Vasto Posted June 20, 2005 Posted June 20, 2005 My parents installed YPC on the family computer to stop my sis from being on the internet so much, and I am afraid that they may try to install it on my computer next. So can you help me bypass it? Every time a http address goes out, the controls start up if you terminated them in the Process manager. The following is everything that I could think would help. (This is the ypc_ypc.INI) [Updates] Latest Build Number=0x04070202 0x02092001=Traffic 920 0x02112702=Traffic 1127 0x03071603=SP2 0x03081401=SP2 0x03102001=SP2 0x03102201=SP2 0x03111001=SP2 0x04061101=SP2 Default=None [Strings] 2010=Cancel [Global Variables] $VAR:appname=YPC $VAR:sbcttitle=SBC / Yahoo! Parental Controls Update $VAR:sbctfile=browser2002091301.exe $VAR:sbcttext=This updates the Yahoo! Parental Controls. Click the "Update Now" button to download and install this update. If you do not wish to install this update, click the "Cancel" button. $VAREND: [Traffic 920] $VAR:sbctbuild=0x02092002 $VAREND: $INC:TrafficProd: [Traffic 1127] $VAR:sbctbuild=0x02112703 $VAREND: $INC:TrafficProd: [TrafficProd] <script> function CheckYPC_PRODUCTION() { if ( document.all("YPC_PRODUCTION").checked ) navigate("YUMCHECK://APP=ypc/REL=$VAR:sbctbuild:/CHK=1/"); else navigate("YUMCHECK://APP=ypc/REL=$VAR:sbctbuild:/CHK=0/"); } </script> <!-- YUMINIT//APP=ypc/REL=$VAR:sbctbuild:/TYP=0/TTL="$VAR:sbcttitle:"/CHK=1/URL="$VAR:sbctfile:"/ARG="/A=ypc /YUM"/SIZ=57344/CRC=0x48eacb55/TIM=1//YUMINIT --> <tr><td VALIGN=top><INPUT TYPE="CHECKBOX" CHECKED NAME="YPC_PRODUCTION" VALUE="1" onclick="javascript:CheckYPC_PRODUCTION()"></td><td><b>$VAR:sbcttitle:</b><br>$VAR:sbcttext:</td></tr> [SP2] $VAR:sp2build=http://us.dl1.yimg.com/download.yahoo.com/dl/yum/browser2004061602.exe $VAR:startbuild=0x04061101 $VAREND: $INC:SP2_UPDATE: [SP2_UPDATE] $VAREND: <!-- YUMINIT//APP=ypc/REL=$VAR:startbuild:/TYP=3/FLG=5/TTL="Update for Windows XP SP2"/CHK=1/URL="$VAR:sp2build:"/SIZ=125544/CRC=0xe8ee83f5/TIM=30/IEV="-5.00.20,5.00.23,5.00.26"//YUMINIT --> [END] (This is the install.log that was made when they install it.) *** Installation Started 11/03/2003 20:29 *** Title: SBC Yahoo! Parental Controls Source: C:\DOCUME~1\KUSOLD~1.VAI\LOCALS~1\Temp\GLB37.tmp | 11-03-2003 | 20:29:48 | 71680 Delete in-use files: On RegDB Key: Software\Yahoo RegDB Val: 1 RegDB Name: Test RegDB Root: 2 RegDB Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform RegDB Val: Yahoo! Parental Controls RegDB Name: YPC 3.0.1 RegDB Root: 2 Made Dir: C:\Program Files\Yahoo!\Parental Controls File Copy: C:\Program Files\Yahoo!\Parental Controls\ypc.exe | 08-14-2003 | 16:07:10 | 2003.8.14.1 | 356417 | 44627969 File Copy: C:\Program Files\Yahoo!\Parental Controls\ypcplug.exe | 07-09-2003 | 14:39:28 | 2003.7.9.1 | 90112 | b7ec6ebf File Copy: C:\Program Files\Yahoo!\Parental Controls\AppBlocked.html | 07-08-2003 | 17:03:04 | | 2551 | bc1d59f7 File Copy: C:\Program Files\Yahoo!\Parental Controls\AskTimeExtension.html | 06-25-2003 | 19:23:54 | | 2103 | 26588772 File Copy: C:\Program Files\Yahoo!\Parental Controls\MessageBox.html | 07-10-2003 | 20:01:06 | | 2096 | 3f036b79 File Copy: C:\Program Files\Yahoo!\Parental Controls\alrt_s.gif | 03-27-2003 | 15:26:06 | | 406 | b0dc92a0 File Copy: C:\Program Files\Yahoo!\Parental Controls\dialog_bg.jpg | 03-27-2003 | 15:26:06 | | 1246 | 34ed7018 File Copy: C:\Program Files\Yahoo!\Parental Controls\spOrder.dll | 04-11-2001 | 14:27:08 | 5.0.2134.1 | 8464 | 292a867c Non-System File: File Copy: C:\WINDOWS\system32\ypclsp.dll | 07-08-2003 | 17:41:24 | 2003.7.8.2 | 155703 | f8daaaea File Copy: C:\Program Files\Yahoo!\Parental Controls\ypcps.dll | 07-07-2003 | 17:51:56 | 2003.7.7.1 | 28672 | 68395c7f File Copy: C:\Program Files\Yahoo!\Parental Controls\unypc.exe | 07-02-2003 | 18:00:56 | 2003.7.2.1 | 183631 | afc1f5a0 Execute path: C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe /ReportUninstall Execute path: C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe /UnregServer File Copy: C:\Program Files\Yahoo!