Over 1 million tech questions and answers.

hijacked webbrowser/spyware issues

Q: hijacked webbrowser/spyware issues

I have started getting popups, search engine tool bars insert into my web browser, and my computer has slowed noticably. I saw a similar post by another user and I think I have a similar problem. I ran Hijackthis and removed a few references to "searchportal" (something like that). That took care of the hijacked webbrowser problem but I still have very poor performance. Also I notice that when I use alt + tab to switch between windows sometimes I notice that an icon for Java on the screen (even though I haven't opened Java). Can you help me get rid of whatever is affecting my computer?

Logfile of HijackThis v1.96.1
Scan saved at 10:17:49 PM, on 1/24/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\WINREG.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\PROGRAM FILES\DELL\RESOLUTION ASSISTANT\COMMON\BIN\RXMON9X.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\DAP\DAP.EXE
C:\QUICKENW\QAGENT.EXE
C:\PROGRAM FILES\NORTON UTILITIES\NPROTECT.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\CLEARSEARCH\LOADER.EXE
C:\PROGRAM FILES\MEDIA\MEDIA\UPDATESTATS.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\QCON32U16.EXE
C:\WINDOWS\SYSTEM\MRTMNGR.EXE
C:\WINDOWS\UPTODATE.EXE
C:\PROGRAM FILES\COMMON FILES\UPDATER\WUPDATER.EXE
C:\WINDOWS\SYSTEM32\PGTOOLS\TATSS.EXE
C:\PROGRAM FILES\COMMON FILES\DPI\DPI.EXE
C:\PROGRAM FILES\NETZERO\EXEC.EXE
C:\QUICKENW\QWDLLS.EXE
C:\PROGRAM FILES\HP DESKJET 610C SERIES\EREG\REMIND32.EXE
C:\PROGRAM FILES\NORTON UTILITIES\SYSDOC32.EXE
C:\WINDOWS\SYSTEM\OQXU.EXE
C:\WINDOWS\SYSTEM\WPDCBW.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NETZERO\EXEC.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\MY DOWNLOADS\HIJACKTHIS.EXE

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {2CF0B992-5EEB-4143-99C0-5297EF71F443} - C:\WINDOWS\SYSTEM\STLBDIST.DLL
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
O3 - Toolbar: Search - {2CF0B992-5EEB-4143-99C0-5297EF71F444} - C:\WINDOWS\SYSTEM\STLBDIST.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [RxMon] C:\Program Files\Dell\Resolution Assistant\Common\bin\RxMon9x.exe
O4 - HKLM\..\Run: [MadExe] C:\PROGRAM FILES\DELL\RESOLUTION ASSISTANT\COMMON\BIN\LaunchRA.exe -boot
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [QAGENT] C:\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [SystemReg] C:\WINDOWS\WINREG.EXE run
O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [ClrSchLoader] \Program Files\ClearSearch\Loader.exe
O4 - HKLM\..\Run: [UpdateStats] C:\Program Files\Media\Media\UpdateStats.exe
O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe C:\WINDOWS\SYSTEM\STLBDIST.DLL,DllRunMain
O4 - HKLM\..\Run: [qcon32u16.exe] C:\WINDOWS\SYSTEM\qcon32u16.exe
O4 - HKLM\..\Run: [RunWindowsUpdate] C:\WINDOWS\UPTODATE.EXE
O4 - HKLM\..\Run: [5QEKE7T5NG9WG2] C:\WINDOWS\SYSTEM\BIN9.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [Tat] C:\WINDOWS\system32\pgtools\tatss.exe
O4 - HKLM\..\Run: [Dpi] C:\PROGRAM FILES\COMMON FILES\DPI\DPI.EXE
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [SystemReg] C:\WINDOWS\WINREG.EXE run
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKCU\..\Run: [uoltray] C:\PROGRAM FILES\NETZERO\EXEC.EXE regrun
O4 - HKCU\..\Run: [qcon32u16.exe] C:\WINDOWS\SYSTEM\qcon32u16.exe
O4 - Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O4 - Startup: Resolution Assistant.lnk = C:\Program Files\Dell\Resolution Assistant\MotiveAssistant\bin\matcli.exe
O4 - Startup: Reminder-hpc41003.lnk = C:\Program Files\HP DeskJet 610C Series\ereg\Remind32.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O4 - Startup: America Online 5.0 Tray Icon.lnk = C:\America Online 5.0\aoltray.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.25.43/09bfed078eb5f29d7505/netzip/RdxIE.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://photos.msn.com/r/neutral/controls/MsnPUpld.cab?5,0,1730,0
O16 - DPF: {0DD4833D-DFFA-11D3-94D7-0050DAC353B6} (DndCtrl Class) - http://www.ofoto.com/OfotoDND.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://lw9fd.law9.hotmail.msn.com/activex/HMAtchmt.ocx

RELEVANCY SCORE 200
Preferred Solution: hijacked webbrowser/spyware issues

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

A: hijacked webbrowser/spyware issues

Read other 11 answers
RELEVANCY SCORE 64.8

Good morning,

My internet explorer has been hijacked and all pages I try to visit result in a page not able to be displayed. I have my hijackthis log and definitely see a lot of bad things in it but I would like some expert advice on what I should fix. Here is my log - I appreciate any help you can provide. Thank you.

