Go Back   Hardware Canucks > PC BUILDERS & TWEAKERS CORNER > Troubleshooting

       
Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old December 19, 2007, 11:50 PM
ebdoradz's Avatar
Allstar
 
Join Date: Mar 2007
Location: Rouyn-Noranda, QC
Posts: 754
Default

strange

are you sure you didnt drank tonight???

joke bud, seriusly its a strange thing, your 1st link, link me to google.ro which is normal. the second one link me to google.ca(french) im french so thats OK, 3rd one is google.com in english ...
__________________
Gigabyte GA-MA790XT-UD4P / AMD Phenom II x3 720BE @ x4/ Crucial Ballistic DDR3 / Sapphire 4830 5112mb / Corsair 620W PSU / 2*80GB Seagate

DFI LP nF4 Ultra-D / AMD Opteron 165 @ 2.7Ghz/ 2*1GB OCZ Gold GX XTC / Sapphire X1950XT / Fortron 450W PSU / 2*Maxtor 80Gb

ABIT KT7A-RAID / AMD Athlon XP 1800+ @ stock/ 2*256mb PC133/ Geforce 4 mx440 / 250W PSU / Maxtor 20GB
Reply With Quote
  #12 (permalink)  
Old December 19, 2007, 11:50 PM
BALISTX's Avatar
Hall Of Fame
F@H
 
Join Date: Feb 2007
Location: Ottawa, ON
Posts: 2,005
Default

Does it only happen with Firefox? Have you tried uninstalling and reinstalling Firefox? If so have you tried installing an older version of Firefox?
__________________
"Though I walk through the shadow of the Valley of Death I shall fear no evil as my C8 Carbine is locked and loaded."

Next Build: E5200 @ 3.6GHz (333x11) | Xigmatek HDT-RS1283 HSF | Biostar TP43D2-A7 | Mushkin Redlines DDR2-1000 @ DDR2-999 5-5-5-12
EVGA 9600 GT 512MB - 650MHz - 1800MHz - 1626MHz | Seagate 'Cuda 250GB 7200rpm SATA2 | Corsair VX550 | CM690 - Custom Atomic Orange Pearl


[Heatware]
[eBay]
[Rosetta]
BALISTX.com
Reply With Quote
  #13 (permalink)  
Old December 20, 2007, 12:48 AM
enaberif's Avatar
Hall Of Fame
 
Join Date: Dec 2006
Location: Grande Prairie, AB
Posts: 8,589
Default

google toolbar installed without you knowing?
Reply With Quote
  #14 (permalink)  
Old December 20, 2007, 03:41 AM
qwerty's Avatar
Top Prospect
 
Join Date: Oct 2007
Location: Brampton, Ontario
Posts: 226
Default

Are you using a proxy or onion routing?

I know that when I use either of these I will get 'google' in all sorts of different languages.

Are you getting any pop ups or other strange happenings?

You may want to look at the chance that you may have a browser hijack problem.

If you think that this may be the case and download this install it to your desktop, follow the scan instructions and post the results here.

Failing that I would search the web for similar types of problems and find out what others did to correct it.
Reply With Quote
  #15 (permalink)  
Old December 20, 2007, 06:52 AM
omgwtf's Avatar
Hall Of Fame
 
