKEY_CLASSES_ROOT\clsid\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\TypeLib {40B1D454-9CA4-43CC-86AA-CB175EAC52FB}
HKEY_CLASSES_ROOT\clsid\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\VersionIndependentProgID DyFuCA_BH.BHObj
HKEY_CLASSES_ROOT\clsid\{00000010-6F7D-442C-93E3-4A4827C2E4C8} BHObj Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000001 0-6F7D-442C-93E3-4A4827C2E4C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000001 0-6F7D-442C-93E3-4A4827C2E4C8}\InprocServer32 C:\WINDOWS\nem220.dll
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 10:25 PM   #48
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
IST.XXXToolbar Toolbar more information...
Details: XXXToolbar is an adult content adware search toolbar for Internet Explorer. XXXToolbar displays pop-up advertisements.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\program files\istsvc\istsvc.exe

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run IST Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run IST Service


IST.SideFind Adware more information...
Details: SideFind installs an adware Internet Explorer browser helper object that installs some extra buttons.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\documents and settings\jace\local settings\temp\sidefind.exe
c:\program files\sidefind\sfexd001
C:\Program Files\SideFind\sfbho.dll
C:\Program Files\SideFind\sidefind.dll
C:\Program Files\SideFind\update\sidefind.exe

Infected folders detected
c:\program files\sidefind
c:\program files\sidefind\update

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7}
HKEY_CLASSES_ROOT\SideFind.Finder.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SideFind.Finde r.1
HKEY_CLASSES_ROOT\clsid\{8CBA1B49-8144-4721-A7B1-64C578C9EED7}
HKEY_CLASSES_ROOT\clsid\{8CBA1B49-8144-4721-A7B1-64C578C9EED7}\InprocServer32 C:\Program Files\SideFind\sidefind.dll
HKEY_CLASSES_ROOT\clsid\{8CBA1B49-8144-4721-A7B1-64C578C9EED7}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{8CBA1B49-8144-4721-A7B1-64C578C9EED7}\ProgID SideFind.Finder.1
HKEY_CLASSES_ROOT\clsid\{8CBA1B49-8144-4721-A7B1-64C578C9EED7}\TypeLib {58634367-D62B-4C2C-86BE-5AAC45CDB671}
HKEY_CLASSES_ROOT\clsid\{8CBA1B49-8144-4721-A7B1-64C578C9EED7}\VersionIndependentProgID SideFind.Finder
HKEY_CLASSES_ROOT\clsid\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} SideFind
HKEY_CLASSES_ROOT\BrowserHelperObject.BAHelper.1
HKEY_CLASSES_ROOT\clsid\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}
HKEY_CLASSES_ROOT\clsid\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}\InprocServer32 C:\Program Files\SideFind\sfbho.dll
HKEY_CLASSES_ROOT\clsid\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}\InprocServer32 ThreadingModel Both
HKEY_CLASSES_ROOT\clsid\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}\ProgID BrowserHelperObject.BAHelper.1
HKEY_CLASSES_ROOT\clsid\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}\TypeLib {D0288A41-9855-4A9B-8316-BABE243648DA}
HKEY_CLASSES_ROOT\clsid\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}\VersionIndependentProgID BrowserHelperObject.BAHelper
HKEY_CLASSES_ROOT\clsid\{A3FDD654-A057-4971-9844-4ED8E67DBBB8} BAHelper Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper.1\CLSID {A3FDD654-A057-4971-9844-4ED8E67DBBB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper.1 BAHelper Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper\CLSID {A3FDD654-A057-4971-9844-4ED8E67DBBB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper\CurVer BrowserHelperObject.BAHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper BAHelper Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7}\InprocServer32 C:\Program Files\SideFind\sidefind.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7}\ProgID SideFind.Finder.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7}\TypeLib {58634367-D62B-4C2C-86BE-5AAC45CDB671}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7}\VersionIndependentProgID SideFind.Finder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8CBA1B4 9-8144-4721-A7B1-64C578C9EED7} SideFind
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8}\InprocServer32 C:\Program Files\SideFind\sfbho.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8}\InprocServer32 ThreadingModel Both
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8}\ProgID BrowserHelperObject.BAHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8}\TypeLib {D0288A41-9855-4A9B-8316-BABE243648DA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8}\VersionIndependentProgID BrowserHelperObject.BAHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8} BAHelper Class
HKEY_LOCAL_MACHINE\Software\Classes\SideFind.Finde r.1
HKEY_LOCAL_MACHINE\Software\Classes\SideFind.Finde r.1\CLSID {8CBA1B49-8144-4721-A7B1-64C578C9EED7}
HKEY_CLASSES_ROOT\SideFind.Finder.1
HKEY_LOCAL_MACHINE\Software\Classes\SideFind.Finde r.1 SideFind
HKEY_LOCAL_MACHINE\Software\Classes\SideFind.Finde r
HKEY_LOCAL_MACHINE\Software\Classes\SideFind.Finde r\CLSID {8CBA1B49-8144-4721-A7B1-64C578C9EED7}
HKEY_LOCAL_MACHINE\Software\Classes\SideFind.Finde r\CurVer SideFind.Finder.1
HKEY_LOCAL_MACHINE\Software\Classes\SideFind.Finde r SideFind
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807} Default Visible Yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807} ButtonText SideFind
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807} HotIcon C:\PROGRA~1\SideFind\sidefind.dll,201
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807} Icon C:\PROGRA~1\SideFind\sidefind.dll,201
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SideFind.Finde r.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807} CLSID {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807} BandCLSID {8CBA1B49-8144-4721-A7B1-64C578C9EED7}
HKEY_LOCAL_MACHINE\Software\Microsoft\SideFind
HKEY_LOCAL_MACHINE\Software\Microsoft\SideFind webautosearch true
HKEY_LOCAL_MACHINE\Software\Microsoft\SideFind shoppingautosearch true
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\SideFind
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\SideFind DisplayName SideFind
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\SideFind UninstallString "C:\Program Files\Sidefind\update\sidefind.exe" /remove
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind account_id 106
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3FDD65 4-A057-4971-9844-4ED8E67DBBB8}
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind PathBHO C:\Program Files\SideFind\sfbho.dll
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind PathDLL C:\Program Files\SideFind\sidefind.dll
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind PathXML C:\Program Files\SideFind\sfexd001
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind PathEXE C:\Program Files\Sidefind\update\sidefind.exe
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind InstallDate 2005-04-04 05:15:11
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind SearchSite http://www.sidefind.com/results.php?target=_external&
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind update 1112678112
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind ver 1.3
HKEY_LOCAL_MACHINE\SOFTWARE\SideFind IntervalBetweenShows 240
HKEY_CLASSES_ROOT\BrowserHelperObject.BAHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserHelperO bject.BAHelper.1