Logfile of HijackThis v1.96.1
Scan saved at 9:19:47 AM, on 8/30/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Fi... Read more

Read other answers
RELEVANCY SCORE 64.8

hen using Firefox or IE, clicking on search results from Google redirects to Btcar.com sometimes to other search engines also.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:27:12 PM, on 10/2/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.20544)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\McAfee\MSC\mcmscsvc.exec:\program files\common files\mcafee\mna\mcnasvc.exec:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exeC:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exeC:\Program Files\McAfee\MPF\MPFSrv.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\UAService7.exeC:\WINDOWS\system32\svchost.exeC:\PROGRA~1\McAfee.com\Agent\mcagent.exeC:\WI... Read more

A:Webbrowser Hijacked

Hi,* Please download FixwareOut from the following site:http://download.bleepingcomputer.com/lonny/Fixwareout.exeSave it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log.

Read other 7 answers
RELEVANCY SCORE 64.8

I have a computer that is infected. I have ran spybot s&d, combofix, and malwarebytes on it to no avail. When I try to do a type anything into the webaddress it takes me to uniquesearch8. I have a hijack this logfile. Please let me know if you would like me to post it. ThanksHere is the Hijack this logLogfile of Trend Micro HijackThis v2.0.2Scan saved at 10:46:22 AM, on 12/7/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16915)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exec:\program files\common files\protexis\license service\psiservice_2.exeC:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exeC:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Analog Devices\Core\smax4pnp.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exeC:\Program Files\Windows Live\Messenger\msnmsgr.... Read more

A:Hijacked webbrowser

I have corrected this problem and removed the virus im pretty sure. However now my print spooler stops responding. I have it set to restart. It appears the virus corrupt a file in relationship to my print spooler any help would be greatly appreciated. I ran a chkdsk/f but that did not fix it. thanks

Read other 3 answers
RELEVANCY SCORE 64.8

Hi, I hope someone can help me.

I have Norton Internet Security 2003, and use As-aware on a regular basis.

Now my browser start page has been changed to: http://topotun.com/index.htm and together with that I get a bunch of unwanted bookmarks to pornsites and a few spyware commercial pop-ups.

I have used Hijack this and get the following log (I use hijack this from a folder in my documents, not on the desktop) :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://topotun.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {2B284CB0-9E5E-4627-A4BE-FECBD5BF9F5B} - C:\WINDOWS\System32\necodd.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ... Read more

A:Hijacked webbrowser (yes, me too)

Read other 13 answers
RELEVANCY SCORE 64

Hello, recently my web browser. On google whenever I search for something I click the link and it would take me to a website called daytotals.com, I close that and try the link again and it would take me to another website. This has been happening for the past week or 2 and I have gotten quite sick of this.
I've tried spyware searches, malware, anti-virus scans and everything. They haven't found anything, even if they do it doesn't fix up my problem.


Quote:




Deckard's System Scanner v20071014.68
Run by JayJay Ciantar on 2008-01-05 21:39:41
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
31: 2008-01-04 23:08:05 UTC - RP68 - Installed Ad-Aware 2007
30: 2008-01-04 22:46:59 UTC - RP67 - Removed AdwareAlert
29: 2008-01-04 22:43:10 UTC - RP66 - Installed AdwareAlert
28: 2008-01-04 22:18:09 UTC - RP65 - Device Driver Package Install: Lexmark Inkjet Drivers Printers
27: 2008-01-04 22:16:18 UTC - RP64 - Device Driver Package Install: Lexmark Imaging devices


-- First Restore Point --
1: 2007-12-22 12:14:26 UTC - RP34 - Windows Update


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as JayJay Ciantar.exe) --------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro Hijac... Read more

A:My webbrowser has been Hijacked by daytotals! :(

Hi, sorry for the delay.

If you still need assistance, please post a fresh main.txt log

Read other 1 answers
RELEVANCY SCORE 63.2

please help, please tell me how to identify and remove the adaware that hijacked my webbrowser.i am not able to identify the hijacker of my browser. at first it seemed to be websearch but then at second glance it does not appear to be websearch.below you can see the hijack log.the problem appears to be: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web--search.comit sets my homepage to www.web--search.com, but in practice i am being directed to www.msn.com. I have tried several adaware removal programs (adware 6.0, scan spyware, BPS spyware adaware remover), but all don't seem to work.i have also tried the suggestions from http://www.boredguru.com/modules/articles/...php?storyid=130, but since it does not appear to be websearch.com, they are of no use.I have also attached a pic of my screen with the search bar. You can see that it is not the same as the one of www.websearch.com.Logfile of HijackThis v1.99.0Scan saved at 22:22:23, on 2005-1-4Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32 ... Read more

A:webbrowser hijacked by unidentifiable hijacker

Adaware 6.0 is an old version and no longer supported. Please download and install Adaware SE 1.05 from here.http://www.lavasoftusa.com/software/adaware/Install the program and launch it.First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files. Exit Adaware.Please make sure that you can view all hidden files. Instructions on how to do this can be found here:How to see hidden files in WindowsRun Hijackthis again, click scan, and Put a checkmark next to each of these. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web--search.comR3 - URLSearchHook: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\webdlg32.dllO2 - BHO: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\webdlg32.dllO2 - BHO: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)O3 - Toolbar: Search Bar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\webdlg32.dllO11 - Options group: [!IESearch] !IESearchO16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Download...bridge-c284.cabO16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -O18 - Protocol: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)Reboot your computer into Safe ModeR... Read more

Read other 1 answers
RELEVANCY SCORE 61.2

The usually innocuous ads on my browser get replaced with very explicit ones. I downloaded several free malware search programs but I can't run them because they all fail to update when I first start them. If I try to paste the update url's into a webbrowser then I find that access is blocked.
Sounds like a very cunning piece of malware if it truly prevents me from downloading something to attack it with. I also noticed that when connecting to other sites I often see a 'resolving proxy' message before it eventually connects. Sounds like I have been hijacked. I have attached my dds file.

