Over 1 million tech questions and answers.

Webbrowser redirector thewebtimesnet

Q: Webbrowser redirector thewebtimesnet

I keep getting directed to thewebtimesnet, id happily kill the person who created it as its a right bugger, i had tried removing this which did cause a few problems, all of which seem to have been sorted now, . net framework removed somethign some how butits stillcontinueing tore direct me.

i read the instructions and hope i have followed them to an understandable level, your help is very kind.

Sorry if i have done this in correctly but im pretty sure its how you had wanted.

Thankyou very much for the help.


dds.txt :
============== Running Processes ===============
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\DAEMON Tools Pro\DTProShellHlp.exe
============== Pseudo HJT Report ===============
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mDefault_Page_URL = hxxp://en.uk.acer.yahoo.com
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\windows\system32\ActiveToolBand.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - No File
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe
mRun: [eRecoveryService]
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
TCP: DhcpNameServer =
TCP: Interfaces\{81753DDB-A7E4-4323-A2A7-616E66921587} : DhcpNameServer =
Notify: igfxcui - igfxdev.dll
Hosts: www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\valued acer customer\appdata\roaming\mozilla\firefox\profiles\x7fuq7xq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=937811&p=
FF - prefs.js: network.proxy.http_port - 1
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\program files\google\update\\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_HBLiteSA.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\valued acer customer\program files\dna\plugins\npbtdna.dll
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-6-21 64512]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-8-14 366640]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-2-18 22712]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-6-20 2152152]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-12-15 1153368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2006-11-2 167936]
S3 CM1063264;C-Media CM106 Like Sound UDAX Interface;c:\windows\system32\drivers\CM106.sys [2009-6-30 1307136]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-6-20 15232]
S3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\system32\drivers\smscirda.sys [2006-12-2 31232]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-09-09 17:11:04 476904 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-09-09 17:11:04 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-07 14:33:17 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-09-07 14:33:17 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-09-07 14:33:17 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-09-07 14:33:17 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-09-07 14:33:17 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-09-04 19:11:24 388096 ----a-r- c:\users\valued acer customer\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-09-04 19:11:24 -------- d-----w- c:\program files\Trend Micro
2011-08-24 02:01:40 5943120 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{adeeb3be-c7fe-43a4-912d-cdb7386679d8}\mpengine.dll
2011-08-24 02:00:37 5943120 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\updates\mpengine.dll
==================== Find3M ====================
2011-07-06 18:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 18:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-28 14:14:36 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-06-21 14:17:47 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-06-20 09:31:32 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover
Windows 6.0.6000 Disk: WDC_WD1200BEVS-26RST0 rev.04.01G04 -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T0L0-0
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x85FBA5DC]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x85fc07b8]; MOV EAX, [0x85fc0834]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x82427F3B] -> \Device\Harddisk0\DR0[0x85B1EAD8]
3 nt[0x824B07E2] -> ntkrnlpa!IofCallDriver[0x82427F3B] -> [0x852F8928]
5 acpi[0x8064332A] -> ntkrnlpa!IofCallDriver[0x82427F3B] -> [0x8526F9D0]
\Driver\atapi[0x85E27CB0] -> IRP_MJ_CREATE -> 0x85FBA5DC
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x132; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IdeDeviceP0T0L0-0 -> \??\IDE#DiskWDC_WD1200BEVS-26RST0___________________04.01G04#5&302caf91&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi -> 0x8520c1f8
user != kernel MBR !!!
sectors 234441646 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
============= FINISH: 21:15:22.09 ===============

c: report from gmer

GMER - GMER - Rootkit Detector and Remover
Rootkit quick scan 2011-09-15 21:26:07
Windows 6.0.6000 Harddisk0\DR0 -> \Device\Ide\IdePort0 WDC_WD1200BEVS-26RST0 rev.04.01G04
Running: gmer.exe; Driver: C:\Users\VALUED~1\AppData\Local\Temp\pwxciuoc.sys
---- Disk sectors - GMER 1.0.15 ----

Disk \Device\Harddisk0\DR0 [email protected] code has been found <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior

---- Devices - GMER 1.0.15 ----

Device \Driver\atapi \Device\Ide\IdePort0 8520C1F8
Device \Driver\atapi \Device\Ide\IdePort1 8520C1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 8520C1F8
Device \Driver\a94klvh7 \Device\Scsi\a94klvh71Port3Path0Target1Lun0 861A51F8
Device \Driver\a94klvh7 \Device\Scsi\a94klvh71 861A51F8
Device \FileSystem\Ntfs \Ntfs 8520D1F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Device\Ide\IdeDeviceP0T0L0-0 -> \??\IDE#DiskWDC_WD1200BEVS-26RST0___________________04.01G04#5&302caf91&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

---- EOF - GMER 1.0.15 ----

Preferred Solution: Webbrowser redirector thewebtimesnet

I recommend downloading and running DAP. It can help sort out any driver and firmware related issues on your system

It's worked out well for many of us in the past.

