Anti-Spyware Forums


Reply
Thread Tools Display Modes

Seeking an explanation - can you help?

 
 
~BD~
Guest
Posts: n/a

 
      16-11-2008, 10:30 AM


When looking at a hijackthis log today (not my own) I copied this item:
http://ie.redirect.hp.com/svs/rdr?TY...io&pf=desktopI
pasted same into Internet Explorer (IE7) address bar, clicked and I was
actually taken here:http://www.aol.co.uk/?src=compaq-desktop.aol.comI did
the same thing with my AOL browser and ended up at the same
place:http://www.aol.co.uk/?src=compaq-desktop.aol.comThis was to be
expected, I suppose, as AOL is based on/uses IE AFAICT.I then carried out a
similar exercise with Firefox (3.0.4)and was taken
here:http://compaq-desktop.aol.com/In all cases the 'final' site was the
main AOL 'master' Web page. www.aol.com I Find this kind of thing
intriguing. I'd welcome sme suggestions as to why this might happen.Dave (XP
Home SP3 and updates - AOL is my ISP)


 
Reply With Quote
 
Peter Foldes
Guest
Posts: n/a

 
      16-11-2008, 12:03 PM
Why do you have a need to crosspost this to 3 different newsgroups

That link takes me and probably others to this page http://www.hp.com/#Product

What you have is the AOL virus .You are definitely infected with it. To fix this virus get rid of AOL and use a proper ISP not one that is Proprietary like the latter and maybe just maybe you will be satisfied and happy after.

I hope this satisfies your ignorance



--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"~BD~" <~BD~@nomail.afraid.com> wrote in message news:%23%(E-Mail Removed)...
> When looking at a hijackthis log today (not my own) I copied this item:
> http://ie.redirect.hp.com/svs/rdr?TY...io&pf=desktopI
> pasted same into Internet Explorer (IE7) address bar, clicked and I was
> actually taken here:http://www.aol.co.uk/?src=compaq-desktop.aol.comI did
> the same thing with my AOL browser and ended up at the same
> place:http://www.aol.co.uk/?src=compaq-desktop.aol.comThis was to be
> expected, I suppose, as AOL is based on/uses IE AFAICT.I then carried out a
> similar exercise with Firefox (3.0.4)and was taken
> here:http://compaq-desktop.aol.com/In all cases the 'final' site was the
> main AOL 'master' Web page. www.aol.com I Find this kind of thing
> intriguing. I'd welcome sme suggestions as to why this might happen.Dave (XP
> Home SP3 and updates - AOL is my ISP)
>
>

 
Reply With Quote
 
BoaterDave
Guest
Posts: n/a

 
      16-11-2008, 03:47 PM
On Nov 16, 12:03*pm, "Peter Foldes" <ok...@hotmail.com> wrote:
> Why do you have a need to crosspost this to 3 different newsgroups
>
> That link takes me and probably others to this pagehttp://www.hp.com/#Product
>
> What you have is the AOL virus .You are definitely infected with it. To fix this virus get rid of AOL and use a proper ISP not one that is Proprietary like the latter and maybe just maybe you will be satisfied and happy after.
>
> I hope this satisfies your ignorance
>
> --
> Peter
>
> Please Reply to Newsgroup for the benefit of others
> Requests for assistance by email can not and will not be acknowledged.
>
> "~BD~" <~...@nomail.afraid.com> wrote in messagenews:%23%(E-Mail Removed). gbl...
> > When looking at a hijackthis log today (not my own) I copied this item:
> >http://ie.redirect.hp.com/svs/rdr?TY...le=EN_US&c=Q10...
> > pasted same into Internet Explorer (IE7) address bar, clicked *and I was
> > actually taken here:http://www.aol.co.uk/?src=compaq-desktop.aol.comIdid
> > the same thing with my AOL browser and ended up at the same
> > place:http://www.aol.co.uk/?src=compaq-desktop.aol.comThiswas to be
> > expected, I suppose, as AOL is based on/uses IE AFAICT.I then carried out a
> > similar exercise with Firefox (3.0.4)and was taken
> > here:http://compaq-desktop.aol.com/Inall cases the 'final' site was the
> > main AOL 'master' Web page.www.aol.comI Find this kind of thing
> > intriguing. I'd welcome sme suggestions as to why this might happen.Dave (XP
> > Home SP3 and updates - AOL is my ISP)


************************************************** ********

This was my reply posted through Outlook Express - it has conveniently
'disappeared'!


