Over 1 million tech questions and answers.

Unwanted redirections, blank page..

Q: Unwanted redirections, blank page..

Hi guys, I've been having some problems recently with my browsers..Certain websites, will not load. I've tried multiple browsers, IE, Mozilla Firefox, Netscape Navigator, etc.The very first time I tried to open these webpages, they would be redirected to some other sites like soundsofopera.comor videocop.com, etc. I went in to Mozilla Firefox and Adblock 'd those redirection sites. I tried opening the page again,and it would give me a blank page, with the status "Done" at the left bottom corner of the browser.Removed text not written by member. Pasting in additional information posted by member posted elsewhere. ~ OBTake a look at Untitled.JPEG. Thanks.In fact, the redirection site changes daily.. it was soundsofopera.com in August 25, and now it's ultrabestportal.com End of paste. ~ OBHere is my log:Logfile of Trend Micro HijackThis v2.0.4Scan saved at 10:01:25 PM, on 26/08/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:WINDOWSSystem32smss.exeC:WINDOWSsystem32csrss.exeC:WINDOWSsystem32winlogon.exeC:WINDOWSsystem32services.exeC:WINDOWSsystem32lsass.exeC:WINDOWSsystem32svchost.exeC:WINDOWSsystem32svchost.exeC:WINDOWSSystem32svchost.exeC:WINDOWSsystem32svchost.exeC:WINDOWSsystem32svchost.exeC:WINDOWSsystem32svchost.exeC:Program FilesCommon FilesSymantec SharedccSetMgr.exeC:Program FilesCommon FilesSymantec SharedccEvtMgr.exeC:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exeC:WINDOWSsystem32spoolsv.exeC:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exeC:Program FilesBonjourmDNSResponder.exeC:Program FilesSymantec AntiVirusDefWatch.exeC:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXEC:Program FilesGoogleUpdateGoogleUpdate.exeC:Program FilesKyoceraFileUtilitySFUSVC.exeC:WINDOWSsystem32svchost.exeC:Program FilesKyoceraFileUtilitynsCatCom.exeC:Program FilesSymantec AntiVirusRtvscan.exeC:WINDOWSSystem32alg.exeC:WINDOWSSystem32svchost.exeC:WINDOWSExplorer.EXEC:WINDOWSsystem32VTTimer.exeC:WINDOWSsystem32S3trayp.exeC:WINDOWSSOUNDMAN.EXEC:Program FilesCyberLinkPowerDVDPDVDServ.exeC:Program FilesJavajre1.6.0_05binjusched.exeC:Program FilesCommon FilesSymantec SharedccApp.exeC:PROGRA~1SYMANT~1VPTray.exeC:Program FilesQuickTimeQTTask.exeC:Program FilesiTunesiTunesHelper.exeC:WINDOWSsystem32ctfmon.exeC:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exeC:Program FilesTomTom HOME 2HOMERunner.exeC:Program FilesMessengermsmsgs.exeC:Program FilesNokiaNokia PC Suite 7PCSuite.exeC:Program FilesKyoceraFileUtilityNsCatCom.exeC:Program FilesWinZipWZQKPICK.EXEC:Program FilesiPodbiniPodService.exeC:Program FilesPC Connectivity SolutionServiceLayer.exeC:Program FilesJavajre1.6.0_05binjucheck.exeC:Program FilesWindows DefenderMsMpEng.exeC:WINDOWSsystem32csrss.exeC:WINDOWSsystem32winlogon.exeC:WINDOWSExplorer.EXEC:WINDOWSsystem32VTTimer.exeC:WINDOWSsystem32S3trayp.exeC:WINDOWSSOUNDMAN.EXEC:Program FilesCyberLinkPowerDVDPDVDServ.exeC:Program FilesJavajre1.6.0_05binjusched.exeC:Program FilesCommon FilesSymantec SharedccApp.exeC:PROGRA~1SYMANT~1VPTray.exeC:Program FilesQuickTimeQTTask.exeC:Program FilesiTunesiTunesHelper.exeC:Program FilesWindows DefenderMSASCui.exeC:WINDOWSsystem32ctfmon.exeC:Program FilesMSN MessengerMsnMsgr.ExeC:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exeC:Program FilesMicrosoft OfficeOFFICE11OUTLOOK.EXEC:Program FilesWinZipWZQKPICK.EXEC:Program FilesJavajre1.6.0_05binjucheck.exeC:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXEC:WINDOWSsystem32spider.exeC:Program FilesMicrosoft ActiveSyncWCESCOMM.EXEC:Program FilesPC Connectivity SolutionTransportsNclUSBSrv.exeC:Program FilesPC Connectivity SolutionTransportsNclRSSrv.exeC:WINDOWSsystem32taskmgr.exeC:Program FilesThreatFireTFTray.exeC:Program FilesThreatFireTFService.exeC:Program FilesSpyware DoctorpctsAuxs.exeC:Program FilesSpyware DoctorpctsSvc.exeC:Program FilesSpyware DoctorpctsTray.exeC:Program FilesSpyware DoctorBDTBDTUpdateService.exeC:Program FilesMicrosoft OfficeOFFICE11OUTLOOK.EXEC:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXEC:Program FilesInternet ExplorerIEXPLORE.EXEC:Program FilesInternet ExplorerIEXPLORE.EXEC:Program FilesInternet ExplorerIEXPLORE.EXEC:Program FilesInternet ExplorerIEXPLORE.EXEC:WINDOWSsystem32msiexec.exeC:Program FilesTrend MicroHiJackThisHiJackThis.exeC:WINDOWSSystem32NOTEPAD.EXER1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.nixat.com/R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.localO2 - BHO: Adobe PDF Reader Link Helper - ACTIVE USERS 4 - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dllO2 - BHO: Browser Defender BHO - ACTIVE USERS 3 - C:Program FilesSpyware DoctorBDTPCTBrowserDefender.dllO2 - BHO: SSVHelper Class - ACTIVE USERS 2 - C:Program FilesJavajre1.6.0_05binssv.dllO2 - BHO: (no name) - ACTIVE USERS 1 - (no file)O2 - BHO: Windows Live Sign-in Helper - ACTIVE USERS 0 - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dllO2 - BHO: Google Toolbar Helper - By default we load generic code, php, css, sql and xml/html; load others here if desired 9 - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dllO2 - BHO: Google Toolbar Notifier BHO - By default we load generic code, php, css, sql and xml/html; load others here if desired 8 - C:Program FilesGoogleGoogleToolbarNotifier5.5.5126.1836swg.dllO2 - BHO: Ask Toolbar BHO - By default we load generic code, php, css, sql and xml/html; load others here if desired 7 - C:Program FilesAsk.comGenericAskToolbar.dllO3 - Toolbar: Ask Toolbar - By default we load generic code, php, css, sql and xml/html; load others here if desired 6 - C:Program FilesAsk.comGenericAskToolbar.dllO3 - Toolbar: Google Toolbar - By default we load generic code, php, css, sql and xml/html; load others here if desired 5 - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dllO3 - Toolbar: PC Tools Browser Guard - By default we load generic code, php, css, sql and xml/html; load others here if desired 4 - C:Program FilesSpyware DoctorBDTPCTBrowserDefender.dllO4 - HKLM..Run: [VTTimer] VTTimer.exeO4 - HKLM..Run: [S3Trayp] S3trayp.exeO4 - HKLM..Run: [SoundMan] SOUNDMAN.EXEO4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exeO4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLinkPowerDVDPDVDServ.exe"O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_05binjusched.exe"O4 - HKLM..Run: [MediaFace Integration] C:Program FilesFellowesMediaFACE 4.0SetHook.exeO4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"O4 - HKLM..Run: [vptray] C:PROGRA~1SYMANT~1VPTray.exeO4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"O4 - HKLM..Run: [Ad-Watch] C:Program FilesLavasoftAd-AwareAAWTray.exeO4 - HKLM..Run: [AppleSyncNotifier] C:Program FilesCommon FilesAppleMobile Device SupportbinAppleSyncNotifier.exeO4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeQTTask.exe" -atboottimeO4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -kO4 - HKLM..Run: [Windows Defender] "C:Program FilesWindows DefenderMSASCui.exe" -hideO4 - HKLM..Run: [ThreatFire] C:Program FilesThreatFireTFTray.exeO4 - HKLM..Run: [ISTray] "C:Program FilesSpyware DoctorpctsTray.exe"O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exeO4 - HKCU..Run: [swg] "C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe"O4 - HKCU..Run: [NBJ] "C:Program FilesAheadNero BackItUpNBJ.exe"O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE"O4 - HKCU..Run: [TomTomHOME.exe] "C:Program FilesTomTom HOME 2HOMERunner.exe"O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /backgroundO4 - HKCU..Run: [PC Suite Tray] "C:Program FilesNokiaNokia PC Suite 7PCSuite.exe" -onlytrayO4 - HKCU..Run: [AdobeUpdater] "C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe"O4 - HKCU..Run: [ZE18MW23GY] C:DOCUME~1DavidLOCALS~1TempBnq.exeO4 - HKCU..RunOnce: [FlashPlayerUpdate] C:WINDOWSsystem32MacromedFlashFlashUtil10d.exeO4 - HKLM..PoliciesExplorerRun: [] O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'LOCAL SERVICE')O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'NETWORK SERVICE')O4 - HKUSS-1-5-21-606747145-115176313-839522115-1005..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe (User 'Jo')O4 - HKUSS-1-5-21-606747145-115176313-839522115-1005..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized (User 'Jo')O4 - HKUSS-1-5-21-606747145-115176313-839522115-1005..Run: [AdobeUpdater] "C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe" (User 'Jo')O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')O4 - Global Startup: Address Book.lnk = ?O4 - Global Startup: Scanner File Utility.lnk = ?O4 - Global Startup: WinZip Quick Pick.lnk = C:Program FilesWinZipWZQKPICK.EXEO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000O8 - Extra context menu item: Google Sidewiki... - res://C:Program FilesGoogleGoogle ToolbarComponentGoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.htmlO9 - Extra button: (no name) - By default we load generic code, php, css, sql and xml/html; load others here if desired 3 - C:Program FilesJavajre1.6.0_05binssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - By default we load generic code, php, css, sql and xml/html; load others here if desired 2 - C:Program FilesJavajre1.6.0_05binssv.dllO9 - Extra button: Create Mobile Favorite - By default we load generic code, php, css, sql and xml/html; load others here if desired 1 - C:Program FilesMicrosoft ActiveSyncINETREPL.DLLO9 - Extra button: (no name) - By default we load generic code, php, css, sql and xml/html; load others here if desired 0 - C:Program FilesMicrosoft ActiveSyncINETREPL.DLLO9 - Extra 'Tools' menuitem: Create Mobile Favorite... -
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//9 - C:Program FilesMicrosoft ActiveSyncINETREPL.DLLO9 - Extra button: Research -
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//8 - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLLO9 - Extra button: (no name) -
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//7 - C:WINDOWSNetwork Diagnosticxpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//6 - C:WINDOWSNetwork Diagnosticxpnetdiag.exeO9 - Extra button: Messenger -
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//5 - C:Program FilesMessengermsmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger -
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//4 - C:Program FilesMessengermsmsgs.exeO16 - DPF:
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//3 (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cabO16 - DPF:
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//2 (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cabO16 - DPF:
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//1 (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cabO16 - DPF:
google_ad_client = "ca-pub-3249370012249755";
/* Forums - Bottom */
google_ad_slot = "5165859604";
google_ad_width = 980;
google_ad_height = 120;
