Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Here's my HJT log as requested by Broni  (Read 13181 times)

0 Members and 1 Guest are viewing this topic.

pepper

    Topic Starter


    Hopeful
  • Thanked: 1
    Here's my HJT log as requested by Broni
    « on: November 13, 2007, 07:50:44 PM »
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:02:56 PM, on 11/13/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    pepper

      Topic Starter


      Hopeful
    • Thanked: 1
      Re: Here's my HJT log as requested by Broni
      « Reply #1 on: November 13, 2007, 07:53:30 PM »
      C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
      C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
      C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
      C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
      C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
      C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
      C:\Program Files\QUICKENW\QWDLLS.EXE
      C:\PROGRA~1\INCRED~1\bin\IMApp.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\ALCXMNTR.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      c:\windows\system\hpsysdrv.exe
      C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
      C:\Program Files\IncrediMail\bin\IncMail.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\Y97H17ES\HiJackThis[1].exe
      C:\WINDOWS\system32\NOTEPAD.EXE

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
      R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
      O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
      O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
      O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL

      pepper

        Topic Starter


        Hopeful
      • Thanked: 1
        Re: Here's my HJT log as requested by Broni
        « Reply #2 on: November 13, 2007, 07:57:09 PM »
        4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
        O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
        O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
        O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
        O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
        O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
        O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
        O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
        O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
        O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
        O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
        O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
        O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
        O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
        O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
        O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
        O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
        O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
        O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
        O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
        O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
        O23 - Service: Trend Micro Protection Against Spyware  (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
        O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
        O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
        O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
        O24 - Desktop Component 0: (no name) - http://www.michaelmcdonald.com/phpBB2/templates/iCGstation/images/banner.jpg
        O24 - Desktop Component 1: (no name) - https://www.paygonline.com/websc/images/bg_contents.png

        --
        End of file - 12660 bytes

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: Here's my HJT log as requested by Broni
        « Reply #3 on: November 13, 2007, 07:59:05 PM »
        I'll take a look...

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: Here's my HJT log as requested by Broni
        « Reply #4 on: November 13, 2007, 08:27:08 PM »
        I didn't find any serious problems, but please, do as follows:

        1. Print this post out, since you won't have an access to it, at some point.

        2. Download, and install Spybot (if you don't have it) from here: http://www.safer-networking.org/en/download/index.html

        3. Close all windows, except for HJT.

        3a. Go Start>Control Panel>Add/Remove, and uninstall Ask Jeeves Toolbar (if present). Some consider it as adware:
        http://www.benedelman.org/spyware/installations/askjeeves-banner/

        4. Put a checkmark next to following HJT entries:

        - R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

        5. Click on "Fix It" button.

        6. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

        7. Run Spybot (check for updates, first), and fix whatever it asks you to fix.

        8. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

        9. Delete following files (if they still exist):

        - AskSBar folder from C:\Program Files\

        10. Turn off System Restore:

        - Windows XP:
           1. Click Start.
           2. Right-click the My Computer icon, and then click Properties.
           3. Click the System Restore tab.
           4. Check "Turn off System Restore".
           5. Click Apply.   
           6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
           7. Click OK.
        - Windows Vista:
           1. Click Start.
           2. Right-click the Computer icon, and then click Properties.
           3. Click on System Protection under the Tasks column on the left side
           4. Click on Continue on the "User Account Control" window that pops up
           5. Under the System Protection tab, find Available Disks
           6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
           7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
           8. Click OK

        11. Restart in Normal Mode.

        12. Turn System Restore on.

        13. Run HJT again, and post back its log back here.
        « Last Edit: November 23, 2007, 05:00:56 PM by Broni »

        pepper

          Topic Starter


          Hopeful
        • Thanked: 1
          Re: Here's my HJT log as requested by Broni
          « Reply #5 on: November 14, 2007, 04:51:14 AM »
          Thank you Broni!  :)

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: Here's my HJT log as requested by Broni
          « Reply #6 on: November 14, 2007, 05:34:41 PM »
          You're welcome:)
          Did all steps work OK? Did Spybot find anything?