Hmmm! 'ello, 'ello. 'ello!

How interesting to find that it was you, Peter, who responded to my
request,
just as you had done to the original poster of the HJT log. viz:-

------------------------------------------------------------------------

Hijack this logs are very hard to interpret. Best to send it to the
Hijack
this people that read and interpret them. They will tell you which
lines are
to be removed.

(http://aumha.org/downloads/hijackthis.zip) is the preferred tool to
use.
It will help you to both identify and remove any hijackware/spyware.
**Post
your log to http://aumha.net/viewforum.php?f=30,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7, or other appropriate
forums for expert analysis

--
Peter

---------------------------------------------------------------------------

I must surely add that the link which I copied and pasted into Google
as a
first step, took me to examples of others who had a similar re-
direction. I
was not at all surprised to discover, long before your reply here,
that the
said link no longer acted as I had described, but had changed to send
one to
Hewlett-Packard.
You may remember that something similar once occurred when
Ann from
the UK User2User group sent me a copy of a screenshot from her
computer by
email. When I opened the screenshot using Notepad, there were 'live'
links
inside which went directly to sites selling the likes of Viagra and
similar
products.

No-one believed me and very quickly 'adjustments' were made (by
external sources I'm sure) so that this phenomena no longer happened.
Others
in that newsgroup were unable to see what I had seen.

You appear to indicate that AOL(UK) is, in itself, is an
'improper'
ISP. You may be correct, but I wonder if you can substantiate that
allegation. Can you?

Dave

--





 
Reply With Quote
 
BoaterDave
Guest
Posts: n/a

 
      17-11-2008, 07:05 AM
On Nov 17, 5:27*am, "Andrew Taylor"
<andrewcrumpleh...@spamcopSUBVERSIVE.com> wrote:
> "BoaterDave" <BoaterD...@hotmail.co.uk> wrote in message
>
> news:5546848d-7291-40c7-a76e-(E-Mail Removed)...
>
> * * * You appear to indicate that AOL(UK) is, in itself, is an
> 'improper'
> ISP. You may be correct, but I wonder if you can substantiate that
> allegation. Can you?
>
> David
>
> One day when you have 3 or 4 hours spare, go into the Windows Registry (
> Start/run - type regedit - enter) and click Find and enter AOL. Count the
> number of changes that AOL makes to the windows registry? Write then all
> down, count them, and let me know.. OK?
>
> I once spent 6 hours removing AOL from a friend's computer manually. I
> thought it would be a 10 minute job.


I take your point Andrew!

The registry changes can only be made though (I think!) if the actual
AOL programme is installed - in my case AOL9 VR

What Peter Foldes seemed to imply was that AOL(UK) as an Internet
Service Provider (ISP) is not to be trusted. As far as I am aware, AOL
is next only to BT (is the second biggest) Broadband supplier in the
UK. I'm sure 'someone' would have noticed if they were up to no good
(wouldn't they? <vbg>)

I'm not so sure about Hewlett Packard though. This is some of the
info. my printer sends back to base: I'm sure I will have authorised
HP to collect data when I accepted their Terms and Conditions, but I
do wonder if other manufacturers take the liberty of sendin back user
activity back to its HQ. Do you (or anyone else) know?

I found it intriguing that the 'questionable' link I found leads
to .......... HP!