//0 - http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exeO16 - DPF: ::: FOOTER (Change skin, language, mark as read, etc) ::: 9 (HSDPlansCtl.ucPlansInt) - https://www.eduweb.vic.gov.au/ncontent/svgm...HSDPlansCtl.CABO16 - DPF: ::: FOOTER (Change skin, language, mark as read, etc) ::: 8 (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1272458925609O16 - DPF: ::: FOOTER (Change skin, language, mark as read, etc) ::: 7 (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0...oUploader55.cabO16 - DPF: ::: FOOTER (Change skin, language, mark as read, etc) ::: 6 (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: ::: FOOTER (Change skin, language, mark as read, etc) ::: 5 (Autodesk WHIP! Control) - https://www.eduweb.vic.gov.au/ncontent/svgm...Public/whip.cabO16 - DPF: ::: FOOTER (Change skin, language, mark as read, etc) ::: 4 (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo...ol/MSNPUpld.cabO17 - HKLMSystemCCSServicesTcpip.. ::: FOOTER (Change skin, language, mark as read, etc) ::: 3: NameServer = 93.188.164.74,93.188.166.224O17 - HKLMSystemCS1ServicesTcpipParameters: NameServer = 93.188.164.74,93.188.166.224O17 - HKLMSystemCCSServicesTcpipParameters: NameServer = 93.188.164.74,93.188.166.224O22 - SharedTaskScheduler: Browseui preloader - ::: FOOTER (Change skin, language, mark as read, etc) ::: 2 - C:WINDOWSsystem32browseui.dllO22 - SharedTaskScheduler: Component Categories cache daemon - ::: FOOTER (Change skin, language, mark as read, etc) ::: 1 - C:WINDOWSsystem32browseui.dllO23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exeO23 - Service: Bonjour Service - Apple Inc. - C:Program FilesBonjourmDNSResponder.exeO23 - Service: Browser Defender Update Service - Unknown owner - C:Program FilesSpyware DoctorBDTBDTUpdateService.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccEvtMgr.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSetMgr.exeO23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:Program FilesSymantec AntiVirusDefWatch.exeO23 - Service: Google Update Service (gupdate1ca32adc6024910) (gupdate1ca32adc6024910) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exeO23 - Service: Google Software Updater (gusvc) - Unknown owner - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe (file missing)O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodbiniPodService.exeO23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:Program FilesLavasoftAd-AwareAAWService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXEO23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exeO23 - Service: SAVRoam (SavRoam) - symantec - C:Program FilesSymantec AntiVirusSavRoam.exeO23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware DoctorpctsAuxs.exeO23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware DoctorpctsSvc.exeO23 - Service: ServiceLayer - Nokia - C:Program FilesPC Connectivity SolutionServiceLayer.exeO23 - Service: SFUSVC - KYOCERA MITA CORPORATION - C:Program FilesKyoceraFileUtilitySFUSVC.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exeO23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exeO23 - Service: Symantec AntiVirus - Symantec Corporation - C:Program FilesSymantec AntiVirusRtvscan.exeO23 - Service: ThreatFire - PC Tools - C:Program FilesThreatFireTFService.exe--End of file - 15463 bytesPasting in DDS log created and posted by this member elsewhere. ~ OBHere are the logs: DDS (Ver_10-03-17.01) - NTFSx86 Run by new at 23:40:19.43 on 08/25/2010 WedInternet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_21Microsoft Windows XP Professional 5.1.2600.3.949.82.1033.18.3033.2195 [GMT -7:00]AV: ???????? *On-access scanning disabled* (Updated) ::: FOOTER (Change skin, language, mark as read, etc) ::: 0AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated) Copyright Information 9FW: Webroot Internet Security Essentials *disabled* Copyright Information 8============== Running Processes ===============C:WINDOWSsystem32svchost -k DcomLaunchsvchost.exeC:WINDOWSSystem32svchost.exe -k netsvcssvchost.exeC:WINDOWSsystem32spoolsv.exeC:Program FilesOnDiskExpressService.exeC:Program FilesJavajre6binjqs.exeC:Program FilesMalwarebytes' Anti-Malwarembamservice.exeC:WINDOWSsystem32PnkBstrA.exeC:WINDOWSsystem32PnkBstrB.exeC:Program FilesMicrosoftSearch Enhancement PackSeaPortSeaPort.exesvchost.exeC:WINDOWSsystem32svchost.exe -k imgsvcC:WINDOWSsystem32conime.exeC:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXEC:WINDOWSRTHDCPL.EXEC:Program FilesMSN ToolbarPlatform4.0.0417.0mswinext.exeC:Program FilesCommon FilesJavaJava Updatejusched.exeC:WINDOWSPLFSetL.exeC:Program FilesiTunesiTunesHelper.exeC:Program FilesCommon FilesAdobeARM1.0AdobeARM.exeC:Program FilesCommon FilesAheadLibNMBgMonitor.exeC:Program FilesWindows LiveMessengermsnmsgr.exeC:Program FilesCommon FilesAheadLibNMIndexStoreSvr.exeC:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exeC:WINDOWSsystem32wscntfy.exeC:Program FilesiPodbiniPodService.exeC:WINDOWSSystem32svchost.exe -k HTTPFilterC:Program FilesMessengermsmsgs.exeC:Program FilesWindows LiveContactswlcomm.exeC:WINDOWSsystem32wuauclt.exeC:WINDOWSexplorer.exeC:Program FilesMicrosoftSearch Enhancement PackSCServerSCServer.exeC:Program FilesMozilla Firefoxfirefox.exeC:Program FilesMozilla Firefoxplugin-container.exeC:Program FilesTrend MicroHijackThisHijackThis.exeC:Documents and SettingsnewDesktopdds.scr============== Pseudo HJT Report ===============uStart Page = hxxp://google.com/BHO: IDMIEHlprObj Class: Copyright Information 7 - c:program filesinternet download managerIDMIECC.dllBHO: Adobe PDF Link Helper: Copyright Information 6 - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dllBHO: PC Tools Browser Guard BHO: Copyright Information 5 - c:program filesspyware doctorbdtPCTBrowserDefender.dllBHO: Copyright Information 4 - No FileBHO: Search Helper: Copyright Information 3 - c:program filesmicrosoftsearch enhancement packsearch helperSEPsearchhelperie.dllBHO: Windows Live ID Sign-in Helper: Copyright Information 2 - c:program filescommon filesmicrosoft sharedwindows liveWindowsLiveLogin.dllBHO: Free TV Bar Toolbar: Copyright Information 1 - c:program filesfree_tv_bartbFre0.dllBHO: Skype add-on for Internet Explorer: Copyright Information 0 - c:program filesskypetoolbarsinternet explorerskypeieplugin.dllBHO: MSN Toolbar BHO: / Copyright 9 - c:program filesmsn toolbarplatform4.0.0417.0npwinext.dllBHO: Java™ Plug-In 2 SSV Helper: / Copyright 8 - c:program filesjavajre6binjp2ssv.dllBHO: JQSIEStartDetectorImpl Class: / Copyright 7 - c:program filesjavajre6libdeployjqsiejqs_plugin.dllTB: Free TV Bar Toolbar: / Copyright 6 - c:program filesfree_tv_bartbFre0.dllTB: MSN Toolbar: / Copyright 5 - c:program filesmsn toolbarplatform4.0.0417.0npwinext.dllTB: PC Tools Browser Guard: / Copyright 4 - c:program filesspyware doctorbdtPCTBrowserDefender.dlluRun: [BgMonitor_ / Copyright 3] "c:program filescommon filesaheadlibNMBgMonitor.exe"uRun: [Skype] "c:program filesskypephoneSkype.exe" /nosplash /minimizeduRun: [msnmsgr] "c:program fileswindows livemessengermsnmsgr.exe" /backgroundmRun: [hpbdfawep] "c:program fileshpdfawepbinhpbdfawep.exe" 1mRun: [RTHDCPL] "RTHDCPL.EXE"mRun: [MSN Toolbar] "c:program filesmsn toolbarplatform4.0.0417.0mswinext.exe"mRun: [Microsoft Default Manager] "c:program filesmicrosoftsearch enhancement packdefault managerDefMgr.exe" -resumemRun: [SunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe"mRun: [PLFSetL] c:windowsPLFSetL.exemRun: [iTunesHelper] "c:program filesitunesiTunesHelper.exe"mRun: [Adobe Reader Speed Launcher] "c:program filesadobereader 9.0readerReader_sl.exe"mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe"mRun: [QuickTime Task] "c:program filesquicktimeQTTask.exe" -atboottimemRun: [Malwarebytes' Anti-Malware] "c:program filesmalwarebytes' anti-malwarembamgui.exe" /starttraydRunOnce: [RunNarrator] Narrator.exeIE: / Copyright 2 - %windir%Network Diagnosticxpnetdiag.exeIE: / Copyright 1 - c:program filesmessengermsmsgs.exeIE: / Copyright 0 - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:program fileswindows livewriterWriterBrowserExtension.dllIE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dllIE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~2office11REFIEBAR.DLLDPF: {03AF249E-119E-4569-838E-167E929EC6DA} - hxxp://www.bigfile.co.kr/client/BigFile.cabDPF: {124250DD-E2CC-4B5B-AE7E-C9AC8A11DF43} - hxxp://edu.ingang.go.kr/LMS/eduport/front/study/common/ftp/StreamNote2_V2.cabDPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cabDPF: {283A7932-A386-496A-9AB0-E8DBFACFF1E5} - hxxp://ondisk.co.kr/setup/OnDiskWebControl.cabDPF: {286A75C3-11FB-4FB4-AC4A-4DD1B0750050} - hxxp://image.cjmall.com/initech/plugin/download_2010/INIS60.cabDPF: {2DCB00FB-3485-486B-BD41-C49AD605264D} - hxxp://www.immigration.go.kr/HP/COM/keytec/easykeytec.cabDPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cabDPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cabDPF: {6CE20149-ABE3-462E-A1B4-5B549971AA38} - hxxp://ck.softforum.co.kr/CKKeyPro/G4C/CKKeyPro3024_32k.cabDPF: {7B1BB066-7BBB-11D4-A34E-0000F01A209C} - hxxp://login.unitel.co.kr/iplug/lmgr2131.cabDPF: {88D969C0-F192-11D4-A65F-0040963251E5} - hxxp://gcc.nefficient.co.kr/gcc/msxml4.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cabDPF: {8DC067B8-911D-473A-90F1-1171B887CDE0} - hxxp://cyimg7.cyworld.com/ImageUpload/CyPictureU1233.cab?20081124DPF: {970E1B88-8AC1-4E31-86D6-BFA769CEF7A6} - hxxp://www.ebslang.co.kr/ebs/ActiveX/eGEBS.cabDPF: {9B75502C-BBED-4BBD-8FE2-822E5E0AD32C} - hxxp://www.ebs.co.kr/ActiveX/MagicLockOCX.cabDPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - hxxp://kings.nefficient.co.kr/kings/kdfx/kdfx311/kdfense8.cabDPF: {BB8C416C-2422-44C6-9F8D-ACB3B74EEBD5} - hxxp://app.filebus.co.kr/app/FilebusWebControl.CABDPF: {BDD22343-1DF0-4983-947F-7604DD9838F8} - hxxp://edu.ingang.go.kr/lms_ingang/script/common_add/MagicSpeeder.cabDPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabDPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cabDPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cabDPF: {E78928A6-3D2A-4BF7-A100-F3FBAA351B49} - hxxps://www.vpay.co.kr/kvpfiles/KVPISPCTLD.cabDPF: {F0320816-41D9-49DD-B2F3-8E7B0AE32796} - hxxp://live.afreeca.com:8057/AFCStarter.cabDPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cabDPF: {FE342FC7-4374-4EBE-86DB-D73AE861F779} - hxxp://file.naver.com/activex/NaverAXGuide.cabDPF: {FE9CE737-7BA6-451D-A4E0-EB4599D46FD6} - hxxp://www.melon.com/cab/MelonActiveXInstaller.cabHandler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:progra~1common~1skypeSKYPE4~1.DLLHandler: smart - {402CA0E4-3090-402e-BE90-3EE9B766EBB0} - c:program filesestsoftaltoolbarALToolBarProtocol.dllNotify: igfxcui - igfxdev.dllSSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll================= FIREFOX ===================FF - ProfilePath - c:docume~1newapplic~1mozillafirefoxprofilesev2v0p7w.defaultFF - component: c:program filesmicrosoftsearch enhancement packsearch helperfirefoxextensionsearchhelperextensioncomponentsSEPsearchhelperff.dllFF - component: c:program filesmozilla firefoxextensions{ab2ce124-6272-4b12-94a9-7303c7397bd1}componentsSkypeFfComponent.dllFF - plugin: c:documents and settingsall usersapplication datanexonngmnpNxGame.dllFF - plugin: c:documents and settingsall usersapplication datanexonusngmnpNxGameUS.dllFF - plugin: c:program filescommon filesgretechnpgomtvx_nie.dllFF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dllFF - plugin: c:program filesmozilla firefoxpluginsnpdeployJava1.dllFF - plugin: c:program filesmozilla firefoxpluginsnpINISAFEWeb60.dllFF - plugin: c:program filesmozilla firefoxpluginsnpOGAPlugin.dllFF - plugin: c:program filesmozilla firefoxpluginsnpxecure.dllFF - plugin: c:program filesmozilla firefoxpluginsnpxwfile.dllFF - plugin: c:program filesmsn toolbarplatform4.0.0417.0npwinext.dllFF - plugin: c:program filessoftforumxecurewebactivexnpxwebplugin.dllFF - plugin: c:program filessoftforumxecurewebactivexnpxwebplugin_file.dllFF - plugin: c:program fileswindows livephoto galleryNPWLPG.dllFF - plugin: c:windowssystem32npKeyPro.dllFF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsmicrosoft.netframeworkv3.5windows presentation foundationdotnetassistantextensionFF - HiddenExtension: Java Console: No Registry Reference - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}FF - HiddenExtension: Java Console: No Registry Reference - c:program filesmozilla firefoxextensions{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}---- FIREFOX POLICIES ----c:program filesmozilla firefoxgreprefsall.js - pref("ui.use_native_colors", true);c:program filesmozilla firefoxgreprefsall.js - pref("ui.use_native_popup_windows", false);c:program filesmozilla firefoxgreprefsall.js - pref("browser.enable_click_image_resizing", true);c:program filesmozilla firefoxgreprefsall.