Over 1 million tech questions and answers.

Teen-biz.com IE Hijack/ Win Min Problem

Q: Teen-biz.com IE Hijack/ Win Min Problem

Hi, when I start my computer and run my IE, the startpage changes to teen-biz.com and a bunch of porn sites are added to my Favorites folder. IE will also open on its own periodically to some porn-site. Lastly, when I shut my computer down, I receive a Winn Min error ("can't end program . . . ").

I've run Ad-Aware, Spybot, SpyHunter and CWShredder but still the above garbage occurs. Can anyone please help? I appreciate any comments. Below is my Hijackthis output. Thank you in advance.

Running processes:
C:\WINNT\Explorer.EXE
C:\program files\timbuktu pro\tb2logon.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Jeremy\HijackThis.exe
C:\WINNT\system32\notepad.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA5} - (no file)
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA6} - (no file)
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA9} - (no file)
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAB} - (no file)
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAC} - (no file)
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAD} - (no file)
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAE} - (no file)
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {D319662B-D5BF-4538-ADF3-8D3E36362608} - C:\Documents and Settings\All Users\Application Data\X0ff\X0ff0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Tb2initPath] "c:\program files\timbuktu pro\tb2init.exe"
O4 - HKLM\..\Run: [TLogonPath] "c:\program files\timbuktu pro\tb2logon.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [msmrqprop.exe] C:\WINNT\system32\msmrqprop.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [msmrqprop.exe] C:\WINNT\system32\msmrqprop.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Access XP\Office10\OSA.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: winlogon.exe
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000000-0000-0000-1234-012398761234} (ClearStream Accelerator) - http://www.riversoftware.net/x0ff.cab
O16 - DPF: {03177121-226B-11D4-B0BE-005004AD3039} (UploaderCtrl Class) - http://members19.clubphoto.com/_img/uploader/atl_uploader.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {886DDE35-E955-11D0-A707-000000521958} - http://69.56.176.78/webplugin.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37813.4177083333
O16 - DPF: {ABD45F35-2E4C-44C0-A075-6EF1DE75398E} (accel Class) - http://www.riversoftware.net/x0ff.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gel.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = gel.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = gel.com

RELEVANCY SCORE 200
Preferred Solution: Teen-biz.com IE Hijack/ Win Min Problem

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

A: Teen-biz.com IE Hijack/ Win Min Problem

Read other 7 answers
RELEVANCY SCORE 62

Hello,
I hope you can help me.
My daughter is experiencing problems with her Windows ME machine. I've cleaned off what I could with Spybot and Adaware. I've also run Norton 2002 and the Micro trend on-line virus scan (although I'm not confident that the on-line scan made it to completion).

I'm seeing alot of modem activity, even when nothing else is running on her PC. She's getting icons on her desktop, pop-ups and spyware. Her machine is running very slowly and locks up on a regular basis.

I've run hijackthis and Hijackthis analyzer. The analyzer log is posted below:
Thanks in advance.
====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 3/2/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 7:41:39 PM, on 3/8/2005
Platform: Window... Read more

A:Parent of Teen needs help! HiJack log

Hi and welcome to TSF.

I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem a.s.a.p

Please be patient with me during this time.

Read other 11 answers
RELEVANCY SCORE 56

I have run Hjt and saved the log. I have also red the other posts I could find regarding this issue. It seems my problem is a bit different than the others.

I do have winlogon.exe in my startup folder, but I can not delete it. It says the file is in use. There are multiple user accounts on this PC, 3 to be exact. The log file from Hjt is below...

TIA
Vince

Logfile of HijackThis v1.97.7
Scan saved at 3:23:20 PM, on 12/16/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\WIN... Read more

A:New Win Min problem with teen-biz.com

Read other 11 answers
RELEVANCY SCORE 45.2

teen-biz has taken over the search engine; the home page, etc on Internet Explorer.

The log is shown
Logfile of HijackThis v1.97.7
Scan saved at 8:53:08 PM, on 12/8/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\SpyKiller\spykiller.exe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\home\Local Settings\Temp\Temporary Directory 1 for hijac... Read more

A:teen-biz

I would appreciate your help
 

Read other 2 answers
RELEVANCY SCORE 45.2

hey guys, everytime i start my computer my home page has been changed to teen-biz. also websites have been added to my favourites list. when i shutdown iget a window come up that says Win Min not responding. and sometimes it says NVIDEA twinwindow not responding. I have tried Spy-bot, adaware 6, cwshredder they get things sometimes but when i reboot its all backthere again. i tried Hijack this and this is what i got.
Logfile of HijackThis v1.97.7
Scan saved at 2:02:16 PM, on 28/11/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\InterVideo\Common\bin\WinCinemaMgr.exe
C:\Program Files\Common Files\InterVideo\SchSvr\SchSv... Read more

RELEVANCY SCORE 45.2

I have had trouble recently with my homepage and serch engines. They have all changed to some teen-biz page, and I am continually getting new sites in my favourites list, and all my sites are deleted. I have run Hijack this and CWShredder. I was wanting to know if there is anything else I need to do.
Thanks

Here is the log:
 

A:teen-biz bug

log posted so we can see it
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\NVIDIA\VI_GRM.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
C:\WINDOWS\SYSTEM\SYSTEM.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\UNZIPPED\HIJACKTHIS[1]\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.wynnumvikings.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://teen-biz.com
F1 - win.ini: load=C:\NVIDIA\vi_grm.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\... Read more

Read other 2 answers
RELEVANCY SCORE 45.2

I'm having the same problem as many others are. Teen biz defaults when i open IE and win min comes up when shutting down. I've included the hijack info that I scanned off of my machine.

