SHOP PRODUCTS
Houzz Logo Print
copanolady

OS Not Found

copanolady
13 years ago

I'm still having problems logging in ~ Zep, if you're online, you asked me to send this list the other day and I found out how reading another old post. Could you or Raven or Owbist or someone please look at it for me? I don't know how to interpret it. Thank you for your patience.

SAR

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 9:30:44 PM, on 2/9/2011

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v8.00 (8.00.6001.18999)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\Windows Sidebar\sidebar.exe

C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\HP\QuickPlay\QPService.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe

C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_ActiveX.exe

C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml?ptnrS=ZRxdm429YYUS&ptb=OlVzOWJJhupJS5igcdXMzA&n=77ce5d58

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: AGSearchHook Class - (0BC6E3FA-78EF-4886-842C-5A1258C4455A) - C:\Program Files (x86)\AGI\common\agcutils.dll

R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - (0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

R3 - URLSearchHook: (no name) - (22e03916-85c5-44b0-8dc9-1830c11238d9) - (no file)

F2 - REG:system.ini: UserInit=userinit.exe,

O1 - Hosts: ::1 localhost

O2 - BHO: &Yahoo! Toolbar Helper - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: HP Print Enhancer - (0347C33E-8762-4905-BF09-768834316C61) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - (3CA2F312-6F6E-4B53-A66E-4E65E497C8C0) - C:\Program Files (x86)\AVG\AVG10\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

O2 - BHO: NCO 2.0 IE BHO - (602ADB0E-4AFF-4217-8AA1-95DAC4DFA408) - (no file)

O2 - BHO: Google Analytics Opt-out Browser Add-on - (75EF13CE-B59E-41ba-8A5A-A944031BD8B4) - C:\Program Files (x86)\Google\Google Analytics Opt-Out\gaoptout.dll

O2 - BHO: Windows Live ID Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: FCTBPos00Pos - (9EBF8AAF-0A31-4786-909A-97A0EF101743) - C:\Users\Ruth\AddThis Toolbar\Toolbar.dll

O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: McAfee SiteAdvisor BHO - (B164E929-A1B6-4A06-B104-2CD0E90A88FF) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O2 - BHO: Google Dictionary Compression sdch - (C84D72FE-E17D-4195-BB24-76C02E2E7C4E) - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O2 - BHO: MSN Toolbar Helper - (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll

O2 - BHO: Inbox Toolbar - (D3D233D5-9F6D-436C-B6C7-E63F77503B30) - C:\PROGRA~2\INBOXT~1\Inbox.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O2 - BHO: HP Smart BHO Class - (FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O3 - Toolbar: (no name) - (7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA) - (no file)

O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: MSN Toolbar - (1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414) - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll

O3 - Toolbar: Google Toolbar - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll

O3 - Toolbar: (no name) - (CCC7A320-B3CA-4199-B1A6-9F516DD69829) - (no file)

O3 - Toolbar: AddThis Toolbar - (B43176CC-4D9E-493B-A636-D9CBFE39C6DA) - C:\Users\Ruth\AddThis Toolbar\Toolbar.dll

O3 - Toolbar: &Inbox Toolbar - (D7E97865-918F-41E4-9CD0-25AB1C574CE8) - C:\PROGRA~2\INBOXT~1\Inbox.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - (0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [SSDMonitor] "C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe"

O4 - HKCU\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - Startup: Webshots.lnk = C:\Program Files (x86)\Webshots\Launcher.exe

O4 - Global Startup: McAfee Security Scan Plus.lnk = ?

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Show or hide HP Smart Web Printing - (DDE87865-83C5-48c4-8357-2F5B1AA84522) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O9 - Extra button: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C:\PROGRA~2\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: (D27CDB6E-AE6D-11CF-96B8-444553540000) (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: (E2883E8F-472F-4FB0-9522-AC9BF37916A7) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: dssrequest - (5513F07E-936B-4E52-9B00-067394E91CC5) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O18 - Protocol: inbox - (37540F19-DD4C-478B-B2DF-C19281BCAF27) - C:\PROGRA~2\INBOXT~1\Inbox.dll

O18 - Protocol: linkscanner - (F274614C-63F8-47D5-A4D1-FBDDE494F8D1) - C:\Program Files (x86)\AVG\AVG10\avgpp.dll

O18 - Protocol: sacore - (5513F07E-936B-4E52-9B00-067394E91CC5) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

O18 - Protocol: wlpg - (E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324) - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O18 - Filter: x-sdch - (B1759355-3EEC-4C1E-B0F1-B719FE26E377) - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files (x86)\AGI\common\win32\PythonService.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe

O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe

O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)

O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe

O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

--

End of file - 15654 bytes

Comments (32)

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    I forgot to mention, I have been trying to uninstall McAfee Site Advisor without success. I strongly believe it's a factor. Thanks.

