Options

Searches Being Hijacked

2

Comments

  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    Smiley433 wrote: »
    Apologies if Vista works completely different from XP but I don't see how you can retrospectively create a restore point. It would probably accept a date next week if you entered one but that doesn't mean it will create a restore point containing anything other than the current installation.

    You create a manual restore point before you are about to make changes to a system which you may later want to reverse. That's what the automated check-points are - an image of the installation before an update to drivers or before some software was performed.

    I now see that you are right. When I was asked for a description I assumed it meant a date.
  • Options
    Thine WonkThine Wonk Posts: 17,190
    Forum Member
    ✭✭
    Smiley433 wrote: »
    That's a bit drastic.


    Not really, the OP has probably spend more hours fixing it than a simple 1 hour to copy your my documents off to a usb stick, drive or DVD and then reinstall.

    They could be days at this going back and forth between the forum and fixing it, and there's no guarantee they'll be able to totally rid themselves, leaving them open to the same thing again.
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    Stig wrote: »
    Have you done this?

    Yes and the problem persists.
  • Options
    Smiley433Smiley433 Posts: 7,900
    Forum Member
    I agree under some circumstances a wipe and reinstall could be quicker getting a working system back up and running again, depending on machine specifics, user confidence and ability, etc.

    However for what would appear to be a redirect problem (i.e. everything else working ok), it does seem like a drastic approach. Plus you don't learn anything doing a reinstall whereas you might learn something with other users offering their help.
  • Options
    BrokenArrowBrokenArrow Posts: 21,665
    Forum Member
    ✭✭✭
    Download and run this,

    http://sourceforge.net/projects/hjt/

    post the log that it comes up with here and someone will tell you which items to delete.
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    Before the problem started to become evident some weeks ago; whenever I searched in Google it took me to Findamo. Now it doesn't. It that a clue?
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    Download and run this,

    http://sourceforge.net/projects/hjt/

    post the log that it comes up with here and someone will tell you which items to delete.

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 15:37:40, on 20/01/2013
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v9.00 (9.00.8112.16457)
    Boot mode: Normal

    Running processes:
    C:\hp\support\hpsysdrv.exe
    C:\Program Files (x86)\AGEIA Technologies\TrayIcon.exe
    C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
    C:\Program Files (x86)\Ask.com\Updater\Updater.exe
    C:\WINDOWS\SysWOW64\rundll32.exe
    C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    C:\hp\kbd\kbd.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_5_502_146_ActiveX.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Users\Linda & Richard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZV64XZWM\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.ask.com/?l=dis&o=101706
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_gb&c=83&bd=Pavilion&pf=cndt
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/hypercam/{C96492F5-1E28-4EFE-8B2D-5C78B780BB13}
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Users\Linda & Richard\AppData\LocalLow\CT2737658\ldrtbFree.dll
    F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
    O1 - Hosts: ::1 localhost
    O2 - BHO: ALOT Toolbar Helper - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files (x86)\alot\bin\BHO\alotBHO.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
    O2 - BHO: Free TV Bar c3 Toolbar - {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - C:\Program Files (x86)\Free_TV_Bar_c3\tbFree.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: FCTBPos00Pos - {745A6D3B-4DB0-4246-B596-9189787D4ED5} - C:\Program Files (x86)\AdventureQuest Worlds Toolbar\Toolbar.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120915220957.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    O2 - BHO: Freemake.YoutubeButton - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - mscoree.dll (file missing)
    O2 - BHO: Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll
    O2 - BHO: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Users\Linda & Richard\AppData\LocalLow\CT2737658\ldrtbFree.dll
    O3 - Toolbar: AdventureQuest Worlds Toolbar - {3385E2D6-567B-4FC6-8F0F-D7A8C6E6118C} - C:\Program Files (x86)\AdventureQuest Worlds Toolbar\Toolbar.dll
    O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files (x86)\alot\bin\alot.dll
    O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll
    O3 - Toolbar: Free TV Bar c3 Toolbar - {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - C:\Program Files (x86)\Free_TV_Bar_c3\tbFree.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Users\Linda & Richard\AppData\LocalLow\CT2737658\ldrtbFree.dll
    O3 - Toolbar: Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll
    O3 - Toolbar: Foxit PDF Creator Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    O4 - HKLM\..\Run: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
    O4 - HKLM\..\Run: [AGEIA PhysX SysTray] "C:\Program Files (x86)\AGEIA Technologies\TrayIcon.exe"
    O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
    O4 - HKLM\..\Run: [Toosdv] rundll32 "C:\Users\Linda & Richard\AppData\Roaming\olethk32N.dll",Efhuvybke
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll
    O20 - AppInit_DLLs: c:\progra~3\bprote~1\20392~1.106\protec~1.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: bProtector - bProtector - C:\ProgramData\bProtectorForWindows\2.0.392.106\bProtect.exe
    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
    O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\MAGIX\Common\Database\bin\fbserver.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
    O23 - Service: Google Update Service (gupdate1c9becb32d06501) (gupdate1c9becb32d06501) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: JoinMEUI Assistant Service - Unknown owner - C:\Program Files (x86)\Join MEPlay\JoinMEPlayAssistantServices.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
    O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
    O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
    O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 16610 bytes
  • Options
    evil cevil c Posts: 7,833
    Forum Member
    Paperhouse, you should have picked a better user name, like Cardhouse, because the cards seem to be tumbling. I'm getting confused by all this and YOU are definitely confused.

