Return to the Computer Help Forum | Post a Follow-Up

 o
Laptop Webcam

Posted by threas (My Page) on
Sat, Feb 18, 12 at 13:50

I can not get the webcam program to launch....It also doesn't not show up under my list of devices...did a lot of things to try and get it to work...any advice?

Theresa


Follow-Up Postings:

 o
RE: Laptop Webcam

Hi Theresa,

Can you provide the name of the Laptop make and model# ?

Joe..


 o
RE: Laptop Webcam

yup...HPG60-445DX NOTEBOOK PC...


 o
RE: Laptop Webcam

Ok. Great! Now all we need to do is a Google search for these key words "HPG60-445DX WEBCAM OPERATION" and see what comes up. Not a bad link see below:

Let us know if it's help or you have other question.

Joe

Here is a link that might be useful: Webcam HPG60


 o
RE: Laptop Webcam

Thanks Joe! I'll check it out and get back to you!

Theresa


 o
RE: Laptop Webcam

Ok. There is a section that I think explains--> doesn't not show up under my list of devices

Good luck!

Joe


 o
RE: Laptop Webcam

I already did this...unless I'm missing something...?


 o
RE: Laptop Webcam

Try doing a System Restore to say yesterday, have you tried that?

Joe


 o
RE: Laptop Webcam

Funny, you should say that... My system restore doesn't work either...was gonna ask about that another time...


 o
RE: Laptop Webcam

Ok. What is the operating system? Might want to try System File checker, need to know operating system though.

Also
Have you tried booting to Safe Mode And doing a System Restore from there?

Joe.


 o
RE: Laptop Webcam

Vista.. I am pretty sure I tried doing a SR in Safe Mode...


 o
more

Try it again, restart the computer, during restart keep tapping the F8 Key, wait for the Advanced Boot Options Menu to appear Black screen with white letters. Once you see that screen use the arrow keys to select the option you want in this case I want you to Select Repair Your Computer once you select it it will be highlighted, hit enter. Then see if System restore works in either regular mode or Boot back to the safe mode and try it there.

If none of this works I want you to go to a thread--See link. It's my thread at Help 2 go. Scroll down to where I give instructions for using System file checker and follow them, here's the link to that thread below"

Here is a link that might be useful: Help 2 go thread System file checker instructions


 o
RE: Laptop Webcam

Thank you...I'll will report back..


 o
RE: Laptop Webcam

Great have fun! And I'll keep my eyes open. Like to address System Restore first. Like we are doing. System file checker might fix everything.

Joe


 o
RE: Laptop Webcam

I followed the System file checker instructions. I think I have system restore back. How can I check to be sure?


 o
RE: Laptop Webcam

Do you have an up to date antivirus..sometimes a virus or trojan can get in and disable the System Restore...Have you recently done a virus scan and a seperate malware scan using Malwarebytes (its free)


 o
RE: Laptop Webcam

I did a scan using Malwarebytes. I'm not sure about having an antivirus. I had a PC checkup a couple months back and the guy said I'm well covered for protection. I had Avast but removed it. I have Norton 360 Interner Security. Should I reinstall anther antivirus?


 o
more 2

"I followed the System file checker instructions. I think I have system restore back. How can I check to be sure?"

Only use 1 Anti Virus program! As long as Norton 360 is current (Up-Dated) and the subscription is current you're ok.

Ok. See if you can create a restore point. Instructions below:

Here is a link that might be useful: Vista restore directions


 o
RE: Laptop Webcam

Thanks, Joe! I'll be back! :)

Theresa


 o
RE: Laptop Webcam

Tried to run a system restore: error message reads:

The restore point could not be created for the following reason: Insufficient storage available to create either the shadow copy or other shadow copy(0x8004231F)

Please try again.


 o
RE: Laptop Webcam

Can you do this for me,

Please download MiniToolBox See link click on it and save it to your desktop . Then:
Checkmark following boxes:

List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
Click Go and post the results in your next reply.

