Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: I did the HJT a few months ago and everything was great but  (Read 15501 times)

0 Members and 1 Guest are viewing this topic.

pepper

    Topic Starter


    Hopeful
  • Thanked: 1
    I did the HJT a few months ago and everything was great but
    « on: January 17, 2008, 09:20:55 PM »
    for some reason it's not so great anymore.  It's locking up and very slow so Broni help!!!! ::)

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: I did the HJT a few months ago and everything was great but
    « Reply #1 on: January 17, 2008, 09:31:29 PM »
    You know the drill....

    1. Run free ESET Online Scanner at: http://www.eset.com/onlinescan/
    Note: This Scanner is for Internet Explorer Only
       1.  You will notice that the "Start" button is grayed out. Place a check mark at "Yes, I accept the Terms of use". The "Start" button will become visible. Click on it.
       2. If it wants to install an ActiveX component allow it
       3. You will be asked to install an ActiveX, click the "Install" button (Note: If you have a Firewall install you may have to approve the installation)
       4. Once ActiveX control is installed click on the "Start" button to initialize the scanner
       5. After initialization is complete uncheck\untick "Remove found threats"
       6. Check\tick "Scan unwanted applications"
       7. Click the "Scan" button
       8. Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt
    Post ESET's log.

    2. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    Print these instructions out.

        * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and Preferences", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
              o Close browsers before scanning.
              o Scan for tracking cookies.
              o Terminate memory threats before quarantining.
        * Click the "Close" button to leave the control center screen.
        * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure everything has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you want to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
              o Click Preferences, then click the Statistics/Logs tab.
              o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
              o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
              o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
        * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    3. Download HijackThis:
    http://www.snapfiles.com/get/hijackthis.html
    Post HijackThis log.

    pepper

      Topic Starter


      Hopeful
    • Thanked: 1
      Re: I did the HJT a few months ago and everything was great but
      « Reply #2 on: January 17, 2008, 09:55:12 PM »
      Sorry Broni but the ESET online scan didn't work for me.  It was taking forever.  Can you it more simple??? ::)

      pepper

        Topic Starter


        Hopeful
      • Thanked: 1
        Re: I did the HJT a few months ago and everything was great but
        « Reply #3 on: January 18, 2008, 06:37:38 AM »
        Sorry I got impatient last night.  I'm running it again now.  :)

        patio

        • Moderator


        • Genius
        • Maud' Dib
        • Thanked: 1769
          • Yes
        • Experience: Beginner
        • OS: Windows 7
        Re: I did the HJT a few months ago and everything was great but
        « Reply #4 on: January 18, 2008, 09:07:25 AM »
        Impatience isn't too good when the Malware Experts are working you thru the stages of cleaning out an infection...

        Trust me it's worth it.
        " Anyone who goes to a psychiatrist should have his head examined. "

        pepper

          Topic Starter


          Hopeful
        • Thanked: 1
          Re: I did the HJT a few months ago and everything was great but
          « Reply #5 on: January 18, 2008, 12:46:10 PM »
          Here's the ESET's log:

          # version=4
          # OnlineScanner.ocx=1.0.0.56
          # OnlineScannerDLLA.dll=1, 0, 0, 51
          # OnlineScannerDLLW.dll=1, 0, 0, 51
          # OnlineScannerUninstaller.exe=1, 0, 0, 49
          # vers_standard_module=2805 (20080118)
          # vers_arch_module=1.063 (20080117)
          # vers_adv_heur_module=1.060 (20070601)
          # EOSSerial=6187565e0fdd6042a9a831e518afb694
          # end=finished
          # remove_checked=false
          # unwanted_checked=true
          # utc_time=2008-01-18 05:18:31
          # local_time=2008-01-18 12:18:31 (-0500, Eastern Standard Time)
          # country="United States"
          # osver=5.1.2600 NT Service Pack 2
          # scanned=1344635
          # found=0
          # scan_time=13872

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: I did the HJT a few months ago and everything was great but
          « Reply #6 on: January 18, 2008, 04:45:50 PM »
          OK, off to next scan...

          pepper

            Topic Starter


            Hopeful
          • Thanked: 1
            Re: I did the HJT a few months ago and everything was great but
            « Reply #7 on: January 18, 2008, 04:48:17 PM »
            Impatience isn't too good when the Malware Experts are working you thru the stages of cleaning out an infection...

