Jump to content

Bypassing Yahoo Parental Controls


Vasto

Recommended Posts

My parents installed YPC on the family computer to stop my sis from being on the internet so much, and I am afraid that they may try to install it on my computer next. So can you help me bypass it? Every time a http address goes out, the controls start up if you terminated them in the Process manager. The following is everything that I could think would help.

 

(This is the ypc_ypc.INI)
[Updates]
Latest Build Number=0x04070202
0x02092001=Traffic 920
0x02112702=Traffic 1127
0x03071603=SP2
0x03081401=SP2
0x03102001=SP2
0x03102201=SP2
0x03111001=SP2
0x04061101=SP2
Default=None

[Strings]
2010=Cancel

[Global Variables]
$VAR:appname=YPC
$VAR:sbcttitle=SBC / Yahoo! Parental Controls Update
$VAR:sbctfile=browser2002091301.exe
$VAR:sbcttext=This updates the Yahoo! Parental Controls.  Click the "Update Now" button to download and install this update.  If you do not wish to install this update, click the "Cancel" button.
$VAREND:

[Traffic 920]
$VAR:sbctbuild=0x02092002
$VAREND:
$INC:TrafficProd:

[Traffic 1127]
$VAR:sbctbuild=0x02112703
$VAREND:
$INC:TrafficProd:

[TrafficProd]
<script>
function CheckYPC_PRODUCTION()
{
if ( document.all("YPC_PRODUCTION").checked )
navigate("YUMCHECK://APP=ypc/REL=$VAR:sbctbuild:/CHK=1/");
else
navigate("YUMCHECK://APP=ypc/REL=$VAR:sbctbuild:/CHK=0/");
}
</script>
<!--  YUMINIT//APP=ypc/REL=$VAR:sbctbuild:/TYP=0/TTL="$VAR:sbcttitle:"/CHK=1/URL="$VAR:sbctfile:"/ARG="/A=ypc /YUM"/SIZ=57344/CRC=0x48eacb55/TIM=1//YUMINIT -->
<tr><td VALIGN=top><INPUT TYPE="CHECKBOX" CHECKED NAME="YPC_PRODUCTION" VALUE="1" onclick="javascript:CheckYPC_PRODUCTION()"></td><td><b>$VAR:sbcttitle:</b><br>$VAR:sbcttext:</td></tr>

[SP2]
$VAR:sp2build=http://us.dl1.yimg.com/download.yahoo.com/dl/yum/browser2004061602.exe
$VAR:startbuild=0x04061101
$VAREND:
$INC:SP2_UPDATE:

[SP2_UPDATE]
$VAREND:
<!--  YUMINIT//APP=ypc/REL=$VAR:startbuild:/TYP=3/FLG=5/TTL="Update for Windows XP SP2"/CHK=1/URL="$VAR:sp2build:"/SIZ=125544/CRC=0xe8ee83f5/TIM=30/IEV="-5.00.20,5.00.23,5.00.26"//YUMINIT -->


[END]