Thanks in advance for your help

Logfile of HijackThis v1.97.7
Scan saved at 7:12:14 PM, on 1/6/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\Program Files\RealVNC\WinVNC\WinVNC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee Firewall\CPDCLNT.EXE
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\Program Files\McAfee\QuickCl... Read more

A:teen biz and win min

Get the CoolWebShredder from this site, update and run it with the browser closed. Then reboot and check and "fix" any of these entries which remain in HijackThis:

http://www.spywareinfo.com/~merijn/cwschronicles.html#cwshredder

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.search-1.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://teen-biz.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://teen-biz.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://teen-biz.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search-1.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.search-1.net/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://teen-biz.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://teen-biz.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.search-1.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = http://www.search-1.net/search.html
O4 - HKLM\..\Run: [WinAuth] C:\WINDOWS\winlogon.exe
O4 - HKLM\..\Run: [] C:\WINDOWS\winlogon.exe

O4 - Global Startup: winlogon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\... Read more

Read other 2 answers
RELEVANCY SCORE 44.8

i am posting on behalf of a friend who, unfortunately, due to being to occupied with family concerns, is unable to log on and post for herself. therefore, i am trying to find out whatever i can for her. her problem (or at least the most bothersome thereof) is being constantly & frequently bombarded by pop-ups & redirects apparently associated with http://teen-biz.com

she has already downloaded, installed and regularly updated and run spybot, adaware as well as hijack this. unfortunately she is still being tormented by having her children be subjected to the extremely profane visual & text attacks that teen-biz seems to feel compelled to launch at every opportunity. as you can see from the following hijack log, teen-biz was found:

Logfile of HijackThis v1.97.7
Scan saved at 11:43:52 AM, on 1/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.ex... Read more

A:teen-biz pop-ups & redirects

Read other 7 answers
RELEVANCY SCORE 44.8

My daughter is wanting a new laptop that will run the game Star Wars The Old Republic.
The system requirements are :
Processor: AMD Athlon 64 X2 Dual Core 4000+ / Intel Core 2 Duo 2.0 GHz or better
Operating System: Windows XP or later
RAM: 2gb
Video Card: min256 MB on-board RAM and support for Shader 3.0

I am looking at HP 17.3" HD+ Notebook 17-x047cl, Intel Core i3-6006U DC Processor, 8GB Memory, 1TB Hard Drive, Backlit Keyboard, Optical and need to know if it fits the requirements
 

Read other answers
RELEVANCY SCORE 44.8

I have an almost 13 year old granddaughter that is very good with logic puzzles and loves the computer and stated an interest in learning how to program games.
While I know my way around the PC, I've never done much in the line of programming. I am considering on buying her for Christmas a beginners guide to C++. My thinking is if she's going to learn she might as well gain some real life experience she can use as opposed to getting her a book on basic or something like that.
My question is two fold to you programmers. Is C++ going to be too difficult for a kid her age? And secondly any other recommendations for a simple C++ book or other suggestions if I'm not on the right path thinking about C++. I did find the MS visual C++ compiler that I downloaded for her and a beginners video from the MS website to supplement the book.
Any help will really be a appreciated.
Floyd
 

A:Help for my teen granddaughter

Read other 9 answers
RELEVANCY SCORE 44.8

From my teenage girl's computer, though I don't know what I'm looking at, I can see a huge difference in these logs between my computer and hers. It's acting really funny, as well!

Logfile of HijackThis v1.99.1
Scan saved at 2:29:53 PM, on 9/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\MyWay\bar\7.bin\mwsoemon.exe
C:\Program Files\winupdates\winupdates.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hdqqtkfydmaqwdnasek.net//...SOLoI9VCx.html
R0 - HKCU\Softwar... Read more

A:Hijackthis-what has my teen done?!

Hi and Welcome
It may help you if you print out or copy this page for easy reference.. Make sure to work through the fixes in the exact order its listed..These instructions only apply to HJT v1.99.1

Please Keep your browser and all open programs closed (except firewalls and antivirus) when you are carrying out the fixes..

Download any of the required programs before attempting to start any of the fixes.


Turn off System Restore instructions (WinXP)
Rightclick My Computer | Properties | System Restore | check ?Turn off System Restore?, <Apply>, <OK>. Reboot. When we have confirmed that your log file is clean, you may renable System Restore and create a new restore point.

SHOW HIDDEN FILES AND FOLDERS.
To show hidden files instructions (WinXP)
Doubleclick My Computer | Tools | Folder Options | View tab
Select Show Hidden Files and Folders
Uncheck Hide extensions for known file types
Uncheck Hide protected operating system files (Recommended)
Select Apply to All Folders | Yes | Apply | OK
------------------------------------------------------------------

If you hav'nt already done so,download and run AboutBuster & CWShredder (check for updates) for a preliminary cleanup first.Some files below may not be present after running the above programs.Full instructions below.