Join Date: Mar 2007
Location: Montreal
Posts: 1,800
Default

eboradz: no i didn't drink...
BALISTX: with firefox and ie 7, yes I tried.
enaberif: i don't think so..that would be a problem?
qwerty: no proxy, no router... no pop ups here is the log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:18:47 AM, on 12/20/2007
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Eset\nod32krn.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Le Robert\Le Petit Robert\prhyper.exe
C:\Program Files (x86)\DAEMON Tools\daemon.exe
C:\Program Files (x86)\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files (x86)\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files (x86)\QuickTime\qttask.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files (x86)\Eset\nod32kui.exe
C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files (x86)\mIRC\mirc.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
F2 - REG:system.ini: UserInit=userinit
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files (x86)\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files (x86)\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files (x86)\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Le Petit Robert Hyperappel] C:\Program Files (x86)\Le Robert\Le Petit Robert\prhyper.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files (x86)\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [BitComet] "C:\Program Files (x86)\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: MSN.com
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V020...5030/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F08836F-6E62-4265-AC4A-97179A97A273}: NameServer = 67.55.0.11 66.49.220.95
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe (file missing)
O23 - Service: Event Log (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing)
O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe (file missing)
O23 - Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\WINDOWS\system32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Net Logon (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files (x86)\Eset\nod32krn.exe
O23 - Service: NT LM Security Support Provider (NtLmSsp) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc64.exe (file missing)
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing)
O23 - Service: IPSEC Services (PolicyAgent) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Remote Desktop Help Session Manager (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe (file missing)
O23 - Service: Security Accounts Manager (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Virtual Disk Service (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe (file missing)
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)

--
End of file - 8206 bytes

Update: I selected the files that the hijack program thought are fisshy and select repair, after that I restarted the pc. When it logged back the toolbar went in windows classic mode and after that the monitor gaved me a No signal ...it restarted by itself again and this time it worked but it gave me a don't send error (winlogon.exe)...

Last edited by omgwtf; December 20, 2007 at 07:03 AM.
Reply With Quote
  #16 (permalink)  
Old December 20, 2007, 09:03 AM
Top Prospect
F@H
 
Join Date: Jun 2007
Location: Toronto area.
Posts: 170
Default

Hammer F8 on the keyboard before you get to the windows loading animation, then choose "last known working settings" or something like that. I would then boot it into safe mode and do a msconfig and undo the changes that were made. It sounds like you buggered up your registry with the "auto fix". If you ever feel the need to disabled start up programs use "msconfig" & "services.msc" for services. You are asking for trouble when you allow a program to mess with those.
__________________
Q6600@3.2ghz
Asus P5N32-E Sli
4gb OCZ Platinum DDR2 @1100mhz
Antec P180
BFG GTX 260 Core 216
Corsair HX-620
Thermaltake Power Express 250W
Raptor150, WD 500gb. WD 300GB
X-Fi Extreme Music
Reply With Quote
  #17 (permalink)  
Old December 20, 2007, 09:53 AM
Beermaster's Avatar
MVP
 
Join Date: Apr 2007
Location: Spruce Grove, AB
Posts: 266
Default

After you get it all working, double check your hosts file, somthing in there could have rewritten it, you never know
__________________
Grovian - *E4300@2.2ghz*Gigabyte DS3L*G.SKILL F2-6400CL5D-2GBNQ 3x1Gb*Sapphire HD4850 1GB*Raptor 75Gb*
Buggz - *E7200@2.9ghz*Asus P5Q*Patriot PC2-6400*eVGA 8800GTS 320gb*WD 160GB CaviarSE*
Lil-Grov – Acer One*8gb SSD*WinXP pro
Tathar – WIP*Q9550*Gigabyte EP45-UD3P*OCZ Reaper PC-8500 4gbX2*OCZ Vertex 120gb*WD 1TB WD1001FALS*BFG GTX275*
Reply With Quote
  #18 (permalink)  
Old December 20, 2007, 03:34 PM
omgwtf's Avatar
Hall Of Fame
 
Join Date: Mar 2007
Location: Montreal
Posts: 1,800
Default

I did something and it worked...the hijack thing must've worked.

Thank you all for your answers.

Last edited by omgwtf; December 20, 2007 at 03:40 PM.
Reply With Quote
Reply

 

Thread Tools
Display Modes

Similar Threads
Thread Thread Starter Forum Replies Last Post
DVD problem bobletman Storage 2 January 27, 2008 12:10 PM
8800GT - Strange Noise Voodoo Troubleshooting 34 January 21, 2008 06:45 PM
Strange Halloween question Eldonko Off Topic 5 October 17, 2007 04:34 PM
Strange Orthos behaviour Mibs Overclocking, Tweaking and Benchmarking 3 August 14, 2007 07:10 PM
problem... omgwtf Troubleshooting 35 May 15, 2007 09:06 PM