Cheers

Dave

 ÿmip://0343c148/default.htmlE 
ABCD
Ø
    -hp psc 1200 seriesJLPT1:K 029614374L 021135968Y Fk
„fGf¬T HCÙI IqY V W X N®
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = / 0 1 5
6 7 8 9 : ; < = / 0 1
5 6 7 8 9 : ; < = ÿ?http://
http://www.timesonline.co.uk/multime...killer-10E 
ABCD
Ø
 6  -hp psc 1200 seriesJLPT1:K 029614374L 021135968Y
FmâfGŽ
U HRýI IY V W X N²
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = ÿ?http://
http://www.timesonline.co.uk/multime...killer-97E 
ABCD
Ø
 0  -hp psc 1200 seriesJLPT1:K 029614374L 021135968Y
F‡âfGÀ
U H„ýI IGY V W X N²
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < =
ÿI.Minutesofthe88thMeeting18.3.0E 
ABCD
Ø   9  -hp psc 1200 seriesJLPT1:K029614374L
021135968Y FFòfGíU H'J I¼#Y V WX N³
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = / 0 1 5
6 7 8 9 : ; < = ÿ?http://
http://www.timesonline.co.uk/multime...killer-98E 
ABCD
Ø
0  -hp psc 1200 seriesJLPT1:K 029614374L 021135968Y F…
2gGU HÓJ I…/Y V W X N¶
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = ÿ?http://
http://www.timesonline.co.uk/multime...killer-97E 
ABCD
Ø
 4  -hp psc 1200 seriesJLPT1:K 029614374L 021135968Y
Fê=gG±U HJ I·/Y V W X N·
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = ÿ?http://
entertainment.timesonline.co.uk/tol/arts_and_entertainmeE 
ABCD
Ø
   -hp psc 1200 seriesJLPT1:K 029614374L 021135968Y
F#IgGu2U HJ IP8Y V W X N¸
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = / 0 1 5
6 7 8 9 : ; < = / 0 1
5 6 7 8 9 : ; < = ÿ?http://
http://www.timesonline.co.uk/multime...sudoku-12E 
ABCD
Ø

  -hp psc 1200 seriesJLPT1:K 029614374L 021135968Y
F#IgGu2U HJ IP8Y V W X N¸
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = ÿ?http://
http://www.timesonline.co.uk/multime...killer-98E 
ABCD
Ø  % :  -hp psc 1200 seriesJLPT1:K 029614374L
021135968Y F¾]gGb?U H +J IPIY V W X N¹
M 11/05/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = ÿ?http://
legacy.aolsvc.aol.com/broadband/homenetworking/rtr_setupE 
ABCD
Ø    !  -hp psc 1200 seriesJLPT1:K029614374L
021135968Y F›ngGÙKU H7J IbUY V W X Nº
M 11/12/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = ÿ?http://
legacy.aolsvc.aol.com/broadband/homenetworking/contentpaE 
ABCD
Ø      -hp psc 1200 seriesJLPT1:K 029614374L
021135968Y F\zgG/UU H´?J I*]Y V W X N»
M 11/12/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = / 0 1 5
6 7 8 9 : ; < = / 0 1
5 6 7 8 9 : ; < = / 0
1 5 6 7 8 9 : ; < = /
0 1 5 6 7 8 9 : ; < =
/ 0 1 5 6 7 8 9 : ; <
= / 0 1 5 6 7 8 9 : ;
< = / 0 1 5 6 7 8
9 : ; < = / 0 1 5 6 7
8 9 : ; < = ÿVirusTotal - Free Online
Vi...E 
ABCD
Ø   ,  -hp psc 1200 seriesJLPT1:K029614374L
021135968Y FriGØ—U HŽkJ I |Y V W X NÄ
M 11/12/08 U UA49NGB25DT0O
Pƒ Q R S T / 0 15 6
7 8 9 : ; < = / 0 1 5
6 7 8 9 : ; < = / 0 1
5 6 7 8 9 : ; < = / 0
1 5 6 7 8 9 : ; < = /
0 1 5 6 7 8 9 : ; < =
/ 0 1 5 6 7 8 9 : ; <


<?xml version="1.0" encoding="UTF-8" ?>
- <Usage_Data_Summary>
<Product_Family>hp psc 1200 series</Product_Family>
- <Printer>
<Serial_Number>UA49NGB25DT0</Serial_Number>
<Total_Page_Count>2756</Total_Page_Count>
<K_Dot_Count>23662962</K_Dot_Count>
<C_Dot_Count>5609432</C_Dot_Count>
<M_Dot_Count>4877198</M_Dot_Count>
<Y_Dot_Count>5864480</Y_Dot_Count>
<K2_Dot_Count>0</K2_Dot_Count>
<C2_Dot_Count>0</C2_Dot_Count>
<M2_Dot_Count>0</M2_Dot_Count>
<Total_Drop_Volumn>1798292</Total_Drop_Volumn>
</Printer>
</Usage_Data_Summary>
 
Reply With Quote
 
Richard Urban
Guest
Posts: n/a

 
      17-11-2008, 01:43 PM
Long ago I worked on a fellows computer. I did it as a "favor" without
compensation. The job took me about 7 hours. I gave the computer back to him
and told him if he put anything from AOL on it I would no longer help him
out.

Damned if he didn't call me up about 6 weeks later with a problem. I went to
his home and, sure enough, there was a bunch of AOL crap on the computer
again.

