|
Answer» When clicking on pics or other links, I hardly get always (most of the time I do not) the URL with the pics or info on that asked for-URL.....just the Google search site with lots of other not wanted URL's...
Have XP Pro with all the gadgets, IE70, Sygate, AVG(both antispyware and antivrius), 4200Mhz AMD Athlon, 2048MbRAM, ...guess that's it...
I had IE60 before, but when changing to IE70, this phenomenon sarted really right away... ...and yes I enabled the cookies thing so every cookie will be accepted...I'm not sure I understand your problem. You say that when you click a link or image you get redirected to a Google search instead of the intended image or web site? Does this happen on all web sites? And this started to happen when you switched to IE 7? Could you maybe give an example link or image that sends you to this Google search? correct!! No, not on all websites, just the ones with *censored* content(no *censored*...not tried out..) and sometimes popstars sites or russian or chinese sites......and no it did not happen with 6.0 version...but I wanna try out 7.0...I still think it could help if you could post a link that redirects you and the link for the Google search site you end up on. If you could use a non *censored* one that WOULD be great. Okay I checked out the link you PM'd me. And I think you've got a browser hijack.
You should start with downloading SuperAntiSpyware and installing it. Then do a scan with it and let it remove any spyware it finds. You should also download HijackThis, do a scan with it and post the log it creates here. Then we'll have one of the resident HijackThis experts take a look at it.ok, just did that...lol...system is clean (except for the regular adware tracking cookie...even AVG antispyware finds it every morning, than deletes it and the next day it's back...)according to the spywareguard, but I will post the hijackthis, is standard at my PC and from the looks of it, no specialities...yet...
By the way my AVG Antispyware v.7.5.1 finds more tracking cookies every morning than this Superstuff finds...pity..,,I follow it's SUGGESTION to delete them but sometimes i wonder if i just quarentene them, wouldnt they be stopped in their tracks anyway?
And after deleting the adwarestuff with the "Super", I still have the same problem I described...lol...Logfile of HijackThis v1.99.1 Scan saved at 12:02:33 AM, on 7/22/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\Smc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE C:\Program Files\Logitech\ImageStudio\LogiTray.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\rsvp.exe C:\Program Files\utorrent\utorrent.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=rar O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\Smc.exe -startgui O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl CLASS) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182162464046 O17 - HKLM\System\CCS\Services\Tcpip\..\{45985BEA-E7F7-4ED8-BFC5-890D120EC717}: NameServer = 85.255.113.107,85.255.112.182 O17 - HKLM\System\CCS\Services\Tcpip\..\{50487B4A-3E0B-402B-AA1E-74701E52F7D1}: NameServer = 85.255.113.107,85.255.112.182 O17 - HKLM\System\CCS\Services\Tcpip\..\{800B9714-B7B7-40E6-A475-85F260FB7687}: NameServer = 85.255.113.107,85.255.112.182 O17 - HKLM\System\CCS\Services\Tcpip\..\{EB8A2749-5CFA-4B60-B419-243488748AC9}: NameServer = 85.255.113.107,85.255.112.182 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.107 85.255.112.182 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\Smc.exe Yeah your log seems to be pretty clean so I have to say that I'm out of ideas atm. You could try to scan your computer with an online AV scanner and see if it picks up something AVG doesn't. Here's a couple but there are many more: http://www.kaspersky.com/virusscanner http://www.pandasoftware.com/products/ActiveScan.htm good old Ewido was the best...until AVG screwed it up....same as Sygate was treated....but thanks for trying...Peterwolfe ..... I'd be inclined to mark the following for removal using Hijackthis........
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{45985BEA-E7F7-4ED8-BFC5-890D120EC717}: NameServer = 85.255.113.107,85.255.112.182 O17 - HKLM\System\CCS\Services\Tcpip\..\{50487B4A-3E0B-402B-AA1E-74701E52F7D1}: NameServer = 85.255.113.107,85.255.112.182 O17 - HKLM\System\CCS\Services\Tcpip\..\{800B9714-B7B7-40E6-A475-85F260FB7687}: NameServer = 85.255.113.107,85.255.112.182 O17 - HKLM\System\CCS\Services\Tcpip\..\{EB8A2749-5CFA-4B60-B419-243488748AC9}: NameServer = 85.255.113.107,85.255.112.182 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.107 85.255.112.182
that should be the lot ........ make sure you close up anything open except hijackthis and click on FIX checked......
Is there any reason you have disabled your java, I dont see it anywhere ?
dl65
Quote from: Peterwolfe on July 22, 2007, 04:20:03 PM good old Ewido was the best...until AVG screwed it up....same as Sygate was treated....but thanks for trying...
This is innaccurate at best,,,AVG has not CHANGED the base code of the program since they took it over, What are you saying ? ?reply dl65: will remove...lol...Java not there because when installing, even from the homesite, I get javabased virusses within 2 minutes......especially when being so stupid to import Azureus...lol..so I decide not to...is this a problem or will this be a problem? if so, I might not install it... ******************************
Patio...lol..everybody is entitled to his own opinion, but: I did a check on my system first with good ole Ewido and surprise, it found more sh*t than AVG v.7.5.1...(which is the latest)....so your remark on AVG is ok, but at least a bit inaccurate...lol... For your information: I use both AVG's antivirus and antipsyware software...lol...have done this with both when they became available on the Net and I still think they both are the best (except for Ewido, that is...sometimes..lol)and only today AVG and Ewido agree upon these...lol:
AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 3:50:37 PM 7/23/2007 + Scan result: C:\Documents and Settings\Peter\Cookies\[email protected][1].txt -> TrackingCookie.Abcsearch : No action taken. C:\Documents and Settings\Peter\Cookies\[email protected][2].txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Peter\Cookies\[email protected][2].txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Peter\Cookies\[email protected][1].txt -> TrackingCookie.Live : No action taken. C:\Documents and Settings\Peter\Cookies\[email protected][1].txt -> TrackingCookie.Paypal : No action taken. C:\Documents and Settings\Peter\Cookies\[email protected][1].txt -> TrackingCookie.Statistik-gallup : No action taken. C:\Documents and Settings\Peter\Cookies\[email protected][2].txt -> TrackingCookie.Yadro : No action taken. C:\Documents and Settings\Peter\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : No action taken. ::Report end ***************************
Deerpark: this superspyware is very cool...it found that adware tracker cookie in abundance but removed it quite regularly from 384x via 144x and 81x to just 1 today!!! And that one appeared when having connected to this site...lol...but well, it is not your fault..lol...and after all the help I got here, the problem is solved.....so either the Superspyware or the hijackstuff did the trick...thanks everybody
QuotePatio...lol..everybody is entitled to his own opinion, but: I did a check on my system first with good ole Ewido and surprise, it found more sh*t than AVG v.7.5.1...(which is the latest)....so your remark on AVG is ok, but at least a bit inaccurate...lol...
Well i don't see how this is possible since the last definitions Ewido added were back in February or even earlier...but you are as you said entitled to your opinion.
|