            Trust me it's worth it.

            patio you are so right.  I will never complain again!!! ;)

            pepper

              Topic Starter


              Hopeful
            • Thanked: 1
              Re: I did the HJT a few months ago and everything was great but
              « Reply #8 on: January 18, 2008, 04:52:07 PM »
              Broni I will have to go to the next scan tomorrow because I have some things I have to do on the computer tonight.  I got to the part where I was in safe mode and was up running the superantispyware but something came up and I had to get out of safe mode.  So I'm hoping tomorrow I can go back into safe mode and start it again.

              Broni


                Mastermind
              • Kraków my love :)
              • Thanked: 614
                • Computer Help Forum
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 8
              Re: I did the HJT a few months ago and everything was great but
              « Reply #9 on: January 18, 2008, 06:43:18 PM »
              That's OK.

              pepper

                Topic Starter


                Hopeful
              • Thanked: 1
                Re: I did the HJT a few months ago and everything was great but
                « Reply #10 on: January 21, 2008, 05:53:23 PM »
                Here is the Hijack This log:

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 7:51:28 PM, on 1/21/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                C:\WINDOWS\system32\spoolsv.exe
                c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\WINDOWS\system32\HPZipm12.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
                C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
                C:\HP\KBD\KBD.EXE
                C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
                C:\Program Files\QUICKENW\QWDLLS.EXE
                C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\WINDOWS\ALCXMNTR.EXE
                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                c:\windows\system\hpsysdrv.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                pepper

                  Topic Starter


                  Hopeful
                • Thanked: 1
                  Re: I did the HJT a few months ago and everything was great but
                  « Reply #11 on: January 21, 2008, 05:54:30 PM »
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                  O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                  O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                  O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                  O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                  O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                  O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                  O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                  O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
                  O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                  O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                  O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                  O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                  O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                  O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
                  O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                  O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                  O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                  O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                  O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                  O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                  O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                  O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                  O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                  --
                  End of file - 9694 bytes

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: I did the HJT a few months ago and everything was great but
                  « Reply #12 on: January 21, 2008, 06:29:25 PM »
                  I need Superantispyware to be run first, and its log posted.
                  Then, comes HJT.

                  pepper

                    Topic Starter


                    Hopeful
                  • Thanked: 1
                    Re: I did the HJT a few months ago and everything was great but
                    « Reply #13 on: January 22, 2008, 05:45:33 PM »
                    Sorry!  I thought I had posted the superantisyware log.  I ran it on the 18th but then I had to do something and didn't post the log.  I just went into the program and I think I found it.  Is this correct?

                    SUPERAntiSpyware Scan Log
                    http://www.superantispyware.com

                    Generated 01/18/2008 at 05:12 PM

                    Application Version : 3.9.1008

                    Core Rules Database Version : 3382
                    Trace Rules Database Version: 1376

                    Scan type       : Complete Scan
                    Total Scan Time : 02:13:28

                    Memory items scanned      : 596
                    Memory threats detected   : 0
                    Registry items scanned    : 5976
                    Registry threats detected : 0
                    File items scanned        : 134331
                    File threats detected     : 1

                    Adware.180solutions/Seekmo
                       C:\SYSTEM VOLUME INFORMATION\_RESTORE{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP62\A0005237.DLL

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: I did the HJT a few months ago and everything was great but
                    « Reply #14 on: January 22, 2008, 08:29:37 PM »
                    I don't see any nasties, but we have to clean couple of entries, then we have to get rid of some startups.

                    Open HJT, and checkmark following entries:

                    - O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                    - O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)

                    and startups:

                    - O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                    - O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                    - O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                    - O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                    - O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                    - O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
                    (why did you install this program? It's not recommended program)
                    - O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    - O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    - O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    - O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
                    - O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE

                    Click "Fix checked".

                    Go Start>Control Panel>Add\Remove, and uninstall:
                    - Real Player (download, and install Real Alternative: http://www.free-codecs.com/download/Real_Alternative.htm)
                    - Max Registry Cleaner
                    - Adobe Acrobat Reader (download, and install Foxit Reader: http://www.foxitsoftware.com/pdf/rd_intro.php)
                    - Panicware Pop-Up Stopper (Internet Explorer includes pop-up stopper, you don't need any 3rd party program)

                    Restart. Post new HJT log.