  • zep516
    13 years ago
    last modified: 9 years ago

    Let me look at it.

    Do you want all tool bars?

    O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: MSN Toolbar - (1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414) - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll
    O3 - Toolbar: Google Toolbar - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: (no name) - (CCC7A320-B3CA-4199-B1A6-9F516DD69829) - (no file)
    O3 - Toolbar: AddThis Toolbar - (B43176CC-4D9E-493B-A636-D9CBFE39C6DA) - C:\Users\Ruth\AddThis Toolbar\Toolbar.dll
    O3 - Toolbar: &Inbox Toolbar - (D7E97865-918F-41E4-9CD0-25AB1C574CE8) - C:\PROGRA~2\INBOXT~1\Inbox.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - (0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O2 - BHO: &Yahoo! Toolbar Helper - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll

    O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

    O2 - BHO: MSN Toolbar Helper - (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll
    O2 - BHO: Inbox Toolbar - (D3D233D5-9F6D-436C-B6C7-E63F77503B30) - C:\PROGRA~2\INBOXT~1\Inbox.dll

    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    There's a few of them. looks like a Tool Bar server. LOL

    Please describe the exact problem you have?

  • Related Discussions

    mac os x (10.4) landscaping/design/garden software??

    Q

    Comments (19)
    Punch! does look interesting. I checked their website and will probably purchase soon. I've been using a draw program for about ten years now called Canvas. It's worked very well for me but the company was sold and it looks like it may not be supported for much longer. It has a paint component as well, but I've been using PhotoShop for imaging for almost as long, so I've never used Canvas for that. The originator of Canvas, a company called Deneba also created an application called DenebaCad, which I purchased but never learned. I've long considered biting the bullet for the cost in dollars and learning curve for the highly rated VectorWorks (originally called MiniCad). It seems like Punch! may be worth checking out as the price is quite reasonable for what it says it can do. Did you ever acquire Punch!, chillin already?
    ...See More

    Are my peppers safe?

    Q

    Comments (4)
    Did they sit out at room temperature for the first 20 hours? That's on the hairy edge for something under-processed or under-acidified. Then to process them, you just wiped the jar rims, put new (?) lids on, and put the room temperature jars in a pot of water and brought them to a boil? That's not a proper process either. The recipe seems fine except for the oil - though The Joy of Pickling (a generally accepted as safe source) has a similar recipe using 1Tbsp of oil on the top of each jar and a 50:50 vinegar ratio, I always omit the oil to be safe. You'd also want to use pickling salt, since sea salt contains impurities. But you should have processed the jars for 10 minutes when you first made them, or poured off the liquid, rinsed the peppers (to get the oil off, the oil is only supposed to be on top), mixed a new brine and boiled it, put the peppers in clean hot jars, filled with hot brine and used new lids before processing for 10 minutes. I wouldn't eat those peppers if you didn't follow that (re)process.
    ...See More

    Android os, questions??

    Q

    Comments (2)
    I would suggest you hang out at one of the cruz forums they have a wealth of info. Also the cruz update page for firmware updates. I have a Pandigital Novel also running Android. It definitely should not be needing end task like that. I am on slatedroid forum tons of info there. The Cruz has much the same features as the Pandigital. You should find out where and how to download your models latest firmware which they issue to help correct problems, for the PDN there have been many firmware updates. Downloads you need to check your firmware version on your device and see if there is a newer one there.I would read both of those pdf guides there on that page and save them to disc so you have them available. whether the makers of Cruz will provide any type of OS upgrade option is up to them and what they can work out with Google. I would not expect full access to Google store, there are some hacks available that can make some of that happen. The pdn forum on slatedroid is amazing and those folks have created all kinds of neat stuff for us including access to the market. I know there is some type of Cruz Market not sure what all that includes. In answer it is up to the maker of the device. best bet though find some Cruz specific forums and also some good Android forums like slatedroid. I just am not that familiar with what all is available for Cruz. Here is a link that might be useful: slatedroid
    ...See More