Here is a link that might be useful: MiniToolBox.exe


 o
RE:Laptop Webcam

will do...


 o
RE: Laptop Webcam

MiniToolBox by Farbar Version: 18-01-2012
Ran by Threas (administrator) on 19-02-2012 at 13:35:20
Microsoft� Windows Vista� Home Premium Service Pack 2 (X86)
Boot Mode: Normal
********************************************************************** *****

========================= Event log errors: ===============================

Application errors:
==================
Error: (02/19/2012 08:05:09 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/19/2012 08:04:28 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (02/19/2012 08:04:28 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (02/19/2012 07:48:40 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/19/2012 07:47:45 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (02/19/2012 07:47:45 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (02/19/2012 04:52:23 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5601

Error: (02/19/2012 04:52:23 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5601

Error: (02/19/2012 04:52:23 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/19/2012 04:52:20 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3136

System errors:
=============
Error: (02/19/2012 08:05:09 AM) (Source: Service Control Manager) (User: )
Description: TfFsMon
TFSysMon

Error: (02/19/2012 08:05:09 AM) (Source: Service Control Manager) (User: )
Description: Norton Internet Security%%3

Error: (02/19/2012 08:05:09 AM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058

Error: (02/19/2012 08:04:41 AM) (Source: ipnathlp) (User: )
Description: The DHCP allocator has disabled itself on IP address 192.168.1.102, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.

Error: (02/19/2012 08:04:41 AM) (Source: ipnathlp) (User: )
Description: The ICS_IPV6 failed to configure IPv6 stack.

Error: (02/19/2012 07:48:41 AM) (Source: Service Control Manager) (User: )
Description: TfFsMon
TFSysMon

Error: (02/19/2012 07:48:41 AM) (Source: Service Control Manager) (User: )
Description: Norton Internet Security%%3

Error: (02/19/2012 07:48:41 AM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058

Error: (02/19/2012 07:47:58 AM) (Source: ipnathlp) (User: )
Description: The DHCP allocator has disabled itself on IP address 192.168.1.102, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.

Error: (02/19/2012 07:47:58 AM) (Source: ipnathlp) (User: )
Description: The ICS_IPV6 failed to configure IPv6 stack.

Microsoft Office Sessions:
=========================

=========================== Installed Programs ============================

Adobe Flash Player 11 Plugin (Version: 11.1.102.55)
Adobe Reader 9.5.0 (Version: 9.5.0)
Amazon Kindle
Apple Application Support (Version: 2.1.6)
Apple Mobile Device Support (Version: 4.0.0.97)
Apple Software Update (Version: 2.1.3.127)
ASPCA Reminder V7F+AU by We-Care.com (Version: 4.0.5.5)
Bejeweled Blitz
Best Removal Tool
Bonjour (Version: 3.0.0.10)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
Conexant HD Audio (Version: 4.58.1.0)
Cyberbackup 2.47
CyberLink YouCam 5 (Version: 5.0.1306)
DriverDoc (Version: 10.0)
Face Theme (Version: 1.0)
FinePix Studio
FinePixViewer Resource (Version: 1.2)
FinePixViewer Ver.5.5 (Version: 5.5)
Google Chrome (Version: 17.0.963.56)
Hewlett-Packard ACLM.NET v1.1.0.0 (Version: 1.00.0000)
HP DVD Play 3.7 (Version: 3.7.0.6310)
HP Help and Support (Version: 2.1.3.0)
HP Product Detection (Version: 11.14.0001)
InstallIQ Updater (Version: 1.4.1.0)
iTunes (Version: 10.5.3.3)
Java Auto Updater (Version: 2.0.6.1)
LaCie USB2 Storage Driver
Malwarebytes Anti-Malware version 1.60.1.1000 (Version: 1.60.1.1000)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 4.1.10111.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Mozilla Firefox 10.0.2 (x86 en-US) (Version: 10.0.2)
Norton 360 (Version: 5.2.0.13)
Norton Bootable Recovery Tool Wizard (Version: 4.1.0.15)
Norton PC Checkup (Version: 2.0.17.20)
Norton Utilities (Version: 14.5)
QuickTime (Version: 7.71.80.42)
Realtek USB 2.0 Card Reader (Version: 6.0.6000.20133)
RegZooka v2.6 (Version: 2.6)
Skype Click to Call (Version: 5.9.9216)
Skype� 5.8 (Version: 5.8.154)
SpyZooka (Version: 2.5)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Yahoo! BrowserPlus 2.9.8