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);c:program filesmozilla firefoxgreprefsall.js - pref("javascript.options.mem.high_water_mark", 32);c:program filesmozilla firefoxgreprefsall.js - pref("javascript.options.mem.gc_frequency", 1600);c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.lu", true);c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.nu", true);c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.nz", true);c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true); c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true); c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--p1ai", true);c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);c:program filesmozilla firefoxgreprefsall.js - pref("network.IDN.whitelist.tel", true);c:program filesmozilla firefoxgreprefsall.js - pref("network.auth.force-generic-ntlm", false);c:program filesmozilla firefoxgreprefsall.js - pref("network.proxy.type", 5);c:program filesmozilla firefoxgreprefsall.js - pref("network.buffer.cache.count", 24);c:program filesmozilla firefoxgreprefsall.js - pref("network.buffer.cache.size", 4096);c:program filesmozilla firefoxgreprefsall.js - pref("dom.ipc.plugins.timeoutSecs", 45);c:program filesmozilla firefoxgreprefsall.js - pref("svg.smil.enabled", false);c:program filesmozilla firefoxgreprefsall.js - pref("ui.trackpoint_hack.enabled", -1);c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.debug", false);c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.agedWeight", 2);c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.bucketSize", 1);c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.maxTimeGroupings", 25);c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.timeGroupingSize", 604800);c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.boundaryWeight", 25);c:program filesmozilla firefoxgreprefsall.js - pref("browser.formfill.prefixWeight", 5);c:program filesmozilla firefoxgreprefsall.js - pref("accelerometer.enabled", true);c:program filesmozilla firefoxgreprefsall.js - pref("html5.enable", false);c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl.require_safe_negotiation", false);c:program filesmozilla firefoxgreprefssecurity-prefs.js - pref("security.ssl3.rsa_seed_sha", true);c:program filesmozilla firefoxdefaultspreffirefox-branding.js - pref("app.update.download.backgroundInterval", 600);c:program filesmozilla firefoxdefaultspreffirefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");c:program filesmozilla firefoxdefaultspreffirefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");c:program filesmozilla firefoxdefaultspreffirefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");c:program filesmozilla firefoxdefaultspreffirefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");c:program filesmozilla firefoxdefaultspreffirefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");c:program filesmozilla firefoxdefaultspreffirefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");c:program filesmozilla firefoxdefaultspreffirefox.js - pref("lightweightThemes.update.enabled", true);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("browser.allTabs.previews", false);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("plugins.update.notifyUser", false);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("toolbar.customization.usesheet", false);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("dom.ipc.plugins.enabled", false);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("browser.taskbar.previews.enable", false);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("browser.taskbar.previews.max", 20);c:program filesmozilla firefoxdefaultspreffirefox.js - pref("browser.taskbar.previews.cachetime", 20);============= SERVICES / DRIVERS ===============R0 PCTCore;PCTools KDS;c:windowssystem32driversPCTCore.sys [2010-8-14 218592]R0 ssfs0bbc;ssfs0bbc;c:windowssystem32driversssfs0bbc.sys [2009-4-2 29808]R1 IDMTDI;IDMTDI;c:windowssystem32driversidmtdi.sys [2010-8-10 75104]R2 DOSMEMIO;MEMIO;c:windowssystem32MEMIO.SYS [2009-12-25 4300]R2 ExpressService;ExpressService;c:program filesondiskExpressService.exe [2009-11-10 1294336]R2 MBAMService;MBAMService;c:program filesmalwarebytes' anti-malwarembamservice.exe [2010-6-13 304464]R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2010-6-13 20952]R3 VMC33E;Vimicro Camera Service VMC33E;c:windowssystem32driversVMC33E.sys [2009-12-25 237952]R3 wowfilter;WOW XT Filter Driver;c:windowssystem32driversWOWFilter.sys [2009-3-24 25560]S1 MpKsl343ed5b3;MpKsl343ed5b3;??c:documents and settingsall usersapplication datamicrosoftmicrosoft antimalwaredefinition updates{ad10df00-539f-4a8d-a074-0c60b8473365}mpksl343ed5b3.sys --> c:documents and settingsall usersapplication datamicrosoftmicrosoft antimalwaredefinition updates{ad10df00-539f-4a8d-a074-0c60b8473365}MpKsl343ed5b3.sys [?]S2 INet Work Process;INet Work Process;c:windowswinetwp.exe [2010-8-15 286208]S2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:program fileswebrootwebrootsecuritySpySweeper.exe [2009-4-2 4048240]S2 WRConsumerService;Webroot Client Service; [x]S3 AhnFlt2k;AhnFlt2k;c:windowssystem32driversAhnFlt2k.sys [2010-1-6 52928]S3 AhnRec2k;AhnRec2k;c:windowssystem32driversAhnRec2k.sys [2010-1-6 20416]S3 AhnRghNt;AhnRghNt;c:windowssystem32driversAhnRghNt.sys [2010-1-6 52800]S3 Ambfilt;Ambfilt;c:windowssystem32driversAmbfilt.sys [2009-12-25 1684736]S3 ATamptNt_ASG;ATamptNt_ASG;??c:program filesahnlabsiteguard2atamptnt.sys --> c:program filesahnlabsiteguard2ATamptNt.sys [?]S3 ATamptNt_V3LITE;ATamptNt_V3LITE;??c:progra~1ahnlabv3liteatamptnt.sys --> c:progra~1ahnlabv3liteATamptNt.sys [?]S3 AYDrvXP_ALYAC;AYDrvXP_ALYAC;c:program filesestsoftalyacAYDrvXP.sys [2010-1-18 27000]S3 CdmDrvNt;CdmDrvNt;c:windowssystem32driversCdmDrvNt.sys [2010-1-6 19616]S3 cpuz132;cpuz132;??c:docume~1laglocals~1tempcpuz132cpuz132_x32.sys --> c:docume~1laglocals~1tempcpuz132cpuz132_x32.sys [?]S3 esgiguard;esgiguard;??c:program filesenigma software groupspyhunteresgiguard.sys --> c:program filesenigma software groupspyhunteresgiguard.sys [?]S3 JRSKD24;JRSKD24;c:windowssystem32JRSKD24.SYS [2010-7-25 39944]S3 kcrtx86;kcrtx86;c:windowssystem32kcrtx86.sys [2010-7-25 126048]S3 Lavasoft Kernexplorer;Lavasoft helper driver;??c:program fileslavasoftad-awarekernexplorer.sys --> c:program fileslavasoftad-awareKernExplorer.sys [?]S3 NPF;NetGroup Packet Filter Driver;c:windowssystem32driversnpf.sys [2007-11-6 34064]S3 scsk5;SCSK5 Driver Service;c:windowssystem32driversscsk5.sys --> c:windowssystem32driversscsk5.sys [?]S3 XDva348;XDva348;??c:windowssystem32xdva348.sys --> c:windowssystem32XDva348.sys [?]S4 Browser Defender Update Service;Browser Defender Update Service;c:program filesspyware doctorbdtBDTUpdateService.exe [2010-8-14 112592]S4 QuickDownload Agent;QuickDownload Agent;c:program filesquickdownloadserviceqdownagent.exe [2009-12-26 110592]S4 QuickDownload Service;QuickDownload Service;c:program filesquickdownloadserviceqdownservice.exe [2009-12-26 106496]S4 QuickDownload Update;QuickDownload Update;c:program filesquickdownloadserviceqdownupdate.exe [2009-12-26 94208]S4 sdAuxService;PC Tools Auxiliary Service;c:program filesspyware doctorpctsAuxs.exe [2010-8-14 366840]S4 sdCoreService;PC Tools Security Service;c:program filesspyware doctorpctsSvc.exe [2010-8-14 1142224]S4 SGsvc;AhnLab SiteGuard Service; [x]S4 SRS_PostInstaller;SRS PostInstaller Service;c:program filessrs labswowxt and tsxt driverSRS_PostInstaller2.exe [2009-3-24 74992]=============== Created Last 30 ================2010-08-26 05:47:26 0 d-----w- c:docume~1newapplic~1PriceGong2010-08-26 05:39:20 245248 ----a-w- c:windowssvchost.exe2010-08-26 05:25:50 0 d-sha-r- C:cmdcons2010-08-26 05:20:23 98816 ----a-w- c:windowssed.exe2010-08-26 05:20:23 77312 ----a-w- c:windowsMBR.exe2010-08-26 05:20:23 256512 ----a-w- c:windowsPEV.exe2010-08-26 05:20:23 161792 ----a-w- c:windowsSWREG.exe2010-08-26 03:55:33 0 d-----w- c:documents and settingsnewTracing2010-08-26 02:47:12 0 d-----r- c:program filesSkype2010-08-26 00:52:23 0 d-----w- c:docume~1newapplic~1Estsoft2010-08-25 23:49:05 0 d-----w- c:program filesNetscape2010-08-25 07:09:24 0 d-----w- c:docume~1alluse~1applic~1NexonUS2010-08-25 04:01:25 0 d-----w- c:windowsRegCure2010-08-24 05:14:23 12145896 ----a-w- c:program filesOnDisksetup.exe2010-08-21 21:36:23 0 d-----w- c:program filesUnlocker2010-08-21 03:40:12 0 d-----w- c:program filesSC192010-08-19 05:59:10 24 ----a-w- c:windowssystem32scskConfigEH.ini2010-08-19 05:59:10 124000 ----a-w- c:windowssystem32driverskcrtx86.sys2010-08-19 05:59:10 0 d-----w- c:docume~1alluse~1applic~1SoftCamp2010-08-19 05:59:09 1784576 ----a-w- c:windowssystem32SCSKMemLink.dll2010-08-19 05:58:27 708096 ----a-w- c:windowssystem32INIcrypto20.dll2010-08-19 05:58:04 143460 ----a-w- c:windowssystem32INIWEBCryptoWrapper.dll2010-08-19 05:58:02 260096 ----a-w- c:windowssystem32INIWebCrypto.dll2010-08-19 05:57:45 241664 ----a-w- c:windowssystem32PubCertDlg.dll2010-08-19 05:57:42 1205544 ----a-w- c:windowssystem32ISPPopUpDlg.exe2010-08-19 05:57:32 923080 ----a-w- c:windowssystem32SCSKAppLink.dll2010-08-19 05:57:03 124928 ----a-w- c:windowssystem32INICertStore.dll2010-08-19 05:56:52 386048 ----a-w- c:windowssystem32INICertManUI.dll2010-08-19 05:45:21 28672 ----a-w- c:windowssystem32ISP_crgen.dll2010-08-19 05:45:20 73728 ----a-w- c:windowssystem32ISP_INISafeNet.dll2010-08-19 05:45:17 6750208 ----a-w- c:windowssystem32KvpVcmd.dll2010-08-17 00:14:54 0 d-----w- c:program filesMetaGeek2010-08-17 00:01:18 0 d-----w- c:program filesNetwork Stumbler2010-08-16 03:23:04 286208 ----a-w- c:windowswinetwp.exe2010-08-16 02:34:15 0 d-----w- c:windowssystem32windows media2010-08-16 02:34:06 0 d-----w- c:program filesWindows Media Components2010-08-16 02:25:36 0 d-----w- C:temp.chicony2010-08-16 02:19:33 99328 -c--a-w- c:windowssystem32dllcachesrusd.dll2010-08-16 02:19:33 99328 ----a-w- c:windowssystem32srusd.dll2010-08-16 02:19:31 6784 -c--a-w- c:windowssystem32dllcacheserscan.sys2010-08-16 02:19:31 6784 ----a-w- c:windowssystem32driversserscan.sys2010-08-16 02:19:29 71680 -c--a-w- c:windowssystem32dllcachefnfilter.dll2010-08-16 02:19:29 71680 ----a-w- c:windowssystem32fnfilter.dll2010-08-16 02:16:41 0 d-----w- C:CamersoftOutput2010-08-16 02:14:08 0 d-----w- c:docume~1alluse~1applic~1WebacamSurveyor2010-08-16 02:09:59 0 d-----w- c:program filesImageSalsa2010-08-16 02:06:47 0 d-----w- c:program filescommon filessnp2uvc2010-08-15 16:56:23 0 d-----w- c:docume~1alluse~1applic~1Webroot2010-08-15 07:38:08 230 ----a-w- c:windowssystem32spupdsvc.inf2010-08-15 07:34:52 0 d-----w- c:docume~1alluse~1applic~1ParetoLogic2010-08-15 07:34:50 0 d-----w- c:program filesParetoLogic2010-08-15 02:39:58 73728 ----a-w- c:windowssystem32javacpl.cpl2010-08-14 23:44:04 0 d-----w- c:program filesReaSoft2010-08-14 23:00:39 882 ----a-w- c:windowsRegSDImport.xml2010-08-14 23:00:39 879 ----a-w- c:windowsRegISSImport.xml2010-08-14 23:00:39 767952 ----a-w- c:windowsBDTSupport.dll2010-08-14 23:00:39 165840 ----a-w- c:windowsPCTBDRes.dll2010-08-14 23:00:39 1652688 ----a-w- c:windowsPCTBDCore.dll2010-08-14 23:00:39 149456 ----a-w- c:windowsSGDetectionTool.dll2010-08-14 23:00:39 131 ----a-w- c:windowsIDB.zip2010-08-14 23:00:39 1152444 ----a-w- c:windowsUDB.zip2010-08-14 22:46:35 7387 ----a-w- c:windowssystem32driverspctgntdi.cat2010-08-14 22:46:35 233136 ----a-w- c:windowssystem32driverspctgntdi.sys2010-08-14 22:46:30 7383 ----a-w- c:windowssystem32driverspctcore.cat2010-08-14 22:46:30 218592 ----a-w- c:windowssystem32driversPCTCore.sys2010-08-14 22:46:29 88040 ----a-w- c:windowssystem32driversPCTAppEvent.sys2010-08-14 22:46:29 7412 ----a-w- c:windowssystem32driversPCTAppEvent.cat2010-08-14 22:46:18 7383 ----a-w- c:windowssystem32driverspctplsg.cat2010-08-14 22:46:18 63360 ----a-w- c:windowssystem32driverspctplsg.sys2010-08-14 22:46:03 0 d-----w- c:program filescommon filesPC Tools2010-08-14 22:46:03 0 d-----w- c:docume~1alluse~1applic~1PC Tools2010-08-14 22:46:02 0 d-----w- c:program filesSpyware Doctor2010-08-14 21:52:56 0 d-----w- c:program filesMSSOAP2010-08-14 21:52:36 0 d-----w- c:program filesWebroot2010-08-14 21:51:02 164 ----a-w- c:windowsinstall.dat2010-08-14 20:33:01 81920 ----a-w- c:windowssystem32ieencode.dll2010-08-14 