    rappatoni mls hoses mac users

    Q

    Comments (11)
    Mac users are disadvantaged by Microsoft, which sometimes refuses to update Mac versions of their software (i.e., Internet Explorer). However, this is not the case for Microsoft Office - there have always been Office for Mac versions available (and they've just released Office2008 for Mac that will run on older PowerPC as well as newer Intel macs, and keeps up with Office2007 for Windows). But it is actually web developers who are truly to blame for sites that only work using IE. Mac users are a small percentage of the market, but as a demographic they are disproportionately wealthy internet users, and it's a dumb mistake to exclude them from one's website design. There are plenty of ways to design sites that are fully functional for Mac browsers. In the meantime, if it's just a matter of the site blocking Mac users via a browser sniffer (which is really poor practice just by the way), definitely try the Firefox extension johanncv referenced. Try Firefox in any case, if you haven't already, and you might be pleasantly surprised at what it can do vis-a-vis Safari. cheers from a Mac specialist :)
    ...See More
  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Hi Zep~ Thanks for responding. I still can't log on easily. I turned the computer off last night and it took at least 30 min to log on. I try all the F#'s, sometimes when I get the Bios, if I 'Save Defaults & Leave' it logs on. This time before that happened, at one point a few lines of white letters at the top said 'Unable to Find Operating System' ~ don't recall how I got out of that one.

    And 'no', I don't want extra toolbars

  • zep516
    13 years ago
    last modified: 9 years ago

    Ok,

    There is no Malware, but a little add / ware. So please follow the next 2 instructions.

    Next

    Double click the hijackthis Icon on the Desktop, Scroll down to Open the Misc Tools section" Click it at the bottom under System tools click "Open Uninstall Manager" over to the right click "Save List"Save it to your Desktop so you may find it, copy and paste it in your next reply.. Post that then do your Malwarebytes scan.

    Then

    Please Download Malwarebytes:
    Please download Malwarebytes' Anti-Malware to your desktop. Click here Free Version. If you already have Malwarebytes up date it before running it.
    Double Click mbam-setup.exe to install the application.
    Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    If an update is found, it will download and install the latest version.
    Once the program has loaded, select "Perform Quick Scan", then click Scan.
    The scan may take some time to finish,so please be patient.
    When the scan is complete, click OK, then Show Results to view the results.
    Make sure that everything is checked, and click Remove Selected.
    When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    Copy&Paste the entire report in your next reply.
    Extra Note:

    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

    That may take a bit to run, just do a Quick scan.

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Zep ~ I'm still working on the first instruction :(
    When it went to 'Save List' .....what list? I still have the one I sent you on Notepad - what's changed? Do I delete those Too Bars mentioned above???

  • zep516
    13 years ago
    last modified: 9 years ago

    I still have the one I sent you on Notepad

    That's the hijackthis log you can delete that. I already have that.

    The other instructions I gave should create a list of everything in your Program an features list, ust to be called the add / remove list. That's what I want.

    Double click the hijackthis Icon on the Desktop, Scroll down to Open the "Misc Tools section" Click it at the bottom. Under System tools click "Open Uninstall Manager" over to the right click "Save List" Save it to your Desktop so you may find it, copy and paste it in your next reply..

    Do not delete anything till I give you instructions to do so.

    Relax and take your time...

  • zep516
    13 years ago
    last modified: 9 years ago

    If you still have issue, move on to the Malwarebytes scan. No problem!

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5742

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19019

    2/11/2011 12:09:53 PM
    mbam-log-2011-02-11 (12-09-53).txt

    Scan type: Quick scan
    Objects scanned: 164275
    Time elapsed: 3 minute(s), 13 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5742

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19019

    2/11/2011 12:09:53 PM
    mbam-log-2011-02-11 (12-09-53).txt

    Scan type: Quick scan
    Objects scanned: 164275
    Time elapsed: 3 minute(s), 13 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Here's one Zep

  • zep516
    13 years ago
    last modified: 9 years ago

    Is this your Homepage and did you set it that way,

    home.mywebsearch.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml?ptnrS=ZRxdm429YYUS&ptb=OlVzOWJJhupJS5igcdXMzA&n=77ce5d58