========================= Memory info: ===================================

Percentage of memory in use: 51%
Total physical RAM: 2813.69 MB
Available physical RAM: 1363.62 MB
Total Pagefile: 5851.88 MB
Available Pagefile: 4321.22 MB
Total Virtual: 2047.88 MB
Available Virtual: 1944.73 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:287.17 GB) (Free:240.51 GB) NTFS
2 Drive d: (RECOVERY) (Fixed) (Total:10.92 GB) (Free:0.12 GB) NTFS

========================= Users: ========================================

User accounts for \\THREAS-PC

Administrator Alex Guest
Threas

**** End of log ****


 o
RE: Laptop Webcam

First:

Please uninstall these programs from your Programs and features list.

Best Removal Tool
RegZooka v2.6 (Version: 2.6)
SpyZooka (Version: 2.5)
Face Theme (Version: 1.0)

If any give uninstall problems, boot to safemode and uninstall from there.

I'm reviewing this: The restore point could not be created for the following reason: Insufficient storage available to create either the shadow copy or other shadow copy(0x8004231F)

Will get back to you.

Joe


 o
RE: Laptop Webcam

Thank you, Joe!


 o
RE:Laptop Webcam

OK, I deleted the above listed programs...


 o
RE: Laptop Webcam

I'm stumped on the error:

The restore point could not be created for the following reason: Insufficient storage available to create either the shadow copy or other shadow copy(0x8004231F)

You have plenty free space too! 1 Drive c: () (Fixed) (Total:287.17 GB) (Free:240.51 GB) NTFS

So Research is required, so far I have found, creating a new admin user account, increasing the shadow copy storage area, checking the shadow copy service is running.

There is a possibility that the shadow copies are using drive / Partition "D" to back up to. Drive d: (RECOVERY) (Fixed) (Total:10.92 GB) (Free:0.12 GB) NTFS

There would not be enough space there an an error would be generated, let me investigate a bit more though.

Is there an External Drive connected to this computer?

Joe


 o
RE: Laptop Webcam

"There is a possibility that the shadow copies are using drive / Partition "D" to back up to. Drive d: (RECOVERY) (Fixed) (Total:10.92 GB) (Free:0.12 GB) NTFS"

Joe, I think you might be right.

NO external drives.


 o
Hijackthis

Ok. One more thing to do as it will help to get an idea of what else might be going on.

Click Here to download HJTInstall.exe
Save HJTInstall.exe to your desktop.
Doubleclick on the HJTInstall.exe icon on your desktop. Right click the Hijackthis Icon and Run as Adminstrator if you use Vista or Windows 7
By default it will install to C:\Program Files\Trend Click on Install.
It will create a HijackThis icon on the desktop.
Once installed, it will launch Hijackthis.
Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" and Paste the entire contents of the log into your next post.
DO NOT use the AnalyzeThis button, its findings are dangerous if misinterpreted.
DO NOT have Hijackthis fix anything yet. Most of what HJT lists will be harmless or even required by your Operating System.


 o
RE: Laptop Webcam

How do I get HJT icon on deskstop.
my choices are:
Do a system scan and save a logfile
Do a system scan only
View the list of backups
Open the Misc Tools section
Open online Hijack This Quickstart
None of the above, just start the program

Or was I supposed to do something else before this point?


 o
RE: Laptop Webcam

Hi threas,

Did you download by clicking the "Click here" in the above post? If not. Click on "Click here" above or use the link I provided below. On the web page choose download wait for 5 seconds and a box will pop up. Choose "Save File" and save it to the desktop. Once there double click it. Then do a system scan and save a log file, log opens in notepad, copy and paste to the forum in your next reply.

Note Vista users should right click on the hijackthis Icon on the desktop and choose "Run as Adminstrator"

Joe :)

Here is a link that might be useful: Hijackthis


 o
RE: Laptop Webcam

I did click on Save File, but i don't see it on my desktop.?? i get the box with the choices above...


 o
more5

That's odd. I noticed they moved hijackthis too! Let me see what I can find out. I'll also download it and see what's going on with it.