          What about your initial issue about those unknown pictures?
          http://www.computerhope.com/forum/index.php/topic,45713.0.html

          pepper

            Topic Starter


            Hopeful
          • Thanked: 1
            Re: Here's my HJT log as requested by Broni
            « Reply #7 on: November 23, 2007, 04:40:12 PM »
            I finally got time to do this.  I had two problems. 

            #8 when I went to tools there as no "folder options" so I went to internet options but I couldn't find it there either.

            #9 I tried to delete AskSBar but got an error message "cannot delete, access denied"

            I still went through the rest of the instructions and here is my new log from HJT

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 6:31:02 PM, on 11/23/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16544)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
            C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
            C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
            C:\HP\KBD\KBD.EXE
            C:\Program Files\Microsoft IntelliPoint\ipoint.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
            C:\WINDOWS\system32\svchost.exe
            C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
            C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
            C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
            C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
            C:\Program Files\QUICKENW\QWDLLS.EXE
            C:\PROGRA~1\INCRED~1\bin\IMApp.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\ALCXMNTR.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            c:\windows\system\hpsysdrv.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\90DUGFGT\HiJackThis[2].exe


            pepper

              Topic Starter


              Hopeful
            • Thanked: 1
              Re: Here's my HJT log as requested by Broni
              « Reply #8 on: November 23, 2007, 04:42:11 PM »
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
              O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
              O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
              O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
              O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
              O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
              O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
              O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
              O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
              O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
              O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
              O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
              O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
              O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
              O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
              O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
              O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
              O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
              O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
              O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
              O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
              O23 - Service: Trend Micro Protection Against Spyware  (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
              O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
              O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
              O24 - Desktop Component 0: (no name) - http://www.michaelmcdonald.com/phpBB2/templates/iCGstation/images/banner.jpg
              O24 - Desktop Component 1: (no name) - https://www.paygonline.com/websc/images/bg_contents.png

              --
              End of file - 10419 bytes

              pepper

                Topic Starter


                Hopeful
              • Thanked: 1
                Re: Here's my HJT log as requested by Broni
                « Reply #9 on: November 23, 2007, 04:44:16 PM »
                I didn't realize that I would have to pay for Spybot in order to get everything fixed.  I had 242 errors and only 15 were removed and to get the 227 remaining I had to pay $29.95.

                I'm going to go check to see if those pictures are gone or still there.

                pepper

                  Topic Starter


                  Hopeful
                • Thanked: 1
                  Re: Here's my HJT log as requested by Broni
                  « Reply #10 on: November 23, 2007, 04:54:01 PM »
                  Well after all that and $29.95 all those pictures are still there!!!    :P :'(

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: Here's my HJT log as requested by Broni
                  « Reply #11 on: November 23, 2007, 05:05:45 PM »
                  I don't know where you went to download Spybot, but Spybot is free, and free at the download link, I gave you:
                  http://www.safer-networking.org/en/download/index.html

                  Now, let me take a look at your HJT log.

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: Here's my HJT log as requested by Broni
                  « Reply #12 on: November 23, 2007, 05:16:07 PM »
                  One more thing...NEVER, EVER pay for any security program without asking for advice!!!

                  Now...

                  1. Print out these instructions as we will need to close every window that is open later in the fix.

                  2. Download SmitfraudFix.exe from here and save it to your desktop:

                  http://www.bleepingcomputer.com/files/smitfraudfix.php

                  3. Next, please reboot your computer into Safe Mode by doing the following:

                     a. Restart your computer

                     b. Start tapping F8 key

                     c. A menu will appear

                     d. Select the first option, to run Windows in Safe Mode.

                  4. Close all open Windows.

                  5. Now, double-click on the SmitFraudfix icon.

                  6. When the tool first starts you will see a credits screen. Simply press any key on your keyboard to get to the next screen.

                  7. You will now see a menu. Press the number 2 on your keyboard and the press the Enter key to choose the option Clean.

                  8. The program will start cleaning your computer and go through a series of cleanup processes. When it is done, it will automatically start the Disk Cleanup program.
                  This program will remove all Temp, Temporary Internet Files, and other files that may be leftover files from this infection. This process can take up a long time depending on your computer, so please be patient. When it is complete, it will close automatically and you should continue with next step.