Possible Browser Hijack Browser Modifier more information...
Details: Possible Browser Hijack redirects Internet Explorer.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.


IST.ISTbar.ActiveX Spyware more information...
Details: ISTactivex is an Internet Explorer redirector that silently modifies homepages and searches using an Internet Explorer toolbar.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected registry keys/values detected
HKEY_CLASSES_ROOT\clsid\{7C559105-9ECF-42b8-B3F7-832E75EDD959}
HKEY_CLASSES_ROOT\clsid\{7C559105-9ECF-42b8-B3F7-832E75EDD959}\InprocServer32 C:\WINDOWS\Downloaded Program Files\istactivex.dll
HKEY_CLASSES_ROOT\clsid\{7C559105-9ECF-42b8-B3F7-832E75EDD959}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{7C559105-9ECF-42b8-B3F7-832E75EDD959}\ProgID ISTx.Installer
HKEY_CLASSES_ROOT\clsid\{7C559105-9ECF-42b8-B3F7-832E75EDD959} Installer Class
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 10:26 PM   #49
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
IST.ISTbar.ContentMatchControl Browser Plug-in more information...
Details: IST.ISTbar.ContentMatchControlis an Internet Explorer redirector that modifies your homepage and searches without your consent using an Internet Explorer toolbar. IST.ISTbar.ContentMatchControl is part of the IST.ISTbar product.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
C:\Program Files\ISTbar\cmctl.dll
C:\Program Files\ISTbar\istbarcm.dll