You can download it direct from this link http://downloaddap.org. (This link will open the download page of DAP so you can save a copy to your computer.)

A: Webbrowser redirector thewebtimesnet

Hello and welcome. Please follow these guidelines while we work on your PC:Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
Please do not run any scans or install/uninstall any applications without being directed to do so.
Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

P2P - I see you have P2P software (BitTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Please see this post for more information. I recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at TSF are complete.

Download TDSSKiller.zip and extract TDSSKiller.exe to your desktopExecute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found then ensure Cure is selected. Important - If there is no option to "Cure" it is critical that you select "Skip"
Then click Continue > Reboot now
Once complete, a log will be produced in c:\. It will be named for example, TDSSKiller.
Post that log, please.
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link

Double click on ComboFix.exe & follow the prompts. If you have trouble, stop and post back. Do not try to repeatedly run comboFix!
When finished, it will produce a report for you.
Please include the following in your next post:TDSSKiller log
ComboFix log

Read other 16 answers

Hey all. I'm currently using IE 6 and wanted to try out some other browsers since I heard IE has a bunch of security holes, slower, etc. What I wanted to know is, which browser do you like the best? I'm thinking about buying Opera 7 but I don't know yet. And I don't mind buying. Well, I gotta sleep and I'll check this tomorrow. Thanks in Advance.

A:Which WebBrowser?

Read other 10 answers

Hi Everyone

I am trying to fix a friend's computer. He had 4 trojans on his pc that he found in January and didn't tell anyone. He is running OS: xp pro 1a.......RAM: 512......cant remember the information about his hard drive except it's an AMD.

The error message he is getting is this:

"cannot open web browser, error message "Downloading from site:res//C\WINDOWS\System32\shdolc.dll/offcancl.htm"

I have tried system restore, it will dont work for him, also tried a reinstall of windows, still no go. I tried to run hijack but it will not read from his floppy disk. I will try to save hijack to a cdrom and run it when I go there on Tuesday.

I would appreciate any suggestions that you can give me. You guys are always so helpful. Thank you.


A:Webbrowser Won't Load

Install avast home edition on your friends pc from a cd rom or jump drive and then run avast antivirus. Get rid of the Trojans then go to firefox and get rid of his IE or Netscape.

This worked for me, but someone else may have a better idea.


Read other 3 answers

When i got to some sites i get this error message "Unable to locate 'SHDocVwCtl.WebBrowser' make shure the internet path was typed in correct" something like that and i dont know how to get rid of it help would be apriciated.


I have the same problem whats the fix ??

Read other 1 answers

Good morning,

My internet explorer has been hijacked and all pages I try to visit result in a page not able to be displayed. I have my hijackthis log and definitely see a lot of bad things in it but I would like some expert advice on what I should fix. Here is my log - I appreciate any help you can provide. Thank you.

Logfile of HijackThis v1.96.1
Scan saved at 9:19:47 AM, on 8/30/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Fi... Read more

Read other answers

I use the following Code to find string in A HTMl in WebBrowser control, but
if HTML support Frame then I get the error (run-time error "438"). any idea
how to fix this error.

Public myfindFirst As Boolean
Public oRange

Private Sub cmdFind_Click()
Dim sSearch As String
If myfindFirst Then
Set oRange = WebBrowser1.Document.body.createTextRange
sSearch = txtFind.Text
If oRange.FindText(sSearch) Then
cmdFind.Caption = "Find Next"

myfindFirst = False
MsgBox ("Search string " & txtFind.Text & " not found.")
End If
Call oRange.Move("character")
sSearch = txtFind.Text
If oRange.FindText(sSearch) Then
MsgBox ("Finished searching Document for string " &
cmdFind.Caption = "Find"
myfindFirst = True
Exit Sub
End If
End If

End Sub


A:vb6 WebBrowser control

Read other 7 answers

some one please tell me how to get my
Shdocvwctl.webbrowser working again i can not for the life of me
figure it out
it pops up on me all the time saying its not working or something
what do i do

Read other answers

I sometimes get an "error message" when attempting to access various websites.

The message is:

"SHdocVwCtl.WebBrowser" "Make sure the path or internet address is correct"

Does this need to be "fixed" and of so how?



I searched Google to find a cure for you but there is not much mentioned There is a reference to vb Accellerator Would this apply ?

Read other 1 answers

When I get to some sites I get this error message "Unable to locate 'SHDocVwCtl.WebBrowser' make sure the internet path is correct"
I cannot find the answer to this, does anyone know the problem and/or how to solve it? Thanks


If you use the "search" feature of this forum you will find this question has been asked before. I went to Google and typed in "SHDocVwCH" without the quote marks and I found where this happens if you are using a browser other than IE. If you use IE to access the site you are looking for it should work just fine. Are you using AOL or Netscape?