I walked - as I told him I would!

--

Richard Urban
Microsoft MVP
Windows Desktop Experience


"Peter Foldes" <(E-Mail Removed)> wrote in message
news:%23YoXjN%(E-Mail Removed)...
Why do you have a need to crosspost this to 3 different newsgroups

That link takes me and probably others to this page
http://www.hp.com/#Product

What you have is the AOL virus .You are definitely infected with it. To fix
this virus get rid of AOL and use a proper ISP not one that is Proprietary
like the latter and maybe just maybe you will be satisfied and happy after.

I hope this satisfies your ignorance



--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"~BD~" <~BD~@nomail.afraid.com> wrote in message
news:%23%(E-Mail Removed)...
> When looking at a hijackthis log today (not my own) I copied this item:
> http://ie.redirect.hp.com/svs/rdr?TY...io&pf=desktopI
> pasted same into Internet Explorer (IE7) address bar, clicked and I was
> actually taken here:http://www.aol.co.uk/?src=compaq-desktop.aol.comI did
> the same thing with my AOL browser and ended up at the same
> place:http://www.aol.co.uk/?src=compaq-desktop.aol.comThis was to be
> expected, I suppose, as AOL is based on/uses IE AFAICT.I then carried out
> a
> similar exercise with Firefox (3.0.4)and was taken
> here:http://compaq-desktop.aol.com/In all cases the 'final' site was the
> main AOL 'master' Web page. www.aol.com I Find this kind of thing
> intriguing. I'd welcome sme suggestions as to why this might happen.Dave
> (XP
> Home SP3 and updates - AOL is my ISP)
>
>


 
Reply With Quote
 
BoaterDave
Guest
Posts: n/a

 
      17-11-2008, 11:58 PM
On Nov 17, 1:43*pm, "Richard Urban"
<richardurbanREMOVET...@hotmail.com> wrote:
> Long ago I worked on a fellows computer. I did it as a "favor" without
> compensation. The job took me about 7 hours. I gave the computer back to him
> and told him if he put anything from AOL on it I would no longer help him
> out.
>
> Damned if he didn't call me up about 6 weeks later with a problem. I wentto
> his home and, sure enough, there was a bunch of AOL crap on the computer
> again.
>
> I walked - as I told him I would!
>
> --
>
> Richard Urban
> Microsoft MVP
> Windows Desktop Experience
>



Thanks for the tale, Richard :-)

Things can, and do, change (for the better I trust!)

Maybe I'm wrong about this, but my perception is that if one simply
uses the telephone line (duly activated by AOL) for ones Broadband
connection, but NOT the AOL browser etc., no registry changes will (or
can possibly be) made on ones computer. Please let me know if I'm
mistaken about this.

Dave
 
Reply With Quote
 
~BD~
Guest
Posts: n/a

 
      19-11-2008, 01:26 PM

"Andrew Taylor" <(E-Mail Removed)> wrote in message
news:492254dc$(E-Mail Removed)...
>
> "BoaterDave" <(E-Mail Removed)> wrote in message
> news:7d15eb32-3422-4d35-85c2-(E-Mail Removed)...
>
> I take your point Andrew!
>
> The registry changes can only be made though (I think!) if the actual
> AOL programme is installed - in my case AOL9 VR
>
> What Peter Foldes seemed to imply was that AOL(UK) as an Internet
> Service Provider (ISP) is not to be trusted. As far as I am aware, AOL
> is next only to BT (is the second biggest) Broadband supplier in the
> UK. I'm sure 'someone' would have noticed if they were up to no good
> (wouldn't they? <vbg>)
>

<snip>
>
> AOL isn't to be trusted because of the thousands of changes it makes to
> your computer without you being aware.
>



Maybe *you* can comment Andrew.

"Maybe I'm wrong about this, but my perception is that if one simply uses
the telephone line (duly activated by AOL) for ones Broadband connection,
but one does NOT install the AOL browser etc., *NO* registry changes will
(or can possibly) be made to one's computer." Am I correct?

TIA

Dave

--


 
Reply With Quote
 
BoaterDave
Guest
Posts: n/a

 
      21-11-2008, 01:56 PM
On Nov 21, 7:25*am, "Andrew Taylor"
<andrewcrumpleh...@spamcopSUBVERSIVE.com> wrote:
> "~BD~" <~...@nomail.afraid.com> wrote in message
>
> news:%(E-Mail Removed)...
>
> > Maybe *you* can comment Andrew.