How to install and run CWShredder

Download CWShredder
Choose the stand alone version. This is free.
Save cwshredder.exe into its own directory, NOT in a T... Read more

Read other 1 answers
RELEVANCY SCORE 44

Hello, folks.
My teen can't get enough of MySpace, YouTube and associated activities. The more she uses them, the more I have to keep cleaning out Virtumonde, Smitfraude, etc. malware that keep repeatingly placed on my PC. I'm tired of the junk! How can she keep using her favorite sites without junking up the PC with malware? I am running Win XP, antivirus is Panda Internet Security (which I love 10x better than Norton or McAfee) plus I also clean out with Spybot often (probably need to do this more often). What guidelines can I give my teen to help prevent malware? She also IM's a lot, and I'm gonna tell her about not clicking on IM links.
Frustrated Mom

A:Keep Getting Reinfected When My Teen Uses Myspace

Do you use the Firefox browser? That will definitely help. You're more likely to get infected on myspace using Internet Explorer.

Spybot is pretty ineffective these days. It was decent several years ago, but now I'd recommend Malwarebytes or SuperAntiSpyware.

Read other 4 answers
RELEVANCY SCORE 44

Hi. Im brandnew to the forrum but i have a good question. I am an avid pc gamer but im only aloud to play teen rated games. Are there any decent teen shooters out? If so, are they recent with good graphics? Thanks!
 

A:Teen First Person Shooter

i play counterstrike source, thats rated mature, i realize thats your problem. I hope im wrong but there may not be any teen rated fps out there. Good Luck to you.
 

Read other 2 answers
RELEVANCY SCORE 44

Toshiba 1.8Ghz laptop
4 GB RAM (recent upgrade to memory 2x1GB, machine only sees 3GB, I can't find the cause, any advice most welcome)
160 GB HDD
Windows XP Media Center sp3

I recently 'cleaned' this computer and upgraded the memory. I left it with Eset running and it seemed fine until a 14 yr old nephew spent one session on it. When I heard about it, the browser was hanging without connecting. System control soon degraded to the point where Windows loads but that is it. Task mgr, file explorer, start button, browser... nothing works. Disk activity is evident but 'it' will not release the machine even after sitting off the ethernet wire for a substantial time after loading the OS. Safe mode available but 'it' blocks the run of Malwarebytes (though the app will load into memory). The only scans I could run were from within safe mode. not sure how useful that may be but RSIT outputs attached. I have DDS scan from safe mode I will place under separate post.

Best advice about next step please. Thank you for taking this under advisement.

A:Toshiba trashed by teen

here is the DDS scan outputs

thank you for helping with this problem.

Read other 2 answers
RELEVANCY SCORE 44

OK. I will attach the HJT log for my son's computer. It is running really slow and is constantly running low on disc space. He was using his computer in safe mode until I found out. I removed some of the crap that he had but have no clue what else there may be. Please help. Computer is only a few months old and should not have too many problems. Thanks....

Here is the LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:46:57 PM, on 2/29/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Pa... Read more

A:HJT Log for my Teen Son's Computer. ARRGG!

Why hasnt anyone replied? This computer is driving me nuts.
 

Read other 1 answers
RELEVANCY SCORE 44

http://www.amazon.com/Lenovo-15-6-Inch-Touchscreen-Laptop-59426255/dp/B00K6ZIFFG/ref=sr_1_1?ie=UTF8&qid=undefined&sr=8-1&keywords=lenovo++i7-4700hq+y50

It's actually over his budget... until his next paycheck, at which point it'll wipe out his savings account.
So before he blows everything he's earned this summer taking orders at a fast-food joint, thought I'd ask if this will be a great choice. It's a Lenovo Y50 laptop sold on Amazon. He looked at it in a Best Buy store where it costs nearly a hundred dollars more. He's a junior in high school this year, so use will be for any school related study/research rolleyes, facebook, Minecraft and he wants to get Skyrim/Elder Scrolls downloaded once he makes his purchase. I think the salesman said that this could be linked to his PS4 - I'm not a techie at all so I don't know that this is hugely important but my son seemed impressed.

I've read reviews dissing the screen. But we saw it in store and didn't think it looked as... unpleasant as some reviewers thought. The other negative thing I've read is something about having to press two keys on the keyboard to control the sound. Again, I don't think that that sounds like a big deal either.

I guess I'm wondering if there's something better for his money or is this actually dang good for $1250 plus tax from Best Buy? (I know Amazon's price is cheaper but hesitate to have to handle any troubles we ... Read more

A:My teen wants to buy this gaming laptop...

Read other 7 answers
RELEVANCY SCORE 43.6

Hi:
Not even sure if this is the right place. My pre-teen cousin installed WINAMP on my mother's computer.
1. Is this a legal program? Is it any good? Does it cost anything monthly?

2. Now The sound on her computer doesn't work. I get an error message from NullSoft. "bad direct sound driver. PLEASE INSTALL Proper drivers OR SELECT another device in configuration." Error Code 887800A

Anything yu can tell me about this or how to fix will be deeply appreciated.

Thanks. wildbill
 

A:Pre-teen installed unknown program?

Read other 8 answers
RELEVANCY SCORE 43.2

This website keeps popping up and I have run Adware and Spybot. It was also charging calls to my phone. I have put a block on my phone with the phone company and now have to send a letter an a email to dispute these charges. I have never been to that web site and it keeps popping up. I did read whre the average person can go remove this with help so Help. This is the information I get when I run spyware.