Read other 3 answers

Hi, I hope someone can help me.

I have Norton Internet Security 2003, and use As-aware on a regular basis.

Now my browser start page has been changed to: http://topotun.com/index.htm and together with that I get a bunch of unwanted bookmarks to pornsites and a few spyware commercial pop-ups.

I have used Hijack this and get the following log (I use hijack this from a folder in my documents, not on the desktop) :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Fisch\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://topotun.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {2B284CB0-9E5E-4627-A4BE-FECBD5BF9F5B} - C:\WINDOWS\System32\necodd.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ... Read more

A:Hijacked webbrowser (yes, me too)

Read other 13 answers

I have several browsers loaded into my system, the most compatable one to use with my computer is the internet explorer. There is a problem of a pornographic add informing me that I have been infected and prompting me to buy their spyware equipment, this happens each time I try to use this home site page. I have spyware protection, spyware bot, and AOL McA.,and sweep the system upon each internet return. This page still remains. I need access to run certain files that are a part of my main system, It's not the best, just needed. I keep this site blocked by default, to keep my family from prompting this site and encountering porn related strong-armed sales tatics. Does anyone have any suggestions?

A:webbrowser adware

Read other 7 answers

Hey, I am having trouble with some ad-ware and I can't for the life of me figure out what exactly it is or how to get rid of it.

Basically, I get this progam called NULL WebBrowser open (can be seen in attachment) and about 10 minutes later, it floods my screen with popups from adultfriendfinder. I'll close all of them including this "NULL" program, however, it will reappear in some time.

I've run Lavasoft ad-aware, Spybot and the online Trend-Micro scanner - nothing has removed this. Searching on google, I cannot seem to find information about it. Any help?

Thanks in advance

A:NULL WebBrowser

Still having the problem...any advice?

Read other 1 answers

I have a computer that is infected. I have ran spybot s&d, combofix, and malwarebytes on it to no avail. When I try to do a type anything into the webaddress it takes me to uniquesearch8. I have a hijack this logfile. Please let me know if you would like me to post it. ThanksHere is the Hijack this logLogfile of Trend Micro HijackThis v2.0.2Scan saved at 10:46:22 AM, on 12/7/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16915)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exec:\program files\common files\protexis\license service\psiservice_2.exeC:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exeC:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Analog Devices\Core\smax4pnp.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exeC:\Program Files\Windows Live\Messenger\msnmsgr.... Read more

A:Hijacked webbrowser

I have corrected this problem and removed the virus im pretty sure. However now my print spooler stops responding. I have it set to restart. It appears the virus corrupt a file in relationship to my print spooler any help would be greatly appreciated. I ran a chkdsk/f but that did not fix it. thanks

Read other 3 answers

hen using Firefox or IE, clicking on search results from Google redirects to Btcar.com sometimes to other search engines also.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:27:12 PM, on 10/2/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.20544)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\McAfee\MSC\mcmscsvc.exec:\program files\common files\mcafee\mna\mcnasvc.exec:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exeC:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exeC:\Program Files\McAfee\MPF\MPFSrv.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\UAService7.exeC:\WINDOWS\system32\svchost.exeC:\PROGRA~1\McAfee.com\Agent\mcagent.exeC:\WI... Read more

A:Webbrowser Hijacked

Hi,* Please download FixwareOut from the following site:http://download.bleepingcomputer.com/lonny/Fixwareout.exeSave it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log.

Read other 7 answers


I'm running:
a)Vista 64BIT and UAC is turned off with IE8 and
b)Win XP 32 bit with IE 6

Under b) I can display a specific webpage (which includes som JS and Ajax) without any problems
Under a) I can't display the page

Are there any known security issues? Do I enable some security settings within Vista or IE8?


A:Webbrowser- Changes between Vista and XP

IE8 is still buggy, i would recommend that you use IE7. However, what page won't it load? What security software is installed?

Read other 4 answers


I need some help in clearing this hijack that have been affecting my web browser and setting to some weird page everytime I on Internet explorer.

Below is the logfile created using Hijackthis. I am posting the whole logfile for a complete view on my system, however I have narrowed the problem to these 2 processes:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lastchaos.in.th/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by MOOzilla

I have tried deleting these 2 files but it will reoccurred once I on IE again, is there a way to remove them completely??

Thanks in advance for the help!!

The logfile is attached as below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:29:21 AM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
... Read more

Read other answers

This webhijacker was caused from a megaupload toolbar that I downloaded a month back. I uninstalled it because It was causing problems such as pop ups and redirects. Now every time I try and go to a web page it redirects me to http://www.megaclick.com/404. Help is appreciated. Here is my hijackthis log if it helps.

(Windows XP Home)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:42 PM, on 12/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOW... Read more

A:WebBrowser Hijack

Read other 7 answers

An error appears that contains something in regard to 'SHDocVwCtl.WebBrowser error loading'. When we click on OK, the entire system just locks up on us. What can we do to fix tis error?