(This is the install.log that was made when they install it.)
***  Installation Started 11/03/2003 20:29  ***
Title: SBC Yahoo! Parental Controls
Source: C:\DOCUME~1\KUSOLD~1.VAI\LOCALS~1\Temp\GLB37.tmp | 11-03-2003 | 20:29:48 | 71680
Delete in-use files: On
RegDB Key: Software\Yahoo
RegDB Val: 1
RegDB Name: Test
RegDB Root: 2
RegDB Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
RegDB Val: Yahoo! Parental Controls
RegDB Name: YPC 3.0.1
RegDB Root: 2
Made Dir: C:\Program Files\Yahoo!\Parental Controls
File Copy: C:\Program Files\Yahoo!\Parental Controls\ypc.exe | 08-14-2003 | 16:07:10 | 2003.8.14.1 | 356417 | 44627969
File Copy: C:\Program Files\Yahoo!\Parental Controls\ypcplug.exe | 07-09-2003 | 14:39:28 | 2003.7.9.1 | 90112 | b7ec6ebf
File Copy: C:\Program Files\Yahoo!\Parental Controls\AppBlocked.html | 07-08-2003 | 17:03:04 | | 2551 | bc1d59f7
File Copy: C:\Program Files\Yahoo!\Parental Controls\AskTimeExtension.html | 06-25-2003 | 19:23:54 | | 2103 | 26588772
File Copy: C:\Program Files\Yahoo!\Parental Controls\MessageBox.html | 07-10-2003 | 20:01:06 | | 2096 | 3f036b79
File Copy: C:\Program Files\Yahoo!\Parental Controls\alrt_s.gif | 03-27-2003 | 15:26:06 | | 406 | b0dc92a0
File Copy: C:\Program Files\Yahoo!\Parental Controls\dialog_bg.jpg | 03-27-2003 | 15:26:06 | | 1246 | 34ed7018
File Copy: C:\Program Files\Yahoo!\Parental Controls\spOrder.dll | 04-11-2001 | 14:27:08 | 5.0.2134.1 | 8464 | 292a867c
Non-System File:
File Copy: C:\WINDOWS\system32\ypclsp.dll | 07-08-2003 | 17:41:24 | 2003.7.8.2 | 155703 | f8daaaea
File Copy: C:\Program Files\Yahoo!\Parental Controls\ypcps.dll | 07-07-2003 | 17:51:56 | 2003.7.7.1 | 28672 | 68395c7f
File Copy: C:\Program Files\Yahoo!\Parental Controls\unypc.exe | 07-02-2003 | 18:00:56 | 2003.7.2.1 | 183631 | afc1f5a0
Execute path: C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe /ReportUninstall
Execute path: C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe /UnregServer
File Copy: C:\Program Files\Yahoo!\Parental Controls\YPCXWizard_DLL.dll | 08-14-2003 | 17:44:24 | 2003.8.6.1 | 188416 | f2537c27
Non-System File:
File Copy: C:\WINDOWS\system32\YPcservice.exe | 05-19-2003 | 16:07:38 | 2003.5.19.1 | 86016 | e1caedd8
Execute path: C:\WINDOWS\System32\ypcservice.exe /UnregServer
RegDB Key: Software\Yahoo\YPC
RegDB Val: 1
RegDB Name: MenuSupport
RegDB Root: 2
RegDB Tree: Software\Yahoo\YPC
RegDB Root: 1
RegDB Tree: Software\Yahoo\YPC
RegDB Root: 2
RegDB Tree: Software\Yahoo\Parental Controls
RegDB Root: 2
RegDB Tree: SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\YPC 3.0.0
RegDB Root: 2
RegDB Tree: Software\Microsoft\Windows\CurrentVersion\Run\YPC
RegDB Root: 2
File Tree: C:\Documents and Settings\All Users\Application Data\ypcinfo.bin
File Tree: C:\PROGRA~1\YAHOO!\PARENT~1\*.*
File Tree: C:\PROGRA~1\YAHOO!\PARENT~1\
RegDB Key: Software\Yahoo\YPC
RegDB Val: C:\Program Files\Yahoo!\Parental Controls
RegDB Name: Path
RegDB Root: 2
RegDB Key: Software\Yahoo\YPC
RegDB Val: 2003.08.14.01
RegDB Name: Version
RegDB Root: 2
RegDB Key: Software\Yahoo\YPC
RegDB Val: 1033
RegDB Name: Language
RegDB Root: 2
RegDB Key: Software\Yahoo\YPC
RegDB Val: 50861057
RegDB Name: Build Number
RegDB Root: 2
RegDB Key: Software\Yahoo\YPC
RegDB Val: C:\PROGRA~1\YAHOO!\PARENT~1
RegDB Name: Path
RegDB Root: 2
RegDB Old: C:\Program Files\Yahoo!\Parental Controls
RegDB Key: Software\Yahoo\YPC
RegDB Val: C:\Documents and Settings\Kusold.VAIO\Start Menu\Programs
RegDB Name: Folder
RegDB Root: 2
RegDB Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SBC Yahoo! Parental Controls
RegDB Val: SBC Yahoo! Parental Controls
RegDB Name: DisplayName
RegDB Root: 2
RegDB Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SBC Yahoo! Parental Controls
RegDB Val: C:\PROGRA~1\YAHOO!\PARENT~1\unypc.exe /S
RegDB Name: UninstallString
RegDB Root: 2
RegDB Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SBC Yahoo! Parental Controls
RegDB Val: C:\Program Files\Yahoo!\Parental Controls\unypc.exe,-0
RegDB Name: DisplayIcon
RegDB Root: 2
Self-Register: C:\Program Files\Yahoo!\Parental Controls\ypcps.dll
Self-Register: C:\Program Files\Yahoo!\Parental Controls\YPCXWizard_DLL.dll
***  Installation Started 11/07/2003 18:06  ***
Title: SBC Yahoo! Parental Controls
Source: C:\DOCUME~1\KUSOLD~1.VAI\LOCALS~1\Temp\GLB1F.tmp | 11-07-2003 | 18:06:34 | 71680
Delete in-use files: On
RegDB Key: Software\Yahoo
RegDB Val: 1
RegDB Name: Test
RegDB Root: 2