    Secondly, REDBUS asked you whether you had an antivirus installed, and if so then he told you to carry out a full scan. You never answered. OK, I see you have McAfee.

    You need to uninstall all those toolbars for a start.
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    evil c wrote: »
    Paperhouse, you should have picked a better user name, like Cardhouse, because the cards seem to be tumbling. I'm getting confused by all this and YOU are definitely confused. When you say you are searching on Google, is Google your home page, by which I mean, when you click on Internet Explorer to go on the net, does it open on Google and do you then start searching, and is this what you have always done?

    Secondly, REDBUS asked you whether you had an antivirus installed, and if so then he told you to carry out a full scan. You never answered.

    Do you know whether you have CCleaner installed as well?

    Google in NOT my home page. My home page is Orange and that work perfectly OK for searching. But Google is a better search engine.

    We have McAfee antivirus and a full scan has been carried out.

    Don't have CCleaner to the best of my knowledge.

    Thanks for your patience.
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    Smiley433 wrote: »
    I agree under some circumstances a wipe and reinstall could be quicker getting a working system back up and running again, depending on machine specifics, user confidence and ability, etc.

    However for what would appear to be a redirect problem (i.e. everything else working ok), it does seem like a drastic approach. Plus you don't learn anything doing a reinstall whereas you might learn something with other users offering their help.

    User confidence and ability non-existant :mad:
  • Options
    evil cevil c Posts: 7,833
    Forum Member
    I'm editing too fast for you! Get rid of those toolbars. What do you need them for anyway? Do you know how to uninstall them?

    Also you have lots of spurious programs installed. What are you using them for? You need to get someone round to sort your computer out. We could be days here!

    You should take a course in computer basics as well and this will give you some confidence. Your council must have free courses running in local libraries. If only I lived near you I could help....maybe!
  • Options
    BrokenArrowBrokenArrow Posts: 21,665
    Forum Member
    ✭✭✭
    You need to delete all those toolbars except the ones relating to google.

    To delete things, just check the item in HIjack this and it will get rid of them for you.

    Also the BHO objects that you don't recgonise (keep ones relating to Microsoft, Google, JAVA, MsAffee and Adobe,
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    You need to delete all those toolbars except the ones relating to google.

    To delete things, just check the item in HIjack this and it will get rid of them for you.

    Also the BHO objects that you don't recgonise (keep ones relating to Microsoft, Google, JAVA, MsAffee and Adobe,

    To my mind a toolbar appears on the screen, but these don't. So I don't know what they are or where they came from; and would be nervous about removing them. Same goes for BHO. Don't even know what BHO is. So by removing the toobars and BHOs, will that resolve the problem?
  • Options
    max99max99 Posts: 9,002
    Forum Member
    There's an awful lot of crap in that HJT log. At this point, I would also have to recommend restoring the machine to factory settings. Whilst it is possible to fix it all without having to resort to a restore, doing it via a forum and having to give instructions every step of the way may turn out to be a far more lengthy and complicated process. Plus, there's no guarantee that all traces of the malware will be removed or that the clean-up process won't actually make things worse.
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    max99 wrote: »
    There's an awful lot of crap in that HJT log. At this point, I would also have to recommend restoring the machine to factory settings. Whilst it is possible to fix it all without having to resort to a restore, doing it via a forum and having to give instructions every step of the way may turn out to be a far more lengthy and complicated process. Plus, there's no guarantee that all traces of the malware will be removed or that the clean-up process won't actually make things worse.

    Or instead of clicking on a link I could copy and paste the website address when using Google.
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    You need to delete all those toolbars except the ones relating to google.

    To delete things, just check the item in HIjack this and it will get rid of them for you.