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-21-299502267-1078145449-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3
--- Spybot - Search && Destroy version: 1.3 ---
2004-05-12 Includes\LSP.sbi
2004-11-29 Includes\Cookies.sbi
2004-12-15 Includes\Dialer.sbi
2004-12-16 Includes\Hijackers.sbi
2004-12-15 Includ... Read more

A:Solved: Hard Core Teen Sex website

Read other 9 answers
RELEVANCY SCORE 43.2

Hello. I am new here but have been following these forums for a couple of weeks. I think the people [??] who create viruses should be treated like any other terrorist.

I have AVG and today when I opened my e-mail, I noticed a message labeled "Teen poll results" above a couple of other entries. So I used Shift and selected all three so I could delete them all at once. However Delete didn't work.

The AVG [Griswold] screen popped up and said it detected a virus. So I pressed "n" and even enter. Meanwhile, behind the AVG box, there was another box showing a file being downloaded. So I quickly clicked the Close X button for Outlook Express. I hope that cut it off at the pass.

So I have some questions:

1) Is there some way to select and delete something from my inbox without it starting to download?

2) Why didn't AVG stop this thing from down loading?

3) Assuming part of the virus downloaded, how do I find it and get rid of it?

That's enough for now. You guys are great.

-Peter
 

A:Teen poll results virus[?] + AVG + Outlook

Read other 7 answers
RELEVANCY SCORE 43.2

Help please. I have a tech savvy 16 year old son that has to use his computer to do his homework, but is abusing it. I need to be able to see how he is using it (sites/time/things he's doing) and ideally restrict the site "affimatively" to just the sites he needs to do his homework. I check history, but he's savvy enuf' to clear individual entries as he goes..... I've reat about Webwatcher adn SpectrePro but have no idea what's good and what he couldn't detect and remove... I'm not that technical.... help please!
 

A:Parent Control S/W for tech savvy teen

Read other 7 answers
RELEVANCY SCORE 43.2

Valis sent me for help. I have Windows 7. I have an administrator account. My son uses a standard account and does not know the password for the administrator account. My son has been visiting unwanted web sites. I need to find the easiest way to block him from visiting this type of site.
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: AMD Athlon(tm) II X4 635 Processor, AMD64 Family 16 Model 5 Stepping 3
Processor Count: 4
RAM: 5886 Mb
Graphics Card: ATI Radeon HD 4200, 256 Mb
Hard Drives: C: Total - 939685 MB, Free - 745733 MB;
Motherboard: Dell Inc., 04GJJT
Antivirus: GFI Software VIPRE, Updated and Enabled
 

A:Solved: teen and unwanted web sites Valis sent me

Read other 7 answers
RELEVANCY SCORE 42.8

I have a couple of older Dell laptops here of the Windows 98 vintage. They have more than ample hard disks and 64 megs of RAM. I'm thinking of turning them into NetBooks for a couple of 10- and 12-year-olds. The laptops both have good batteries USB ports and PCMCIA slots so wireless will be an easy task.

Here's the question: How practical a job is this and what OS would be best?

I know just a very little about NetBooks, mostly what I've learned by looking at them on the store shelves.
 

A:Turn an old Win98 laptop into a NetBook for pre-teen child?

Read other 6 answers
RELEVANCY SCORE 42.8

Hi

I am a dad who wants to give his rebellious pre-teen daughter some control on her laptop, like update iTunes or install games, but she cannot do such as a Standard User.

I initially setup her laptop with both of us (dad and daughter) as admin users. I wanted to be an admin user to help install updates, backup, and check for viruses, etc... Dad as "Home IT guy".

However, in her rebellious attitude over the last couple of months, she removed me as an admin; so, I had no way for login. Pissed IT dad.

IT dad took her laptop away for a week, demanded her password, created IT dad as admin and changed frustrated daughter into standard user.

All fine. No. Daughter wants to upgrade iTunes (admin login required), install games (admin login required), etc... (admin login required). Non-IT mom does not want to do IT stuff (i.e. "admin login required" stuff).

Is there a way to allow my daughter (degraded to Standard User) to have some admin privileges (to perform upgrades and downloads without "admin login required"), but without having the permissions from removing other administrators (i.e. IT dad)?

In other words, IT parents as Uber-Administrators and User children as Limited-Adminstrators (i.e., cannot remove a Uber-Adminstrator but can upgrade and download software)?

IT Dad wants to know, thx

jeff in seattle

A:Windows 7 Pro: Parent adminstration control and rebellious pre-teen

Sorry, I dont have an answer for you, but I'm in exactly the same boat. because I have three sons that install programs and updates like your daughter, that required me to intervene on a multiple-times-per-days basis I gave my kids administrative accounts on their own computers.

BIG MISTAKE!!

I use OpenDNS to prevent access to undesirable web stuff, and so I can have some semblence of knowledge of what is going on. But they hack, and they crack and they circumvent every bit of security I add.

Now I am considering setting them to standard users. And that means non-stop whining, negatively charged atmosphere, and daily interventions by me to install, update, remove and configure things on their PCs.

I feel for you. I hope someone here will be able to offer some guidance to us frustrated parents.

Tanya

Read other 4 answers
RELEVANCY SCORE 38.4

Does anyone know of a good simulation game on the order of Sims, but rated for a child of 10. She wants to be able to take care of a family, but her parents, of course, don't want all the teen rated material to be a part of it.

We would really prefer one we can buy and download rather than have to go out and get it.

Thanks for any suggestions.
Peg
 

A:Good simulation games not rated "teen"

Don't think there is any simulation games like the Sims.
 