A:SHDocVwCtl.WebBrowser error

im stumped- try running windows update maybe?

Read other 1 answers

Whenever i go to apple.com and try to watch something in my browser using quicktime it crashes, looked in the log and found this in the description.Felaktigt program iexplore.exe, version 6.0.2900.2180, felaktig modul quicktimeh264.qtx, version, felaktig adress 0x00054c8a.It's in Swedish but i hope that doesn't matter. Does anyone know whats happening, i have googled it but didn't find mutch and i have reinstalled both graphics drivers and quicktime.Please give advice Edit: Moved topic to the more appropriate forum. ~ Animal

Read other answers

Hello all,

I was recently victim to the VIRUS PROTECT scam. Thanks to the posts herein, I believe I successfully removed most of the malware. However, I still have a persistent and sporadic bug that redirects my web search links to a rogue url. Here is an example of an attempt to link to search result from "cod liver oil" :

(http://alfasort.com/search.php?q=cod%20liver%20oil )

The alfasort string is the ubiquitous prefix. I am using Microsoft's Internet Explorer. I am running Kaspersky Internet Security suite.

Can anyone here graciously offer some direction on how to eliminate this annoyance?

Thank you.


A:Webbrowser High-jack

Hello MtnGntx, welcome to the forum.Need to know exactly what you did ... so Did you do/run these? How to remove VirusProtect or Virus Protect (Removal Instructions)Next, please download RogueRemover and save to you Desktop. (compatible with Windows 2000, NT, XP, Vista)Double-click on rr-free-setup.exe to install in C:\Program Files\RogueRemover and follow the prompts.During installation an icon will automatically be created on your Desktop.If the program does not open after installation, double-click on the RogueRemover icon to launch.Select "Check for Updates" and click Download if any are found.Wait for the updates to finish downloading, then Close the update window.Select "Scan" and follow the onscreen directions to remove anything found.If nothing is found, exit RogueRemover.If RogueRemover finds something, it will present a list of detected items.Click "Remove selected", then Yes at the prompt.Wait for the removal to complete and then close RogueRemover.If using Windows Vista, be sure to Run As Administrator Download and scan with SUPERAntiSpyware, Free for Home UsersDouble-click SUPERAntiSpyware.exe and use the default settings for installation.An icon will be created on your desktop. Double-click that icon to launch the program.If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from HERE... Read more

Read other 6 answers

I used to have aol as my ISP and I cancel and uninstall all the aol there was in my computer, but my web browser in the internet explorer still showing aol instead of windows any ideas of why this is happening if there is nothing else to ramove in add/remove programs. Can somebody please help is it hidden somewhere else.
Thank you very much in advance.

A:Need Help Removing AOL as my webbrowser - And NewDotNet

Read other 16 answers

Im using C# under Visual Studio .NET 2003 for Windows 2000. Im trying to use the MS WebBrowser control on my form but without much luck. Documentation is sh*t.

Im connecting to a URL which is in frames (frame one's name="one", frame two's name="two"). I need to access the first frame's HTML contents, in particular, the <form name="myForm"> area which has the element <input name="ConnectID" type=text>. I would like to alter the "ConnectID" value as well as programmtically click the form's SUBMIT button.

How do I do all of this with the WebBrowser control, or the IHTML interface.


Read other answers

Hey guys,
I'm looking for a very lightweight browser that has minimal system impact while gaming + streaming.

I'm streaming a 720p/45fps stream and game performance is nice so long as I do not have my addon-heavy Firefox browser open. I suspect it's the annoying flash that has the severe system resource penalties.

I need those addons on that browser to be productive so I'll need either a Firefox lite mode which can be launched with the click of button (without hassle), or a completely different browser that supports Flash.

I only need that browser to watch the quality of my stream, and to chat with my viewers + browsing lulz pages during my downtime (1+5~tabs=).
Or can I bypass this in another way?
I currently have process priority manager where I have set flash and plugin container to 'low' priority. But this doesn't really help for that particular issue.

Flash is not generally slowing the system down from get-go, but after several minutes; while having my own stream feedback open and playing: the system slows down.
Soon as I close my browser, performance is back up.

W7 x64
GTX670M, i7 3610, Browser & Game on SSD (128gb - 90%)

edit, add:
Oh, and I'm looking for qualified experience opinions in general.

A:Lightweight webbrowser with flash

Perhaps try SlimBoat portable:

Best Web Browser for Mac, Linux and Windows. Fastest Cross-platform Internet Browser.

Configuration can be a little confusing!

Opera Portable 64bit vs Cyberfox 64bit vs SlimBoat Portable 32bit
Memory usage - all of the above with one tab open. Opera and SlimBoat both run from folders on desktop

Memory usage - Cyberfox (installed) one tab open, Opera (run from desktop) one tab open,
SlimBoat (run from folder on RAMdisk) five tabs open.