Thanks in advance for looking in to this.

A:webbrowser ads are hijacked and access blocked to malware repair sites

I was finally able to update Malwarebytes with the latest updates by connecting my laptop to my company's network whose firewall somehow foils `the virus blocking my access to update sites. Once I downloaded the updates and did a scan the virus was removed. See attached scan log

Read other 3 answers
RELEVANCY SCORE 47.6

A couple days ago I found myself infected with spyware and trojans. My virus scanner started blocking repeated trojan attacks, and I found that my Firefox browser was messed up. I could not run searches on google, access my gmail account, or go onto youtube. Things that I could do in IE or if I ran my computer in safe mode w/ networking. I ran adaware personal and removed one trojan, but still my browser was messed up and not allowing me to view certain sites and overall acting really slow. I downloaded the HijackThis program and resolved to get a log and see if I could spot anything, and perhaps upload it to one of the many forums that offer help. I ran the scan and noticed that I could upload the log to trendmicro, I tried that and the entire program shut down with an error. I hit the "more info" button, and saw a specific dll in my windows/system32 directory looked to have interfered with it. It was an "awtqnkhe.dll." I went into safe mode to try and delete it as that has worked in the past, and I had no luck removing it. I ran the combofix program, but that seems to have helped little if at allToday, I started to work on the problem again and its only worsened. I get frequent error messages especially when browsing something like "My Computer." They'll say that there are problems with a rundll32.exe and needs to be shut down, among other myriad of messages. At times I'll get a buffer overflow which forces explorer to shut down. When shutting ... Read more

A:Trojan & Spyware, Hijacked Browser, Intefering With Spyware Removal Programs (awtqnkhe.dll)

Hello jwbowyer,

Welcome to Bleeping Computer

Sorry about the delay. If you still need help, please post a new HijackThis log to make sure nothing has changed, and I'll be happy to look at it for you.

Thanks,
tea

Read other 2 answers
RELEVANCY SCORE 46.8

Okay, About three months ago, I got hacked HARD...permissions were changed, administrator rights were removed from my administrator accounts, etc. i was flabbergasted. THe iactually didn't bother me though until I ran a MBAM scan and found 133 viruses and spyware instances on my drive (NOT including tracking cookies!). I cleaned and recleaned, using MBAM, SuperantiSpyware, Avira, running each one in safe mode first, then loading into my normal account and running them, and finally erasing my user account and creating a new one. But even after the new user account was created with Administrator privileges, I still routinely received virus and Malware threat warnign flags from MBAM and Avira. Eventually, Avira and MBAM were disabled and Avira was "deleted" (Windows will not uninstall because the setup.exe file has been 'Changed" and won't reinstall it because I don't have "Administrator privileges" on my Administrator accounts!) even though at startup I receive an error message saying that Avira has been corrupted. The most telling issue is that antivirus and spyware/Malware scans come up clean on Safe mode scans, but using my normal account, the machine reboots. Using Superantispyware I notice that it's always during the memory test that this occurs (and in Safe Mode, it passes through this section with no issue). None of my antivirus programs will download updates, even ones I start manually, and although I have no problem acc... Read more

A:Machine reboots during Spyware scan...won't load updates. Issues issues issues!

bump
 

Read other 3 answers
RELEVANCY SCORE 45.6

I try to run Housecall 6.5 & Kacpersky scans and my computer is slowed to a crawl about 5 seconds after the scan starts. I have downloaded Threatfire and scanned my computer, and downloaded Malwarebytes - Anti-Malware and scanned, the problem is not fixed. I have a svc.host in my Task-Manager that is alway using between 2 & 5% of my CPU, but in reallity seems to be freezing my computer.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:27:55 PM, on 2/8/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0013)Boot mode: Safe mode with network supportRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\svchost.exeD:\Programme\HijackThis.exeK:\Programs\Safari\Safari.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://at7.hpwis.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://at7.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = ... Read more

A:Internet hijacked when running spyware/malware removal programs, internet also hijacked intermittently when CPU not in use

Hello texasrocker,Can you run in Normal Mode at all? If so, please post further HijackThis logs made in Normal Mode. HijackThis can't see everything when run in Safe Mode.Please run HijackThis! and click "Scan." Place checks next to the following entries, if present:R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blankR3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: (no name) - {072CA835-0624-47B2-83D6-A7A5CD5C22DA} - (no file)O2 - BHO: (no name) - {353B8BD5-5CF2-4036-83AF-48F67CBE369C} - (no file)O2 - BHO: (no name) - {3AB032E2-DD70-4071-91E2-303A1798B817} - (no file)O2 - BHO: (no name) - {4c4c1a5a-e630-47af-b1c4-186a9586d1c3} - (no file)O2 - BHO: (no name) - {5B1CB136-01BF-4EDC-99AB-0F10A8AC847C} - (no file)O2 - BHO: (no name) - {6A1DDB8F-98EB-464D-BA0B-BA9584A1DF28} - (no file)O2 - BHO: (no name) - {9C35323A-05D9-42BF-8BE4-6DDB4AAE02B2} - C:\WINDOWS\system32\mlJdDVOf.dll (file missing)O2 - BHO: (no name) - {C31DEA2A-708E-40D8-8F59-9996C03D8CFB} - (no file)O2 - BHO: (no name) - {D181EE8E-AF1F-4237-AFDC-BA1092CB449D} - (no file)O2 - BHO: (no name) - {DF1BF564-5FB0-4B60-A3BA-493F1D0D5EA7} - (no file)O2 - BHO: (no name) - {DFE33175-4231-4E50-8595-945F248E5142} - C:\Dokumente und Einstellungen\Craig Milam\Lokale Einstellungen\Temporary Internet Files\Content.IE5&... Read more