Read other 1 answers
RELEVANCY SCORE 31.2

Logfile of HijackThis v1.97.7
Scan saved at 6:27:26 PM, on 6/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\d3cx32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\msey.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Melvin\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.everquest2.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.everquest2.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dellnet.com/
O2 - BHO: (no name) - {EFEB7B9D-B57D-A014-388E-9F8DEE9656A7} - C:\WINDOWS\system32\ntcb32.dll
O4 - HKLM\..\Run: [msey.exe] C:\WINDOWS\system32\msey.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwa... Read more

A:Pop-up problem & browser hijack problem log included.

First, please make a new folder to put your HijackThis.exe into. Anywhere on your hard drive is fine other than your Desktop or the Temp folder. We suggest you use C:\Program Files\HijackThis but feel free to use any name or folder you like. Unzip HijackThis again and save the contents (Hijackthis.exe) to the new folder you made. Then navigate to it and run HijackThis from there. This is to ensure it makes the necessary backups for recovery if needed.
Run Hijack This again and put a check by these. Close all windows except Hijack This and click Fix checked"

O2 - BHO: (no name) - {EFEB7B9D-B57D-A014-388E-9F8DEE9656A7} - C:\WINDOWS\system32\ntcb32.dll

O4 - HKLM\..\Run: [msey.exe] C:\WINDOWS\system32\msey.exe
Restart to safe mode.

How to start your computer in safe mode

First in safe mode click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Find and delete:

The C:\WINDOWS\system32\msey.exe file
Next navigate to the C:\Documents and Settings\Melvin\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Te... Read more

Read other 2 answers
RELEVANCY SCORE 30.4

Hi guys really hope you can help me out..im at my wits end...i have windows xp operating system on my fujitsu siemens desktop PC

i use PC guard antivirus and antispyware which is provided by my isp provider which is virginmedia in the UK.

PC guard has identified a spyware problem in my registry .I keep getting messages saying spyware has been detected and it has been deleted...but it does not appear to be solved..the problem is located at hkey_local_machine\system\controlset001\enum\root\legacy_tdssserv

i dont know if this other problem i have is related or not....my google search has been hijacked....i get redirected to ad sites every time a google search is done on the pc..also im prevented from accessing troubleshooting forums such as bleepingcomputer.com...i have had to use a laptop to join the forum to try to solve the problem...

can anyone out there please assist...
thanks

espuna

A:Spyware Problem And Or Hijack Problem

tdssserv.sys is a sign of a very nasty rootkit. IMPORTANT NOTE: One or more of the identified infections was related to a rootkit component. Rootkits and backdoor Trojan are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge. If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? Although the rootkit was identified and removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to... Read more

Read other 3 answers
RELEVANCY SCORE 30.4

Hey Guys, have a few problems here so will list actions and then results. I hope I have got this right this time but am having trouble accessing your web site to follow the links that you have with in "What to do first" section.1. Downloaded a torrent for avi conversion and AVG picked it as a virus and then shut-down, I think?2. Started getting this message all he time and a new page opening up with IE. I use Firefox as my default browser.3. ran both spybot and ad-aware spybot found many different items so I fixed them all ad-aware had great trouble running and after a re-boot would not run.4. I posted to the wrong section at bleeping and it was diverted and now firefox shuts down with a fault every time I click the link to where it has been moved.5. I had dss installed and have done the scan and will post it at the end of this explination.6. Running xp home7. I also have just noticed that ther is a text message in my taskbar saying "virus alert!"8. have run AVG three times with different results and Trojans found each time...when it comes to repair or remove the problems AVG informs me that the files are to large and I cant do any thing to remove tham other than delete the files them self, which I have done.9. Have also run systems mech and removed any junk and obsolete itemsOk here is the dss scan infoDeckard's System Scanner v20071014.68Run by me on 2008-07-20 13:17:42Computer is in Normal Mode.-------------------------------------------------------... Read more

A:Virus Problem And Hijack Problem

Logfile of Trend Micro HijackThis v2.0.2Scan saved at 13:42: VIRUS ALERT!, on 20/07/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware\aawservice.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\PROGRA~1\AVG\AVG8\avgwdsvc.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\HPZipm12.exeC:\Program Files\CyberLink\Shared files\RichVideo.exeC:\WINDOWS\system32\svchost.exeC:\PROGRA~1\AVG\AVG8\avgrsx.exeC:\PROGRA~1\AVG\AVG8\avgemc.exeC:\PROGRA~1\AVG\AVG8\avgtray.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Photolightning\autodetect.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\... Read more

Read other 14 answers
RELEVANCY SCORE 29.6

Hi guys, I'm new here and hope you can help me.. I got a hijacking problem I've read some other posts on this topic but, it ain't working (I can't seem to find any of the files they are saying to delete. Everytime I shut down my machine I get a "Win Min" Error, and my home page has been perminently changed to yoursearcher.com. Help would be much appreciated.

Logfile of HijackThis v1.98.2
Scan saved at 15:39:31, on 15-11-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\K-Lite Codec Pack\real\Update_OB\realsched.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\HistoryKill\histkill.exe
C:\windows\llmoxsh.exe
C:\Program Files\Logitech\ImageStudio\LowLight.exe
C:\Program Files\HistoryKill\hkPopupKiller.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Progs\totalcmd\TOTA... Read more

A:Hijack log problem

Problems won't last much longer!