\Parental Controls\YPCXWizard_DLL.dll | 08-14-2003 | 17:44:24 | 2003.8.6.1 | 188416 | f2537c27 Non-System File: File Copy: C:\WINDOWS\system32\YPcservice.exe | 05-19-2003 | 16:07:38 | 2003.5.19.1 | 86016 | e1caedd8 Execute path: C:\WINDOWS\System32\ypcservice.exe /UnregServer RegDB Key: Software\Yahoo\YPC RegDB Val: 1 RegDB Name: MenuSupport RegDB Root: 2 RegDB Tree: Software\Yahoo\YPC RegDB Root: 1 RegDB Tree: Software\Yahoo\YPC RegDB Root: 2 RegDB Tree: Software\Yahoo\Parental Controls RegDB Root: 2 RegDB Tree: SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\YPC 3.0.0 RegDB Root: 2 RegDB Tree: Software\Microsoft\Windows\CurrentVersion\Run\YPC RegDB Root: 2 File Tree: C:\Documents and Settings\All Users\Application Data\ypcinfo.bin File Tree: C:\PROGRA~1\YAHOO!\PARENT~1\*.* File Tree: C:\PROGRA~1\YAHOO!\PARENT~1\ RegDB Key: Software\Yahoo\YPC RegDB Val: C:\Program Files\Yahoo!\Parental Controls RegDB Name: Path RegDB Root: 2 RegDB Key: Software\Yahoo\YPC RegDB Val: 2003.08.14.01 RegDB Name: Version RegDB Root: 2 RegDB Key: Software\Yahoo\YPC RegDB Val: 1033 RegDB Name: Language RegDB Root: 2 RegDB Key: Software\Yahoo\YPC RegDB Val: 50861057 RegDB Name: Build Number RegDB Root: 2 RegDB Key: Software\Yahoo\YPC RegDB Val: C:\PROGRA~1\YAHOO!\PARENT~1 RegDB Name: Path RegDB Root: 2 RegDB Old: C:\Program Files\Yahoo!\Parental Controls RegDB Key: Software\Yahoo\YPC RegDB Val: C:\Documents and Settings\Kusold.VAIO\Start Menu\Programs RegDB Name: Folder RegDB Root: 2 RegDB Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SBC Yahoo! Parental Controls RegDB Val: SBC Yahoo! Parental Controls RegDB Name: DisplayName RegDB Root: 2 RegDB Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SBC Yahoo! Parental Controls RegDB Val: C:\PROGRA~1\YAHOO!\PARENT~1\unypc.exe /S RegDB Name: UninstallString RegDB Root: 2 RegDB Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SBC Yahoo! Parental Controls RegDB Val: C:\Program Files\Yahoo!\Parental Controls\unypc.exe,-0 RegDB Name: DisplayIcon RegDB Root: 2 Self-Register: C:\Program Files\Yahoo!\Parental Controls\ypcps.dll Self-Register: C:\Program Files\Yahoo!\Parental Controls\YPCXWizard_DLL.dll *** Installation Started 11/07/2003 18:06 *** Title: SBC Yahoo! Parental Controls Source: C:\DOCUME~1\KUSOLD~1.VAI\LOCALS~1\Temp\GLB1F.tmp | 11-07-2003 | 18:06:34 | 71680 Delete in-use files: On RegDB Key: Software\Yahoo RegDB Val: 1 RegDB Name: Test RegDB Root: 2 (Hijack this log) Logfile of HijackThis v1.99.1 Scan saved at 2:28:37 PM, on 6/20/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe C:\program files\support.com\client\bin\tgcmd.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\WINDOWS\system32\r?ndll32.exe C:\Program Files\Sony\VAIO Action Setup\VAServ.exe C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe C:\Program Files\Trend Micro\PC-cillin 2000\pccntupd.exe C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE C:\Program Files\Folding@Home\FAH502-Console.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe C:\Program Files\AIM95\aim.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE C:\Program Files\Folding@Home\FahCore_78.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe C:\WINDOWS\system32\YPCSER~1.EXE C:\PROGRA~1\YAHOO!\browser\ycommon.exe I:\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/?.intl=us R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/?.intl=us R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {EC3B8429-2B42-4C77-AA76-6FA05CC8CAA7} - (no file) O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\bin\tgcmd.exe /server O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [OpwareSE2] "D:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [YPC] C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Dtx] C:\WINDOWS\system32\r?ndll32.exe O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0 O4 - HKCU\..\Run: [System Kernal Support] system.exe O4 - Global Startup: VAIO Action Setup (Server).lnk = ? O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: RealTime.lnk = C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe O4 - Global Startup: Photo Loader supervisory.lnk.disabled O4 - Global Startup: Photo Loader supervisory.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: RemindU - file://C:\Program Files\topMoxie\TEMP\upromise_script0.htm O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\topMoxie\TEMP\upromise_script0.htm (file missing) (HKCU) O10 - Broken Internet access because of LSP provider 'ypclsp.dll' missing O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://64.55.105.205/Java/cfs31229.cab O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v3/vet_install_popup.pl?1&4&04.00.09.13&unknown&unknown&http://www.thomasville.com/Products/product.asp?ItemID=1790 O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio5_0_2_6.cab O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE O23 - Service: FAH@C:+Program Files+Folding@Home+FAH502-Console.exe - Stanford University - C:\Program Files\Folding@Home\FAH502-Console.exe O23 - Service: FireDaemon Service: Folding (Folding) - Sublime Solutions Pty Ltd - C:\Program Files\FireDaemon\FireDaemon.