                  9. When Disk Cleanup is finished, you will be presented with an option asking Do you want to clean the registry ? (y/n). At this screen you should press the Y button on your keyboard and then press the Enter key.

                  10. When this last routine is finished, you will be presented with a red screen stating Computer will reboot now. Close all applications. You should now press the spacebar on your computer. A counter will appear stating that the computer will reboot in 15 seconds. Do not cancel this countdown and allow your computer to reboot.

                  11. Once the computer has rebooted, you will be presented with a Notepad screen containing a log of all the files removed from your computer.
                  Save that log to your desktop, and attach it to your next reply.

                  pepper

                    Topic Starter


                    Hopeful
                  • Thanked: 1
                    Re: Here's my HJT log as requested by Broni
                    « Reply #13 on: November 23, 2007, 05:23:00 PM »
                    Okay I'm going to print this but first I have to tell you that I went to Spybot from the link you posted and ran the scan and it found 242 errors but only 15 would be fixed for free.  I had to pay the $29.95 to get the remaining errors fixed.

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: Here's my HJT log as requested by Broni
                    « Reply #14 on: November 23, 2007, 05:39:06 PM »
                    Quote
                    I had to pay the $29.95 to get the remaining errors fixed.
                    I-M-P-O-S-S-I-B-L-E!!!
                    Did you download THIS:


                    [saving disk space - old attachment deleted by admin]

                    pepper

                      Topic Starter


                      Hopeful
                    • Thanked: 1
                      Re: Here's my HJT log as requested by Broni
                      « Reply #15 on: November 23, 2007, 07:36:48 PM »
                      Not impossible!!!  #10 - red screen never happened.  When everything was done I had to restore my wallpaper and my homepage.  I still have 44,739 pictures and I'm done now.  Thanks for your patience.    :)

                      SmitFraudFix v2.253
                       
                      Scan done at 20:33:45.78, Fri 11/23/2007
                      Run from C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix
                      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                      The filesystem type is NTFS
                      Fix run in safe mode

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                      !!!Attention, following keys are not inevitably infected!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Killing process


                      »»»»»»»»»»»»»»»»»»»»»»»» hosts


                      127.0.0.1       localhost

                      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                      S!Ri's WS2Fix: LSP not Found.


                      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                      GenericRenosFix by S!Ri


                      »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{53BC7CEC-322C-4C1A-90AB-8832261DCF00}: DhcpNameServer=65.32.5.74 65.32.5.75
                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{B79CD0E0-7DB7-4724-A9D0-ED3179536593}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{53BC7CEC-322C-4C1A-90AB-8832261DCF00}: DhcpNameServer=65.32.5.74 65.32.5.75
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{B79CD0E0-7DB7-4724-A9D0-ED3179536593}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
                      HKLM\SYSTEM\CS3\Services\Tcpip\..\{53BC7CEC-322C-4C1A-90AB-8832261DCF00}: DhcpNameServer=65.32.5.74 65.32.5.75
                      HKLM\SYSTEM\CS3\Services\Tcpip\..\{B79CD0E0-7DB7-4724-A9D0-ED3179536593}: DhcpNameServer=16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=65.32.5.74 65.32.5.75
                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=65.32.5.74 65.32.5.75
                      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=65.32.5.74 65.32.5.75


                      »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                      !!!Attention, following keys are not inevitably infected!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      "System"=""


                      »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
                       
                      Registry Cleaning done.
                       
                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                      !!!Attention, following keys are not inevitably infected!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll


                      »»»»»»»»»»»»»»»»»»»»»»»» End




                      Broni


                        Mastermind
                      • Kraków my love :)
                      • Thanked: 614
                        • Computer Help Forum
                      • Computer: Specs
                      • Experience: Experienced
                      • OS: Windows 8
                      Re: Here's my HJT log as requested by Broni
                      « Reply #16 on: November 23, 2007, 07:40:22 PM »
                      Your next step...