                    P. S. Having itchy fingers, lately? Installing some programs without asking around?

                    pepper

                      Topic Starter


                      Hopeful
                    • Thanked: 1
                      Re: I did the HJT a few months ago and everything was great but
                      « Reply #15 on: January 24, 2008, 03:32:56 AM »
                       :) :) :) :) :) :) :) :)  Yeah sometimes I get carried away!!!

                      Getting ready for work right now.  I'll do that tonight.  Thanks Broni!

                      Broni


                        Mastermind
                      • Kraków my love :)
                      • Thanked: 614
                        • Computer Help Forum
                      • Computer: Specs
                      • Experience: Experienced
                      • OS: Windows 8
                      Re: I did the HJT a few months ago and everything was great but
                      « Reply #16 on: January 24, 2008, 05:18:01 PM »
                      Bring me good news :)

                      pepper

                        Topic Starter


                        Hopeful
                      • Thanked: 1
                        Re: I did the HJT a few months ago and everything was great but
                        « Reply #17 on: January 25, 2008, 12:34:52 AM »
                        Dang now I'm here and your not.  I'm a little worried about some of your instructions.  I do a quarterly newsletter with lot's of graphic, pictures,etc and it scared me when I saw some of the programs you want me to delete.  Talk to me Broni...LOL!!!

                        Broni


                          Mastermind
                        • Kraków my love :)
                        • Thanked: 614
                          • Computer Help Forum
                        • Computer: Specs
                        • Experience: Experienced
                        • OS: Windows 8
                        Re: I did the HJT a few months ago and everything was great but
                        « Reply #18 on: January 25, 2008, 09:33:40 AM »
                        Sometimes, I need to sleep a little....LOL

                        Don't worry. I'd never advice you with any dangerous moves.
                        As for
                        Quote
                        and startups:
                        no programs will be removed. They will be only prevented from starting with your computer starting.

                        pepper

                          Topic Starter


                          Hopeful
                        • Thanked: 1
                          Re: I did the HJT a few months ago and everything was great but
                          « Reply #19 on: January 25, 2008, 08:14:27 PM »
                          Okay.  Would you believe now I'm having another problem that I've been working on all day so after I do the HJT I'm going to bug you with another one which I can't believe is happening.  I'm off to HJT.

                          Broni


                            Mastermind
                          • Kraków my love :)
                          • Thanked: 614
                            • Computer Help Forum
                          • Computer: Specs
                          • Experience: Experienced
                          • OS: Windows 8
                          Re: I did the HJT a few months ago and everything was great but
                          « Reply #20 on: January 25, 2008, 08:17:50 PM »
                          OK.

                          pepper

                            Topic Starter


                            Hopeful
                          • Thanked: 1
                            Re: I did the HJT a few months ago and everything was great but
                            « Reply #21 on: January 25, 2008, 08:20:57 PM »
                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 10:18:16 PM, on 1/25/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                            C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                            C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                            C:\WINDOWS\system32\HPZipm12.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
                            C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
                            C:\HP\KBD\KBD.EXE
                            C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
                            C:\Program Files\QUICKENW\QWDLLS.EXE
                            C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                            C:\WINDOWS\ALCXMNTR.EXE
                            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\IncrediMail\bin\IncMail.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            c:\windows\system\hpsysdrv.exe
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


                            pepper

                              Topic Starter


                              Hopeful
                            • Thanked: 1
                              Re: I did the HJT a few months ago and everything was great but
                              « Reply #22 on: January 25, 2008, 08:21:31 PM »
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                              O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                              O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                              O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                              O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                              O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                              O4 - HKLM\..\Run: [RCAutoLiveUpdate] "C:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" -AUTO
                              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                              O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
                              O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                              O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                              O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                              O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                              O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                              O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                              O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
                              O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                              O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                              O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                              O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                              O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                              O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                              O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                              O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                              O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                              O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                              O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                              O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                              --
                              End of file - 9839 bytes

                              Broni


                                Mastermind
                              • Kraków my love :)
                              • Thanked: 614
                                • Computer Help Forum
                              • Computer: Specs
                              • Experience: Experienced
                              • OS: Windows 8
                              Re: I did the HJT a few months ago and everything was great but
                              « Reply #23 on: January 25, 2008, 08:34:59 PM »
                              What happened? Did you follow my instructions from post #14?

