Unsolved
This post is more than 5 years old
21 Posts
0
17397
August 20th, 2004 00:00
too many processes!
In task manager, I noticed that I have like 4+ running processes that are titled "svchost.exe"....can I just end those processes? They are probably spyware, correct? Also, I have more than one that imply internet explorer, but with different names.....PLEASE HELP!
No Events found!


jwatt
4.4K Posts
0
August 20th, 2004 00:00
What are the exact names of the two programs you describe as "imply internet explorer, but with different names"?
You may want to download, install, update and run Ad-Aware and Spybot as described in this article, and see if they find any spyware or malware.
Have you scanned your system with your anti-virus software after updating it with the latest definitions?
Jim
jwatt
4.4K Posts
0
August 20th, 2004 01:00
Yes.
I click on the "Big E", to surf, it acts weird. Like, I get,"/msn.:/moved here." on a blank page,then I hit refresh, and I get it,but it's slow....
Is that the exact message you're seeing? Does it happen with all sites, or a specific site? If it's a specific site, can you post the URL (Address) for the site?
Jim
jwatt
4.4K Posts
0
August 20th, 2004 01:00
Jim
alexa999
21 Posts
0
August 20th, 2004 01:00
ok, so just because it's in the system, they would show up as processes?I have spybot and ad aware and etrust.for my firewall and antivirus. I have checked both of the ones you mentioned...but everytime I click on the "Big E", to surf, it acts weird. Like, I get,"/msn.:/moved here." on a blank page,then I hit refresh, and I get it,but it's slow....
alexa999
21 Posts
0
August 20th, 2004 02:00
jwatt
4.4K Posts
0
August 20th, 2004 02:00
Jim
alexa999
21 Posts
0
August 20th, 2004 14:00
Sorry it took so long, but here's what I get :
m/'>here.
jwatt
4.4K Posts
0
August 20th, 2004 15:00
Jim
alexa999
21 Posts
0
August 21st, 2004 19:00
jwatt
4.4K Posts
0
August 21st, 2004 19:00
Are you saying that this only happens once, when you first launch Internet Explorer? If you hit "Refresh", your expected home page appears, and everything's fine until you close down Internet Explorer?
If that's what you're seeing, what happens if you temporarily set your home page to another site? Do you get the same symptoms?
Jim
alexa999
21 Posts
0
August 22nd, 2004 02:00
Ok, I changed my homepage to blank...seems to show just that(blank);but when I clicked "use default" ,this is what came up:
/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
jwatt
4.4K Posts
0
August 22nd, 2004 03:00
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
If I then click on "Home", I receive the front page from msn.com, which is http://www.msn.com/
Note that yours is incomplete. It lacks the portion, " http://www.microsoft.com".
"Use blank" is different. It uses an internal link within Internet Explorer, which isn't a URL in the usual sense.
I think you've already run Ad-Aware and Spybot, so there's not much reason to run them again. But something's has corrupted your Internet Explorer settings. You may want to reinstall Internet Explorer, as described in this link.
If the problem still isn't resolved, download HijackThis, a malware analysis and removal tool. Create a directory (folder) in the root level of your C: drive named HJT. Unzip HijackThis.zip into the newly created directory.
After installing HijackThis.exe in the directory C:\HJT, run Hijackthis from that directory. Click on the 'scan' button and then 'save log' button. Save the file in the directory C:\HJT. Use a name like HijackThis.txt.
Copy and paste the contents of the log you saved in a new message in the Virus and Trojan Removals board at TomCoyote.org for review by certified volunteer experts. Registration is required before posting. Be sure to describe the problem you're experiencing. DON'T ATTEMPT TO FIX ANYTHING REPORTED BY HIJACKTHIS without expert advice!
There are lots more people with malware problems they haven't been able to resolve than there are expert HijackThis analysts, so please be patient. See this post by ChrisRLG for other sites available for analyzing your HijackThis log.
Jim