    Also the BHO objects that you don't recgonise (keep ones relating to Microsoft, Google, JAVA, MsAffee and Adobe,

    OK I plucked up the courage to remove the relevant toolbars and BHO and it hasn't made any difference.
  • Options
    StigStig Posts: 12,446
    Forum Member
    ✭✭
    Paperhouse wrote: »
    OK I plucked up the courage to remove the relevant toolbars and BHO and it hasn't made any difference.
    If you had correctly followed the Internet Explorer reset instructions given earlier then you shouldn't have had any toolbars to remove :confused:
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    This is wierd.

    If I go to Google or any of the search engines which I am having trouble with and click once on a link, it takes me gooness knows where.

    If I double click on a link it takes me to where I want.

    And having double clicked on a subject link I then only need to click once on any link of that subject for it to work.
  • Options
    LION8TIGERLION8TIGER Posts: 8,484
    Forum Member
    Paperhouse wrote: »
    OK I plucked up the courage to remove the relevant toolbars and BHO and it hasn't made any difference.

    So have you removed all of these .......

    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

    R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Users\Linda & Richard\AppData\LocalLow\CT2737658\ldrtbFree.dll

    O2 - BHO: ALOT Toolbar Helper - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files (x86)\alot\bin\BHO\alotBHO.dll

    O2 - BHO: Free TV Bar c3 Toolbar - {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - C:\Program Files (x86)\Free_TV_Bar_c3\tbFree.dll

    O2 - BHO: FCTBPos00Pos - {745A6D3B-4DB0-4246-B596-9189787D4ED5} - C:\Program Files (x86)\AdventureQuest Worlds Toolbar\Toolbar.dll

    O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll

    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

    O2 - BHO: Freemake.YoutubeButton - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - mscoree.dll (file missing)

    O2 - BHO: Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll

    O2 - BHO: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Users\Linda & Richard\AppData\LocalLow\CT2737658\ldrtbFree.dll

    O3 - Toolbar: AdventureQuest Worlds Toolbar - {3385E2D6-567B-4FC6-8F0F-D7A8C6E6118C} - C:\Program Files (x86)\AdventureQuest Worlds Toolbar\Toolbar.dll

    O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files (x86)\alot\bin\alot.dll

    O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll

    O3 - Toolbar: Free TV Bar c3 Toolbar - {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - C:\Program Files (x86)\Free_TV_Bar_c3\tbFree.dll

    O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Users\Linda & Richard\AppData\LocalLow\CT2737658\ldrtbFree.dll

    O3 - Toolbar: Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll

    O3 - Toolbar: Foxit PDF Creator Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

    O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"

    O4 - HKLM\..\Run: [Toosdv] rundll32 "C:\Users\Linda & Richard\AppData\Roaming\olethk32N.dll",Efhuvybke

    O20 - AppInit_DLLs: c:\progra~3\bprote~1\20392~1.106\protec~1.dll

    O23 - Service: bProtector - bProtector - C:\ProgramData\bProtectorForWindows\2.0.392.106\bProtect.exe

    O23 - Service: JoinMEUI Assistant Service - Unknown owner - C:\Program Files (x86)\Join MEPlay\JoinMEPlayAssistantServices.exe

    ...... and rebooted the computer.
  • Options
    whoever,heywhoever,hey Posts: 30,992
    Forum Member
    ✭✭✭
    I didn't even realise Zynga had a toolbar!
  • Options
    Thine WonkThine Wonk Posts: 17,190
    Forum Member
    ✭✭
    This is a lost cause I think. So much junk on that machine and the OP will simply get it into a mess again surely?
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    Thine Wonk wrote: »
    This is a lost cause I think. So much junk on that machine and the OP will simply get it into a mess again surely?

    Not at all. It must have taken the family and I more than six years to get it to this state.
  • Options
    StigStig Posts: 12,446
    Forum Member
    ✭✭
    Paperhouse wrote: »
    Not at all. It must have taken the family and I more than six years to get it to this state.

    If its six years old them a reinstall of Windows is long overdue.

    If you have a backup of all your data (which of course you have, right?) then it's usually quite a quick process.

    Have you ever told us the make/model of your PC?
  • Options
    max99max99 Posts: 9,002
    Forum Member
    Paperhouse wrote: »
    Not at all. It must have taken the family and I more than six years to get it to this state.

    All the more reason to restore to factory settings.

    And if your files aren't backed up, it will also force you to learn how to do so.
  • Options
    PaperhousePaperhouse Posts: 1,710
    Forum Member
    ✭✭✭
    All joking aside I think it's time to buy a new computer.
Sign In or Register to comment.