                              pepper

                                Topic Starter


                                Hopeful
                              • Thanked: 1
                                Re: I did the HJT a few months ago and everything was great but
                                « Reply #24 on: January 25, 2008, 08:39:39 PM »
                                Oh my word I think I'm losing it!!!  LOL!!! I'm sorry.  This other problem has taken over my thinking.  I'll do it right now!!!

                                Broni


                                  Mastermind
                                • Kraków my love :)
                                • Thanked: 614
                                  • Computer Help Forum
                                • Computer: Specs
                                • Experience: Experienced
                                • OS: Windows 8
                                Re: I did the HJT a few months ago and everything was great but
                                « Reply #25 on: January 25, 2008, 08:46:28 PM »
                                Take it easy...One step at a time...

                                pepper

                                  Topic Starter


                                  Hopeful
                                • Thanked: 1
                                  Re: I did the HJT a few months ago and everything was great but
                                  « Reply #26 on: January 25, 2008, 08:56:58 PM »
                                  Gosh I hope I deleted everything correctly.  I'm not sure but let me know please.

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 10:54:49 PM, on 1/25/2008
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                  C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                  C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                  C:\Program Files\Bonjour\mDNSResponder.exe
                                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                  C:\WINDOWS\system32\HPZipm12.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                  C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                  C:\HP\KBD\KBD.EXE
                                  C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                  C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  pepper

                                    Topic Starter


                                    Hopeful
                                  • Thanked: 1
                                    Re: I did the HJT a few months ago and everything was great but
                                    « Reply #27 on: January 25, 2008, 08:57:53 PM »
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                                    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                    O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                                    O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                                    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                                    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                                    O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                                    O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                    O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                    O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                                    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                    O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                                    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                                    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                                    O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                                    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                                    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                                    --
                                    End of file - 8085 bytes

                                    Broni


                                      Mastermind
                                    • Kraków my love :)
                                    • Thanked: 614
                                      • Computer Help Forum
                                    • Computer: Specs
                                    • Experience: Experienced
                                    • OS: Windows 8
                                    Re: I did the HJT a few months ago and everything was great but
                                    « Reply #28 on: January 25, 2008, 09:08:48 PM »
                                    It looks pretty good, except for two entries....

                                    1. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

                                    2. Open HJT, and checkmark following entries:
                                    - O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                    - O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)

                                    3. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

                                    4. Delete following files/folders (if present):

                                    - ShoppingReport folder from C:\Program Files

                                    5. Turn off System Restore:

                                    - Windows XP:
                                       1. Click Start.
                                       2. Right-click the My Computer icon, and then click Properties.
                                       3. Click the System Restore tab.
                                       4. Check "Turn off System Restore".
                                       5. Click Apply.   
                                       6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                                       7. Click OK.
                                    - Windows Vista:
                                       1. Click Start.
                                       2. Right-click the Computer icon, and then click Properties.
                                       3. Click on System Protection under the Tasks column on the left side
                                       4. Click on Continue on the "User Account Control" window that pops up
                                       5. Under the System Protection tab, find Available Disks
                                       6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                                       7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                                       8. Click OK

                                    6. Restart in Normal Mode.

                                    7. Turn System Restore on.

                                    8. Post new HijackThis log.

                                    pepper

                                      Topic Starter


                                      Hopeful
                                    • Thanked: 1
                                      Re: I did the HJT a few months ago and everything was great but
                                      « Reply #29 on: January 25, 2008, 09:14:11 PM »
                                      I'm on it!  Thanks Broni!

                                      Broni


                                        Mastermind
                                      • Kraków my love :)
                                      • Thanked: 614
                                        • Computer Help Forum
                                      • Computer: Specs
                                      • Experience: Experienced
                                      • OS: Windows 8
                                      Re: I did the HJT a few months ago and everything was great but
                                      « Reply #30 on: January 25, 2008, 09:14:59 PM »
                                      Sure thing.