20:33:01 81920 ----a-w- c:windowssystem32dllcacheieencode.dll2010-08-14 03:20:57 0 ----a-w- C:dump_dvd.vob2010-08-13 20:29:32 105 ----a-w- c:windowsVMSTI000.bmp2010-08-13 18:47:52 0 d-----w- c:program filesSpybot - Search & Destroy2010-08-13 18:47:52 0 d-----w- c:docume~1alluse~1applic~1Spybot - Search & Destroy2010-08-13 18:33:49 0 d-----w- c:docume~1alluse~1applic~1DriverScanner2010-08-13 08:14:15 0 d-----w- c:program filesMSXML 4.02010-08-13 08:01:24 456704 -c----w- c:windowssystem32dllcachesmtpsvc.dll2010-08-13 07:56:45 74752 -c----w- c:windowssystem32dllcachemsw3prt.dll2010-08-13 07:56:45 104960 -c----w- c:windowssystem32dllcachewin32spl.dll2010-08-13 07:52:58 91136 -c----w- c:windowssystem32dllcachentprint.dll2010-08-13 07:50:25 135168 -c----w- c:windowssystem32dllcacheshsvcs.dll2010-08-13 07:44:51 57344 -c----w- c:windowssystem32dllcacheuexfat.dll2010-08-13 07:44:51 57344 ------w- c:windowssystem32uexfat.dll2010-08-13 07:44:51 133632 -c----w- c:windowssystem32dllcacheexfat.sys2010-08-13 07:44:51 133632 ------w- c:windowssystem32driversexfat.sys2010-08-13 07:44:50 278528 -c----w- c:windowssystem32dllcacheulib.dll2010-08-13 07:44:06 0 d-----w- c:windowsRegistryBooster 22010-08-13 07:42:51 90112 -c----w- c:windowssystem32dllcachewshext.dll2010-08-13 07:42:51 512000 -c--a-w- c:windowssystem32dllcachejscript.dll2010-08-13 07:42:51 180224 -c----w- c:windowssystem32dllcachescrobj.dll2010-08-13 07:42:51 172032 -c----w- c:windowssystem32dllcachescrrun.dll2010-08-13 07:42:50 430080 -c--a-w- c:windowssystem32dllcachevbscript.dll2010-08-13 07:42:50 155648 -c----w- c:windowssystem32dllcachewscript.exe2010-08-13 07:42:50 135168 -c----w- c:windowssystem32dllcachecscript.exe2010-08-13 07:42:03 330752 -c----w- c:windowssystem32dllcacheipnathlp.dll2010-08-13 07:34:02 92672 -c----w- c:windowssystem32dllcachepolicman.dll2010-08-13 07:34:02 68096 -c----w- c:windowssystem32dllcachentdsapi.dll2010-08-13 07:34:02 175104 -c----w- c:windowssystem32dllcachew32time.dll2010-08-13 07:34:01 199680 -c----w- c:windowssystem32dllcachegptext.dll2010-08-13 07:34:01 113152 -c----w- c:windowssystem32dllcachedsuiext.dll2010-08-13 07:34:00 407040 -c----w- c:windowssystem32dllcachenetlogon.dll2010-08-13 07:33:59 68096 -c----w- c:windowssystem32dllcacheadsmsext.dll2010-08-13 07:32:14 62976 -c----w- c:windowssystem32dllcachecdrom.sys2010-08-13 07:32:13 465920 -c----w- c:windowssystem32dllcacheimapi2fs.dll2010-08-13 07:32:13 465920 ------w- c:windowssystem32imapi2fs.dll2010-08-13 07:32:13 317952 -c----w- c:windowssystem32dllcacheimapi2.dll2010-08-13 07:32:13 317952 ------w- c:windowssystem32imapi2.dll2010-08-13 07:29:38 295424 -c----w- c:windowssystem32dllcachetermsrv.dll2010-08-13 06:33:41 0 d-----w- c:program filesStarCraft II2010-08-13 05:12:57 44928 ------w- c:windowssystem32driversagpcpq.sys2010-08-13 05:11:17 19569 ----a-w- c:windows003146_.tmp2010-08-12 19:52:14 0 d-----w- c:program filesWindows Media Connect 22010-08-12 19:06:59 0 d-----w- c:program filesMSN Toolbar2010-08-12 19:04:07 0 d-----w- c:docume~1alluse~1applic~1PC Drivers HeadQuarters2010-08-12 19:04:06 0 d-----w- c:program filesMSN Toolbar Installer2010-08-12 18:46:06 0 d-----w- c:program filesDaum2010-08-12 07:14:53 0 d-----w- c:docume~1alluse~1applic~1Rising2010-08-12 07:14:10 0 d-----w- c:program filesRising2010-08-12 03:17:42 0 d-----w- c:docume~1alluse~1applic~1Kaspersky Lab Setup Files2010-08-12 00:03:30 95024 ----a-w- c:windowssystem32driversSBREDrv.sys2010-08-11 22:15:20 0 d-----w- c:windows95431C66CF9A4913BFFF6050785AFB65.TMP2010-08-11 22:15:17 0 d-----w- c:program filescommon filesWise Installation Wizard2010-08-11 09:20:46 52736 ----a-w- c:windowssystem32driverslngehind.sys2010-08-11 08:43:31 77824 ----a-w- c:windowssystem32xvid.ax2010-08-11 08:43:31 765952 ----a-w- c:windowssystem32xvidcore.dll2010-08-11 08:43:31 180224 ----a-w- c:windowssystem32xvidvfw.dll2010-08-11 08:43:30 0 d-----w- c:program filesXvid2010-08-10 18:16:10 75104 ----a-w- c:windowssystem32driversidmtdi.sys2010-08-10 18:16:10 210352 ----a-w- c:windowssystem32idmmbc.dll2010-08-10 12:15:58 94208 ----a-w- c:windowssystem32QuickTimeVR.qtx2010-08-10 12:15:58 69632 ----a-w- c:windowssystem32QuickTime.qts2010-08-09 23:01:34 1049600 ------w- c:windowssystem32TERUTENAUTHDATA2010-08-09 23:00:57 0 d-----w- c:windowssystem32LOG2010-08-09 23:00:56 0 d-----w- c:program filescommon filesTeruten2010-08-09 23:00:53 0 d-----w- c:program filesTeruten2010-08-07 04:43:11 0 d-----w- c:program filesav1002010-08-06 23:44:27 0 d-----w- c:program filesRivaTuner v2.24 MSI Master Overclocking Arena 2009 edition2010-08-06 04:08:16 0 d-----w- c:program filesuTorrent2010-08-06 03:51:37 360320 ----a-w- c:windowssystem32driverstcpip.copy2010-08-05 07:13:32 163840 ----a-w- c:windowsSetACL.exe2010-08-05 06:32:32 0 d-----w- c:program filesQtracker2010-08-05 06:14:13 22328 ----a-w- c:windowssystem32driversPnkBstrK.sys2010-08-05 06:13:54 103736 ----a-w- c:windowssystem32PnkBstrB.exe2010-08-05 06:13:51 66872 ----a-w- c:windowssystem32PnkBstrA.exe2010-08-05 02:28:36 0 d-----w- c:program filesCall of Duty 4 - Modern Warfare2010-08-04 04:57:09 324 ----a-w- c:windowsgame.ini2010-08-02 19:30:37 37458 ----a-w- c:windowssystem32vtpkt2010-07-28 20:42:44 0 d-----w- c:program filesSC2Maps2010-07-28 20:37:24 1435716 ----a-w- C:(4)_-_Twilight_Fortress.s2ma2010-07-28 20:37:23 1703076 ----a-w- C:(2)_-_Shakuras_Plateau.s2ma2010-07-28 20:37:23 1575712 ----a-w- C:(2)_-_Lost_Temple.s2ma2010-07-28 20:37:23 1575708 ----a-w- C:(4)_-_Lost_Temple.s2ma2010-07-28 18:10:06 255496 ----a-w- c:windowssystem32UnInstall_CrossCert.exe2010-07-28 18:10:02 0 d-----w- c:program filesCrossCert2010-07-27 21:11:19 0 d-----w- c:docume~1alluse~1applic~1Blizzard Entertainment2010-07-27 21:10:56 0 d-----w- c:docume~1alluse~1applic~1Blizzard2010-07-27 18:37:23 0 d-----w- c:program filescommon filesBlizzard Entertainment==================== Find3M ====================2010-08-24 05:45:20 12 ----a-w- c:program filesOnDisk_ver.ini2010-08-24 05:18:46 10 ----a-w- c:program filesOnDiskver.ini2010-08-15 02:39:42 423656 ----a-w- c:windowssystem32deployJava1.dll2010-07-26 05:06:16 17160 ----a-w- c:windowssystem32JRSUKD25.SYS2010-07-26 05:06:16 126048 ----a-w- c:windowssystem32kcrtx86.sys2010-07-26 05:06:11 39944 ----a-w- c:windowssystem32JRSKD24.SYS2010-07-26 04:48:38 124424 ----a-r- c:windowssystem32CKAgent.exe2010-07-23 01:44:37 1278216 ----a-w- c:program fileseGSignPlus_ActiveX_ForEBS.exe2010-07-20 01:22:26 21764 ----a-w- c:windowssystem32CoreAAC-uninstall.exe2010-07-18 22:40:32 61952 ----a-w- c:windowssystem32execryptorvb.dll2010-07-15 23:40:58 475136 ----a-w- c:windowssystem32p3melon.dll2010-07-14 06:33:27 921600 ----a-w- c:windowssystem32vorbisenc.dll2010-07-14 06:33:11 188416 ----a-w- c:windowssystem32vorbis.dll2010-07-14 06:33:08 237568 ----a-w- c:windowssystem32OggDS.dll2010-07-14 06:33:04 45056 ----a-w- c:windowssystem32ogg.dll2010-07-14 06:33:03 102160 ----a-w- c:windowssystem32vb6ko.dll2010-07-14 05:56:43 57893 ----a-w- c:windowssystem32MelonActiveXUninst.exe2010-06-30 12:23:55 149504 ----a-w- c:windowssystem32schannel.dll2010-06-24 12:10:44 667136 ----a-w- c:windowssystem32wininet.dll2010-06-23 13:44:04 1851904 ----a-w- c:windowssystem32win32k.sys2010-06-22 02:58:01 65536 ----a-w- c:windowsIFinst27.exe2010-06-17 14:03:00 80384 ----a-w- c:windowssystem32iccvid.dll2010-06-17 09:14:50 651264 ----a-w- c:windowssystem32P3MelonSvr.exe2010-06-15 01:47:24 86016 ----a-w- c:windowssystem32frapsvid.dll2010-06-14 07:41:45 1172480 ----a-w- c:windowssystem32msxml3.dll2010-06-14 04:11:30 94208 ----a-w- c:windowsScUnin.exe2010-06-14 04:11:30 12488 ----a-w- c:windowsscunin.dat2010-06-10 16:40:12 860896 ----a-w- c:windowssystem32MelonWebPlayer.dll2010-06-03 18:12:06 296472 ----a-w- c:windowssystem32NaverFDL.exe2010-06-01 17:37:48 221568 ------w- c:windowssystem32MpSigStub.exe============= FINISH: 23:40:47.50 ===============With GMER.. Everytime I run gmer.exe , my computer would just crash and lag as hell.I just can't run gmer.. I'm sorry if these informations are not enough to solve the problem. ):Thanks in advance.Since I cannot transfer an attachment, I am pasting the attach.txt log in the text box. ~ OBUNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH ITDDS (Ver_10-03-17.01)==== Disk Partitions ============================= Disabled Device Manager Items ================= System Restore Points ===================No restore point in system.==== Installed Programs ======================32 bit Windows Card Reader DriverAcrobat.comAd-AwareAdobe Acrobat 8 Professional - English, Fran?is, DeutschAdobe Acrobat 8.1.3 ProfessionalAdobe AIRAdobe Anchor Service CS3Adobe Asset Services CS3Adobe Bridge CS3Adobe Bridge Start MeetingAdobe Camera Raw 4.0Adobe CMapsAdobe Color - Photoshop SpecificAdobe Color Common SettingsAdobe Color EU Extra SettingsAdobe Color JA Extra SettingsAdobe Color NA Recommended SettingsAdobe Default Language CS3Adobe Device Central CS3Adobe Dreamweaver CS3Adobe ExtendScript Toolkit 2Adobe Extension Manager CS3Adobe Flash Player 10 ActiveXAdobe Flash Player 10 PluginAdobe Fonts AllAdobe Help Viewer CS3Adobe Linguistics CS3Adobe PDF Library FilesAdobe Photoshop CS3Adobe Reader 9.3Adobe SetupAdobe Stock Photos CS3Adobe Type SupportAdobe Update Manager CS3Adobe Version Cue CS3 ClientAdobe WinSoft Linguistics PluginAdobe XMP Panels CS3Apple Application SupportApple Mobile Device SupportApple Software UpdateATI Catalyst Install ManagerBioShockBonjourCamtasia Studio 6Catalyst Control Center Core ImplementationCatalyst Control Center Graphics Full ExistingCatalyst Control Center Graphics Full NewCatalyst Control Center Graphics LightCatalyst Control Center Graphics Previews CommonCatalyst Control Center Graphics Previews Vistaccc-core-staticccc-utilityCCC Help EnglishCCleanerCisco EAP-FAST ModuleCisco LEAP ModuleCisco PEAP ModuleDell Resource CDDell Wireless WLAN CardFlashFXP v3Hide My IP 5.0Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)Java Auto UpdaterJava™ 6 Update 21LiveUpdate 3.3 (Symantec Corporation)Malwarebytes' Anti-MalwareMarket SamuraiMicrosoft .NET Framework 3.5 SP1Microsoft Office Access MUI (English) 2007Microsoft Office Access Setup Metadata MUI (English) 2007Microsoft Office Enterprise 2007Microsoft Office Excel MUI (English) 2007Microsoft Office Groove MUI (English) 2007Microsoft Office Groove Setup Metadata MUI (English) 2007Microsoft Office InfoPath MUI (English) 2007Microsoft Office OneNote MUI (English) 2007Microsoft Office Outlook MUI (English) 2007Microsoft Office PowerPoint MUI (English) 2007Microsoft Office Proof (English) 2007Microsoft Office Proof (French) 2007Microsoft Office Proof (Spanish) 2007Microsoft Office Proofing (English) 2007Microsoft Office Publisher MUI (English) 2007Microsoft Office Shared MUI (English) 2007Microsoft Office Shared Setup Metadata MUI (English) 2007Microsoft Office Visio MUI (English) 2007Microsoft Office Visio Professional 2007Microsoft Office Word MUI (English) 2007Microsoft Visual C++ 2005 RedistributableMozilla Firefox (3.6.8)Opera 10.60PDF SettingsSENukeSigmaTel AudioSkinsSkype?4.2SteamSuper Suggester 1.0.0Supreme Commander 2Symantec Endpoint Protection Small Business EditionTextPad 5TheBestSpinnerTrillianUN.CO.VER. 2.0Update for Microsoft .NET Framework 3.5 SP1 (KB963707)Visual C++ 2008 x86 Runtime - (v9.0.30729)Visual C++ 2008 x86 Runtime - v9.0.30729.01WinampWindows Driver Package - Logitech HIDClass (10/16/2006 1.0)WinRAR archiverWinSCP 4.2.7==== End Of File ===========================Thankyou to Orlando Bloom, Here is the Untitled.JPEG . I need to tell you something ..The redirection page used to change daily.But now, a different symptom occurs, starting some point yesterday.The errors I get in Both IE AND Firefox. I have the screenshots for both errors, so check them out too.P.S- I have IE 6. // untitled.JPEG is what happened about 2 days ago, That does not happen anymore. IE Error.JPEG and Mozilla Firefox Error.JPEG is what happens now.Merged post containing images to initial post. ~ OB