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DC341F1 B-EC77-47BE-8F58-96E83861CC5A}
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}\ProgID TestContentMatchControl1.ContentMatchTag.1
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}\Properties Ticket 0069052169482
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}\Properties Version 10
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}\Properties BuildName 876051
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}\TypeLib {E9A5B71C-093B-4F34-AF07-34FCA89BA0DF}
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}\VersionIndependentProgID TestContentMatchControl1.ContentMatchTag
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A} ContentMatchTag Class
HKEY_CLASSES_ROOT\clsid\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}
HKEY_CLASSES_ROOT\clsid\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}\InprocServer32 C:\Program Files\ISTbar\istbarcm.dll
HKEY_CLASSES_ROOT\clsid\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\TestContentMatchControl1.Content MatchTag.1
HKEY_CLASSES_ROOT\clsid\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}\ProgID ISTbar.BarObj
HKEY_CLASSES_ROOT\clsid\{FAA356E4-D317-42a6-AB41-A3021C6E7D52} ISTbar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TestContentMat chControl1.ContentMatchTag.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FAA356E 4-D317-42a6-AB41-A3021C6E7D52}
HKEY_CLASSES_ROOT\ISTbar.BarObj
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ISTbar.BarObj
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}\InprocServer32 C:\Program Files\ISTbar\cmctl.dll
HKEY_CLASSES_ROOT\clsid\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}\InprocServer32 ThreadingModel Apartment


IST.SlotchBar Toolbar more information...
Details: Slotch Bar is an adware toolbar program for affiliates to distribute on sites. Affiliates get paid per install of the toolbar.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\program files\istbar\cmctl.dll
c:\program files\istbar\imagemap_normal.bmp
c:\program files\istbar\istbarcm.dll
c:\program files\istbar\version.txt
c:\program files\istbar\xml_istbar.xml

Infected folders detected
c:\program files\istbar

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DC341F1 B-EC77-47BE-8F58-96E83861CC5A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\SharedDLLs C:\WINDOWS\Downloaded Program Files\ISTactivex.dll
HKEY_CLASSES_ROOT\TestContentMatchControl1.Content MatchTag.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TestContentMat chControl1.ContentMatchTag.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FAA356E 4-D317-42a6-AB41-A3021C6E7D52}
HKEY_CLASSES_ROOT\ISTbar.BarObj
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ISTbar.BarObj
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ISTactivex.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ISTactivex.dll .Owner {7C559105-9ECF-42B8-B3F7-832E75EDD959}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ISTactivex.dll {7C559105-9ECF-42B8-B3F7-832E75EDD959}


PeopleOnPage Browser Modifier more information...
Details: The PeopleOnPage program is an adware and browser redirector that purports to be an Internet Explorer sidebar, and displays a list of other users of the current site.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\system32\auto_update_uninstall.exe
c:\windows\system32\auto_update_uninstall.log
C:\Program Files\CxtPls\ace.dll
C:\Program Files\AutoUpdate\AutoUpdate.exe

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run AutoUpdater
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\aproposclient
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\aproposclient UninstallString "C:\Program Files\CxtPls\uninstaller.exe"
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\aproposclient DisplayName CtxPls
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\uninstall\aproposclient DisplayIcon C:\Program Files\CxtPls\uninstaller.exe
HKEY_LOCAL_MACHINE\software\envolo
HKEY_LOCAL_MACHINE\software\envolo\AutoUpdate\Stat e AM_version 1.0.174
HKEY_LOCAL_MACHINE\software\envolo\AutoUpdate\Stat e EnvoloAutoUpdater_version 1.0.24
HKEY_LOCAL_MACHINE\software\envolo\AutoUpdate PollInterval 86400
HKEY_LOCAL_MACHINE\software\envolo\AutoUpdate ServerUrl http://envolo.peopleonpage.com:80/servlets/auto_update
HKEY_LOCAL_MACHINE\software\envolo\AutoUpdate DestDir C:\Program Files\AutoUpdate\AutoUpdate.exe
HKEY_LOCAL_MACHINE\software\envolo\AutoUpdate HostId {29BBEAA4-99E7-4B61-B8F7-A03C93BD9F84}
HKEY_LOCAL_MACHINE\software\envolo\AutoUpdate NextPingTime64 1112678159


180search Assistant Adware more information...
Details: 180search Assistant displays pop-up advertismenets.
Status: Quarantined
Moderate threat - Moderate-risk items have some potential for harm, but may be part of a wanted service. Users may decide to ignore such programs after review.