                                      pepper

                                        Topic Starter


                                        Hopeful
                                      • Thanked: 1
                                        Re: I did the HJT a few months ago and everything was great but
                                        « Reply #31 on: January 25, 2008, 09:40:11 PM »
                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 11:36:39 PM, on 1/25/2008
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\Ati2evxx.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                        C:\Program Files\Bonjour\mDNSResponder.exe
                                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                        C:\WINDOWS\system32\HPZipm12.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\Ati2evxx.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                        C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                        C:\HP\KBD\KBD.EXE
                                        C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        pepper

                                          Topic Starter


                                          Hopeful
                                        • Thanked: 1
                                          Re: I did the HJT a few months ago and everything was great but
                                          « Reply #32 on: January 25, 2008, 09:41:17 PM »
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                          O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                          O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                          O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                          O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                                          O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                                          O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                                          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                                          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                                          O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                                          O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                          O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                          O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                          O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                          O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                                          O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                                          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                          O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                          O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                                          O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                                          O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                                          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                                          O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                                          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                                          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                          O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                          O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                                          --
                                          End of file - 8036 bytes

                                          Broni


                                            Mastermind
                                          • Kraków my love :)
                                          • Thanked: 614
                                            • Computer Help Forum
                                          • Computer: Specs
                                          • Experience: Experienced
                                          • OS: Windows 8
                                          Re: I did the HJT a few months ago and everything was great but
                                          « Reply #33 on: January 25, 2008, 09:44:59 PM »
                                          Those two entries are still there, so we'll try some other ways...
                                          Is ShoppingReport program listed under Start>Control Panel>Add\Remove?
                                          If so, uninstall it from there.

                                          I may be getting off of my computer, so if I'm not here, when you reply, we'll continue tomorrow.

                                          pepper

                                            Topic Starter


                                            Hopeful
                                          • Thanked: 1
                                            Re: I did the HJT a few months ago and everything was great but
                                            « Reply #34 on: January 25, 2008, 09:46:40 PM »
                                            Okay Broni.  Thank you!

                                            pepper

                                              Topic Starter


                                              Hopeful
                                            • Thanked: 1
                                              Re: I did the HJT a few months ago and everything was great but
                                              « Reply #35 on: January 25, 2008, 09:51:48 PM »
                                              Yes it was there and I just deleted it!!! Talk to you tomorrow I hope!  ;)

                                              Broni


                                                Mastermind
                                              • Kraków my love :)
                                              • Thanked: 614
                                                • Computer Help Forum
                                              • Computer: Specs
                                              • Experience: Experienced
                                              • OS: Windows 8
                                              Re: I did the HJT a few months ago and everything was great but
                                              « Reply #36 on: January 25, 2008, 09:53:33 PM »
                                              Restart. Post new HJT log.

                                              pepper

                                                Topic Starter


                                                Hopeful
                                              • Thanked: 1
                                                Re: I did the HJT a few months ago and everything was great but
                                                « Reply #37 on: January 26, 2008, 12:40:27 PM »
                                                Here is new log:

                                                Logfile of Trend Micro HijackThis v2.0.2
                                                Scan saved at 2:38:25 PM, on 1/26/2008
                                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                                MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                                Boot mode: Normal

                                                Running processes:
                                                C:\WINDOWS\System32\smss.exe
                                                C:\WINDOWS\system32\winlogon.exe
                                                C:\WINDOWS\system32\services.exe
                                                C:\WINDOWS\system32\lsass.exe
                                                C:\WINDOWS\system32\Ati2evxx.exe
                                                C:\WINDOWS\system32\svchost.exe
                                                C:\WINDOWS\System32\svchost.exe
                                                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                                C:\WINDOWS\system32\spoolsv.exe
                                                c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                                C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                                C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                                C:\Program Files\Bonjour\mDNSResponder.exe
                                                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                                C:\WINDOWS\system32\svchost.exe
                                                C:\WINDOWS\system32\Ati2evxx.exe
                                                C:\WINDOWS\Explorer.EXE
                                                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                                C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                                C:\HP\KBD\KBD.EXE
                                                C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                                C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                                                C:\WINDOWS\system32\ctfmon.exe
                                                C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                                C:\WINDOWS\system32\wuauclt.exe
                                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                                pepper

                                                  Topic Starter


                                                  Hopeful
                                                • Thanked: 1
                                                  Re: I did the HJT a few months ago and everything was great but
                                                  « Reply #38 on: January 26, 2008, 12:41:49 PM »
                                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                  O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                  O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                                  O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                                                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                                  O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                                                  O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                                  O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                                                  O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                                                  O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                                                  O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                                                  O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                                                  O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                                  O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                                  O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                                  O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                                  O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                                                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                                                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                                                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                                  O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                                  O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                                                  O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                                                  O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                                                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                                                  O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                                                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                                                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                                  O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                                  O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                                  O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                                  O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                                  O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                                  O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                                                  --
                                                  End of file - 7968 bytes