(Hijack this log)
Logfile of HijackThis v1.99.1
Scan saved at 2:28:37 PM, on 6/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\program files\support.com\client\bin\tgcmd.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\r?ndll32.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe
C:\Program Files\Trend Micro\PC-cillin 2000\pccntupd.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Folding@Home\FAH502-Console.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\Folding@Home\FahCore_78.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe
C:\WINDOWS\system32\YPCSER~1.EXE
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
I:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/?.intl=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {EC3B8429-2B42-4C77-AA76-6FA05CC8CAA7} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\bin\tgcmd.exe /server
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [OpwareSE2] "D:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [YPC] C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Dtx] C:\WINDOWS\system32\r?ndll32.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [System Kernal Support] system.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: RealTime.lnk = C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe
O4 - Global Startup: Photo Loader supervisory.lnk.disabled
O4 - Global Startup: Photo Loader supervisory.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU - file://C:\Program Files\topMoxie\TEMP\upromise_script0.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\topMoxie\TEMP\upromise_script0.htm (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'ypclsp.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://64.55.105.205/Java/cfs31229.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v3/vet_install_popup.pl?1&4&04.00.09.13&unknown&unknown&http://www.thomasville.com/Products/product.asp?ItemID=1790
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio5_0_2_6.cab
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: FAH@C:+Program Files+Folding@Home+FAH502-Console.exe - Stanford University - C:\Program Files\Folding@Home\FAH502-Console.exe
O23 - Service: FireDaemon Service: Folding (Folding) - Sublime Solutions Pty Ltd - C:\Program Files\FireDaemon\FireDaemon.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

(Startup Log)
StartupList report, 6/20/2005, 2:30:12 PM
StartupList version: 1.52.2
Started from : I:\hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\program files\support.com\client\bin\tgcmd.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\r?ndll32.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe
C:\Program Files\Trend Micro\PC-cillin 2000\pccntupd.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Folding@Home\FAH502-Console.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\Folding@Home\FahCore_78.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe
C:\WINDOWS\system32\YPCSER~1.EXE
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
I:\hijackthis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
VAIO Action Setup (Server).lnk = ?
Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
RealTime.lnk = C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe
Photo Loader supervisory.lnk.disabled
Photo Loader supervisory.lnk = ?
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
Pop3trap.exe = "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
WebTrapNT.exe = "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
ZTgServerSwitch = c:\program files\support.com\client\bin\tgcmd.exe /server
nwiz = nwiz.exe /install
YBrowser = C:\Program Files\Yahoo!\browser\ybrwicon.exe
IPInSightMonitor 01 = "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
2wSysTray = C:\Program Files\2Wire\2PortalMon.exe
DeadAIM = rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
MediaFace Integration = C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
gcasServ = "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
OpwareSE2 = "D:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
YPC = C:\PROGRA~1\YAHOO!\PARENT~1\ypc.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

(Default) = 

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
Dtx = C:\WINDOWS\system32\r?ndll32.exe
SpySweeper = "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
System Kernal Support = system.exe

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - (no file) - {EC3B8429-2B42-4C77-AA76-6FA05CC8CAA7}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Spybot-S&D (easy mode).job
Disk Cleanup.job