RELEVANCY SCORE 200
Preferred Solution: Unwanted redirections, blank page..

I recommend downloading and running DAP. It can help sort out any driver and firmware related issues on your system

It's worked out well for many of us in the past.

You can download it direct from this link http://downloaddap.org. (This link will open the download page of DAP so you can save a copy to your computer.)

A: Unwanted redirections, blank page..

Hi Changg,Welcome to Bleeping Computer!My name is mpascal, and I will be helping you fix your problem.Before we begin, I would like give a few guidelines so that we can fix your problem as quickly and efficiently as possible:Be sure to follow all my instructions carefully! If there is anything you don't understand, don't hesitate to ask.Please do not do anything or perform other steps unless I have asked you to do so.Please make sure you post all logs I ask you to, and make sure that the entire log gets posted.Don't attach any logs unless asked. Posting them in the forums will make them easier to analyze.If you are unsure of how to reply, or need help with anything regarding the website, please look here.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below I will review and take the steps necessary with you to get your machine back in working order clean and free of malware.STEP 1 - MBAMNote: In the event that you already have MBAM installed, you do not need to reinstall it. Simply Updating it and doing a Quickscan is sufficient.Please download Malwarebytes Anti-Malware (v1.44) and save it to your desktop.Download Link 1Download Link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.Make sure you are connected to the Internet.Double-click on mbam-setup.exe to install the application.For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.When the installation begins, follow the prompts and do not make any changes to default settings.When installation has finished, make sure you leave both of these checked:Update Malwarebytes' Anti-MalwareLaunch Malwarebytes' Anti-MalwareThen click Finish.MBAM will automatically start and you will be asked to update the program before performing a scan.If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.On the Scanner tab:Make sure the "Perform Quick Scan" option is selected.Then click on the Scan button.If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".Click OK to close the message box and continue with the removal process.Back at the main Scanner screen:Click on the Show Results button to see a list of any malware that was found.Make sure that everything is checked, and click Remove Selected.When removal is completed, a log report will open in Notepad.The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.Exit MBAM when done.Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.STEP 2 - GMERPlease download GMER from one of the following locations and save it to your desktop:Main MirrorThis version will download a randomly named file (Recommended)Zipped MirrorThis version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.Disconnect from the Internet and close all running programs.Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.Now click the Scan button. If you see a rootkit warning window, click OK.When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.Click the Copy button and paste the results into your next reply.Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.-- If you encounter any problems, try running GMER in safe mode.-- If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning.STEP 3 - OTLDownload OTL to your desktop.Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.When the window appears, underneath Output at the top change it to Minimal Output.In the Custom Scans box, copy and paste the following:CODEnetsvcs%SYSTEMDRIVE%\*.*%systemroot%\Fonts\*.com%systemroot%\Fonts\*.dll%systemroot%\Fonts\*.ini%systemroot%\Fonts\*.ini2%systemroot%\Fonts\*.exe%systemroot%\system32\spool\prtprocs\w32x86\*.*%systemroot%\REPAIR\*.bak1%systemroot%\REPAIR\*.ini%systemroot%\system32\*.jpg%systemroot%\*.jpg%systemroot%\*.png%systemroot%\*.scr%systemroot%\*._sy%APPDATA%\Adobe\Update\*.*%ALLUSERSPROFILE%\Favorites\*.*%APPDATA%\Microsoft\*.*%PROGRAMFILES%\*.*%APPDATA%\Update\*.*%systemroot%\*. /mp /sCREATERESTOREPOINT%systemroot%\System32\config\*.sav%PROGRAMFILES%\bak. /s%systemroot%\system32\bak. /s%ALLUSERSPROFILE%\Start Menu\*.lnk /x%systemroot%\system32\config\systemprofile\*.dat /x%systemroot%\*.config%systemroot%\system32\*.dbHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rsClick the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.When the scan completes, it will open two notepad windows. OTL.Txt and Extras.txt. These are saved in the same location as OTL.Please copy (Edit->Select All, Edit->Copy) the contents of the files, and post it with your next reply.STEP 4 - ReplyPlease reply with the following logs:MBAM LogGMER LogOTL Log

Read other 18 answers
RELEVANCY SCORE 82

hello,

i am really desperate. I have problems with redirections shaibaoj.com ... and some chinese recepise redirections. I have tried to clean stuff with at least 10 programs but unsucessfully. I also formated computer , but problem did survive !!!

its a little better when i use public wifi, but when i use private router/modem its almost impossible to surf over the internet...

Please help me
 

A:Browser redirections on chinese recipes page or blank page

Hello,

They call me TwinHeadedEagle around here, and I'll be working with you.

Before we start please read and note the following:

At the top of your post, please click on the "Watch thread" button and make sure to check Watch this thread...and receive email notifications. This will send an email to you as soon as I reply to your topic, allowing me to solve your problem faster.
Please do not install any new software during the cleaning process other than the tools I provide for you. This can hinder the cleaning process. Please do not perform System Restore or any other restore.
Instructions I give to you are very simple and made for complete beginner to follow. That's why you need to read through my instructions carefully and completely before executing them.
Please do not run any tools other than the ones I ask you to, when I ask you to. Some of these tools can be very dangerous if used improperly. Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.