Start using flash and Memory usage roughly doubles.

Read other 8 answers

My browser was defaulting to msap and I can't open any applications without getting an unkown error. Any suggestions? Here is my log.......

Thanks in advance.

Logfile of HijackThis v1.99.0
Scan saved at 1:33:32 AM, on 12/20/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP1 (5.00.2920.0000)

Running processes:
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\Program Files\America Online 7.0\waol.exe
C:\Documents and Settings\Administrator\D... Read more

A:error with desktop and webbrowser need help

Read other 16 answers

Hello, recently my web browser. On google whenever I search for something I click the link and it would take me to a website called daytotals.com, I close that and try the link again and it would take me to another website. This has been happening for the past week or 2 and I have gotten quite sick of this.
I've tried spyware searches, malware, anti-virus scans and everything. They haven't found anything, even if they do it doesn't fix up my problem.


Deckard's System Scanner v20071014.68
Run by JayJay Ciantar on 2008-01-05 21:39:41
Computer is in Normal Mode.

-- Last 5 Restore Point(s) --
31: 2008-01-04 23:08:05 UTC - RP68 - Installed Ad-Aware 2007
30: 2008-01-04 22:46:59 UTC - RP67 - Removed AdwareAlert
29: 2008-01-04 22:43:10 UTC - RP66 - Installed AdwareAlert
28: 2008-01-04 22:18:09 UTC - RP65 - Device Driver Package Install: Lexmark Inkjet Drivers Printers
27: 2008-01-04 22:16:18 UTC - RP64 - Device Driver Package Install: Lexmark Imaging devices

-- First Restore Point --
1: 2007-12-22 12:14:26 UTC - RP34 - Windows Update

Backed up registry hives.
Performed disk cleanup.

-- HijackThis (run as JayJay Ciantar.exe) --------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------

Emulating logfile of Trend Micro Hijac... Read more

A:My webbrowser has been Hijacked by daytotals! :(

Hi, sorry for the delay.

If you still need assistance, please post a fresh main.txt log

Read other 1 answers

I have a very strange error, if you can call it that. It's mostly occurring at random AFAIK, but when it happens it keeps going for quite a while.

The problem is; when I click a link anywhere, the browser(firefox in my case) might decide to not load it. There's no error page, the spinning thingy doesn't even spinn. And it won't load unless I click the correct amount of times(usually more than 2). Too many and it resets the counter.

As this is a laptop, I've moved between school and home, this occurs at both places so I narrowed the search down to my computer.

Posting HJT log, incase you can find anything here.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:00:38, on 2008-05-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.ex... Read more

Read other answers

I'm posting here on recommendation of the support engineer I've been in contact with at
[link removed]
Developer Community Visual studio. I am unable to post links with my account to it. it has an id of 642834
On some computers I can with a very simple .net application cause a silent crash of the whole application by attempting to print using the WebBrowser component. On those computers I get the same behaviour when attempting to print using Internet Explorer.
In a simple application where I've dragged out a button and a WebBrowser in the Visual Studio designer I add the following in the code behind

public partial class Form1 : Form
public Form1()

private void Button1_Click(object sender, EventArgs e)

with the button click event being bound to Button1_Click of course.
This causes a crash. Looking in the Event Viewer I see the following message at the same time of the crash.

Faulting application name: WindowsFormsApp1.exe, version:, time stamp: 0xaf8b1ae6
Faulting module name: MSHTML.dll, version: 11.0.17134.829, time stamp: 0x8429479d
Exception code: 0x4000001f
Fault offset: 0x00d65391
Faulting process id: 0x4c98
Faulting application start time: 0x01d5388ff4e51d42
Faulting application path: C:\Users\perhyy\source\repos\WindowsFormsApp4\WindowsFormsApp1\bin\Debug\Windows... Read more

Read other answers

Application REQUIRES persistent cookies to be set, however cookies has to be deleted when application terminates
One way is to delete IE cookies itself 
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 2 
Is there any API to delete cookies only with respect to specific WebBrowser Control process
If the only option is to delete IE cookies itself,is there a way to do it silently without getting IE clearing cookies dialog

Read other answers

please help, please tell me how to identify and remove the adaware that hijacked my webbrowser.i am not able to identify the hijacker of my browser. at first it seemed to be websearch but then at second glance it does not appear to be websearch.below you can see the hijack log.the problem appears to be: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web--search.comit sets my homepage to www.web--search.com, but in practice i am being directed to www.msn.com. I have tried several adaware removal programs (adware 6.0, scan spyware, BPS spyware adaware remover), but all don't seem to work.i have also tried the suggestions from http://www.boredguru.com/modules/articles/...php?storyid=130, but since it does not appear to be websearch.com, they are of no use.I have also attached a pic of my screen with the search bar. You can see that it is not the same as the one of www.websearch.com.Logfile of HijackThis v1.99.0Scan saved at 22:22:23, on 2005-1-4Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32 ... Read more