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that Display the contents of System Folders' is checked. Windows XP's search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that Search system folders, Search hidden files and folders, and Search subfolders are checked.

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that it's clean, you may turn it back on and create a new restore point.

Download CWShredder and click on Fix (it will automatically fix anything it finds for you). If it asks if you want to delete a certain random file, choose No and post that filename here.

Reboot into Safe Mode (hit F8 key until menu shows up).

Make sure to close any open browsers. Go into HijackThis->Config->... Read more

Read other 3 answers
RELEVANCY SCORE 29.6

Hi,

My pc has recently started hanging and crashing a lot whereas before it was fine. I use Norton and also have AdAware, Spybot and SpywareBlaster. Thought if I posted a log some-one could tell me if there was anything untowards.

Thanks in advance, Mick
Logfile of HijackThis v1.99.0
Scan saved at 07:39:47, on 06/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.ex... Read more

A:HiJack This Log - Have I a problem?

hi, welcome to TSG.
IMPORTANT! Move Hijack this from the Temp, or from the zip folder to it's own folder!

Make a new folder in C:\ and call it Hijack this, and Save hijack this to
this folder so that it runs properly and can make back ups. Click scan,
then save the log and post it here so we can take a look at it for you.
* Download the trial version of Ewido Security Suite here
http://www.ewido.net/en/

* Install ewido.
* During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
* Launch ewido
* It will prompt you to update click the OK button and it will go to the main screen
* On the left side of the main screen click update
* Click on Start and let it update.
* DO NOT run a scan yet. You will do that later in safe mode.
*Download Cleanup from Here

http://www.stevengould.org/software/cleanup/download.html

* A window will open and choose SAVE, then DESKTOP as the destination.
* On your Desktop, click on Cleanup40.exe icon.
* Then, click RUN and place a checkmark beside "I Agree"
* Then click NEXT followed by START and OK.
* A window will appear with many choices, keep all the defaults as set when the Slide Bar to the left is set to Standard Quality.
* Click OK
* DO NOT RUN IT YET

* Click here for info on how to boot to safe mode if you don't already know
how.

http://service1.symantec.com/SUPPOR...2001052409420406?OpenDocument&src=sec_d... Read more

Read other 1 answers
RELEVANCY SCORE 29.6

I would appreciate if some one can help me in removing this malware stuff form my computer. Whenever I open I open my browser another page pops up saying i should install the software on that page cos my page is slow or has virus. The url for that page which opens is ....http://antispywaresuite.com/data/in...04061708156a0b57055b5f5055015066083955500555v....
Thanks!
 

Read other answers
RELEVANCY SCORE 29.6

quick querie, trying to scan my system with the hijackthis.exe file but it keeps getting shut down a few seconds after the scan starts or the program itself begins (i'm assuming the vista security 2012 virus is responsible for this)

any ideas for a fix?
 

A:Hijack This Problem

See if this will run:

Download RogueKiller to your desktop
Quit all running programs
For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
When prompted, type 1 and validate by tapping Enter
The RKreport.txt shall be generated next to the executable.
If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.
 

Read other 1 answers
RELEVANCY SCORE 29.6

SPAM / Advertisement deleted.

Issued warning points!

A:HiJack Problem, HELP!

SPAM / Advertisement deleted.

Issued more warning points!

Read other 2 answers
RELEVANCY SCORE 29.6

I am facing host hijacking problem. I am posting the hijack this log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:39:50 AM, on 8/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\S24EvMon.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\ZCfgSvc.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\1XConfig.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
d:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
D:\Program Files\McAfee\VirusScan\McShield.exe
D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
D:\Program Files\SiteAdvisor\6261\SiteAdv.exe
D:\WINDOWS\stsystra.exe
D:\Program Files\McAfee.com\Agent\mcagent.exe
D:\Program Files\Google\Google Talk\googletalk.exe
D:\Program Files\Dell\QuickSet\quickset.exe
D:\Program Files\McAfee\MPF\MPFSrv.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\WINDOWS\system32\drivers\svchost.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\McAfee\MSK\Ms... Read more

Read other answers
RELEVANCY SCORE 29.6

hi all,
this is the second time this month .... with the same annoying hijack.... im starting to hate the internet.... argh!

help appreciated...

the ever amazed,

Striker.


Logfile of HijackThis v1.98.2
Scan saved at 16:49:44, on 22/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Documents and Settings\Caner\Application Data\pb??.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\imsins.log:qrgpt
C:\DOCUME~1\Caner\LOCALS~1\Temp\Rar$EX00.794\AboutBuster\AboutBuster.exe
C:\WINDOWS\system32\atlho.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Caner\Desktop\Programs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\edwso.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\edwso.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res:... Read more

A:not another hijack this problem!!!!

Hi and welcome to TSF

Firstly lets download a few tools:

Download FixAgent from Trend Micro. Save it to your desktop, so it will be easy to access.

Download home mssing, to your desktop.

Please download Adaware SE and install it if you don't have it already. Make sure it's the newest version and check for any updates before running it. Go to this site to get the plug-in for fixing VX2 variants. Also make sure to customize the settings in Adaware for better scan results. Run the scan and fix everything that it finds.

Reboot your computer and post a fresh Hijack This log.