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Acrobat.com
    Acrobat.com
    Activation Assistant for the 2007 Microsoft Office suites
    ActiveCheck component for HP Active Support Library
    AddThis Toolbar
    Adobe AIR
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader X (10.0.1)
    AIM 6
    Apple Application Support
    Apple Software Update
    Compatibility Pack for the 2007 Office system
    CyberLink YouCam
    D3DX10
    DVD Suite
    EA Link
    ESET Online Scanner v3
    FLV Player
    Google Analytics Opt-out Browser Add-on
    Google Toolbar for Internet Explorer
    Google Toolbar for Internet Explorer
    Google Update Helper
    Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Active Support Library
    HP Customer Experience Enhancements
    HP Doc Viewer
    HP Easy Setup - Frontend
    HP Help and Support
    HP Quick Launch Buttons 6.30 E1
    HP QuickPlay 3.7
    HP Update
    HP User Guides 0088
    HP Wireless Assistant
    HPAsset component for HP Active Support Library
    Inbox Toolbar
    Java(TM) 6 Update 2
    Java(TM) 6 Update 23
    Junk Mail filter update
    LabelPrint
    Malwarebytes' Anti-Malware
    McAfee SiteAdvisor
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office Home and Student 2007
    Microsoft Office Live Add-in 1.5
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Works
    Mozilla Firefox (3.6.13)
    MSN Toolbar
    MSVCRT
    MSVCRT_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    muvee autoProducer 6.1
    My HP Games
    NetWaiting
    Network Print Monitor for Windows 2000/XP/2003/Vista
    New England Snow Screen Saver
    Picasa 3
    Power2Go
    PowerDirector
    QuickTime
    RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
    SBC Yahoo! DSL Home Networking Installer
    Security Update for 2007 Microsoft Office System (KB2288621)
    Security Update for 2007 Microsoft Office System (KB2288931)
    Security Update for 2007 Microsoft Office System (KB2289158)
    Security Update for 2007 Microsoft Office System (KB2344875)
    Security Update for 2007 Microsoft Office System (KB2345043)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft Office Excel 2007 (KB2345035)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office PowerPoint 2007 (KB982158)
    Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB2344993)
    Segoe UI
    Slingbox Flash Tour
    SlingPlayer
    Spelling Dictionaries Support For Adobe Reader 9
    Spybot - Search & Destroy
    The Sims� Life Stories
    tropicaltango_3151927 Screen Saver
    TWC Customer Controls
    Update for 2007 Microsoft Office System (KB2284654)
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office OneNote 2007 (KB980729)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Viewpoint Media Player
    Visual C++ 8.0 Runtime Setup Package (x64)
    Visual C++ 8.0 Runtime Setup Package (x64)
    Visual Studio 2008 x64 Redistributables
    Webshots Desktop
    Windows 7 Upgrade Advisor
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Essentials
    Windows Live Installer
    Windows Live Mail
    Windows Live Mail
    Windows Live Movie Maker
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Yahoo! Toolbar

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    "Is this your Homepage and did you set it that way,
    home.mywebsearch.com"

    No, actually MSN.com has always been my homepage - I know how to change it, just haven't ~ is that a problem?

  • zep516
    13 years ago
    last modified: 9 years ago

    Please enter the Programs & Features and remove these items.

    Start>ControlPanel>Programs & Features, wait for the list to show and remove these programs in Bold

    AddThis Toolbar
    Google Toolbar for Internet Explorer
    Google Toolbar for Internet Explorer
    Google Update Helper
    Inbox Toolbar
    Java(TM) 6 Update 2
    McAfee SiteAdvisor
    MSN Toolbar
    Viewpoint Media Player
    Yahoo! Toolbar

    Let me know if any do not remove.

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    O.K. Zep ~ all uninstalled EXCEPT McAfee SiteAdvisor which I knew it wouldn't - darn thing.
    I tried many times yesterday & today but I just get a Microsoft Windows box that says:

    "SiteAdvisor has stopped working
    A problem caused the program to stop working correctly. Windows will close the program & notify you if a solution is available.

    Close Program (X)"

  • zep516
    13 years ago
    last modified: 9 years ago

    Don't worry about that for now.

    Next

    Please disable teatimer in Spybot S&D It could interfere with fixes, here's how:

    * Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
    * On the left hand side, click on Tools, then click on the Resident Icon in the list.
    * Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
    * Click on the "System Startup" icon in the List
    * Uncheck the "TeaTimer" box and "OK" any prompts.
    * If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
    * Exit Spybot S&D when done.

    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.

    Let me know when Tea Timer is disabled.

    If you have issue here, go to the programs and features again And uninstall Spybot Search & Destroy. You / we can install it back when all done.