--------------------------------------------------

Enumerating Download Program Files:

[Microsoft Office Template and Media Control]
InProcServer32 = C:\PROGRA~1\MICROS~2\OFFICE11\IEAWSDC.DLL
CODEBASE = http://office.microsoft.com/templates/ieawsdc.cab

[MetaStreamCtl Class]
InProcServer32 = C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
CODEBASE = https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v3/vet_install_popup.pl?1&4&04.00.09.13&unknown&unknown&http://www.thomasville.com/Products/product.asp?ItemID=1790

[yucsetreg Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\yucconfig.dll
CODEBASE = C:\Program Files\Yahoo!\common\yucconfig.dll

[YInstStarter Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\common\yinsthelper.dll

[FilePlanet Download Control Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\FilePlanetDownloadCtrl.dll
CODEBASE = http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab

[GSDACtl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\gsda.dll
CODEBASE = http://launch.gamespyarcade.com/software/launch/alaunch.cab

[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37470.246875

[YahooYMailTo Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\ymmapi.dll
CODEBASE = http://download.yahoo.com/dl/installs/ymail/ymmapi.dll

[YAddBook Class]
InProcServer32 = C:\PROGRA~1\Yahoo!\Common\yaddbook.dll
CODEBASE = http://download.yahoo.com/dl/mail/ac4sbc.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\macromed\flash\Flash.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[&Yahoo! Companion]
InProcServer32 = C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio5_0_2_6.cab

--------------------------------------------------

Enumerating Winsock LSP files:

Protocol #1: YPCLSP.dll (file MISSING)
Protocol #2: YPCLSP.dll (file MISSING)
Protocol #3: YPCLSP.dll (file MISSING)
Protocol #23: YPCLSP.dll (file MISSING)

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

--------------------------------------------------
End of report, 8,315 bytes
Report generated in 0.250 seconds

Command line options:
  /verbose  - to add additional info on each section
  /complete - to include empty sections and unsuspicious data
  /full     - to include several rarely-important sections
  /force9x  - to include Win9x-only startups even if running on WinNT
  /forcent  - to include WinNT-only startups even if running on Win9x
  /forceall - to include all Win9x and WinNT startups, regardless of platform
  /history  - to list version history only

 

Any help would be appreciated.

Share this post


Link to post
Share on other sites

it would be even better if you had two hard drives. make them totally independant. like dont have it ask you which one u want to run at boot up. just tel the computer which HDD to boot from and it will load that specific OS. also make sure that the OS ur parents see doesnt reflect the second drive. i.e. dont assign a drive letter to it. if you dont have two hard drives, i would try the MSCONFIG thing. if the process isnt running, then it cant do nethign lol. also check the services. hope this helps :)

Share this post


Link to post
Share on other sites

it would be even better if you had two hard drives. make them totally independant. like dont have it ask you which one u want to run at boot up. just tel the computer which HDD to boot from and it will load that specific OS. also make sure that the OS ur parents see doesnt reflect the second drive. i.e. dont assign a drive letter to it. if you dont have two hard drives, i would try the MSCONFIG thing. if the process isnt running, then it cant do nethign lol. also check the services. hope this helps :)

495468[/snapback]

 

I don't have two HDDs. Also, I am trying not to disable the tasks from starting up because my dad is two computer smart to realize that it isn't running. I am looking more for a way to kill the tasks, then after I am done browsing to start the tasks back up again.

Share this post


Link to post
Share on other sites

I don't have two HDDs. Also, I am trying not to disable the tasks from starting up because my dad is two computer smart to realize that it isn't running. I am looking more for a way to kill the tasks, then after I am done browsing to start the tasks back up again.

495823[/snapback]

 

come chat with me on msn, ive got several viable solutions for you if you havn't already figured it out

 

my msn is

[email protected]

 

I do all my coding in VB6 still :blush:

Share this post


Link to post
Share on other sites

Being a parent I am closing this thread.....

 

I know this will sound weird to people today...but you "could" just walk up to your parents and...ummm....wait for it......

 

talk to them..

 

really....you could...

Discuss it with them and see how they feel...

 

Cheers

Share this post


Link to post
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...