Read other 4 answers
RELEVANCY SCORE 44

Hello, I've got an icon on my toolbar that continuously flickers between a red crossbar circle (think Ghostbusters logo w/o the ghost) and a white, circled question mark. Every 2 minutes or so, an info balloon will pop-up from there and give a warning stating "System has detected a number of spyware/adware on your computer, click here to download a solution". When you click the link, it takes you to spylocked.com, which is a site advertising a product called Spylocked, a supposed spyware remover. Even when I attempt to right click the icon, it links to the site, and there's no manual way to get rid of it, even choosing which toolbar icons show up and which to stay hidden. It just stays there, frequently popping up.
I've followed the 5 step instructions, and here are my DSS reports, as well as my Panda Activescan report:
++++++++++++++++
MAIN TXT DSS:
Deckard's System Scanner v20070328.36
Run by Chris on 2007-04-10 at 20:59:06
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
29: 2007-04-11 00:59:15 UTC - RP134 - Deckard's System Scanner Restore Point
28: 2007-04-10 00:22:01 UTC - RP133 - System Checkpoint
27: 2007-04-04 19:53:32 UTC - RP132 - Software Distribution Service 2.0
26: 2007-03-29 03:33:36 UTC - RP131 - Re... Read more

A:Unable to delete toolbar icon with link to false spyware remover/spyware issues

Hello and welcome to TSF

I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem a.s.a.p

Please be patient with me during this time.

You may wish to subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Read other 14 answers
RELEVANCY SCORE 43.2

Hey all. I'm currently using IE 6 and wanted to try out some other browsers since I heard IE has a bunch of security holes, slower, etc. What I wanted to know is, which browser do you like the best? I'm thinking about buying Opera 7 but I don't know yet. And I don't mind buying. Well, I gotta sleep and I'll check this tomorrow. Thanks in Advance.
 

A:Which WebBrowser?

Read other 10 answers
RELEVANCY SCORE 42.8

Hi!!

I need some help in clearing this hijack that have been affecting my web browser and setting to some weird page everytime I on Internet explorer.

Below is the logfile created using Hijackthis. I am posting the whole logfile for a complete view on my system, however I have narrowed the problem to these 2 processes:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lastchaos.in.th/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by MOOzilla

I have tried deleting these 2 files but it will reoccurred once I on IE again, is there a way to remove them completely??

Thanks in advance for the help!!

The logfile is attached as below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:29:21 AM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\RTProxy.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
... Read more

Read other answers
RELEVANCY SCORE 42.8

I sometimes get an "error message" when attempting to access various websites.

The message is:

"SHdocVwCtl.WebBrowser" "Make sure the path or internet address is correct"

Does this need to be "fixed" and of so how?

Sam
 

A:SHdocVwctl.WebBrowser

I searched Google to find a cure for you but there is not much mentioned There is a reference to vb Accellerator Would this apply ?
 

Read other 1 answers
RELEVANCY SCORE 42.8

I use the following Code to find string in A HTMl in WebBrowser control, but
if HTML support Frame then I get the error (run-time error "438"). any idea
how to fix this error.
Thanks,
Harry
Code:

Public myfindFirst As Boolean
Public oRange

Private Sub cmdFind_Click()
Dim sSearch As String
If myfindFirst Then
Set oRange = WebBrowser1.Document.body.createTextRange
sSearch = txtFind.Text
If oRange.FindText(sSearch) Then
oRange.Select
oRange.scrollIntoView
cmdFind.Caption = "Find Next"

myfindFirst = False
Else
MsgBox ("Search string " & txtFind.Text & " not found.")
End If
Else
Call oRange.Move("character")
sSearch = txtFind.Text
If oRange.FindText(sSearch) Then
oRange.Select
oRange.scrollIntoView
Else
MsgBox ("Finished searching Document for string " &
txtFind.Text)
cmdFind.Caption = "Find"
myfindFirst = True
Exit Sub
End If
End If

End Sub

 

A:vb6 WebBrowser control

Read other 7 answers
RELEVANCY SCORE 42.8

some one please tell me how to get my
Shdocvwctl.webbrowser working again i can not for the life of me
figure it out
it pops up on me all the time saying its not working or something
what do i do
 

Read other answers
RELEVANCY SCORE 42.8

When I get to some sites I get this error message "Unable to locate 'SHDocVwCtl.WebBrowser' make sure the internet path is correct"
I cannot find the answer to this, does anyone know the problem and/or how to solve it? Thanks
 

A:SHDocVxCtl.WEbBrowser

If you use the "search" feature of this forum you will find this question has been asked before. I went to Google and typed in "SHDocVwCH" without the quote marks and I found where this happens if you are using a browser other than IE. If you use IE to access the site you are looking for it should work just fine. Are you using AOL or Netscape?
 