                      Download and scan with SUPERAntiSpyware Free for Home Users:
                      http://www.superantispyware.com/

                          * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                          * An icon will be created on your desktop. Double-click that icon to launch the program.
                          * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                          * Under "Configuration and Preferences", click the Preferences button.
                          * Click the Scanning Control tab.
                          * Under Scanner Options make sure the following are checked (leave all others unchecked):
                                o Close browsers before scanning.
                                o Scan for tracking cookies.
                                o Terminate memory threats before quarantining.
                          * Click the "Close" button to leave the control center screen.
                          * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                          * On the left, make sure you check C:\Fixed Drive.
                          * On the right, under "Complete Scan", choose Perform Complete Scan.
                          * Click "Next" to start the scan. Please be patient while it scans your computer.
                          * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                          * Make sure everything has a checkmark next to it and click "Next".
                          * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                          * If asked if you want to reboot, click "Yes".
                          * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                                o Click Preferences, then click the Statistics/Logs tab.
                                o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                                o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                                o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
                          * Click Close to exit the program.

                      pepper

                        Topic Starter


                        Hopeful
                      • Thanked: 1
                        Re: Here's my HJT log as requested by Broni
                        « Reply #17 on: November 24, 2007, 01:38:44 PM »
                        This scan took 6 1/2 hours but it's okay I got my tree decorated while it was scanning!!!   :)

                        SUPERAntiSpyware Scan Log
                        http://www.superantispyware.com

                        Generated 11/24/2007 at 03:24 PM

                        Application Version : 3.9.1008

                        Core Rules Database Version : 3349
                        Trace Rules Database Version: 1349

                        Scan type       : Complete Scan
                        Total Scan Time : 06:16:25

                        Memory items scanned      : 549
                        Memory threats detected   : 0
                        Registry items scanned    : 6055
                        Registry threats detected : 0
                        File items scanned        : 339998
                        File threats detected     : 84

                        Adware.Tracking Cookie
                           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           C:\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           C:\olddata\WINDOWS\Cookies\[email protected][1].txt
                           C:\olddata\WINDOWS\Cookies\[email protected][2].txt
                           C:\olddata\WINDOWS\Cookies\default@media-general[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adecn[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adknowledge[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adknowledge[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@admarketplace[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@atwola[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@belnk[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@burstnet[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@burstnet[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cassava[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@easy-hit-counters[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ez-tracks[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@hotbar[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@imrworldwide[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@interclick[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@interclick[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@kanoodle[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@kanoodle[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@media-general[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@medianewsgroup[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@nextag[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@nextag[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@partner2profit[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@partner2profit[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@precisionclick[2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@toplist[1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][2].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][3].txt
                           D:\bkup\Documents and Settings\Compaq_Owner\Cookies\[email protected][1].txt
                           D:\bkup\olddata\WINDOWS\Cookies\[email protected][1].txt
                           D:\bkup\olddata\WINDOWS\Cookies\[email protected][2].txt
                           D:\bkup\olddata\WINDOWS\Cookies\default@media-general[1].txt

                        Broni


                          Mastermind
                        • Kraków my love :)
                        • Thanked: 614
                          • Computer Help Forum
                        • Computer: Specs
                        • Experience: Experienced
                        • OS: Windows 8
                        Re: Here's my HJT log as requested by Broni
                        « Reply #18 on: November 24, 2007, 01:45:33 PM »
                        That's it, or there is more?
                        If not, post fresh HJT log.