>
> > "Maybe I'm wrong about this, but my perception is that if one simply uses
> > the telephone line (duly activated by AOL) for ones Broadband connection,
> > but one does NOT install the AOL browser etc., *NO* registry changes will
> > (or can possibly) be made to one's computer." Am I correct?

>
> At some stage you must have installed AOL V9 from an AOL installation disk?



Not so, Andrew!

Well, to be truthful (as always!) I have, in the past, used an
installation disk provided by AOL to initiate matters (especially in
dial-up days). When I first subscribed to Broadband when it became
available here by the sea (in Devon) AOL sent, by post, a Netgear
router and a special 'set-up' CD which programmed the router as well
as installing the AOL browser. It also doubled-up as an easy route to
set up a home network by inserting it into another computer!

However, right now I am scribing this note on machine with a freshly
installed Windows XP SP3 OS and which has had NO disk from AOL
anywhere near it! Nor have I downloaded AOL 9.0 VR from the Internet
(which is possible and which I've done in the past). So this 'clean'
machine is connected wirelessly to the router which I have set up
manually with Wi-Fi Protected Access™ (WPA). It is thereby connected
to the Internet.

One reason I've stuck with AOL as my *ISP* is because their stated
priority is to strive to provide a 'safe' web environment (don't
laugh!). Maybe, just maybe, their server provides a modicum of
additional protection!

HTH

Dave

--
 
Reply With Quote
 
BoaterDave
Guest
Posts: n/a

 
      22-11-2008, 09:12 AM


"Peter Foldes" wrote:

> Why do you have a need to crosspost this to 3 different newsgroups
>
> That link takes me and probably others to this page http://www.hp.com/#Product
>
> What you have is the AOL virus .You are definitely infected with it. To fix this virus get rid of AOL and use a proper ISP not one that is Proprietary like the latter and maybe just maybe you will be satisfied and happy after.
>
> I hope this satisfies your ignorance


> --
> Peter
>
> Please Reply to Newsgroup for the benefit of others
> Requests for assistance by email can not and will not be acknowledged.



I apologise for my ignorance, Mr Foldes but I still do not understand. I
think that you are, perhaps, 'pulling my leg' as we say in the UK!

So. I'll ask again:

"Imbeady2" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...

> When looking at a hijackthis log today (not my own) I copied this item:
>
> http://ie.redirect.hp.com/svs/rdr?TY...io&pf=desktopI
>
> I then pasted same into Internet Explorer (IE7) address bar, clicked and I
> was actually taken here: http://www.aol.co.uk/?src=compaq-desktop.aol.com
>
> I did the same thing with my AOL browser and ended up at the same place:
> http://www.aol.co.uk/?src=compaq-desktop.aol.com
>
> This was to be expected, I suppose, as AOL is based on/uses IE AFAICT.
>
> I then carried out a similar exercise with Firefox (3.0.4)and was taken
> here: http://compaq-desktop.aol.com/
>
> In all cases the 'final' site was the main AOL 'master' Web page.
> www.aol.com
>
> NOW that same link above takes one to http://www.hp.com/#Product
>
> I find this kind of thing intriguing. I'd welcome some suggestions as to why
> this might happen.
>
> Dave (XP Home SP3 and updates - AOL is my ISP)


--


 
Reply With Quote
 
Peter Foldes
Guest
Posts: n/a

 
      22-11-2008, 09:32 AM

> I did the same thing with my AOL browser and ended up at the same place:
> http://www.aol.co.uk/?src=compaq-desktop.aol.com



Andrew

The above is from one of his posts just a few days ago.So much for BD not having AOL installed.Who knows what to believe


--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"Andrew Taylor" <(E-Mail Removed)> wrote in message news:49266258$(E-Mail Removed)...
>
> "~BD~" <~BD~@nomail.afraid.com> wrote in message
> news:%(E-Mail Removed)...
>>
>> Maybe *you* can comment Andrew.
>>
>> "Maybe I'm wrong about this, but my perception is that if one simply uses
>> the telephone line (duly activated by AOL) for ones Broadband connection,
>> but one does NOT install the AOL browser etc., *NO* registry changes will
>> (or can possibly) be made to one's computer." Am I correct?
>>

> At some stage you must have installed AOL V9 from an AOL installation disk?
>
>

 
Reply With Quote
Reply

Tags
explanation, seeking

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 05:45 AM.