I dont know which one it is but I get redirected in my search engine.
And also one of those web pages that pops up telling you that your computer is full of viruses and starts scanning.
Please, any help greatly Appreciated.


Logfile of Trend Micro HijackThis v2.0.
Scan saved at 6:58:50 PM, on 2/2/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Windows\sspro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched]

Dani AI

Generated

The HijackThis output shown here is truncated (as pointed out). Helpers need a complete log so they can identify browser‑hijack and startup entries. Post the full HijackThis log (save the scan log so it includes entries through O23) or, better, produce FRST’s two logs (FRST.txt and Addition.txt) and paste them. Instructions: see Trend Micro’s HijackThis log guide and the FRST tutorial. ()

Immediate triage (do not pay or call numbers shown by popups): don’t follow popup “scans,” do not purchase software from those pages, and avoid entering credentials. If the fake‑AV blocks downloads, boot to Safe Mode and run up‑to‑date on‑demand scanners (Malwarebytes, ESET Online Scanner or Microsoft Safety Scanner) to get a first cleanup and save their logs. If anything is removed, capture and keep the logs for follow‑up. For official downloads and one‑time scanners see Malwarebytes, ESET Online Scanner and Microsoft Safety Scanner; law enforcement guidance on scareware explains why payment is dangerous. (malwarebytes.com)

If redirects persist after those scans, collect diagnostic info and do targeted cleanup: use Autoruns to review/disable suspicious startup entries, reset the Hosts file to the Microsoft default, and reset Internet Explorer to defaults. If asked by helpers, run FRST and supply both FRST logs — do not run automatic FRST fixlists or advanced removal scripts unless a trained helper gives a specific fix (these can break Windows). When returning, paste (plain text) the full HijackThis log or FRST logs plus any Malwarebytes/ESET/MSERT logs; that lets volunteers pinpoint the offending startup, BHO, proxy/hosts or driver and give a safe removal plan. (learn.microsoft.com)

Your log is incomplete. It should contain entries numbered through O23.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.