A:webbrowser hijacked by unidentifiable hijacker

Adaware 6.0 is an old version and no longer supported. Please download and install Adaware SE 1.05 from here.http://www.lavasoftusa.com/software/adaware/Install the program and launch it.First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files. Exit Adaware.Please make sure that you can view all hidden files. Instructions on how to do this can be found here:How to see hidden files in WindowsRun Hijackthis again, click scan, and Put a checkmark next to each of these. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web--search.comR3 - URLSearchHook: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\webdlg32.dllO2 - BHO: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\webdlg32.dllO2 - BHO: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)O3 - Toolbar: Search Bar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\webdlg32.dllO11 - Options group: [!IESearch] !IESearchO16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Download...bridge-c284.cabO16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -O18 - Protocol: mp3 - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)Reboot your computer into Safe ModeR... Read more

Read other 1 answers

Hi Everyone!I have obtained this Elitebook 8560W and itīs running Windows 10 Pro 64-bit. The laptop has dedicated quickkeys on the top right corner. I want to change the "internet" key to open Chrome instead of Edge /IE. I have changed the default app in the Windows setting to Chrome. This did not do anything to the key. I have removed both Edge and IE from windows and the key is now unresponsive. How can I modify this to open Chrome? Can anyone help me with this? //Chri11e

Read other answers

I have an application which embed IE Webbrowser to display a Rich text editor based on CKEditor (which web based editor). But, on my computer it does not work because the policy security_HKLM_only is set to 1.
I've tried to reproduce on machine which I have administrator rights, when I set the key to 1, the editor does not work anymore and when I set the value to 0, it works fine.
I displayed the user agent of webbrowser by adding to my page this script: alert(navigator.userAgent);
The output:
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET 4.0C; .NET4.0E)

And the script: alert(document.documentMode); has the following output: 5.
I tried also to set my process in HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION to 0x2AF9 (IE11) but it does not work.

When I test on IE (not embedded  browser) it works fine.
Do you have any idea why the behavior is different between the IE and embedded webbrowser? and if there are some ways to bypass this behavior?

Thank you.

Read other answers

Hey any one got any ideas, when i start up my pc and try to open up my web browser weather its firefox or internet explorer it taking about 5 minutes or so but then when its open it works grand.

I've defraged the registery
defraged the hd
got rid of anything on my startup that does not need to be there
ran all updates with ms and antivirus software

O also this pc is nearly 5 years old with only 512 or ram, Pentium 4 so not to modern by any standards but still enough power to run web browsers and some speed.

any help would be great

thanks leon

A:Solved: Problems opening up Webbrowser

Read other 12 answers

I'm having problems checking my email. I go onto hotmail, and when I look at my inbox, my entire webbrowser closes out. What's up with that?

The only thing I did prior to that happening, is I was creating a rule for my Outlook box to delete messages with certain texts in the subject heading. But Outlook, on my computer, does not even connect to my hotmail account.

I doubt that's what caused it, but now I can't check my email with my computer.

Read other answers

I have started getting popups, search engine tool bars insert into my web browser, and my computer has slowed noticably. I saw a similar post by another user and I think I have a similar problem. I ran Hijackthis and removed a few references to "searchportal" (something like that). That took care of the hijacked webbrowser problem but I still have very poor performance. Also I notice that when I use alt + tab to switch between windows sometimes I notice that an icon for Java on the screen (even though I haven't opened Java). Can you help me get rid of whatever is affecting my computer?

Logfile of HijackThis v1.96.1
Scan saved at 10:17:49 PM, on 1/24/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:... Read more

A:hijacked webbrowser/spyware issues

Read other 11 answers

Hi!First time poster (and I'm Swedish so I'll apologize in advance for my english which isn't perfect).I have red the guide and tried to follow it as good as I can, but apologize if the post is not done according to the rules.Problem started yesterday when starting Firefox, before Firefox started I was greeted by this messagebox;When pressing 'OK' or closing the window, a new one popped up;After a few more clicks it start downloading files to 'C:\Users\Petra\appdata\Locallow\TMS' (It's also telling me what it's downloading and to where)If I check the downloaded files it is tagged by TopMarketSearch, Ltd. which could explain the name of the folder.If I keep clicking this seems to be going on forever.Thisvhappens with both Firefox and IE, Chrome however does not act like this.If I check the processes this window is spawned by firefox.exe or internet explorer. This also shows if I run Internet Explorer in the Kaspersky Sandbox where I can see that a new thread is spawned from iexplore.exe with the ID mentioned in the first box.If I close the browser the windows stops comming.Kaspersky PURE or AVG Free 2011 (now uninstalled) doesn't find anything.Any help would be greatly appreciated.Best regards,RichardDDS Log;.DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by Petra at 20:21:16,91 on 2011-03-07Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23Microsoft Windows 7 Home Premium 6.1.7600.0.1252.46.1053.18.28... Read more

A:Starts downloading files when starting a webbrowser

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you are unable to create a log because your computer cannot start up successfully please provide detailed information about the Windows version you are using: What we in particular need to know is version, edition and if it is a 32bit or a 64bit system. [/b]If you are unsure about any of these caracteristics, just let us know and we'll help you figuring it out. Please also tell us if you have your Windows CD/DVD handy.Please include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Even if you have already provided information about y... Read more

Read other 2 answers

Hey guys,

Sorry but I have very little experience in developing but here it goes.

