Reply to Message

Reply to Message

View discussion in a popup

Replying to:
Midnight Star
5 Rhenium

Re: Internet Explorer has taken over my computer

conlie,
 
Let's start with this...
 
Reboot your computer into "Safe Mode"
 

 
From a command line, or "Start | Run...", run "services.msc", then locate and stop the following services:
 
[Norton Auto Protect] ...or... nava.exe
[Microsoft media] ...or... winmplayers.exe
 

 
Open the "Windows Task Manager", then 'end' the following processes, if present:
 
  • gvkbsrv.exe
  • kbarsrv.exe
  • nava.exe
  • winmplayers.exe
Be sure to refresh the list and make sure they're no longer running.
 

 
Run HiJackThis, then click "Config...", then "Misc Tools", then:
 
1) "Delete a file on reboot"
2) Browse to and double-click on the following (one at a time):
 
C:\WINDOWS\gvkbsrv.exe
C:\WINDOWS\kbarsrv.exe
nava.exe    <=== Look in c:\windows c:\windows\system : c:\windows\system32
winmplayers.exe   <=== Look in c:\windows c:\windows\system : c:\windows\system32
 
3) After double-clicking on each of the above file(s), when prompted to reboot, select "No".
 

 
In the lower-right hand of HiJackThis click "back", then click "Scan", then check(tick) the following, if present:
 
 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost;
 
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
 
O4 - HKLM\..\Run: [GvkbSrv32] C:\WINDOWS\gvkbsrv.exe
O4 - HKLM\..\Run: [KbarSrv32] C:\WINDOWS\kbarsrv.exe
O4 - HKLM\..\RunServices: [Norton Auto Protect] nava.exe
O4 - HKLM\..\RunServices: [Microsoft media] winmplayers.exe
 
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
(If you didn't set this using something like Spybot's Immunize feature, then have hjt 'fix' it.)
 
Reboot your computer normally.
 

Post back a new log.

Mike.

0 Kudos