|
Donations |
|
|
|
|
|
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
|
|
|
Survey |
|
|
|
|
|
|
|
|
Translate |
|
|
|
|
|
|
|
|
|
|
View previous topic :: View next topic |
Author |
Message |
AviationHamster
Cadet
Joined: May 16, 2004
Posts: 2
Location: USA
|
Posted: Sun May 16, 2004 5:10 am Post subject: Two Log Off Buttons And Cant Shutdown/Restart |
|
|
My Friends computer won't let her log off. Since I'm in hawaii and shes in Cal this presents a problem i cant see her stuff. Now she says she has two log off buttons as opposed to one log off and one shutdown. I can't think of what might be causing that problem but any help would be appreciated. |
|
Back to top |
|
|
norbie
1st Responder
Joined: Feb 21, 2004
Posts: 270
Location: UK
|
Posted: Sun May 16, 2004 5:14 am Post subject: |
|
|
Hi there,
Go to and download : HijackThis located at http://computercops.biz/zx/phoenix22/hijackthis.zip
Create and Unzip to a folder not your Desktop or the Temp folder, doubleclick HijackThis.exe, and hit "Scan".
Most of what it lists will be harmless or even required, so do NOT fix anything yet.
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log somewhere, and please show us its contents.
Then copy and paste the contents of your Hijack This log here, and i'll tell you what to do.
Good Luck!
_________________
Norbie
----------------------------
www.norbiesworld.co.uk |
|
Back to top |
|
|
AviationHamster
Cadet
Joined: May 16, 2004
Posts: 2
Location: USA
|
Posted: Sun May 16, 2004 5:26 am Post subject: |
|
|
Ok this is her log
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\WINDOWS\system32\utilman.exe
C:\Documents and Settings\Rosie\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.somethingpositive.net/
R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Corel Corporation Registration] "C:\Program Files\Corel\WordPerfect Office 2002\Register\NAVBrowser.exe" /r /i "C:\Program Files\Corel\WordPerfect Office 2002\Register\NavLoad.ini"
O4 - HKLM\..\Run: [Microsoft Update] navmgrd.exe
O4 - HKLM\..\Run: [Microsoft Inet Xp..] teekids.exe
O4 - HKLM\..\Run: [avserve2.exe] C:\WINDOWS\avserve2.exe
O4 - HKLM\..\RunServices: [Microsoft Update] navmgrd.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Microsoft Update] navmgrd.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C7AC38FA-1E04-40AE-B4FF-381430EE4860}: NameServer = 207.69.188.187 207.69.188.186 |
|
Back to top |
|
|
norbie
1st Responder
Joined: Feb 21, 2004
Posts: 270
Location: UK
|
Posted: Sun May 16, 2004 5:52 am Post subject: |
|
|
hi,
heres what she must fix, by selecting the boxes next to them:
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Microsoft Inet Xp..] teekids.exe
O4 - HKLM\..\Run: [avserve2.exe] C:\WINDOWS\avserve2.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Microsoft Update] navmgrd.exe
(there are two or more of these)
R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
When she has selected those, she needs to click on fix selected, then restart her computer even if that means turning it off at the mains.
The she should download Ad-Aware 6, from http://download.com.com/3001-8022-10214379.html
This should help remove some of this stuff as well. When she has downloaded it, she should update it, then do a scan of her whole computer.
When it has finished scanning, select ALL the boxes on the left, and click on next.
Restart the computer, and paste back a new log here
Good Luck!
_________________
Norbie
----------------------------
www.norbiesworld.co.uk |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
|
Powered by phpBB 2.0.8a © 2001 phpBB Group
Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops
|