You mentioned that this is the second time this month you've posted a log so this is a good time to set up protection against further attacks. Read How Did I Get Infected In The First Place?. You need an antivirus that is continually updated, a good firewall, a spyware blocker such as Spyware Blaster, and a real time spyware program such as Spyware Guard, to prevent spyware intrusions. IE-Spyad is another excellent program that places over 4000 websites and domains in the IE Restricted list, which will help prevent attempts to infect your system. All of the above have good free versions available. However, be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

More information and downloads are available at the following links:

Spyware Blaster
Spyware Guard
IE-Spyad

I do not... Read more

Read other 19 answers
RELEVANCY SCORE 29.6

Hello,

Somehow my home page is set as mk:@MSITStore:C:\spe\start.chm::/start.html# and i cannot change. Everytime i try to change it it just keeps on coming back. Also when I try and access other website i am redirected to this website http://www.heretofind.com/show.php?i...www.google.com. CAN ANYONE HELP ME PLEASE.

A:Hijack problem. Someone pls help me

Please go into Windows Explorer, click on C:\ > File > New Folder and call it HJK, or another name of your choice. Go to this site and download Hijack This. Install the program into the folder you created then run it. Click Scan. Save the log file to Notepad, then copy and post it back here. Make sure to include the System information at the top of the log as well.

Read other 1 answers
RELEVANCY SCORE 29.6

I woke up this morning to find ou that I probably had a virus. I got the NT Authority thing that shut down my computer. Somehow I was able to reboot. I went to Microsoft and did their Live OneCare scan as my McAfee didn't find anything. Microsoft found the following problems:Backdoor:WinNT/Rustock.gen!B PWS:Win32/zbot.gen!R VirTool:Win32/obfuscator.ETI opted to have them removed, which it said it successfully did. But when I rebooted, I got an error message for every program that tried to open. Here is a sample of the message (I got this one by opening Irfanview so I could show you).I get this message every time something tries to execute. (This problem kept me from running the DDS Tool this forum recommended.)I was able to download Hijack This and get a log report that I'm posting below.I have Windows XP Professional, version 2002, SP3Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:19:46 PM, on 7/3/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16850)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\WLTRYSVC.EXEC:\WINDOWS\System32\bcmwltry.exeC:\Program Files\Lavasoft\Ad-Aware\AAWService.exeC:\... Read more

A:Hijack This log and other problem

I read some other posts made by other users with similar problems. I ran Malwarebytes and got the following log:

Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> No action taken.

Files Infected:
c:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> No action taken.
c:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> No action taken.
c:\WINDOWS\system32\lowsec\user.ds.lll (Stolen.data) -> No action taken.
C:\WINDOWS\system32\drivers\str.sys (Rootkit.Agent) -> No action taken.

I had... Read more

Read other 11 answers
RELEVANCY SCORE 29.6

hi..

i made a mistake.. i removed everything when i scaned my drive with hijack..
everything know is going wrong.. i cannot enable auto-protect in Norton antivirus.. my tool bar is removed..
and still i couldn't remove that damn trojan which is called about:blank or trojan.startpage..

may i have help here to restore my registry and to remove that trojan..??

(sorry for my bad english )

thanks..
 

A:problem with hijack!!

Read other 16 answers
RELEVANCY SCORE 29.6

When using IE I continuously get to a "page cannot be displayed" message, but then I click refresh and everything loads. Then I'll go to another page and pictures won't load, just X's; then I hit refresh and it all works. I have to refresh everything everytime I change pages.
Logfile of HijackThis v1.97.7
Scan saved at 7:56:57 PM, on 5/16/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.usatoday.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKCU\..\Run: [ares] "C:\PROGRAM FILES\ARES\ARES.EXE" -h
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O9 - Extra button: AIM (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .asp: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4445535... Read more

A:IE Problem, HiJack Log Here

Make sure you have all the Critical Updates and Service Packs from http://windowsupdate.microsoft.com

***

Get, install, update and run free Ad-aware (and its HexDump plug-in) from http://www.lavasoftusa.com/software/adaware/

First in the main window look in the bottom right corner and click on Check for updates now and download the latest reference files.

Make sure the following settings are made and on -------ON=GREEN

From main window :Click Start then Activate in-depth scan (recommended)

Click Use Custom Scanning Options' then click Customize' and have these options selected: Under Drives and Folders put a check by Scan Within Archives and below that under Memory and Registry put a check by all the options there.

Now click on the General button in that same window make the button 'red' next to, 'Automatically quarantine objects prior to removal; Automatically save log file should be green and Safe Mode should be green.' Under the the Tweak button , Under Scanning engine select: Unload recognized processes during scanning and under Cleaning Engine select: Let windows remove files in use at next reboot.

Click proceed to save your settings.

Now to scan just click the Next button.

When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

Restart your computer.
 

Read other 1 answers
RELEVANCY SCORE 29.6

Using Windows XP-sp1. System runs pretty good. One consistent problem I am having is that whenever I try to do a scan, such as anti virus, or online virus scans, my system freezes up. It will run scans with Adaware 6 and Spybot with no freeze up. Please help!!!

Thanks in advance

Logfile of HijackThis v1.96.4
Scan saved at 10:35:21 AM, on 9/6/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\System32\S3tray2.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WebRunner Accelerator\webrunner.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner.YOUR-KYBTG65GXE\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = h... Read more

A:Please look at my hijack log.....do I have a problem?