Read other 3 answers
RELEVANCY SCORE 42.8

This webhijacker was caused from a megaupload toolbar that I downloaded a month back. I uninstalled it because It was causing problems such as pop ups and redirects. Now every time I try and go to a web page it redirects me to http://www.megaclick.com/404. Help is appreciated. Here is my hijackthis log if it helps.

(Windows XP Home)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:42 PM, on 12/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOW... Read more

A:WebBrowser Hijack

Read other 7 answers
RELEVANCY SCORE 42.8

Hi Everyone

I am trying to fix a friend's computer. He had 4 trojans on his pc that he found in January and didn't tell anyone. He is running OS: xp pro 1a.......RAM: 512......cant remember the information about his hard drive except it's an AMD.

The error message he is getting is this:

"cannot open web browser, error message "Downloading from site:res//C\WINDOWS\System32\shdolc.dll/offcancl.htm"

I have tried system restore, it will dont work for him, also tried a reinstall of windows, still no go. I tried to run hijack but it will not read from his floppy disk. I will try to save hijack to a cdrom and run it when I go there on Tuesday.

I would appreciate any suggestions that you can give me. You guys are always so helpful. Thank you.

Susi
 

A:Webbrowser Won't Load

Install avast home edition on your friends pc from a cd rom or jump drive and then run avast antivirus. Get rid of the Trojans then go to firefox and get rid of his IE or Netscape.

This worked for me, but someone else may have a better idea.
www.avast.com

www.firefox.com
 

Read other 3 answers
RELEVANCY SCORE 42.8

I have several browsers loaded into my system, the most compatable one to use with my computer is the internet explorer. There is a problem of a pornographic add informing me that I have been infected and prompting me to buy their spyware equipment, this happens each time I try to use this home site page. I have spyware protection, spyware bot, and AOL McA.,and sweep the system upon each internet return. This page still remains. I need access to run certain files that are a part of my main system, It's not the best, just needed. I keep this site blocked by default, to keep my family from prompting this site and encountering porn related strong-armed sales tatics. Does anyone have any suggestions?
 

A:webbrowser adware

Read other 7 answers
RELEVANCY SCORE 42.8

When i got to some sites i get this error message "Unable to locate 'SHDocVwCtl.WebBrowser' make shure the internet path was typed in correct" something like that and i dont know how to get rid of it help would be apriciated.
 

A:'SHDocVwCtl.WebBrowser'

I have the same problem whats the fix ??
 

Read other 1 answers
RELEVANCY SCORE 42.8

Hey, I am having trouble with some ad-ware and I can't for the life of me figure out what exactly it is or how to get rid of it.

Basically, I get this progam called NULL WebBrowser open (can be seen in attachment) and about 10 minutes later, it floods my screen with popups from adultfriendfinder. I'll close all of them including this "NULL" program, however, it will reappear in some time.

I've run Lavasoft ad-aware, Spybot and the online Trend-Micro scanner - nothing has removed this. Searching on google, I cannot seem to find information about it. Any help?

Thanks in advance
 

A:NULL WebBrowser

Still having the problem...any advice?
 

Read other 1 answers
RELEVANCY SCORE 42.8

Hello

I'm running:
a)Vista 64BIT and UAC is turned off with IE8 and
b)Win XP 32 bit with IE 6

Under b) I can display a specific webpage (which includes som JS and Ajax) without any problems
Under a) I can't display the page

Are there any known security issues? Do I enable some security settings within Vista or IE8?

Thanks!

A:Webbrowser- Changes between Vista and XP

IE8 is still buggy, i would recommend that you use IE7. However, what page won't it load? What security software is installed?

Read other 4 answers
RELEVANCY SCORE 42.4

First of all, let me preface this that I am not a computer expert so I really need someone to kind of slowly lead me thru this. My computer runs well for a while with no issues... if I leave and come back (especially after a few hours), it slows down...Also recently, when I restart the computer to get it back to normal, it seems like it takes forever for Windows to start up.... sometimes after several attempts and the black screen with the options about restarting Windows in Safe Mode and Windows Did Not Start Successfully.... Here is my HiJackThis log....Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:22:27 AM, on 11/17/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\LEXPPS.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\fxssvc.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.e... Read more

A:Spyware Issues/slow Computer/windows Issues

Hi Chillin662!

I will be handling your log to help you get cleaned up. Please give me some time to look it over and I will get back to you as soon as possible. I'm in Hijackthis school and Teachers will check my posts.
Sorry that it took us so long to get back to you, but as you can see we're stumped withthe amout of logs.

Before we can start, please post a fresh hijackthis log back here.

Read other 6 answers
RELEVANCY SCORE 42

I used to have aol as my ISP and I cancel and uninstall all the aol there was in my computer, but my web browser in the internet explorer still showing aol instead of windows any ideas of why this is happening if there is nothing else to ramove in add/remove programs. Can somebody please help is it hidden somewhere else.
Thank you very much in advance.
 

A:Need Help Removing AOL as my webbrowser - And NewDotNet

Read other 16 answers
RELEVANCY SCORE 42

Hi,
I have a very strange error, if you can call it that. It's mostly occurring at random AFAIK, but when it happens it keeps going for quite a while.