All tools we use here are completely clean and do not contain any malware. If your antivirus detects them as malicious, please disable your antivirus and then continue.
If during the process you run across anything that is not in my instructions, please stop and ask. If any tool is running too much time (few hours), please stop and inform me.
I visit forum several times at day, making sure to respond to everyon... Read more

Read other 1 answers
RELEVANCY SCORE 82

TwinHeadedEagle said:





Hello,

They call me TwinHeadedEagle around here, and I'll be working with you.

Before we start please read and note the following:

At the top of your post, please click on the "Watch thread" button and make sure to check Watch this thread...and receive email notifications. This will send an email to you as soon as I reply to your topic, allowing me to solve your problem faster.
Please do not install any new software during the cleaning process other than the tools I provide for you. This can hinder the cleaning process. Please do not perform System Restore or any other restore.
Instructions I give to you are very simple and made for complete beginner to follow. That's why you need to read through my instructions carefully and completely before executing them.
Please do not run any tools other than the ones I ask you to, when I ask you to. Some of these tools can be very dangerous if used improperly. Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.

All tools we use here are completely clean and do not contain any malware. If your antivirus detects them as malicious, please disable your antivirus and then continue.
If during the process you run across anything that is not in my instructions, please stop and ask. If any tool is running too much time (few hours), please stop and inform me.
I visit forum se... Read more

Read other answers
RELEVANCY SCORE 58.8

Most unusual problem occurs when I close a folder on my desk top - I get an active blank web page with the address "about:blank". If I hit the home icon I go directly to my normal google.news home page. Since I usually don't want to be on the internet at the time, all I have to do is close the page to get off-line, but it is very frustrating.

For example, if I open and close the following d/t folders, I get the "about:blank" web page: My Docs; My Computer; My Network Places; Recycle Bin; Short-cut to Program Folder. It also occurs if I create an empty d/t folder and open/close it.

My O/S is Win XP-Home and rest of my system is available in my user profile. I have run AdAware SE, Spybot S&D, CCleaner & RegCure to no avail.

Your advice would be most appreciated.
 

A:Unwanted "about:blank" web page

Read other 10 answers
RELEVANCY SCORE 58

Hello:

I need some serious help with this one. I am running Windows XP Pro version 2002 SP 2, and Internet Explorer 7 (version: 7.0.5730.13). I can't get rid of IE7 search page redirections; my IE7 search page selections are redirected to Ads.

In the past three days my computer has been infected with this behavior. The IE Browser contains a "search toolbar" (there seems to be no way to not display it), and regardless of whether I do Internet searches by typing in the Toolbar editbox, or I navigate out to www.google.com or yahoo and then perform any type of search, once the search page has been displayed - then any selection made by me, of one of the items on that search page, will cause a redirection away (from the url where it was supposed to go) out to some totally unrelated ADvertisment-related web site.

The redirections do not go to the same AD site each time, but out to random and varied AD sites, so it is hard to characterize (one Ad page that comes up with some frequency is www.theclickcheck.com ).

I ran the HiJackThis tool, and attempted some cleanup of 1 "BHO" (browser helper object) item that looked like it had no useful purpose. I also ran Malwarebytes Anti-Malware and it did not find any problems at all for me to cleanup. I will post the logs of both of these below. I also ran an AntiRootkit tool, and that displayed a bunch of things ("hidden file" items) but none of them were recommended for removal. I also had uninstalled G... Read more

A:Help: Can't get rid of IE7 search page redirections

I also ran DDS.
Here is the DDS output log file:
_______________________________

DDS (Ver_09-09-24.01) - NTFSx86
Run by Derek at 17:16:20.90 on Sat 09/26/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.5.0_12
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1378 [GMT -4:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Microsoft S... Read more

Read other 3 answers
RELEVANCY SCORE 58

Hello:I need some serious help with this one. I am running Windows XP Pro version 2002 SP 2, and Internet Explorer 7 (version: 7.0.5730.13).In the past two days my computer has been infected with this behavior. The IE Browser contains a "search toolbar" (there seems to be no way to not display it), and regardless of whether I do Internet searches by typing in the Toolbar editbox, or I navigate out to www.google.com or yahoo and then perform any type of search, once the search page has been displayed - then any selection made by me, of one of the items on that search page, will cause a redirection away (from the url where it was supposed to go) out to some totally unrelated ADvertisment-related web site.The redirections do not go to the same AD site each time, but out to random and varied AD sites, so it is hard to characterize (one Ad page that comes up with some frequency is www.theclickcheck.com ).I ran the HIJackThis tool, and attempted some cleanup of 1 "BHO" (browser helper object) item that looked like it had no useful purpose. I also ran Malwarebytes Anti-Malware and it did not find any problems at all for me to cleanup. I will post the logs of both of these below. I also ran an AntiRootkit tool, and that displayed a bunch of things ("hidden file" items) but none of them were recommended for removal. I also had uninstalled Google Toolbar (which had been on my system), but with this now gone my IE7 Browser window still displays a &quo... Read more

A:Help: can't get rid of IE7 search page redirections

I also ran DDS.
Here is the DDS output log file:
_______________________________

DDS (Ver_09-09-24.01) - NTFSx86
Run by Derek at 17:16:20.90 on Sat 09/26/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.5.0_12
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1378 [GMT -4:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft S... Read more

Read other 5 answers
RELEVANCY SCORE 58

Hi

I have a problem. My office has many labs, but from a single lab when someone prints a word document onto a particular printer, it gives out an extra blank page. This blank page is not seen in the print preview unlike which was discussed in the previous forums.

This problem has been encountered only for word documents but not for .pdf files. I have tried even with a single page of word printing, it gives out another blank page. Can anyone resolve this problem. I dont think its the problem with the printer because it works well with other labs and .pdf files from this lab too. Anyways its a HP Laserjet 5SiMX.
 

A:Word document prints an extra blank page but that blank page is not seen in preview

Is the printer in question the default printer for the PC in that lab? Print preview shows how the document would appear based on the settings of the default printer - using another printer can cause changes such as this.
 

Read other 1 answers
RELEVANCY SCORE 57.6

Especially with google search results, links redirect to ad based websites.
DDS (Ver_10-12-05.01) - NTFS_AMD64
Run by Cory Cline at 23:04:10.41 on Fri 12/10/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3835.2395 [GMT -6:00]
============== Running Processes ===============

C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\atieclxx.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\windows\system32\taskhost.exe
C:\window... Read more

A:Random internet web page redirections

Hi CorySCline, and welcome to Bleeping Computer.Download OTL.exe by OldTimer to your Desktop.Close all windows and double click OTL.exe.In the "Custom Scans/Fixes" window (under the light green bar) paste the following in bold:

netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

Click Run Scan and let the program run uninterrupted.When the scan completes, it will open two Notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Post both logs in this thread.You may need to use two posts to get it all.

Read other 2 answers
RELEVANCY SCORE 49.6

Hey guys,

I have a client at my workplace who has some problems in Internet Explorer 7 on a Windows XP desktop system.

You see, every time my client wanted to print out something, he/she usually goes into print preview. From there, there is a blank page on the first page, but there is some text on the second (and subsequent) pages. He/she is trying to print from a pop-up window with the menu bars and buttons in place.

I have to experiment and play around with the zoom buttons and even change it from portrait and landscape. My client is trying to print some reports and statistics for the VOIP lines on the administration page. How do I fix the particular issue?

My best guess is to upgrade the entire IE web browser to 8 (or maybe 9). Any other suggestions?

A:IE7 - print preview shows blank on first page, but some text on 2nd page

Hello simon726,

I would recommend upgrading to IE8. IE9 is not compatible with XP.

Also is the computer running the latest service pack?

Read other 3 answers
RELEVANCY SCORE 49.6

I hope that title will be searchable
I have a problem when opening a new tab on iexplorer 11. Once opening a new tab, it shows a blank page but I would like it to open to the new tabs page, the page that shows the ten most commonly used web pages. I go to internet options, click on the tabs button, make the change from blank page to new tabs page, click apply, ok, ok. All works well for a while but it then somehow mysteriously changes back. I can not seem to get the desired change to remain. Any suggestions?
Thanks
 

A:Solved: ie 11, opening new tab, new tabs page keeps switching to blank page

Read other 6 answers
RELEVANCY SCORE 49.6

I am trying to help out a friend with their computer that was infested with a few trojan horses and a virus or two. I have fixed most of it, but still have problems when trying to use intenet explorer. Here is the HijackThis log file:

Logfile of HijackThis v1.99.1
Scan saved at 7:00:02 PM, on 9/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ntzc32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program File... Read more

A:Solved: about:blank page replaced by bogus search page

Read other 6 answers
RELEVANCY SCORE 49.6

I often right click in IE (I'm actually using Avant, a kind of IE mask I guess) and select Create Shortcut. It puts a shortcut and my desktop to that page. This mysteriously stopped working. The icon appears on my desktop with the page title and all, but when I double click it, it just opens up my browser and loads about:blank. In the shortcut file's properties, it just says:

Type: Internet Shortcut
Description: (the title of the page)

and then gives me the file's size, location, etc., but it doesn't list the URL anywhere. It's just getting on my nerves having to copy a page's URL to a text file on my desktop if I want to remind myself of something.
 

A:Simple but annoying. Web page shortcuts just open a blank IE page.

Sounds like you have been hijacked by about:blank. Go to this website that will help you remove it.
http://www.pchell.com/support/aboutblank.shtml
 

Read other 1 answers
RELEVANCY SCORE 49.2

Hey guys and gals

I recently have been fighting IE with my home page defaulting back to blank page. I recently read a previous thread on this and I think I have the same problem. Here are my HJT and CWS reports, HEEEEELLLLLLP!

Thanks a lot.

Gerry
Logfile of HijackThis v1.97.7
Scan saved at 8:25:57 PM, on 5/7/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\LXSUPMON.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\ScanSoft\PaperPort\PPWebCap.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Easy\TV Capture\RemoteCtl.exe
C:\Program Files\Sierra Im... Read more

A:IE Home Page switching to blank page, I think I've been hijacked

Read other 7 answers
RELEVANCY SCORE 49.2

Hiya folks

Just a quick question really... How do I stop Opera loading a blank page as the homepage? I have set the home page to Yahoo four times, then re-opened successfully each time, then a bit later on it loads a blank?

Any suggestions?

Any other hints or tips for opera would be appreciated coz I only installed it today, for a change and coz it has the tabbed feature which is good - for me.

Thanks for looking

A:Opera 9.02 Loading Blank Page As Home Page

Hiya folks How do I stop Opera loading a blank page as the homepage? I have set the home page to Yahoo four times, then re-opened successfully each time, then a bit later on it loads a blank? Any suggestions?Are you meaning when you click the "New tab" button?? That it loads a blank page? Or when you open Opera that after a few times it opens with a blank page? If you mean from "New tab" those are always blank. Any other hints or tips for opera would be appreciated coz I only installed it today, for a change and coz it has the tabbed feature which is good - for me.Thanks for lookinghttp://operalover.tntluoma.com/ For tips on how to use Opera. Scroll down to the bottom of the page and look on the right side for the "30 Day Series".

Read other 2 answers
RELEVANCY SCORE 49.2

Hi Team,

We have our company intranet site set as the default page for all users ,the users are using IE 11 ,but for some of the users when the laptop is started and when they open IE, the
page shows blank ?why does this happens

TechGUy,System Administrator.

Read other answers
RELEVANCY SCORE 49.2

Hi. I know about the common problem of people creating blank pages when they don't mean to, but this is not that problem. If I open a new document and type a few characters, it will print a completely blank page, followed by a page with my characters. If I print a 10-page document, it will print 20 pages - 10 blank interspersed with the 10 pages of the document. It prints the blank page first. I've looked through the Word prefs and don't see anything that could cause this. I deleted Normal.dot Any ideas very welcome.
 

A:Word 2007 prints a blank page for every page

Welcome to the forum.

I am guessing your header is messed up. You can look into editing it and saving over top of the normal.dotx but I would just suggest finding the normal.dotx and renaming it normal.old and see if that fixes your problem.
 

Read other 3 answers
RELEVANCY SCORE 49.2

Hi my wife’s friend’s computer is having a problem, first it didn’t have any virus scan problem – so I installed AVG 7.0. AVG ran clean with the current updates. I also ran Adaware and Spybot with current updates and they removed some spyware programs.