                        pepper

                          Topic Starter


                          Hopeful
                        • Thanked: 1
                          Re: Here's my HJT log as requested by Broni
                          « Reply #19 on: November 24, 2007, 01:47:43 PM »
                          HJT Log:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 3:41:02 PM, on 11/24/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                          C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
                          C:\WINDOWS\system32\HPZipm12.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                          C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                          C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
                          C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
                          C:\HP\KBD\KBD.EXE
                          C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
                          C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
                          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                          C:\Program Files\QUICKENW\QWDLLS.EXE
                          C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
                          C:\WINDOWS\ALCXMNTR.EXE
                          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          c:\windows\system\hpsysdrv.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\90DUGFGT\HiJackThis[1].exe


                          pepper

                            Topic Starter


                            Hopeful
                          • Thanked: 1
                            Re: Here's my HJT log as requested by Broni
                            « Reply #20 on: November 24, 2007, 01:49:20 PM »
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                            R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
                            O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                            O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                            O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                            O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                            O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
                            O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                            O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                            O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                            O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                            O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
                            O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                            O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
                            O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
                            O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                            O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                            O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                            O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                            O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
                            O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                            O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                            O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                            O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                            O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                            O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                            O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                            O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
                            O23 - Service: Trend Micro Protection Against Spyware  (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
                            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                            O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
                            O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                            O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

                            --
                            End of file - 9810 bytes

                            Broni


                              Mastermind
                            • Kraków my love :)
                            • Thanked: 614
                              • Computer Help Forum
                            • Computer: Specs
                            • Experience: Experienced
                            • OS: Windows 8
                            Re: Here's my HJT log as requested by Broni
                            « Reply #21 on: November 24, 2007, 02:22:21 PM »
                            OK, I had to go back, because you've never answered one of my questions:
                            Go Start>Control Panel>Add/Remove, and uninstall Ask Jeeves Toolbar. It may be called Ask Toolbar. Is it there?

                            pepper

                              Topic Starter


                              Hopeful
                            • Thanked: 1
                              Re: Here's my HJT log as requested by Broni
                              « Reply #22 on: November 24, 2007, 03:10:01 PM »
                              I saw that Ask Toolbar but wasn't sure if it was the same as Jeeves.  I just now uninstalled it.

                              Broni


                                Mastermind
                              • Kraków my love :)
                              • Thanked: 614
                                • Computer Help Forum
                              • Computer: Specs
                              • Experience: Experienced
                              • OS: Windows 8
                              Re: Here's my HJT log as requested by Broni
                              « Reply #23 on: November 24, 2007, 03:12:34 PM »
                              Very good. Give me your new HJT log.

                              pepper

                                Topic Starter


                                Hopeful
                              • Thanked: 1
                                Re: Here's my HJT log as requested by Broni
                                « Reply #24 on: November 24, 2007, 03:17:06 PM »
                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 5:14:50 PM, on 11/24/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                C:\WINDOWS\system32\HPZipm12.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
                                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
                                C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
                                C:\HP\KBD\KBD.EXE
                                C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
                                C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
                                C:\Program Files\QUICKENW\QWDLLS.EXE
                                C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\Program Files\Alwil Software\Avast4\setup\avast.setup
                                C:\Program Files\IncrediMail\bin\IncMail.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\BWW234EH\HiJackThis[1].exe


                                pepper

                                  Topic Starter


                                  Hopeful
                                • Thanked: 1
                                  Re: Here's my HJT log as requested by Broni
                                  « Reply #25 on: November 24, 2007, 03:18:49 PM »
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                  O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                  O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                                  O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                                  O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                                  O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                                  O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                                  O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
                                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                  O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\RunOnce: [AskSBar Uninstall] rundll32 C:\PROGRA~1\UNINST~1.DLL,O -3
                                  O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
                                  O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                                  O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                                  O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                  O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                  O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
                                  O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                  O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                                  O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                                  O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                  O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                                  --
                                  End of file - 9068 bytes

                                  Broni


                                    Mastermind
                                  • Kraków my love :)
                                  • Thanked: 614
                                    • Computer Help Forum
                                  • Computer: Specs
                                  • Experience: Experienced
                                  • OS: Windows 8
                                  Re: Here's my HJT log as requested by Broni
                                  « Reply #26 on: November 24, 2007, 03:22:04 PM »
                                  You need to restart your computer to complete that uninstall (so far, so good), and post a new log. We're almost there.