The problem is; when I click a link anywhere, the browser(firefox in my case) might decide to not load it. There's no error page, the spinning thingy doesn't even spinn. And it won't load unless I click the correct amount of times(usually more than 2). Too many and it resets the counter.

As this is a laptop, I've moved between school and home, this occurs at both places so I narrowed the search down to my computer.

Posting HJT log, incase you can find anything here.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:00:38, on 2008-05-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\BlackBox\blackbox.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.ex... Read more

Read other answers
RELEVANCY SCORE 42

Hey guys,
I'm looking for a very lightweight browser that has minimal system impact while gaming + streaming.

I'm streaming a 720p/45fps stream and game performance is nice so long as I do not have my addon-heavy Firefox browser open. I suspect it's the annoying flash that has the severe system resource penalties.

I need those addons on that browser to be productive so I'll need either a Firefox lite mode which can be launched with the click of button (without hassle), or a completely different browser that supports Flash.

I only need that browser to watch the quality of my stream, and to chat with my viewers + browsing lulz pages during my downtime (1+5~tabs=).
Or can I bypass this in another way?
I currently have process priority manager where I have set flash and plugin container to 'low' priority. But this doesn't really help for that particular issue.

Flash is not generally slowing the system down from get-go, but after several minutes; while having my own stream feedback open and playing: the system slows down.
Soon as I close my browser, performance is back up.

W7 x64
GTX670M, i7 3610, Browser & Game on SSD (128gb - 90%)

edit, add:
Oh, and I'm looking for qualified experience opinions in general.

A:Lightweight webbrowser with flash

Perhaps try SlimBoat portable:

Best Web Browser for Mac, Linux and Windows. Fastest Cross-platform Internet Browser.

Configuration can be a little confusing!

Opera Portable 64bit vs Cyberfox 64bit vs SlimBoat Portable 32bit
Memory usage - all of the above with one tab open. Opera and SlimBoat both run from folders on desktop

Memory usage - Cyberfox (installed) one tab open, Opera (run from desktop) one tab open,
SlimBoat (run from folder on RAMdisk) five tabs open.

Start using flash and Memory usage roughly doubles.

Read other 8 answers
RELEVANCY SCORE 42

Hello all,

I was recently victim to the VIRUS PROTECT scam. Thanks to the posts herein, I believe I successfully removed most of the malware. However, I still have a persistent and sporadic bug that redirects my web search links to a rogue url. Here is an example of an attempt to link to search result from "cod liver oil" :

(http://alfasort.com/search.php?q=cod%20liver%20oil )

The alfasort string is the ubiquitous prefix. I am using Microsoft's Internet Explorer. I am running Kaspersky Internet Security suite.

Can anyone here graciously offer some direction on how to eliminate this annoyance?

Thank you.

WPM

A:Webbrowser High-jack

Hello MtnGntx, welcome to the forum.Need to know exactly what you did ... so Did you do/run these? How to remove VirusProtect or Virus Protect (Removal Instructions)Next, please download RogueRemover and save to you Desktop. (compatible with Windows 2000, NT, XP, Vista)Double-click on rr-free-setup.exe to install in C:\Program Files\RogueRemover and follow the prompts.During installation an icon will automatically be created on your Desktop.If the program does not open after installation, double-click on the RogueRemover icon to launch.Select "Check for Updates" and click Download if any are found.Wait for the updates to finish downloading, then Close the update window.Select "Scan" and follow the onscreen directions to remove anything found.If nothing is found, exit RogueRemover.If RogueRemover finds something, it will present a list of detected items.Click "Remove selected", then Yes at the prompt.Wait for the removal to complete and then close RogueRemover.If using Windows Vista, be sure to Run As Administrator Download and scan with SUPERAntiSpyware, Free for Home UsersDouble-click SUPERAntiSpyware.exe and use the default settings for installation.An icon will be created on your desktop. Double-click that icon to launch the program.If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from HERE... Read more

Read other 6 answers
RELEVANCY SCORE 42

Im using C# under Visual Studio .NET 2003 for Windows 2000. Im trying to use the MS WebBrowser control on my form but without much luck. Documentation is sh*t.

Im connecting to a URL which is in frames (frame one's name="one", frame two's name="two"). I need to access the first frame's HTML contents, in particular, the <form name="myForm"> area which has the element <input name="ConnectID" type=text>. I would like to alter the "ConnectID" value as well as programmtically click the form's SUBMIT button.

How do I do all of this with the WebBrowser control, or the IHTML interface.

Thanks.
 

Read other answers
RELEVANCY SCORE 42

An error appears that contains something in regard to 'SHDocVwCtl.WebBrowser error loading'. When we click on OK, the entire system just locks up on us. What can we do to fix tis error?
 

A:SHDocVwCtl.WebBrowser error

im stumped- try running windows update maybe?
 

Read other 1 answers
RELEVANCY SCORE 42

I keep getting directed to thewebtimesnet, id happily kill the person who created it as its a right bugger, i had tried removing this which did cause a few problems, all of which seem to have been sorted now, . net framework removed somethign some how butits stillcontinueing tore direct me.

i read the instructions and hope i have followed them to an understandable level, your help is very kind.

Sorry if i have done this in correctly but im pretty sure its how you had wanted.