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Zep ~ Spybot S&D is uninstalled. I followed your instructions but when I got to Resident-There was nothing anywhere that said "TeaTimer". I clicked on the System Startup icon and again no reference to "TeaTimer". Then per your last line I uninstalled Spybot S&D and it shut the computer down. Had trouble getting back on again. Had the black screen with blinking (blippin) curser. Finally hit Alt/Cntrl/Del & it went to black screen with F toolbar on bottom - tapped F8 several times.....and it started up! Do I need a new computer????

  • zep516
    13 years ago
    last modified: 9 years ago

    You defiantly have some issue going on. Lets try and finish what we started. We are just cleaning up some stuff here. Your boot problems sound as if they go a little deeper.

    Important You will need to print these instructions out, or better view them on anther computer! because you will not be able to see them.

    Please close all Browser windows including this one, close all running applications.

    Then

    Double click the hijackthis Icon on the desktop. Do a System Scan Only wait for the scan results to display. Once displayed, place a check mark in the following entries listed below in bold. Because we removed some toolbars you may not see all entries, take your time and go through the list. Just put a check mark in the box to the left of each entry.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml?ptnrS=ZRxdm429YYUS&ptb=OlVzOWJJhupJS5igcdXMzA&n=77ce5d58

    R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - (0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    R3 - URLSearchHook: (no name) - (22e03916-85c5-44b0-8dc9-1830c11238d9) - (no file)

    O2 - BHO: &Yahoo! Toolbar Helper - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll

    O2 - BHO: NCO 2.0 IE BHO - (602ADB0E-4AFF-4217-8AA1-95DAC4DFA408) - (no file)

    O2 - BHO: FCTBPos00Pos - (9EBF8AAF-0A31-4786-909A-97A0EF101743) - C:\Users\Ruth\AddThis Toolbar\Toolbar.dll

    O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll

    O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

    O2 - BHO: McAfee SiteAdvisor BHO - (B164E929-A1B6-4A06-B104-2CD0E90A88FF) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll

    O2 - BHO: MSN Toolbar Helper - (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll

    O2 - BHO: Inbox Toolbar - (D3D233D5-9F6D-436C-B6C7-E63F77503B30) - C:\PROGRA~2\INBOXT~1\Inbox.dll

    O3 - Toolbar: (no name) - (7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA) - (no file)

    O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll

    O3 - Toolbar: MSN Toolbar - (1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414) - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll

    O3 - Toolbar: Google Toolbar - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll

    O3 - Toolbar: (no name) - (CCC7A320-B3CA-4199-B1A6-9F516DD69829) - (no file)

    O3 - Toolbar: AddThis Toolbar - (B43176CC-4D9E-493B-A636-D9CBFE39C6DA) - C:\Users\Ruth\AddThis Toolbar\Toolbar.dll

    O3 - Toolbar: &Inbox Toolbar - (D7E97865-918F-41E4-9CD0-25AB1C574CE8) - C:\PROGRA~2\INBOXT~1\Inbox.dll

    O3 - Toolbar: McAfee SiteAdvisor Toolbar - (0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064) - c:\PROGRA~2\mcafee
    \SITEAD~1\mcieplg.dll

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

    O4 - Startup: Webshots.lnk = C:\Program Files (x86)\Webshots\Launcher.exe

    O4 - Global Startup: McAfee Security Scan Plus.lnk = ?

    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater
    \GoogleUpdaterService.exe

    O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe

    O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe

    Once all the check marks are in place:


    Click Fix Checked

    Close Hijackthis.

    Reboot The computer

    Next

    Post a fresh hijackthis log, That is do a System scan and save a log file this will be the new log after fixes.

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    I'm going to try again today, Zep. Yesterday my computer clogged and I couldn't delete the item in queue (still there) I plan to unplug telephone line and connections to reboot.

    Off subject, I have a large aquarium with a 15-16" Black Ghost Knifefish & he's suddenly dying which breaks my heart - I've had him for over 12 years & average life span is 10. Then I found out this morning that someone I know & respect who was in his 20's died this morning of a freak fall. Feel sad. Puts things in perspective, doesn't it?

  • zep516
    13 years ago
    last modified: 9 years ago

    It sure does, I too have an aquarium 55G salt water.

    Take your time. All i need is the new hijackthis log after the deletions. Do not do anything else to the computer as far as removing or installing anything while we are in the middle of this.