There is nothing unusual about the Scanlog. You could certainly due without this though, it is of use only to program developers:

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

Have you tried running your Scans in Safe Mode? (press f8 promptly on startup to access the boot menu and the Safe Mode option)

If it runs without problem there, then try using msconfig to "clean boot" and see if you can pinpoint a particular startup which is causing a conflict.

http://support.microsoft.com/default.aspx?scid=KB;en-us;q310353
 

Read other 2 answers
RELEVANCY SCORE 29.6

Hello,

I have been following the old threads about removing this problem "ISLALERT_WINDOWNAME_{DA5EA0DE-0190-4755-9ABE-C6DBF5A1008B}"

Is there an easier way of removing this from my system than was previously described as the thread I looked at dated from 2004?

The message appears when I shut down my computer, and it also prevents me from updating my definitions, opening any of the Nortons security programs that I have.

Hope you can help?

Regards

Ariake
 

Read other answers
RELEVANCY SCORE 29.6

I downloaded a copy of v.2 of HiJack This and when I run in on the machine I am having trouble with, Norton's realtime virus protection pops up a virus window.


The program will run and produce a log, but I don't see an option to save the log.

Where can I get a copy of HiJack This that I know is clean?

Thanks in advance

A:Problem with HiJack This

Where are you downloading it from? It's possibly a False Positive by Norton.

How many threads do you have going here? How many machines? Are they all yours?

http://www.techsupportforum.com/secu...jkjkj-dll.html

Are all these questions relating to this thread, which already has a reply?

http://www.techsupportforum.com/secu...irus-more.html

Please do not create multiple threads for the same issue. If they are not the same issue, be sure to point that out in your threads.

Read other 1 answers
RELEVANCY SCORE 29.6

This morning I started having issues with getting pop up ads out of nowhere on my computer. I've used a couple spyware removal programs and my McAfee virus scan but the problem still persists as ads still pop up and my internet has a lag to it. My friend suggested downloading Hijack This and posting my log on here. Here is the Hijack This log:

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\QdrModule\QdrModule10.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Intel\Intel Application Accelerator\... Read more

A:Possible hijack problem

Hello and welcome to TSF


Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

===============================================================

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.Close all applications and windows.
Double-click on dss.exe to run it, and follow the prompts.
When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt <-this one will be minimized
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt here.
Please attach extra.txt to your post.
To attach a file to a new post, simplyClick the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
copy and paste the following into the "Upload File from your Computer" box:C:\Deckard\System Scanner\extra.txt

Click Upload.
What DSS will do: create a new System Restore point in Windows XP and Vista.
clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and pl... Read more

Read other 11 answers
RELEVANCY SCORE 29.6

Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\Java\jre1.6.0_04\bin\jusched.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\sm56hlpr.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Free Download Manager\fdm.exeC:\Documents and Settings\spaztastical\Desktop\Folder\Compy preform tests\CoreTemp\Core Temp.exeC:\Documents and Settings\spaztastical\Desktop\Folder\TC98228E\TClock.exeC:\Program Files\OpenOffice.org 2.4\program\soffice.exeC:\Program Files\OpenOffice.org 2.4\program\soffice.BINC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Alwil S... Read more

A:Hijack Log: Not Sure What The Problem Is

Hello, Lill. to BleepingComputer.comMy name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)Please give me some time to look over your computer's log(s).Please take note of the following:In the meantime, please refrain from making any changes to your computer.Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.Finally, please reply using the button in the lower left hand corner of your screen.We need to create a Deckard's System Scanner (DSS) LogPlease download Deckard's System Scanner (DSS) from one of the links below and save to your Desktop.Primary MirrorSecondary Mirror

DSS will do the following:Create a new System Restore point in Windows XP and Vista.Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.Check some important areas of your system and produce a report for an analyst to review.Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is n... Read more

Read other 16 answers
RELEVANCY SCORE 29.6

hi, i think my brother's pc has a lot of problem... i tried to download hijackthis, but it closes just a moment after i open it, and there is a little window but i can't read it because is very very fast to close. i can't understand why, i downloaded also PepiMK's CoolWWWSearch.SmartKiller removal tool first and ran it, but it say there aren't problems. could you please help me' i think i've got to run hijack to discover the real problems... thank you very much ps: i hope this is the right forum! =)

A:Problem With Hijack

Mod addition to have topic requeued for member review.

Read other 1 answers
RELEVANCY SCORE 29.6

I have a laptop that runs extremely slow. I believe I have some type of hijack problem because everytime I try to log into a site (like Hotmail), I get the 404 error, but in the address line, it's changed to some "golive.com" address.

Also, typing things in blocks are delayed by like 5 seconds. Meaning, I'll type it now, and 5 seconds later, it'll populate.

Can anyone help? What do I need to start off doing? Anything to download?

Appreciate anyone's help.
 

A:Very possible hijack problem...HELP

Read other 16 answers
RELEVANCY SCORE 29.6

I have been having a number of viruses, spyware and adware things being installed on my computer recently, and also severe system slowdown at startup (sometimes for up to 2 minutes without my being able to do anything), so I have posted a copy of my Hijack This log, and anyone who can tell me what i do not need / should get rid of etc... I would be extremely grateful:

Logfile of HijackThis v1.97.7
Scan saved at 10:26:09 AM, on 4/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Paul\Local Settings\Temp\Temporary Directory 2 for hijackthis1977.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cbekg.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\cbekg.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cbekg.dll/sp.html (obf... Read more

A:Hijack This log and a problem (please help)

Read other 9 answers