Thankyou very much for the help.

ftj

dds.txt :
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\... Read more

A:Webbrowser redirector thewebtimesnet

Hello and welcome. Please follow these guidelines while we work on your PC:Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
Please do not run any scans or install/uninstall any applications without being directed to do so.
Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

P2P - I see you have P2P software (BitTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Please see this post for more information. I recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at TSF are complete.

Download TDSSKiller.zip and extract TDSSKiller.exe to your desktopExecute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found then ensure Cure is selected. ... Read more

Read other 16 answers
RELEVANCY SCORE 42

Whenever i go to apple.com and try to watch something in my browser using quicktime it crashes, looked in the log and found this in the description.Felaktigt program iexplore.exe, version 6.0.2900.2180, felaktig modul quicktimeh264.qtx, version 7.2.0.240, felaktig adress 0x00054c8a.It's in Swedish but i hope that doesn't matter. Does anyone know whats happening, i have googled it but didn't find mutch and i have reinstalled both graphics drivers and quicktime.Please give advice Edit: Moved topic to the more appropriate forum. ~ Animal

Read other answers
RELEVANCY SCORE 42

My browser was defaulting to msap and I can't open any applications without getting an unkown error. Any suggestions? Here is my log.......

Thanks in advance.

Logfile of HijackThis v1.99.0
Scan saved at 1:33:32 AM, on 12/20/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP1 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINNT\System32\svchost.exe
C:\em\opt\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\Promon.exe
C:\em\opt\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINNT\System32\msrexe.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\Program Files\America Online 7.0\waol.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Administrator\D... Read more

A:error with desktop and webbrowser need help

Read other 16 answers
RELEVANCY SCORE 41.6

Please can someone help me. I have been hijacked by someone or something.
My home site used to be dslstart.verizon.net.

Now whenever I click on Internet Explorer I go to http://gotosearch.org/404/index.php?aid=218.

I can get to other places like Yahoo, but within a couple of clicks, I am back at gotosearch. It is driving me insane. I had a misierable time just registering on your website because of the hijack. I had an equally miserable time tring to submit this question.
My PC is Windows M/E.
My internet explorer version is 6.0.2600.0000IS.
Can someone help me to remove this so that I can enjoy the internet again?

Thanks,
Ray Minchillo
 

A:Hijacked by Spyware

Read other 10 answers
RELEVANCY SCORE 41.6

Hi all,
I'm back and infected again.... This time the infection seems to be in ms office. Even as I type this topic my cursor disapears after every word typed. I have to click the cursor back onto the page type a word or two and it disapears again. This also happens in excel. It says Excel Alert - Your table possibly corepted. Start scan for harmful malware. The name is Best SecureExpertCleaner. I've Run MalwareBytes Anti-malware until it found no malware. Ran SuperAntiSpyware until nothing was found. Any Help would be apreciated.

A:Hijacked By Spyware

Follow the instruction to run SmitfraudFix given here.

Read other 3 answers
RELEVANCY SCORE 41.6

Hi,

This is the second time I'm writing this since my computer just up and restarted itself a second ago. Anyways, Norton tells me that I have Adware.SAHAgent but I can't find the files to delete them or the registry keys they tell me about on Symantec's so called help page. Spybot found a bunch of junk but not all of it will delete. At first no matter what it found, it looked like it was redirecting the host to 69.20.16.183 but as soon as I got online it started downloading a bunch of other mess.

So that I can get this posted before anything else adds itself, here's my HJT log run through the HJTAnalyzer. Could you help me clean up my mess, please? Last time I had a problem you helped me so much.

Thanks, spartan



Log was analyzed using HijackThis Analyzer - Updated on 1/3/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
O3 - Toolbar: Norton AntiVirus - {42... Read more

A:Hijacked by spyware

We will need other logs from you also after this fix. So fix first and then restart. Post all the logs together (see below).

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that Display the contents of System Folders' is checked. Windows XP's search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that Search system folders, Search hidden files and folders, and Search subfolders are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that ... Read more

Read other 19 answers
RELEVANCY SCORE 41.6

Just downloaded Hijackthis and found plenty of bad stuff. Have about 5 people surf the web from my computer (stupid roomates) and always find crap. So here is my log. I hope you can help me out.

Logfile of HijackThis v1.96.0
Scan saved at 5:15:02 PM, on 8/10/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON UTILITIES\NPROTECT.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ISTSVC\ISTSVC.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\MSREXE.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\WINDOWS MEDIA COMPONENTS\TOOLS\REXPROXY.EXE
C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\DISTILLR\ACROTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.jetseeker.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.jetseeker.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jetseeker.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page... Read more

A:Hijacked by spyware

Read other 8 answers
RELEVANCY SCORE 41.6

I've been hijacked by malicious files and spyware that is constantly reoccuring when I do scans and all that. It has disabled the abillity of me being able to put up a desktop background. If someone can help me please let me know. I'm posting a HJT log file here in this thread. Thank you.

Logfile of HijackThis v1.99.1
Scan saved at 5:08:35 PM, on 5/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\shnlog.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\System32\msvcmm32.exe
C:\bsw.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MOVIEL~1\MOVIEL~1\MOVIEL~1.EXE
C:\WINDOWS\System32\intmon.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\S... Read more

A:Hijacked by spyware, need help!!