    Thanks...

    Joe

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Correction ~ I meant to say my printer clogged

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Hi Zep ~ I managed to get my printer going again and went thru the list you sent, carefully. Hijackthis 'fixed' 18 of the items but it looks like at least an equal number were not on their list. Can you tell me what to do now??

  • zep516
    13 years ago
    last modified: 9 years ago

    Hi,

    I need to see a new log now. So do a system scan and save a log file. Post that log. I expect a few more entries to be there that we will need to fix. Where almost done.

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Thank you for responding Zep ~ You're a peach! Will do that now, and yes, we're almost there - it's actually running pretty good (& faster) now but I'm still worried about shutting completely down and having it start up correctly. I'm just putting it in 'sleep' which is working well but I'd like to be able to just 'shut down'. But I want to get rid of as much junk as possible having gone this far in unfamilar territory with your help...

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:09:17 AM, on 2/13/2011
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.19019)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Windows Sidebar\sidebar.exe
    C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\HP\QuickPlay\QPService.exe
    C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
    C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

    O16 - DPF: (D27CDB6E-AE6D-11CF-96B8-444553540000) (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: (E2883E8F-472F-4FB0-9522-AC9BF37916A7) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: dssrequest - (5513F07E-936B-4E52-9B00-067394E91CC5) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: linkscanner - (F274614C-63F8-47D5-A4D1-FBDDE494F8D1) - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
    O18 - Protocol: sacore - (5513F07E-936B-4E52-9B00-067394E91CC5) - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: wlpg - (E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324) - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files (x86)\AGI\common\win32\PythonService.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
    O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

    --
    End of file - 6457 bytes

  • zep516
    13 years ago
    last modified: 9 years ago

    Hi,

    Looks like we are missing some entries or it just posted wrong. Please re-post the log. Or do a System Scan and save a log file again and post it.

    Missing some RO'S, R1'S. 08'S & 09 ENTRIES, A few 04's are missing too.

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    I ran it again - hope it has everything:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:46:50 PM, on 2/13/2011
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.19019)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Windows Sidebar\sidebar.exe
    C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\HP\QuickPlay\QPService.exe
    C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
    C:\PROGRA~2\Webshots\webshots.scr
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: AGSearchHook Class - "0BC6E3FA-78EF-4886-842C-5A1258C4455A> - C:\Program Files (x86)\AGI\common\agcutils.dll
    F2 - REG:system.ini: UserInit=userinit.exe,
    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - "02478D38-C3F9-4efb-9B51-7695ECA05670> - (no file)
    O2 - BHO: HP Print Enhancer - "0347C33E-8762-4905-BF09-768834316C61> - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHelperStub - "18DF081C-E8AD-4283-A596-FA578C2EBDC3> - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - "3CA2F312-6F6E-4B53-A66E-4E65E497C8C0> - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
    O2 - BHO: NCO 2.0 IE BHO - "602ADB0E-4AFF-4217-8AA1-95DAC4DFA408> - (no file)
    O2 - BHO: Google Analytics Opt-out Browser Add-on - "75EF13CE-B59E-41ba-8A5A-A944031BD8B4> - C:\Program Files (x86)\Google\Google Analytics Opt-Out\gaoptout.dll
    O2 - BHO: SSVHelper Class - "761497BB-D6F0-462C-B6EB-D4DAF1D92D43> - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live ID Sign-in Helper - "9030D464-4C02-4ABF-8ECC-5164760863C6> - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: McAfee SiteAdvisor BHO - "B164E929-A1B6-4A06-B104-2CD0E90A88FF> - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - "DBC80044-A445-435b-BC74-9C25C1C588A9> - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: HP Smart BHO Class - "FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856> - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: (no name) - "7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA> - (no file)
    O3 - Toolbar: (no name) - "CCC7A320-B3CA-4199-B1A6-9F516DD69829> - (no file)
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - "0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064> - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SSDMonitor] "C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Startup: Webshots.lnk = C:\Program Files (x86)\Webshots\Launcher.exe
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - "08B0E5C0-4FCB-11CF-AAA5-00401C608501> - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - "08B0E5C0-4FCB-11CF-AAA5-00401C608501> - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    O9 - Extra button: Send to OneNote - "2670000A-7350-4f3c-8081-5663EE0C6C49> - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - "2670000A-7350-4f3c-8081-5663EE0C6C49> - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - "92780B25-18CC-41C8-B9BE-3C9C571A8263> - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Show or hide HP Smart Web Printing - "DDE87865-83C5-48c4-8357-2F5B1AA84522> - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O13 - Gopher Prefix:
    O16 - DPF: "D27CDB6E-AE6D-11CF-96B8-444553540000> (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: "E2883E8F-472F-4FB0-9522-AC9BF37916A7> - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: dssrequest - "5513F07E-936B-4E52-9B00-067394E91CC5> - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: linkscanner - "F274614C-63F8-47D5-A4D1-FBDDE494F8D1> - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
    O18 - Protocol: sacore - "5513F07E-936B-4E52-9B00-067394E91CC5> - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: wlpg - "E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324> - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files (x86)\AGI\common\win32\PythonService.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
    O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