I have an existing program and I have been tasked with adding a help section via HTML. I have the HTML help working but I wanted to try and integrate it in the app instead of opening IE. I'm stuck and clueless

Here is what I have so far (pretty much nothing) but I want to point the WPF control WebBrowser to a specific location and index.html file "\\mysrv\help\index.html"
<Page x:Class="AppName.PageHelp"
d:DesignHeight="768" d:DesignWidth="1024"
<RowDefinition Height="*"/>
<ScrollViewer Grid.Row="0" Margin="0">
<WebBrowser Height="768" Width="1024"/>
Like I said I'm clueless and I'm not married to what I have above so if there is a better control to use... Read more

A:Solved: Help in C# VS WebBrowser to open Index.HTML

NM i figured it out.

Read other 6 answers


I have web browser object on a windows form. I want to be able to acess the source of the file. As the web browser will be displaying only xml/rss I can not use the .DocumentText property as that gives a HTML formated version of the RSS.

I need to get acess to the pure source of the web browser (if you right click and select View Source. That displays only the xml)

Any Ideas would be great


Read other answers

In AOL and Internet Explorer, an error message often appears, stating: "Cannot find 'SHDocVwCtl.WebBrowser'. Make sure path or Internet address is correct." This message is under the heading, "Internet Explorer". I am running Windows XP and this message has been quite a nuisance. After the error pops up, I am sometimes disconnected from the Internet. Can somebody please help me fix this problem?

I run Ad-Aware 6 often, so I don't think its a spyware problem. Just in case, here is my HijackThis log file:

Logfile of HijackThis v1.98.2
Scan saved at 1:50:21 AM, on 8/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessD... Read more

A:Internet Explorer error: 'SHDocVwCtl.WebBrowser'

I am having the same problem - can anyone help? Unlike tool319, I am a beginner. Thanks in advance.

Read other 2 answers


I've had som big issues recently with trojans and spyware.
I use NOD32 (bought and legal) and it blocks the same trojans every day, the only one I can remember the name of right now is PrivacySet.B or something like that.

I get constant pop-ups, my webbrowser (firefox) stops loading pages now and then specially searchengines like Google stop working for me.

I performed the 5 steps you required before posting.

Step 1: Done, none of the programs were found.
Step 2: Ran the Pandasearch, it disinfected 3 files I think. It found a total of 25-30 infections including Virtumonde.
Step 3: Installed both the applications.
Step 4: Could not update, it says Code: 80070422 wich is weird, as I am logged in as Administrator on the only account in windows vista that I have.
Step 5: Ran Deckard's System Scanner and posted the main.txt log below and attached the extra.txt.

Deckard's System Scanner v20071014.68
Run by Jimmie on 2008-05-29 15:24:23
Computer is in Normal Mode.

-- Last 4 Restore Point(s) --
4: 2008-05-28 22:43:42 UTC - RP27 - Installed Ad-Aware 2007
3: 2008-05-28 14:18:57 UTC - RP26 - Microsoft Office Word Viewer 2003 installerades
2: 2008-05-28 14:07:22 UTC - RP25 - SPTD setup V1.50
1: 2008-05-27 10:19:14 UTC - RP23 - Last known good configuration

Backed up registry hives. ... Read more

A:Pop-ups, Webbrowser slow, internet searchengines stop working

Bump. Computers getting so bad, thankful for any help at all :/

Read other 14 answers

Help! I think I have a virus on my computer. I tried to download McAfee Virus Scan, but every time I try, I get an error message stating: "Cannot find SHDocVwCtl.WebBrowser. Make sure the path or Internet address is correct." What does that mean, and does it have anything to do with the reason I can't download McAfee?? Thanks!!!!

A:cannot download McAfee, SHDocVwCtl.WebBrowser error message

Are there any new programs running in task manager?

Just to be safe, download Hijack This:

Make sure it's in a permanent folder of your creation
Launch the program, run a scan
Then save the log file it creates
Copy and paste that log back into this thread

Read other 1 answers

The usually innocuous ads on my browser get replaced with very explicit ones. I downloaded several free malware search programs but I can't run them because they all fail to update when I first start them. If I try to paste the update url's into a webbrowser then I find that access is blocked.
Sounds like a very cunning piece of malware if it truly prevents me from downloading something to attack it with. I also noticed that when connecting to other sites I often see a 'resolving proxy' message before it eventually connects. Sounds like I have been hijacked. I have attached my dds file.