                                                  Broni


                                                    Mastermind
                                                  • Kraków my love :)
                                                  • Thanked: 614
                                                    • Computer Help Forum
                                                  • Computer: Specs
                                                  • Experience: Experienced
                                                  • OS: Windows 8
                                                  Re: I did the HJT a few months ago and everything was great but
                                                  « Reply #39 on: January 26, 2008, 12:55:36 PM »
                                                  Since you uninstalled ShoppingReport, open HJT, and checkmark the following:
                                                  - O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                                  - O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                                  Click "Fix checked".

                                                  In Windows Explorer, navigate to C:\Program Files, and remove ShoppingReport folder. If denied, try Safe Mode.

                                                  Restart, post new HJT log.

                                                  pepper

                                                    Topic Starter


                                                    Hopeful
                                                  • Thanked: 1
                                                    Re: I did the HJT a few months ago and everything was great but
                                                    « Reply #40 on: January 26, 2008, 02:19:32 PM »
                                                    Sorry Broni do you mean go to run and enter C:\Program Files?  I got confused on this part. ???

                                                    Broni


                                                      Mastermind
                                                    • Kraków my love :)
                                                    • Thanked: 614
                                                      • Computer Help Forum
                                                    • Computer: Specs
                                                    • Experience: Experienced
                                                    • OS: Windows 8
                                                    Re: I did the HJT a few months ago and everything was great but
                                                    « Reply #41 on: January 26, 2008, 02:58:40 PM »
                                                    No. Start>Programs>Accessories>Windows Explorer
                                                    You used Windows Explorer before.

                                                    pepper

                                                      Topic Starter


                                                      Hopeful
                                                    • Thanked: 1
                                                      Re: I did the HJT a few months ago and everything was great but
                                                      « Reply #42 on: January 26, 2008, 03:31:26 PM »
                                                      There was no folder for Shopping Report.  Should I go into safe mode to find it?

                                                      Broni


                                                        Mastermind
                                                      • Kraków my love :)
                                                      • Thanked: 614
                                                        • Computer Help Forum
                                                      • Computer: Specs
                                                      • Experience: Experienced
                                                      • OS: Windows 8
                                                      Re: I did the HJT a few months ago and everything was great but
                                                      « Reply #43 on: January 26, 2008, 04:32:57 PM »
                                                      It's OK.
                                                      Most likely, it disappeared, when you uninstalled Shopping Report

                                                      New HJT log, please.

                                                      pepper

                                                        Topic Starter


                                                        Hopeful
                                                      • Thanked: 1
                                                        Re: I did the HJT a few months ago and everything was great but
                                                        « Reply #44 on: January 26, 2008, 04:43:40 PM »
                                                        Logfile of Trend Micro HijackThis v2.0.2
                                                        Scan saved at 6:41:36 PM, on 1/26/2008
                                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                                        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                                        Boot mode: Normal

                                                        Running processes:
                                                        C:\WINDOWS\System32\smss.exe
                                                        C:\WINDOWS\system32\winlogon.exe
                                                        C:\WINDOWS\system32\services.exe
                                                        C:\WINDOWS\system32\lsass.exe
                                                        C:\WINDOWS\system32\Ati2evxx.exe
                                                        C:\WINDOWS\system32\svchost.exe
                                                        C:\WINDOWS\System32\svchost.exe
                                                        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                                        C:\WINDOWS\system32\spoolsv.exe
                                                        c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                                        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                                        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                                        C:\Program Files\Bonjour\mDNSResponder.exe
                                                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                                        C:\WINDOWS\system32\svchost.exe
                                                        C:\WINDOWS\system32\Ati2evxx.exe
                                                        C:\WINDOWS\Explorer.EXE
                                                        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                                        C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                                        C:\HP\KBD\KBD.EXE
                                                        C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                                        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                                                        C:\WINDOWS\system32\ctfmon.exe
                                                        C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                                        C:\WINDOWS\system32\wuauclt.exe
                                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                                        pepper