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE (Startup Log) StartupList report, 6/20/2005, 2:30:12 PM StartupList version: 1.52.2 Started from : I:\hijackthis\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe C:\program files\support.com\client\bin\tgcmd.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\WINDOWS\system32\r?ndll32.exe C:\Program Files\Sony\VAIO Action Setup\VAServ.exe C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe C:\Program Files\Trend Micro\PC-cillin 2000\pccntupd.exe C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE C:\Program Files\Folding@Home\FAH502-Console.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe C:\Program Files\AIM95\aim.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE C:\Program Files\Folding@Home\FahCore_78.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe C:\WINDOWS\system32\YPCSER~1.EXE C:\PROGRA~1\YAHOO!\browser\ycommon.exe I:\hijackthis\HijackThis.exe -------------------------------------------------- Listing of startup folders: Shell folders Common Startup: [C:\Documents and Settings\All Users\Start Menu\Programs\Startup] VAIO Action Setup (Server).lnk = ? Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe RealTime.lnk = C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe Photo Loader supervisory.lnk.disabled Photo Loader supervisory.lnk = ? Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup Pop3trap.exe = "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" WebTrapNT.exe = "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" ZTgServerSwitch = c:\program files\support.com\client\bin\tgcmd.exe /server nwiz = nwiz.exe /install YBrowser = C:\Program Files\Yahoo!\browser\ybrwicon.exe IPInSightMonitor 01 = "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" 2wSysTray = C:\Program Files\2Wire\2PortalMon.exe DeadAIM = rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs MediaFace Integration = C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe gcasServ = "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" OpwareSE2 = "D:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" YPC = C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx (Default) = -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background Dtx = C:\WINDOWS\system32\r?ndll32.exe SpySweeper = "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0 System Kernal Support = system.exe -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=*Registry value not found* drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670} (no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (no name) - (no file) - {EC3B8429-2B42-4C77-AA76-6FA05CC8CAA7} -------------------------------------------------- Enumerating Task Scheduler jobs: Spybot-S&D (easy mode).job Disk Cleanup.job -------------------------------------------------- Enumerating Download Program Files: [Microsoft Office Template and Media Control] InProcServer32 = C:\PROGRA~1\MICROS~2\OFFICE11\IEAWSDC.DLL CODEBASE = http://office.microsoft.com/templates/ieawsdc.cab [MetaStreamCtl Class] InProcServer32 = C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll CODEBASE = https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v3/vet_install_popup.pl?1&4&04.00.09.13&unknown&unknown&http://www.thomasville.com/Products/product.asp?ItemID=1790 [yucsetreg Class] InProcServer32 = C:\Program Files\Yahoo!\Common\yucconfig.dll CODEBASE = C:\Program Files\Yahoo!\common\yucconfig.dll [YInstStarter Class] InProcServer32 = C:\Program Files\Yahoo!\Common\yinsthelper.dll CODEBASE = C:\Program Files\Yahoo!\common\yinsthelper.dll [FilePlanet Download Control Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\FilePlanetDownloadCtrl.dll CODEBASE = http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab [GSDACtl Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\gsda.dll CODEBASE = http://launch.gamespyarcade.com/software/launch/alaunch.cab [{9F1C11AA-197B-4942-BA54-47A8489BB47F}] CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37470.246875 [YahooYMailTo Class] InProcServer32 = C:\Program Files\Yahoo!