Thanks in advance for looking in to this.

A:webbrowser ads are hijacked and access blocked to malware repair sites

I was finally able to update Malwarebytes with the latest updates by connecting my laptop to my company's network whose firewall somehow foils `the virus blocking my access to update sites. Once I downloaded the updates and did a scan the virus was removed. See attached scan log

Read other 3 answers

After installing the Security Updates from the October 2016 Rollup/Quality Update. IE crashes when you open an .eml file. An application hosting a WebBrowser control (ieframe.dll) also crashes when doing that. This happens on Win7 and Win10 (maybe others
I couldn't test).
Here is the error: 
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<Provider Name="Application Error" />
<EventID Qualifiers="0">1000</EventID>
<TimeCreated SystemTime="2016-10-21T12:47:19.000000000Z" />
<Security />
<Data>C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE</Data>
<Data>C:\Windows\SysWOW64\ntdll.dll</Data> ... Read more

Read other answers

Okay, no logs. Our search engine links are corrupted into various irrelevant results. Sometimes a search produces a useful result, sometimes not. Google searches for Bleepingcomputer and Ford produced working links. A Google search for General Mills showed their corporate web address as the first link. When clicked, Firefox went to this address: h**p://whatsinnews.com/a1/search.php?qq=general+mills.

Malware Bytes says it repeatedly blocks outgoing attempts to connect to two malicious websites: and

What to do?

The hard drive was recently reformatted due to a similar problem.

Windows XP Pro + SP3
Malwarebytes, Microsoft Security Essential, Spybot Search and Destroy.
HijackThis is installed.


Someone insisted on installing Symantec in addition to MBAM. It conflicted immediately, running itself when I started a full scan in MBAM.

Symantec pulled up Trojan.Maljava and a generic "downloader" listed as jar_cache290828547...

MBAM claims 1 registry key was infected with "Trojan.FakeAlert.SA"
Symantec and MBAM have convinced themselves that they have quarantined and deleted these hacks. I will run the scans again in a little while and see what turns up.

Read other 18 answers

Working on a computer and having some weird issues.  It seems to only redirect in IE, not Firefox.  hosts file is clean.  Nothing reported by full licensed copy of Malwarebytes or Vipre AV software.  Advanced System Care also reports no errors.  Get IE redirect in normal and NO add-ons mode. 
Took this machine from client site and plugged into my network, no problems or redirects.  Took back to clients site and redirects were immediate.  Have manually added DNS entries of and at both sites but didn't seem to matter.
Any suggestions on next steps?
Thanks In Advance,
Never mind- found root kit with TDSSKiller that was causing redirect.  Not sure why it only happened at client site but ...... it works now!

Read other answers

Sometimes when i am online my computer goes to homes dot com when i type in google .

I have scanned with avg turns up clean everytime !

I scan with MBAM and its clean too !

super anti spyware found some objects yesterday and removed them . after that it comes up clean too !

below you will find my hijack this log

I hope this helps

need anything just ask .


Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything. We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. To help Bleeping Computer better assist you please perform the following steps:*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/419447 <<< CLICK THIS LINK If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.*************************************************** If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lo... Read more

Read other 4 answers

*I NO LONGER NEED HELP WITH THIS ISSUE Thank YouA couple times i have noticed I am getting redirected to a search engine/links site when ever i click a link. For instance, some times when i log in to facebook, i put in my info and press the login key, and it will redirect me to ask.com. Other times i will click a link from my school's website and it will redirect me to a random site with many links. It only happens sometimes but it just started recently. I'm not sure whats going on. Malwarebytes and Microsoft Security Essentials have found nothing. What is going on?DDS (Ver_10-03-17.01) - NTFSx86 Run by Britt at 21:27:59.21 on Sun 09/12/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.210 [GMT -5:00]AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exec:\Program Files\Microsoft Security Essentials\MsMpEng.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exesvchost.exeC:\WINDOWS\System32\WLTRYSVC.EXEC:\WINDOWS\System32\bcmwltry.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Common Files\Motive\McciCMService.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\... Read more


Hello , And to the Bleeping Computer Malware Removal Forum. My name is Elise and I'll be glad to help you with your computer problems.I will be working on your malware issues, this may or may not solve other issues you may have with your machine.Please note that whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.The cleaning process is not instant. Logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happen. Please reply using the Add/Reply button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, send me or a moderator a personal message with the address of the thread or feel free to create a new one.You may want to keep the link to this topic in your favorites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.-----------------------------------------------------------If you have since resolved the original problem you were having, we would appreciate you... Read more

Read other 2 answers