Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: I did the HJT a few months ago and everything was great but  (Read 15617 times)

0 Members and 1 Guest are viewing this topic.

pepper

    Topic Starter


    Hopeful
  • Thanked: 1
    I did the HJT a few months ago and everything was great but
    « on: January 17, 2008, 09:20:55 PM »
    for some reason it's not so great anymore.  It's locking up and very slow so Broni help!!!! ::)

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: I did the HJT a few months ago and everything was great but
    « Reply #1 on: January 17, 2008, 09:31:29 PM »
    You know the drill....

    1. Run free ESET Online Scanner at: http://www.eset.com/onlinescan/
    Note: This Scanner is for Internet Explorer Only
       1.  You will notice that the "Start" button is grayed out. Place a check mark at "Yes, I accept the Terms of use". The "Start" button will become visible. Click on it.
       2. If it wants to install an ActiveX component allow it
       3. You will be asked to install an ActiveX, click the "Install" button (Note: If you have a Firewall install you may have to approve the installation)
       4. Once ActiveX control is installed click on the "Start" button to initialize the scanner
       5. After initialization is complete uncheck\untick "Remove found threats"
       6. Check\tick "Scan unwanted applications"
       7. Click the "Scan" button
       8. Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt
    Post ESET's log.

    2. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    Print these instructions out.

        * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and Preferences", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
              o Close browsers before scanning.
              o Scan for tracking cookies.
              o Terminate memory threats before quarantining.
        * Click the "Close" button to leave the control center screen.
        * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure everything has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you want to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
              o Click Preferences, then click the Statistics/Logs tab.
              o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
              o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
              o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
        * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    3. Download HijackThis:
    http://www.snapfiles.com/get/hijackthis.html
    Post HijackThis log.

    pepper

      Topic Starter


      Hopeful
    • Thanked: 1
      Re: I did the HJT a few months ago and everything was great but
      « Reply #2 on: January 17, 2008, 09:55:12 PM »
      Sorry Broni but the ESET online scan didn't work for me.  It was taking forever.  Can you it more simple??? ::)

      pepper

        Topic Starter


        Hopeful
      • Thanked: 1
        Re: I did the HJT a few months ago and everything was great but
        « Reply #3 on: January 18, 2008, 06:37:38 AM »
        Sorry I got impatient last night.  I'm running it again now.  :)

        patio

        • Moderator


        • Genius
        • Maud' Dib
        • Thanked: 1769
          • Yes
        • Experience: Beginner
        • OS: Windows 7
        Re: I did the HJT a few months ago and everything was great but
        « Reply #4 on: January 18, 2008, 09:07:25 AM »
        Impatience isn't too good when the Malware Experts are working you thru the stages of cleaning out an infection...

        Trust me it's worth it.
        " Anyone who goes to a psychiatrist should have his head examined. "

        pepper

          Topic Starter


          Hopeful
        • Thanked: 1
          Re: I did the HJT a few months ago and everything was great but
          « Reply #5 on: January 18, 2008, 12:46:10 PM »
          Here's the ESET's log:

          # version=4
          # OnlineScanner.ocx=1.0.0.56
          # OnlineScannerDLLA.dll=1, 0, 0, 51
          # OnlineScannerDLLW.dll=1, 0, 0, 51
          # OnlineScannerUninstaller.exe=1, 0, 0, 49
          # vers_standard_module=2805 (20080118)
          # vers_arch_module=1.063 (20080117)
          # vers_adv_heur_module=1.060 (20070601)
          # EOSSerial=6187565e0fdd6042a9a831e518afb694
          # end=finished
          # remove_checked=false
          # unwanted_checked=true
          # utc_time=2008-01-18 05:18:31
          # local_time=2008-01-18 12:18:31 (-0500, Eastern Standard Time)
          # country="United States"
          # osver=5.1.2600 NT Service Pack 2
          # scanned=1344635
          # found=0
          # scan_time=13872

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: I did the HJT a few months ago and everything was great but
          « Reply #6 on: January 18, 2008, 04:45:50 PM »
          OK, off to next scan...

          pepper

            Topic Starter


            Hopeful
          • Thanked: 1
            Re: I did the HJT a few months ago and everything was great but
            « Reply #7 on: January 18, 2008, 04:48:17 PM »
            Impatience isn't too good when the Malware Experts are working you thru the stages of cleaning out an infection...