                                  pepper

                                    Topic Starter


                                    Hopeful
                                  • Thanked: 1
                                    Re: Here's my HJT log as requested by Broni
                                    « Reply #27 on: November 24, 2007, 03:32:40 PM »
                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 5:30:42 PM, on 11/24/2007
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                    C:\WINDOWS\system32\HPZipm12.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                    C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                    C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
                                    C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
                                    C:\HP\KBD\KBD.EXE
                                    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                                    C:\Program Files\iTunes\iTunesHelper.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
                                    C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
                                    C:\Program Files\QUICKENW\QWDLLS.EXE
                                    C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\Program Files\iPod\bin\iPodService.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\WINDOWS\ALCXMNTR.EXE
                                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                    c:\windows\system\hpsysdrv.exe
                                    C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\HEWFZADW\HiJackThis[1].exe

                                    pepper

                                      Topic Starter


                                      Hopeful
                                    • Thanked: 1
                                      Re: Here's my HJT log as requested by Broni
                                      « Reply #28 on: November 24, 2007, 03:33:50 PM »
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                      O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                      O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                                      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                                      O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                                      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                                      O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                                      O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
                                      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                      O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
                                      O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                                      O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                                      O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                      O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                      O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
                                      O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                                      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                                      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                                      O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                                      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                                      O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                                      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                                      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                                      --
                                      End of file - 9094 bytes

                                      Broni


                                        Mastermind
                                      • Kraków my love :)
                                      • Thanked: 614
                                        • Computer Help Forum
                                      • Computer: Specs
                                      • Experience: Experienced
                                      • OS: Windows 8
                                      Re: Here's my HJT log as requested by Broni
                                      « Reply #29 on: November 24, 2007, 03:37:55 PM »
                                      Nice. You're clean...

                                      Now, what about those few thousands of pictures?

                                      pepper

                                        Topic Starter


                                        Hopeful
                                      • Thanked: 1
                                        Re: Here's my HJT log as requested by Broni
                                        « Reply #30 on: November 24, 2007, 03:49:25 PM »
                                        Before this there was 44,739 and now there is 44,740.  LOL!!!!!!

                                        Broni


                                          Mastermind
                                        • Kraków my love :)
                                        • Thanked: 614
                                          • Computer Help Forum
                                        • Computer: Specs
                                        • Experience: Experienced
                                        • OS: Windows 8
                                        Re: Here's my HJT log as requested by Broni
                                        « Reply #31 on: November 24, 2007, 03:53:16 PM »
                                        OK, OK...where are they located?

                                        Broni


                                          Mastermind
                                        • Kraków my love :)
                                        • Thanked: 614
                                          • Computer Help Forum
                                        • Computer: Specs
                                        • Experience: Experienced
                                        • OS: Windows 8
                                        Re: Here's my HJT log as requested by Broni
                                        « Reply #32 on: November 24, 2007, 03:58:54 PM »
                                        I'm leaving for the movies, right now, so we'll have to continue tomorrow.

                                        pepper

                                          Topic Starter


                                          Hopeful
                                        • Thanked: 1
                                          Re: Here's my HJT log as requested by Broni
                                          « Reply #33 on: November 25, 2007, 09:10:38 AM »
                                          Thanks Broni for your help.  My computer is definitely running faster even though all those pictures are still there. 

                                          There is something on my desktop that I would like to get rid of.  It wasn't there before.  The words "Windows XP Home Edition" etc.  How do I get rid of that?

                                          Broni


                                            Mastermind
                                          • Kraków my love :)
                                          • Thanked: 614
                                            • Computer Help Forum
                                          • Computer: Specs
                                          • Experience: Experienced
                                          • OS: Windows 8
                                          Re: Here's my HJT log as requested by Broni
                                          « Reply #34 on: November 25, 2007, 02:22:30 PM »
                                          You're welcome... ;D

                                          I need to know, where those pictures are...

                                          Quote
                                          The words "Windows XP Home Edition" etc.  How do I get rid of that?
                                          Where on your desktop is it? It may be not possible to remove it. Was it always there?

                                          pepper

                                            Topic Starter


                                            Hopeful
                                          • Thanked: 1
                                            Re: Here's my HJT log as requested by Broni
                                            « Reply #35 on: November 25, 2007, 03:17:11 PM »
                                             The Windows XP Home Edition is on the lower right hand corner of my desktop.  It was never there before.