My problem now is when I try to access Microsoft’s Windows Update page all I get is a BLANK white screen with a message "Done” in the bottom left corner. I get the same results when I go to the Symantic Security Check web page and I click on the GO button to do the security check, it open a new BLANK white window???

Could this Virus, spyware or just a setting???

HP Pavilion 7955
P4 1.5 ghz
XP Home (SP1)
256 MB RAM
32 MB HD with 6 GB used.
MSN Toolbar

Please help, thanks.
 

A:IE blank page accessing windows update page

The blank windows in IE problem was solved by running a IEfix utility, which can download from here.
 

Read other 1 answers
RELEVANCY SCORE 49.2

Hi there.
I recently had a trojan dnschanger on my laptop. I tried using malwarebytes program to remove it several times and then gave up and sent it in to get repaired at a shop in town. They told me there was no infection and sent it back to me. I reran the test and sure enough it was gone. but...

What had originally made me try using malwarebytes to scan ( avg, spybot s&d, and adaware did not find anything) was that my browser was acting strange. When I do a Google search and click on one of the results, it will load a blank page saying 'done' in the bottom corner, then after 5 seconds or so it will then load the page i wanted.

For instance, I click on "hxxp://en.kioskea.net/forum/affich-115088-using-web-browser-page-loads-but-screen-blank" search result and it puts this:

"hxxp://www.google.ca/url?sa=t&source=web&ct=res&cd=1&ved=0CAcQFjAA&url=http%3A%2F%2Fen.kioskea.net%2Fforum%2Faffich-115088-using-web-browser-page-loads-but-screen-blank&rct=j&q=browser+loads+blank+page+then+&ei=W6JzS6q_G8PgnAec2vmyCQ&usg=AFQjCNHiczGbtPYRraVBQ_7hGcgLE2f6LQ&as_acct=9dm612l7ldg&cr=s6ar6l7"

into the top bar and sits on the blank,'done' page for 5 or 10 secs then goes to the "hxxp://en.kioskea.net/forum/affich-115088-using-web-browser-page-loads-but-screen-blank" page after.

It is driving me crazy. This is doing it in firefox 3.5.7 and also in ie 8.0.7600.16385 - (i rarely use ie)
On a side not... Read more

A:browsers load blank page, then page requested

Find out if you have bad DNS servers :Click Start Menu, type cmd in the search box. When you see cmd.exe, right click on it and select Run as administratorIn the command prompt type, ipconfig /allThen copy paste the DNS servers in your next reply.You are using Canadian Google. try using the main Google site by typing http://www.google.com/webhp?hl=en in your web browser and then search through it.

Read other 3 answers
RELEVANCY SCORE 49.2

I have read the merijn Cool Web Search chronicles and used Ad-aware, Spybot, and CWS shredder to remove the spyware from my computer. Everything works, until i restart, where the about:blank page reappears with the CWS.Searchx spyware.

Here's the HijackThis! log:
---------------------------
Logfile of HijackThis v1.98.2
Scan saved at 2:56:50 PM, on 8/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\System32\ibmpmsvc.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\tp4mon.exe
D:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
D:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\AIM\aim.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Documents and Settings\Frank and Liz\My Documents\Spyware Removers\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://D:\DOCUME~1\FRANKA~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://D:\DOCUME~1\FRANKA~1\LOCALS... Read more

A:CWS.Searchx variant - about:blank page not so blank

Read other 16 answers
RELEVANCY SCORE 48.4

would someone please help me with this problem?

I click on a new tab and it comes up as a blank page rather than your first home page.

so I change the setting in: tools > internet options > tabs > settings > when a new tab is opened, open..... ok ok).

It works fine during the current session, however after a shutdown and restart, new tab opens as a blank page again.

any help greatly appreciated.

the problem started after I uninstalled and then reinstalled avg free antivirus (trying to see if that was messing up fios media manage).

I have windows 7 home premium 64 bit.

thanks,
Chas

A:click new tab and it comes up blank page rather than first home page

Does pressing Ctrl+T keys help?

Read other 9 answers
RELEVANCY SCORE 48.4

My OS is Windows 7, My problem is I've tried to load a website on (Chrome , IE, Firefox ) and for example pinterest is one on the many sites that not load correctly.It will load the header and show a white page on tab and all links are blank will not load. I'm defiantly not a tech girl so please be patient with me Thanks in advance !
 

Read other answers
RELEVANCY SCORE 48

When I close down after using the internet often there is a web page remaining from a site I have not been on. It is a sort of pop-up advertising on-line gambling. Is it malware? nothing is showing on a routine scan.

A:unwanted web page

Hello and welcome to TSF.

We want all our members to perform the steps outlined in the link given below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply.

Read other 1 answers
RELEVANCY SCORE 48

I just bought this computer and already I am plagued by the unwanted "Conduit search" page and have thus far, been unable to get rid of it. Can anyone shed some light on this?

Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, 64 bit
Processor: Intel(R) Atom(TM) CPU D525 @ 1.80GHz, Intel64 Family 6 Model 28 Stepping 10
Processor Count: 4
RAM: 2037 Mb
Graphics Card: Intel(R) Graphics Media Accelerator 3150, 256 Mb
Hard Drives: C: Total - 138525 MB, Free - 102719 MB;
Motherboard: Acer, Veriton Z290G
Antivirus: PC Cleaner Pro, Updated: Yes, On-Demand Scanner: Disabled

Actually, I am using Vipre Premium Anti Virus
 

A:Unwanted web page

Read other 12 answers
RELEVANCY SCORE 48

Windows xp, ie8.

I have been getting //rvzr-a.akamaihd.net coming up on my pc and I cannot see how to get rid of it, apart from the cancel X at the top of the screen.
Where is it coming from and can I stop it as it takes over the computer when loading.
 

A:unwanted web page

Read other 12 answers
RELEVANCY SCORE 48

I have started getting an unwanted web page show up on my pc.  I'm running windows 7.  In the tab it says (Sponsorship) on the address line it says    m.goodthingshappen.com.  Warns me that my computer is in poor shape.  That it is a certified Microsoft partner and wants me to download a repair tool.  I've run Malware and bytes, CC cleaner. Search and Destroy.  So far it doesn't seem to hurt any thing but it keeps coming back. yipnyapThanksEdit: Moved topic from Windows 7 to the more appropriate forum. ~ Animal

A:Unwanted web page.

 
 Install and run MBAM
Information about MBAM: http://www.bleepingcomputer.com/virus-removal/how-to-use-malwarebytes-anti-malware-tutorial
If this scan has been done, please post the log into your next reply.
===================================================
 
  Running TDSSKiller to obtain log
 
Note: Don't cure or delete a threat, but choose skip for all instead.
Please download TDSSKiller from here and save it to your Desktop
Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters

In the Additional options: Check Detect TDLFS file system
Click Start Scan and allow the scan process to run.
Choose for all threats to Skip for all of them.
Click Continue
Please post the TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically c:\)
===================================================
 
 ESET Online Scanner
 
Note: If your AV is blocking Eset online scanner, please temporarily disable your AV.
 
I'd like us to scan your machine with ESET OnlineScan This process may may take several hours, that is normal.
Hold down Control and click on this link to open ESET OnlineScan in a new window.
Click the  button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on esetsmartinstaller_enu.exe to download the ESET Smart Instal... Read more

Read other 12 answers
RELEVANCY SCORE 47.6

Hello:

Need help, please! My new laptop is running Win 7 Home Premium (64 bit) -- also, IE 9, Windows Live Mail and Windows Live Hotmail. Here's the problem:

When composing a new email, it looks fine until it is sent. The recipient, however, recieves a message riddled with unwanted "blank" lines between paragraphs and lines of text. This is not acceptable, especially for business correspondence.

No issues were experienced with my first 3-4 emails. Since then, the problem has been consistent. Might I have inadvertently changed a setting somewhere?

Many thanks for your advice. Dennis M.

A:Unwanted blank lines in outgoing emails

  
Quote: Originally Posted by Dennis Miller


...IE 9, Windows Live Mail and Windows Live Hotmail...


Are you using Hotmail through the program (WLM) or through the browser (IE9)?

Read other 3 answers
RELEVANCY SCORE 47.6

Hi..I'm new here so please bear with me.

Every time I switch on my pc and go online I get a web page come up that has replaced my home page of choice. A search engine I've never heard of and don't want.
I go into settings/general and delete it and put in my own web page of choice only to have it reappear next time I go online. Is there any way I can get rid of this for good and keep my home page of choice permenantly.

Thanks for any advice.
 

A:Unwanted home page ?!?

Read other 9 answers
RELEVANCY SCORE 47.6

Can anyone help me get rid of unwanted home page & pop-ups. If have run NoAdware and HijackThis which shows all sorts of R0, R1, O2 and O4 lines in log file which means little to me.

These programs can't seem to fix these unwanted statements in registers however ? How to get rid of it ? Tx, Michiel
 

A:How to get rid off unwanted home page ?

Read other 16 answers
RELEVANCY SCORE 47.6

I seem to be infected with some malware that directs my browser to an unwanted web site--'Adultfriendfinder'.

In Safe Mode, I have run updated versions of AVG, Ewido, Microsoft Antispyware, Spybot S&D, CW Shredder, Adaware w/ VX2, Spyware Blaster, Spyware Guard. Also ran Windows Update for all fixes, etc.

I previously had a program listed in Add/Remove Programs called Mysearchbar, but I couldn't uninstall it, and a search of My Computer didn't locate it. However, the last set of scans seems to have removed it.

Also--possibly related--I am unable to enable Internet Connection Firewall on my dialup connection. I get a message 'Cannot enable shared access. Error 1060: the specified service does not exist as an installed service.' I don't know how to deal with this.

I'm using Windows XP Home.

Here's the Hijackthis log. Any assistance would be much appreciated.

Andy Mason

*******************************

Logfile of HijackThis v1.99.1
Scan saved at 8:26:29 PM, on 2/3/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\... Read more

A:Unwanted web page--possible hijack?

I am currently reviewing your log. Please note that this is under the supervision of an expert analyst. I will be back with a fix for your problem as soon as possible.

Please be patient with me during this time.

We also suggest that you Subscribe to this thread to be notified of fixes as soon as they are posted by our Team. You can do this simply by clicking the "Thread Tools" button located in the original thread line and selecting "Subscribe to this Thread".

Read other 12 answers
RELEVANCY SCORE 47.6

I am running a Dell desktop win xp pro sp 3. I have a worm that I cannot remove. It will open additional pages in IE that seem to be selling or advertising info. I have the pop up blocker on. Using Avast professional addition. I have done a full system scan and a boot time scan, both indicate signs of a trojan but cannot delete or move. I also run updated versions of Ad-Aware and Spybot search & destroy and delete what they find. Also have run CCleaner and delete what it finds. I did have the postcard.exe virus/worm, but now it appears to be gone, but the IE pages still open as well as some pages won't open at all. Please advise what more I can do. Thanks - Kevin

A:Unwanted Page redirects and pop ups

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

Please copy this page to Notepad and Save it to your Desktop in order to assist you when carrying out the following instructions.

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding.
Ensure that there aren't any opened browsers when you are carrying out the procedures below.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

------------------------------------------------------

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper.

------------------------------------------------------

Please uninstall the following via Start->(or My Computer)->Control Panel->Add or Remove Programs if it still exists:

Viewpoint Media Player<<This is ... Read more

Read other 2 answers
RELEVANCY SCORE 47.6

My operating system is Windows 98. I have an annoying website that comes up as my homepage when I connect onto the internet. It doesn't always come up immediately either. What I see first is a message box saying that a plugin is in progress and then the unwanted webpage pops up. How can I once and for all get rid of this website file???

Thanks for any help.
undefined

A:Unwanted home page

Your Homepage has been Hijacked. Go to the security site on this Forum .
Download and run Hijack this and post your log in the Hijack this site and one of the Security Experts will help you.

Read other 2 answers
RELEVANCY SCORE 47.6

Hi everyone,
I have Win98 and IE6. I have inherited a very unsavoury web page as my home page and I cannot get rid of it. I reset the homepage to yahoo or similar but every time I boot up this other home page (porn)is loaded. I have tried deleting it and searching for it. The search said it was in temp internet files so I deleted it but still it comes back every time I start up. Very frustrating. Please help.
Regards
Ray.
 