Infected files detected
c:\program files\180solutions\sais.exe
c:\windows\mtavexst.exe
c:\program files\180solutions\sais.log
c:\program files\180solutions\saisau.dat
c:\program files\180solutions\saishook.dll
c:\program files\180solutions\sais_gdf.dat
c:\program files\180solutions\sais_kyf.dat

Infected folders detected
c:\program files\180solutions
c:\program files\180solutions\fleok

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run sais
HKEY_CURRENT_USER\Software\sais action_url_version 50
HKEY_CURRENT_USER\Software\sais action_url_last_chunk 0
HKEY_CURRENT_USER\Software\sais action_url_last_full_version 50
HKEY_CURRENT_USER\Software\sais key_file 470
HKEY_CURRENT_USER\Software\sais kw_last_chunk 2
HKEY_CURRENT_USER\Software\sais cbc 1
HKEY_CURRENT_USER\Software\sais geourl_last_full_version 11
HKEY_CURRENT_USER\Software\sais geourl_current_version 11
HKEY_CURRENT_USER\Software\sais actionurl_last_full_version 152
HKEY_CURRENT_USER\Software\sais actionurl_current_version 152
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run sais
HKEY_CURRENT_USER\Software\sais keyword_last_full_version 469
HKEY_CURRENT_USER\Software\sais keyword_current_version 469
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\sais
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\sais DisplayName Uninstall 180searchAssistant
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\sais UninstallString c:\program files\180solutions\sais.exe /uninst_simple_init=y
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\sais DisplayIcon c:\program files\180solutions\sais.exe,0
HKEY_LOCAL_MACHINE\SOFTWARE\sais
HKEY_LOCAL_MACHINE\SOFTWARE\sais mt1 018F10C8B66112A5FB11F0336A0BEF70D188EBBFB663C575F7 543D0EBDBE2D82E9
HKEY_LOCAL_MACHINE\SOFTWARE\sais mt2 0133E6A9110F79B695B4A7E206724D0F1BE88A3F50
HKEY_LOCAL_MACHINE\SOFTWARE\sais mt3 01341E51656DA0EA0FB38BB1137EF3A56D84F1F463
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run mtavexst
HKEY_LOCAL_MACHINE\SOFTWARE\sais gma 1
HKEY_LOCAL_MACHINE\SOFTWARE\sais gvi 1
HKEY_LOCAL_MACHINE\SOFTWARE\sais gpi 1
HKEY_LOCAL_MACHINE\SOFTWARE\sais boom
HKEY_LOCAL_MACHINE\SOFTWARE\sais boom_ver 1
HKEY_LOCAL_MACHINE\SOFTWARE\sais did 841
HKEY_LOCAL_MACHINE\SOFTWARE\sais duid 233iiexkqvqvzuoyohksrfhgcwdyec
HKEY_LOCAL_MACHINE\SOFTWARE\sais partner_id 383894550
HKEY_LOCAL_MACHINE\SOFTWARE\sais product_id 841
HKEY_LOCAL_MACHINE\SOFTWARE\sais umt 016B7598278286786603D998ABF5AEDE37216DFB5DAC81215E AEEE03CF8B63607E
HKEY_CURRENT_USER\Software\sais
HKEY_CURRENT_USER\Software\sais last_conn_h 29702357
HKEY_CURRENT_USER\Software\sais last_conn_l 1198106832
HKEY_CURRENT_USER\Software\sais we 5
HKEY_CURRENT_USER\Software\sais
HKEY_CURRENT_USER\Software\sais TimeOffset -25175


Detected Spyware Cookies
No spyware cookies were found during this scan.
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-03-2005, 10:26 PM   #50
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
All From One God Damned Site That Lawrence Connor Posted

Fuck You Lawrence Connor, You Will Be Paid Back
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright 2000- Jelsoft Enterprises Limited.