                                                          Topic Starter


                                                          Hopeful
                                                        • Thanked: 1
                                                          Re: I did the HJT a few months ago and everything was great but
                                                          « Reply #45 on: January 26, 2008, 04:44:24 PM »
                                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                                                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                                          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                          O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                                          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                          O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                                          O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                                                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                                          O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                                          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                                                          O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                                                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                                          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                                                          O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                                                          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                                                          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                                                          O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                                                          O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                                          O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                                          O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                                          O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (file missing)
                                                          O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                                                          O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                                                          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                                                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                                          O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                                          O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                                                          O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                                                          O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                                          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                                                          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                                                          O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                                                          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                                                          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                                          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                                          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                                          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                                          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                                          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                                          O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                                          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                                          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                                          O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                                                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                                          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                                                          --
                                                          End of file - 7968 bytes

                                                          Broni


                                                            Mastermind
                                                          • Kraków my love :)
                                                          • Thanked: 614
                                                            • Computer Help Forum
                                                          • Computer: Specs
                                                          • Experience: Experienced
                                                          • OS: Windows 8
                                                          Re: I did the HJT a few months ago and everything was great but
                                                          « Reply #46 on: January 26, 2008, 05:06:37 PM »
                                                          OK....
                                                          Go Start>Run, type in:
                                                          regedit
                                                          Click OK.
                                                          Registry Editor will open.
                                                          Navigate to:
                                                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions
                                                          In Extensions folder, you'll see sub-folders (left pane) with alphanumeric characters (see attached image from my registry).
                                                          Find following sub-folders:
                                                          - C5428486-50A0-4a02-9D20-520B59A9F9B2
                                                          - C5428486-50A0-4a02-9D20-520B59A9F9B3 (same as the first one, except for last number)
                                                          Right click on each folder, click Delete
                                                          Close Registry Editor.
                                                          Restart computer.
                                                          Post new HJT log.

                                                          [file cleanup - saving space - attachment deleted by admin]

                                                          pepper

                                                            Topic Starter


                                                            Hopeful
                                                          • Thanked: 1
                                                            Re: I did the HJT a few months ago and everything was great but
                                                            « Reply #47 on: January 26, 2008, 05:19:08 PM »
                                                            Logfile of Trend Micro HijackThis v2.0.2
                                                            Scan saved at 7:16:38 PM, on 1/26/2008
                                                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                                                            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                                            Boot mode: Normal

                                                            Running processes:
                                                            C:\WINDOWS\System32\smss.exe
                                                            C:\WINDOWS\system32\winlogon.exe
                                                            C:\WINDOWS\system32\services.exe
                                                            C:\WINDOWS\system32\lsass.exe
                                                            C:\WINDOWS\system32\Ati2evxx.exe
                                                            C:\WINDOWS\system32\svchost.exe
                                                            C:\WINDOWS\System32\svchost.exe
                                                            C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                                            C:\WINDOWS\system32\spoolsv.exe
                                                            c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                                            C:\WINDOWS\system32\Ati2evxx.exe
                                                            C:\WINDOWS\Explorer.EXE
                                                            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                                            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                                            C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
                                                            C:\HP\KBD\KBD.EXE
                                                            C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                                            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                                                            C:\WINDOWS\system32\ctfmon.exe
                                                            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                                            C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                                            C:\Program Files\Bonjour\mDNSResponder.exe
                                                            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                            C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                                            C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                                            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                                            C:\WINDOWS\system32\HPZipm12.exe
                                                            C:\WINDOWS\system32\svchost.exe
                                                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                                            pepper

                                                              Topic Starter


                                                              Hopeful
                                                            • Thanked: 1
                                                              Re: I did the HJT a few months ago and everything was great but
                                                              « Reply #48 on: January 26, 2008, 05:19:58 PM »
                                                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                                                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                                                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                                              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                              O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
                                                              O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
                                                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                                              O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6172\SiteAdv.exe"
                                                              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                                              O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                                              O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                                                              O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
                                                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                                              O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                                                              O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                                                              O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                                                              O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                                                              O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
                                                              O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                                              O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                                              O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
                                                              O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                                                              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                                                              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                                                              O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                                              O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                                                              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
                                                              O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                                                              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167343560406
                                                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                                                              O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
                                                              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                                                              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                                              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                                              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                                              O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                                                              O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                                                              O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                                                              O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                                              O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                                                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                                              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                                              O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
                                                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                                              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                                              O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                                                              --
                                                              End of file - 7671 bytes