A:Unwanted Home Page

Read other 6 answers
RELEVANCY SCORE 47.6

I need to know how to get rid of search-world page which comes on atuuomaticaly when ever i start up

 

A:how to rid computer of an unwanted page

Hi, and welcome to the TSG forum

i suspect you have spyware/virus

have you carried out any scans

anyway
post a hjt log
HIJACK THIS:

Download and copy hijackthis to its own folder , it makes backups so keeping them separate and available can be useful.

Note the Spyware tools websites are very often under attack and so I have provided more than 1 location to download from:

http://www.tomcoyote.org/hjt/
http://209.133.47.200/~merijn/downloads.html
http://www.thespykiller.co.uk/
http://www.majorgeeks.com/download3155.html
http://aumha.org/downloads/hijackthis.exe
http://www.thewhities.com/
http://www.sherrylynn.us/privacypolicy (this has an older version 1.97 - if you can not get to any of the above sites)

Close all open windows and open Hijack This. Click “Scan”. When the scan is finished (it only takes a second), the scan button will change to “Save Log”.
Click on “Save Log” and then save it to NotePad.
Click on “Edit” – “Select all” – “copy” and then “paste” into the thread.
DO NOT FIX ANYTHING wait advice from one of the many security experts in this forum.

I currently do not have the skill/competence to advise and poor advice can be far more damaging to your PC with this software, and so I will be unable to add any advice on the log and so will nolonger be replying to your post with regards to the HJT issue, so please have patience and wait for one of the secruity experts to provide further detailed advice

i will however, be notifie... Read more

Read other 1 answers
RELEVANCY SCORE 47.6

I notice that others have posted something about the subject unwanted page that pops up when I go to some site (like CNET) and click a Download button. The URL of the page is http://rvzr-a.akamaihd.net/sd/wrap-0.01.html?u=http%3A%2F%2Frvzr-a.akamaihd.net%2Fsd%2Fapps%2Ffusionx%2F0.0.3.html%3Faff%3D1700-1016. It is always blank, but pops up in front of the page I'm on. I have run Malwarebytes and SuperAntiSpyware, and they find nothing. I have HiJackThis on my laptop and can run and save a log, but per the instructions, will not do that until asked.

I notice this only happens with Firefox, my default browser. It does not appear if I use IE, so I suspect something has altered the configuration file for Firefox.

What is this thing and how do I stop it from appearing?
 

A:akamaihd.net - unwanted page

Read other 3 answers
RELEVANCY SCORE 47.6

Hey,
ive got this problem with my internet explorer browser.
Each time i open it, my home page isnt the one that ive set, its changed to something about spyware.
I know that i have gotten spyware on my computer that is causing this, however none of my scans are showing anything.
Is there a way to delete it from the regisrty?
Any help would be great
Cheers

A:Unwanted Home Page

Hi,
please go through the 'Having problems with spyware/viruses' in my sig. This will help you get rid of the hijack, and remove all the spyware, and hopefully even speed up you computer.

Read other 1 answers
RELEVANCY SCORE 47.6

Hey all,

I don't know how this happened, but I now have this default home page for some weird search portal which I don't know how to get rid of.

I can change to another page through tools->internet options then home page, but every time I restart the computer, it will go back to this default unwanted home page.

I have a feeling you need to change something in the registry, what I don't know - anyone have an idea out there or any other methods of getting rid of this.

I have tried using a few spyware detectors to no avail either.

Thanks - any comments very much appreciated
 

A:Unwanted Home Page

Read other 10 answers
RELEVANCY SCORE 47.6

I have windows xp and MSIE 7. AOL 9.0 SE was installed on my computer (stuck with dial-up due to geography). When I now open MSIE, the AOL Toolbar page is the opening page. Even though it is supposed to not appear once use, it continues to come up as the opening page in MSIE, even though my home page is Google. I understand that removel of the AOL toolbar does not solve this problem and compounds the problem with error messages in MSIE. Help please!

Read other answers
RELEVANCY SCORE 47.6

IE page scrolls when I press up/down arrows on my keyboard. Any way to get rid of this nuisance?

I have IE8, Vista SP2.

Read other answers
RELEVANCY SCORE 47.6

Hello.
Hope someone can help. As I search on Google, a automatic unwanted new page pops up with an MSN Search on it. How can you turn this off or stop it from happening? If it wasn't MSN one would say its a malware of some kind. Any one know how to deal with it?
Thanks in advance.

A:Unwanted MSN Search page

MSN still has redirects though, and that makes what it is doing malicious (because you are not in control of how your system is working).

Check your hosts file and see if there are any entries there that shouldn't be. That's the easiest way to redirect a search. Did you download any MSN toolbars or anything?

Read other 2 answers
RELEVANCY SCORE 47.6

Logfile of HijackThis v1.97.7Scan saved at 12:14:35 PM, on 4/28/04Platform: Windows 98 SE (Win9x 4.10.2222A)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\INOTASK.EXEC:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\INORT9X.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\MOUSE\SYSTEM\EM_EXEC.EXEC:\WINDOWS\LOGWAT95.EXEC:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\REALMON.EXEC:\WINDOWS\SYSTEM\QTTASK.EXEC:\WINDOWS\OLEHELP.EXEC:\PROGRAM FILES\HANDSPRING\HOTSYNC.EXEC:\WINDOWS\SYSTEM\DDHELP.EXEC:\WINDOWS\SYSTEM\PSTORES.EXEC:\WINDOWS\SYSTEM\SPOOL32.EXEC:\PROGRAM FILES\WINZIP\WZQKPICK.EXEC:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXER1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://any-find.com/sp.htmR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://any-find.com/sp.htmR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://any-find.com/index.htmR0 - HKLM\Software\Microsoft\Intern... Read more

A:unwanted home page

You are infected with a variant of the CoolWebSearch.Download CWShredder from the below link and unzip it into a directory. Start CWShredder and click on the FIx button to have it remove all CWS infections it finds.Download CWShredder from:http://www.merijn.org/files/cwshredder.zipAfter you download the program, unzip it into a directory. Make sure all browser windows are closed and double click on the cwshredder.exe to start the program. When the program is loaded click on the "Check for Update" button, and if it finds an new version it will download it. You should then double click on cwshredder.exe again and click on the "FIX" button (not the "Scan only" button) and let it scan your computer.To get the best results it is recommended that you run it in safe mode. Reboot windows and press F8 at boot/windows startup, usually right after the beep. Then select safe mode.A tutorial that goes over this process step by step can be found here:How to remove CoolWebSearch with CoolWeb ShredderOnce that is completed you should follow these steps in order to clean your computer of Malware which can include Viruses, Trojans, Worms, Spyware, Hijackers and DialersStep 1:Download Spybot and Adaware from the following locations and install them. You should run both programs and clean up what it finds. This is to gaurantee that you find the most malware you can installed on your computer.Before running the scans on both programs, it is mandatory that you updat... Read more

Read other 2 answers
RELEVANCY SCORE 47.6

Hi... I bet you guys get this a lot...... but somehow I've become stuck with some po*y searchco as my home page and I don't want it. Dunno how this happend. Can someone please show me how to get rid of it...
 

A:Unwanted home page ?!?

Click on the link in my signature to download Hijack This. Download it and click "Save".

It’s very important that you save it to its own folder on your hard drive, such as program files (not temporary files or the desktop), so that it can create proper back-ups and be able to restore them if necessary.

The downloaded program will be a .zip file. Extract the .exe file from it and save in the permanent folder you just created.

Click on Hijackthis.exe to launch the program.

Click the "Scan" button when the scan is finished the scan button will become "Save Log" click that and save the log.

The log should open in notepad. Click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.

DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
 

Read other 1 answers
RELEVANCY SCORE 47.6

Really strange happening!!~
Hi guys
I use Windows 98

Until yesterday - whenever I logged in to the net, the first page I saw - and the one I wanted by default - was the www.megalink.net web site. (That is our ISP). But something happened yesterday that is very distressing. Since then, when I click on the I.E. icon to log-on , what comes up is a Google page - with the headline "I can Find It" at the top. And the URL in the address line is www.icanfindit.net/?aid=577.

So I went into IE Tools, Internet options, General and sure enough, that new URL is in the address line for the home page address. So I changed it back to the Megalink URL, clicked APPLY and OK. Then I manually changed the URL in the IE screen to Megalink, and it came up. I went back into Tools, Internet Options and clicked save current.

But when I log off and back on - the same problem recurs. And while the Google page is loading, this line appears on the task bar at the bottom of the screen: http://4-counter.com/?b=crue

Any thoughts?

anxiously - StanC
 

A:Unwanted starting page on log-on

Read other 16 answers
RELEVANCY SCORE 47.6

When I start the computer, it shows the desktop for a second, then a file opens. I just have to click the red "X" in the top right corner and it goes back to the desktop, but how do I get rid of the file that opens. It is called "common" and there's nothing in it.
 

A:Unwanted page at boot up.

What program is "common" opening in? Or is it a file folder?
Click the Help menu to see what program -- if it just says About Windows, then it is a folder that is opening in My Computer. If so, check the address bar to see the full path to this folder. If the address bar is not displayed, click View | Toolbars and check it. If your system is not set to display the full path, you can click the down arrow at the right end of the address bar, and that will let you see just where this "Common" folder is located. paste that path into your next reply.
Or, you can click Tools | Folder Options..., View tab, and check one of the Display the full path in the ??? bar options.

Whether it's a folder, or a file opening in a program, we need to find out where it's starting from. Copy and paste the following code into Notepad, then save it on your desktop as Runkey.bat Be sure you set the Save As Type: setting to All Files. Then double click the file. A notepad window will open up. Paste the contents into your next reply.

Code:
if exist regkey.txt del regkey.txt
>> regkey.txt reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /s
>> regkey.txt reg query "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /s
>> regkey.txt reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer" /v DesktopProcess
Start regkey.txt
Exit
Also, check the startup folder (Start | All Programs | Startup) to see if ... Read more

Read other 3 answers
RELEVANCY SCORE 47.6

Hi, I followed your advice for Scrollisalegend about an unwanted web page... It was the same page that was plague-ing me, so I followed the same directions. Here is my Hijackthis log...
Logfile of HijackThis v1.97.3
Scan saved at 1:43:28 PM, on 11/3/2003
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\ptsnoop.exe
C:\WINDOWS\SYSTEM\DLA\TFSWCTRL.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\DCFSSVC.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\IGFXTRAY.EXE
C:\WINDOWS\SYSTEM\HKCMD.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\KODAK\KODAK EASYSHARE SOFTWARE\BIN\EASYSHARE.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOBNZ08.EXE
C:\PROGRAM FILES\LOGITECH\WINGMAN PROFILER\LWPEVNTM.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOEVM08.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOSTS08.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\UNZIP WIZARD\UNZIPWIZ.EXE
C:\TEMP\UNZIPWIZ\HIJACKTHIS.EXE

R0 - HKLM\Software\Microsoft\I... Read more

A:unwanted web home page also

well if you had the same problem as Scrollisalegend then you had a CWS hijack, running the programs from that thread cured the problem, but to ensure you stay cured
read here and download the security updates mentioned at the bottom
http://www.spywareinfo.com/~merijn/cwschronicles.html
 

Read other 1 answers
RELEVANCY SCORE 47.6

Hi-------- Got infected with with something that changed my home page. I have been unable to correct the problem thru Internet options, general tab. Is there some other way to acomplish this task?
 

A:unwanted home page

You will need to download hijackthis and run a scan. Also spybot

see here:
http://www.webattack.com/get/hijackthis.html

http://www.safer-networking.org/index.php?page=download

remember, please check these out BEFORE you start downloading.
When you have run a hijackthis scan then post the logs here and soemone will help you out.

These programs will show you what has taken over and then those with good knowledge of reg entries and viruses will be able to tell you what to fix. good luck
 

Read other 2 answers
RELEVANCY SCORE 47.6

Can anyone help with removing the pagebreak on page 1 (so as to bring page 1 and 2 together?) thanks
 

A:unwanted page break

Hi ibm.

Not sure what overall result you're looking for, but try this.

1. Select the entire table.

2. Table > Table Properties > Row: uncheck "Specify height", check "Allow row to break across pages".

hth,
bomb
 

Read other 3 answers