            Trust me it's worth it.

            patio you are so right.  I will never complain again!!! ;)

            pepper

              Topic Starter


              Hopeful
            • Thanked: 1
              Re: I did the HJT a few months ago and everything was great but
              « Reply #8 on: January 18, 2008, 04:52:07 PM »
              Broni I will have to go to the next scan tomorrow because I have some things I have to do on the computer tonight.  I got to the part where I was in safe mode and was up running the superantispyware but something came up and I had to get out of safe mode.  So I'm hoping tomorrow I can go back into safe mode and start it again.

              Broni


                Mastermind
              • Kraków my love :)
              • Thanked: 614
                • Computer Help Forum
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 8
              Re: I did the HJT a few months ago and everything was great but
              « Reply #9 on: January 18, 2008, 06:43:18 PM »
              That's OK.

              pepper

                Topic Starter


                Hopeful
              • Thanked: 1
                Re: I did the HJT a few months ago and everything was great but
                « Reply #10 on: January 21, 2008, 05:53:23 PM »
                Here is the Hijack This log:

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 7:51:28 PM, on 1/21/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                C:\WINDOWS\system32\spoolsv.exe
                c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\WINDOWS\system32\HPZipm12.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
                C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
                C:\HP\KBD\KBD.EXE
                C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
                C:\Program Files\QUICKENW\QWDLLS.EXE
                C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\WINDOWS\ALCXMNTR.EXE
                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                c:\windows\system\hpsysdrv.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                pepper

                  Topic Starter


                  Hopeful
                • Thanked: 1
                  Re: I did the HJT a few months ago and everything was great but
                  « Reply #11 on: January 21, 2008, 05:54:30 PM »
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                  O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                  O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                  O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                  O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                  O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                  O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                  O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                  O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
                  O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                  O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                  O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                  O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                  O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                  O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
                  O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                  O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                  O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                  O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                  O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                  O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                  O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                  O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                  O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                  --
                  End of file - 9694 bytes

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: I did the HJT a few months ago and everything was great but
                  « Reply #12 on: January 21, 2008, 06:29:25 PM »
                  I need Superantispyware to be run first, and its log posted.
                  Then, comes HJT.

                  pepper

                    Topic Starter


                    Hopeful
                  • Thanked: 1
                    Re: I did the HJT a few months ago and everything was great but
                    « Reply #13 on: January 22, 2008, 05:45:33 PM »
                    Sorry!  I thought I had posted the superantisyware log.  I ran it on the 18th but then I had to do something and didn't post the log.  I just went into the program and I think I found it.  Is this correct?

                    SUPERAntiSpyware Scan Log
                    http://www.superantispyware.com

                    Generated 01/18/2008 at 05:12 PM

                    Application Version : 3.9.1008

                    Core Rules Database Version : 3382
                    Trace Rules Database Version: 1376

                    Scan type       : Complete Scan
                    Total Scan Time : 02:13:28

                    Memory items scanned      : 596
                    Memory threats detected   : 0
                    Registry items scanned    : 5976
                    Registry threats detected : 0
                    File items scanned        : 134331
                    File threats detected     : 1

                    Adware.180solutions/Seekmo
                       C:\SYSTEM VOLUME INFORMATION\_RESTORE{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP62\A0005237.DLL

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: I did the HJT a few months ago and everything was great but
                    « Reply #14 on: January 22, 2008, 08:29:37 PM »
                    I don't see any nasties, but we have to clean couple of entries, then we have to get rid of some startups.

                    Open HJT, and checkmark following entries:

                    - O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                    - O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)

                    and startups:

                    - O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                    - O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                    - O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                    - O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                    - O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                    - O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
                    (why did you install this program? It's not recommended program)
                    - O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    - O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    - O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    - O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
                    - O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE

                    Click "Fix checked".

                    Go Start>Control Panel>Add\Remove, and uninstall:
                    - Real Player (download, and install Real Alternative: http://www.free-codecs.com/download/Real_Alternative.htm)
                    - Max Registry Cleaner
                    - Adobe Acrobat Reader (download, and install Foxit Reader: http://www.foxitsoftware.com/pdf/rd_intro.php)
                    - Panicware Pop-Up Stopper (Internet Explorer includes pop-up stopper, you don't need any 3rd party program)

                    Restart. Post new HJT log.

                    P. S. Having itchy fingers, lately? Installing some programs without asking around?