\Common\ymmapi.dll CODEBASE = http://download.yahoo.com/dl/installs/ymail/ymmapi.dll [YAddBook Class] InProcServer32 = C:\PROGRA~1\Yahoo!\Common\yaddbook.dll CODEBASE = http://download.yahoo.com/dl/mail/ac4sbc.cab [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\macromed\flash\Flash.ocx CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [&Yahoo! Companion] InProcServer32 = C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio5_0_2_6.cab -------------------------------------------------- Enumerating Winsock LSP files: Protocol #1: YPCLSP.dll (file MISSING) Protocol #2: YPCLSP.dll (file MISSING) Protocol #3: YPCLSP.dll (file MISSING) Protocol #23: YPCLSP.dll (file MISSING) -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\System32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll -------------------------------------------------- End of report, 8,315 bytes Report generated in 0.250 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only Any help would be appreciated. Share this post Link to post Share on other sites More sharing options...
94Camaro Posted June 21, 2005 Posted June 21, 2005 Maybe disabling the process from starting up in the first place in msconfig? Check both the services and startup tabs? Share this post Link to post Share on other sites More sharing options...
SoCalMixedGuy Posted June 21, 2005 Posted June 21, 2005 Install 2 copies of you OS on your HD, leave one on for them to install it on, then just switch OS. Theyll never know. Share this post Link to post Share on other sites More sharing options...
CNUco2007 Posted June 21, 2005 Posted June 21, 2005 it would be even better if you had two hard drives. make them totally independant. like dont have it ask you which one u want to run at boot up. just tel the computer which HDD to boot from and it will load that specific OS. also make sure that the OS ur parents see doesnt reflect the second drive. i.e. dont assign a drive letter to it. if you dont have two hard drives, i would try the MSCONFIG thing. if the process isnt running, then it cant do nethign lol. also check the services. hope this helps Share this post Link to post Share on other sites More sharing options...
Vasto Posted June 21, 2005 Posted June 21, 2005 it would be even better if you had two hard drives. make them totally independant. like dont have it ask you which one u want to run at boot up. just tel the computer which HDD to boot from and it will load that specific OS. also make sure that the OS ur parents see doesnt reflect the second drive. i.e. dont assign a drive letter to it. if you dont have two hard drives, i would try the MSCONFIG thing. if the process isnt running, then it cant do nethign lol. also check the services. hope this helps 495468[/snapback] I don't have two HDDs. Also, I am trying not to disable the tasks from starting up because my dad is two computer smart to realize that it isn't running. I am looking more for a way to kill the tasks, then after I am done browsing to start the tasks back up again. Share this post Link to post Share on other sites More sharing options...
GuJuMaN89 Posted June 21, 2005 Posted June 21, 2005 does yahoo have its own browser? if so install firefox and use that Share this post Link to post Share on other sites More sharing options...
Coolzero101 Posted June 21, 2005 Posted June 21, 2005 I don't have two HDDs. Also, I am trying not to disable the tasks from starting up because my dad is two computer smart to realize that it isn't running. I am looking more for a way to kill the tasks, then after I am done browsing to start the tasks back up again. 495823[/snapback] come chat with me on msn, ive got several viable solutions for you if you havn't already figured it out my msn is [email protected] I do all my coding in VB6 still Share this post Link to post Share on other sites More sharing options...
exeter_acres Posted June 21, 2005 Posted June 21, 2005 Being a parent I am closing this thread..... I know this will sound weird to people today...but you "could" just walk up to your parents and...ummm....wait for it...... talk to them.. really....you could... Discuss it with them and see how they feel... Cheers Share this post Link to post Share on other sites More sharing options...
Recommended Posts