                                                              Broni


                                                                Mastermind
                                                              • Kraków my love :)
                                                              • Thanked: 614
                                                                • Computer Help Forum
                                                              • Computer: Specs
                                                              • Experience: Experienced
                                                              • OS: Windows 8
                                                              Re: I did the HJT a few months ago and everything was great but
                                                              « Reply #49 on: January 26, 2008, 05:32:03 PM »
                                                              Very nice. Everything gone, and clean :)
                                                              How is your computer doing?

                                                              CCleaner time...
                                                              1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                                                              2. Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

                                                              Post back, when you're done.

                                                              pepper

                                                                Topic Starter


                                                                Hopeful
                                                              • Thanked: 1
                                                                Re: I did the HJT a few months ago and everything was great but
                                                                « Reply #50 on: January 26, 2008, 05:49:55 PM »
                                                                Did that.  Thank you Broni. That was fun!  :) Everything seems to be running great now.  How often should I run the cleaner?

                                                                I have another problem that has nothing to do with what we've been working on but it's driving me crazy.  It started about two months ago with emails.  If I have an email from someone and we reply back and forth several times I get this message and they do to.

                                                                This message has been processed by Symantec's AntiVirus Technology.
                                                                 
                                                                Unknown00000000.data was not scanned for viruses because too many nested levels of files were found.
                                                                 
                                                                 
                                                                For more information on antivirus tips and technology, visit
                                                                http://ses.symantec.com/

                                                                There is an attachment and I have to open that up and reply to the person and when I reply it doesn't use my default email program.  I had Norton anti-virus years ago so I went into search and found 39 Symantec files and deleted them.  I thought that would stop it but it didn't.  So I did another search and found 47 Norton files and deleted them.  I thought that would solve the problem but it didn't.  I emailed Symantec and this is what they said.

                                                                Thank you for contacting Symantec Global Enterprise Customer Care.
                                                                 
                                                                You should not receive the message that you are getting unless a Symantec product is installed.  Have you recently purchased a new computer that could have a trial version of our product?
                                                                 
                                                                If you are still using the same computer that you removed the Norton AntiVirus program from, there may be some files left on the computer.  If it was the Consumer product (Norton AntiVirus 2006,  Norton Internet Security 2007 etc)  the link below has a removal tool:
                                                                 
                                                                http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039?Open&src=&docid=2005011310334907&nsf=nsw.nsf&view=0&dtype=&prod=&ver=&osv=&osv_lvl=&seg=hm
                                                                 
                                                                I ran the removal tool and it's still happening.  I don't know what to do next.
                                                                 

                                                                Broni


                                                                  Mastermind
                                                                • Kraków my love :)
                                                                • Thanked: 614
                                                                  • Computer Help Forum
                                                                • Computer: Specs
                                                                • Experience: Experienced
                                                                • OS: Windows 8
                                                                Re: I did the HJT a few months ago and everything was great but
                                                                « Reply #51 on: January 26, 2008, 05:55:46 PM »
                                                                I'm glad, things are back to normal :)
                                                                Quote
                                                                How often should I run the cleaner?
                                                                Once a month should be OK, but in your case....put those *censored* itchy finger into some ice before installing some crap again....LOL

                                                                Now...I propose, you start new topic about your separate problem.
                                                                It'll bring more people attention.

                                                                pepper

                                                                  Topic Starter


                                                                  Hopeful
                                                                • Thanked: 1
                                                                  Re: I did the HJT a few months ago and everything was great but
                                                                  « Reply #52 on: January 26, 2008, 06:07:03 PM »
                                                                  okey dokey oh computer guru!!!  LOL!!!

                                                                  Broni


                                                                    Mastermind
                                                                  • Kraków my love :)
                                                                  • Thanked: 614
                                                                    • Computer Help Forum
                                                                  • Computer: Specs
                                                                  • Experience: Experienced
                                                                  • OS: Windows 8
                                                                  Re: I did the HJT a few months ago and everything was great but
                                                                  « Reply #53 on: January 26, 2008, 06:11:56 PM »
                                                                  Not yet. I need some more posts to become "guru".....LOL