Read other 7 answers
RELEVANCY SCORE 41.6

Hello,
I have an application which embed IE Webbrowser to display a Rich text editor based on CKEditor (which web based editor). But, on my computer it does not work because the policy security_HKLM_only is set to 1.
I've tried to reproduce on machine which I have administrator rights, when I set the key to 1, the editor does not work anymore and when I set the value to 0, it works fine.
I displayed the user agent of webbrowser by adding to my page this script: alert(navigator.userAgent);
The output:
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET 4.0C; .NET4.0E)

And the script: alert(document.documentMode); has the following output: 5.
I tried also to set my process in HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION to 0x2AF9 (IE11) but it does not work.

When I test on IE (not embedded  browser) it works fine.
Do you have any idea why the behavior is different between the IE and embedded webbrowser? and if there are some ways to bypass this behavior?

Thank you.
Regards

Read other answers
RELEVANCY SCORE 41.6

Hi Everyone!I have obtained this Elitebook 8560W and itīs running Windows 10 Pro 64-bit. The laptop has dedicated quickkeys on the top right corner. I want to change the "internet" key to open Chrome instead of Edge /IE. I have changed the default app in the Windows setting to Chrome. This did not do anything to the key. I have removed both Edge and IE from windows and the key is now unresponsive. How can I modify this to open Chrome? Can anyone help me with this? //Chri11e

Read other answers
RELEVANCY SCORE 41.6

Application REQUIRES persistent cookies to be set, however cookies has to be deleted when application terminates
One way is to delete IE cookies itself 
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 2 
Is there any API to delete cookies only with respect to specific WebBrowser Control process
If the only option is to delete IE cookies itself,is there a way to do it silently without getting IE clearing cookies dialog

Read other answers
RELEVANCY SCORE 41.6

I'm having problems checking my email. I go onto hotmail, and when I look at my inbox, my entire webbrowser closes out. What's up with that?

The only thing I did prior to that happening, is I was creating a rule for my Outlook box to delete messages with certain texts in the subject heading. But Outlook, on my computer, does not even connect to my hotmail account.

I doubt that's what caused it, but now I can't check my email with my computer.
 

Read other answers
RELEVANCY SCORE 41.6

I'm posting here on recommendation of the support engineer I've been in contact with at
[link removed]
Developer Community Visual studio. I am unable to post links with my account to it. it has an id of 642834
On some computers I can with a very simple .net application cause a silent crash of the whole application by attempting to print using the WebBrowser component. On those computers I get the same behaviour when attempting to print using Internet Explorer.
In a simple application where I've dragged out a button and a WebBrowser in the Visual Studio designer I add the following in the code behind

public partial class Form1 : Form
{
public Form1()
{
InitializeComponent();
webBrowser1.Navigate("www.google.com");
}

private void Button1_Click(object sender, EventArgs e)
{
webBrowser1.ShowPrintDialog();
}
}

with the button click event being bound to Button1_Click of course.
This causes a crash. Looking in the Event Viewer I see the following message at the same time of the crash.

Faulting application name: WindowsFormsApp1.exe, version: 1.0.0.0, time stamp: 0xaf8b1ae6
Faulting module name: MSHTML.dll, version: 11.0.17134.829, time stamp: 0x8429479d
Exception code: 0x4000001f
Fault offset: 0x00d65391
Faulting process id: 0x4c98
Faulting application start time: 0x01d5388ff4e51d42
Faulting application path: C:\Users\perhyy\source\repos\WindowsFormsApp4\WindowsFormsApp1\bin\Debug\Windows... Read more

Read other answers
RELEVANCY SCORE 41.6

Hey any one got any ideas, when i start up my pc and try to open up my web browser weather its firefox or internet explorer it taking about 5 minutes or so but then when its open it works grand.

I've defraged the registery
defraged the hd
got rid of anything on my startup that does not need to be there
ran all updates with ms and antivirus software

O also this pc is nearly 5 years old with only 512 or ram, Pentium 4 so not to modern by any standards but still enough power to run web browsers and some speed.

any help would be great

thanks leon
 

A:Solved: Problems opening up Webbrowser

Read other 12 answers
RELEVANCY SCORE 41.2

Whenever I start up, my desktop is changed to a black spyware warning/removal add. Also my task manager button has been disabled so that I can not access it.

The web address I am directed to from the spyware add taking up my desktop is : http://213.159.117.130/?affid=NAT-25

I have already run CWS Shredder, Spybot, and Adaware. Here is my HJT log after running all of these programs:

Logfile of HijackThis v1.98.2
Scan saved at 9:34:38 AM, on 3/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\kernels32.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\PROGRA~1\THEWEA~1\The Weather Channel.exe
C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Nhksrv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shar... Read more

A:Hijacked Desktop with Spyware Add

A new version of Hijack This has been released so get rid of the old one and
download from this site http://www.thespykiller.co.uk/downloads.htm
Run Hijackthis and fix the following items. Be sure all windows are closed except for hijackthis.

O2 - BHO: (no name) - {0F9561D0-03B2-44a3-89A6-E95E417CBA25} - C:\WINDOWS\cerbmod.dll

O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels32.exe

O9 - Extra button: (no name) - {578FC4E3-151E-456c-AF8E-B63061EFE228}} - (no file)

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe

How to boot to safe mode

Because XP will not always show you hidden files and folders by default, Go to Start > Search and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden files and folders" and "Search system subfolders"

Next click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"


Boot to safe mode and delete these files
C:\WINDOWS\cerbmod.dll

C:\WINDOWS\system32\kernels32.exe
Delete your temporary files:
In safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go t... Read more

Read other 2 answers