    --
    End of file - 12673 bytes

  • zep516
    13 years ago
    last modified: 9 years ago

    Very good! Looking better......

    I need to make a list of several more entries that we need to fix just like we did before. This time we will need to boot to safe mode. I will get the list of entries and give full instructions in next post. I need time to look it over.

  • zep516
    13 years ago
    last modified: 9 years ago

    Hi SAR,

    Please restart the computer now, during restart keep pressing the F8 Key on the computer, until you reach the advanced boot options menu (Black screen with white leters). Use the arrow key on the keyboard to select Safe Mode..Once the safe mode is selected (Hilighted) hit enter. Let the computer boot to the Safe Mode. Once in safe mode. Open Hijackthis from the Icon on the desktop, just like we did before. Do a system scan only Place a check mark in the following entries below be sure to get them all and no others,

    O2 - BHO: (no name) - "02478D38-C3F9-4efb-9B51-7695ECA05670> - (no file)
    O2 - BHO: NCO 2.0 IE BHO - "602ADB0E-4AFF-4217-8AA1-95DAC4DFA408> - (no file)
    O2 - BHO: McAfee SiteAdvisor BHO - "B164E929-A1B6-4A06-B104-2CD0E90A88FF> - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: (no name) - "7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA> - (no file)
    O3 - Toolbar: (no name) - "CCC7A320-B3CA-4199-B1A6-9F516DD69829> - (no file)
    O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Startup: Webshots.lnk = C:\Program Files (x86)\Webshots\Launcher.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe

    Once all check marks are in place.

    Click on Fix checked
    Close Hijackthis Program.
    Reboot back to normal mode.

    Then

    Again do a System Scan & Save a log file ,

    Post that log in a reply. Before posting you can review the log yourself to see if those entries are gone, if there not boot back to safe mode and try again. If any linger don't worry just post it.

    What Anti Virus was installed on this machine prior to AVG?

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Hi Zep,

    I had a horrible time with F8 (didn't work) & getting to 'Safe Mode' - had to check Ask.com and go to msconfig. Finally got there and did as instructed ~ then, couldn't get OUT of 'Safe Mode' back to 'Normal'. Finally succeceded and here I am. Since this is getting long ~ I'm going to run scan again & post with a new title. I'll try 'No OS Found' ~ here goes.

  • zep516
    13 years ago
    last modified: 9 years ago

    Did you force a Safe Mode from msconfig. Never recommend. You're lucky you got out! It's getting clear you do have possible Hare drive issues here or something.

    Rather have you stay in this thread, starting a new topic not needed.

  • zep516
    13 years ago
    last modified: 9 years ago

    The other thing here is if the drive is possibly failing or going to better to to get data off it know before running scans.

  • copanolady
    Original Author
    13 years ago
    last modified: 9 years ago

    Just about to say 'uncle' here Zep. I just got a new hard drive on this computer about 3 months ago! I wish I didn't have to give up on this computer but it seems hopeless. You've been so patient and nice to stay with me but I feel like I'm swimming in deep water & can't see the land. I don't know if it's a virus or something else(?)insideous I picked up somewhere. I know I didn't screw up THAT bad.

  • zep516
    13 years ago
    last modified: 9 years ago

    That's ok we made a lot of progress. I hope you may have learned something in the process and I think you have. That Operating System not found error and the other boot problems you appear to have, I don't think relates to a Malware or Virus. I'm not sure what it is. I was never addressing that issue, only getting rid of all those Tool Bars and start up programs. The only other suggestion I could make is to run a hard drive scan from the Hard drive manufactures site. Or take it in to a shop.

    I'd like to thank you for following directions so well. Even with a not so good machine. I know what that's like.