                                            I find the pictures when I go to search and check pictures and videos.  Some of my pictures are there but 95% of them are weird pictures and I have no idea how they got there.

                                            Broni


                                              Mastermind
                                            • Kraków my love :)
                                            • Thanked: 614
                                              • Computer Help Forum
                                            • Computer: Specs
                                            • Experience: Experienced
                                            • OS: Windows 8
                                            Re: Here's my HJT log as requested by Broni
                                            « Reply #36 on: November 25, 2007, 03:21:00 PM »
                                            Since we did all that security cleaning, delete all those unwanted pictures, and watch closely, if they'll reappear.

                                            pepper

                                              Topic Starter


                                              Hopeful
                                            • Thanked: 1
                                              Re: Here's my HJT log as requested by Broni
                                              « Reply #37 on: November 25, 2007, 03:27:32 PM »
                                              A friend told me not to delete them because they maybe related to programs.  I'm afraid to delete them.  When you do a search on your computer for pictures and videos how many do you have?

                                              evilfantasy

                                              • Malware Removal Specialist
                                              • Moderator


                                              • Genius
                                              • Calm like a bomb
                                              • Thanked: 493
                                              • Experience: Experienced
                                              • OS: Windows 11
                                              Re: Here's my HJT log as requested by Broni
                                              « Reply #38 on: November 25, 2007, 03:29:30 PM »
                                              I find the pictures when I go to search and check pictures and videos.  Some of my pictures are there but 95% of them are weird pictures and I have no idea how they got there.

                                              Templates from photo editing programs?

                                              Broni


                                                Mastermind
                                              • Kraków my love :)
                                              • Thanked: 614
                                                • Computer Help Forum
                                              • Computer: Specs
                                              • Experience: Experienced
                                              • OS: Windows 8
                                              Re: Here's my HJT log as requested by Broni
                                              « Reply #39 on: November 25, 2007, 03:32:20 PM »
                                              I don't know of any videos, being needed by your OS.
                                              There are some graphic files (like icons) needed by some programs, but they are located in particular program's folder.
                                              It'd helpful, if you state in what folder you have those files.


                                              pepper

                                                Topic Starter


                                                Hopeful
                                              • Thanked: 1
                                                Re: Here's my HJT log as requested by Broni
                                                « Reply #40 on: November 25, 2007, 04:10:35 PM »
                                                I think they are all in different folders.  When you do a search for pictures doesn't it check all the folders for pictures?

                                                Broni


                                                  Mastermind
                                                • Kraków my love :)
                                                • Thanked: 614
                                                  • Computer Help Forum
                                                • Computer: Specs
                                                • Experience: Experienced
                                                • OS: Windows 8
                                                Re: Here's my HJT log as requested by Broni
                                                « Reply #41 on: November 25, 2007, 04:14:20 PM »
                                                Quote
                                                When you do a search for pictures doesn't it check all the folders for pictures?
                                                Yes.
                                                In that case, I think, you need to take couple of days off, and check those pictures one-by-one. I can't imagine any other advice, since I don't want you to delete your own pictures.

                                                CBMatt

                                                • Mod & Malware Specialist


                                                • Prodigy

                                                • Sad and lonely...and loving every minute of it.
                                                • Thanked: 167
                                                  • Yes
                                                • Experience: Experienced
                                                • OS: Windows 7
                                                Re: Here's my HJT log as requested by Broni
                                                « Reply #42 on: November 27, 2007, 05:07:25 AM »
                                                A word of advice...your HijackThis is in a temporary location where it (and its backups) will eventually be deleted.  I would advise moving (or re-downloading) it to a new permanent location where it can be kept safely.

                                                Also...those pictures probably aren't anything to worry about.  Most of them are probably from various programs/games/whatever.  They should be harmless.  However, if you would like to clear up some space, you could go through them all and try to determine if there are any you can safely get rid of.  Keep in mind that this will probably take you quite awhile.
                                                Quote
                                                An undefined problem has an infinite number of solutions.
                                                —Robert A. Humphrey