Joe


 o
You're right bad download

Try the link below :)

Joe

Here is a link that might be useful: Download hijackthis


 o
RE: Laptop Webcam

Now it's on my desktop! Thanks. I'll follow the above directions and report back...


 o
No EXE. Icon

I only see the HJT Icon, not the exe. icon though...please advise..


 o
RE: Laptop Webcam

Can you right click on the Icon and choose "Run as Administrator" then do a system scan and save a log file?

Let me know..

Joe


 o
Install hijackthis

Actually when you first downlaod hijackthis, double click the hijackthis icon to install it, then the regular Icon will appear, right click on that one and run as adminstrator


 o
No EXE. Icon

No "Run as Administrator" choice,just back to the run screen...


 o
maim menu tab

Hit the main menu tab see what options that will bring up, if you see that.


 o
RE: Laptop Webcam

It says Welcome to HiJack This>>>Yada,Yada....
Then the choices are as above:

Do a system scan and save a logfile
Do a system scan only
View the list of backups
Open the Misc Tools section
Open online Hijack This Quickstart
None of the above, just start the program


 o
RE: Laptop Webcam

Do a system scan and save a logfile

Will that work? I am having trouble with it too!


 o
RE:Laptop Webcam

I think that will work...i'll do that...


 o
RE: Laptop Webcam

I ran the scan. window popped up "can't find HJT/Trends.....file (Something like that)would you like to create one?" i said yes. Now there is an empty box. I can't copy and paste the results either....???


 o
RE: Laptop Webcam

Actually, the empty box is Notepad. Should I create a folder???


 o
RE: Laptop Webcam

Yes create a folder see what happens :)


 o
RE: Laptop Webcam

I saved the file, but I don't know what is supposed to happen next...?


 o
RE: Laptop Webcam

When we first downloaded hijackthis, the install Icon should have gone to the desktop, at that point you would have doubled click that Icon and Hijackthis would have automatically installed to C:\Programfiles\TrendMicro\hijackthis.exe

See if it's in there: Know how to get there?

Click > Start > double click Computer double click Local disk when that opens look for Program files folder and double click it, inside that folder look for Trend Micro folder and double click it, inside there should be Hijackthis exe. If you find it double click it and see if it will run from there.



 o
Hijack This

Got it, Thanks! Here it is:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:06:11 PM, on 2/19/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Norton 360\Engine\5.2.0.13\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\YouCam\YouCamService.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Threas\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler.exe
C:\Program Files\CyberLink\YouCam\YouCam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\SpyZooka\spyzooka.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O2 - BHO: Symantec NCO BHO - (602ADB0E-4AFF-4217-8AA1-95DAC4DFA408) - C:\Program Files\Norton 360\Engine\5.2.0.13\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - (6D53EC84-6AAE-4787-AEEE-F4628F01010C) - C:\Program Files\Norton 360\Engine\5.2.0.13\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O2 - BHO: SkypeIEPluginBHO - (AE805869-2E5C-4ED4-8F7B-F1F7851A4497) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: WeCareReminder - (D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: ShopAtHomeIEHelper - (E8DAAA30-6CAA-4b58-9603-8E54238219E2) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: Microsoft Live Search Toolbar - (1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: ShopAtHome Toolbar - (98279C38-DE4B-4bcf-93C9-8EC26069D6F4) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O3 - Toolbar: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O3 - Toolbar: Norton Toolbar - (7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA) - C:\Program Files\Norton 360\Engine\5.2.0.13\coIEPlg.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [YouCam Service] "C:\Program Files\CyberLink\YouCam\YouCamService.exe" /s
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Threas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'Default user')
O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - (91774881-D725-4E58-B298-07617B9B86A8) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - (8C7461EF-2B13-11d2-BE35-3078302C2030) - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: cyberbackup.Service - Cyberlab - C:\Program Files\Cyberbackup\CyberbackupService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdx_device - - C:\Windows\system32\lxdxcoms.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.2.0.13\ccSvcHst.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10497 bytes


 o
RE: Laptop Webcam

Ok good old Hijackthis. There's some issues to be addressed and I really need to look it over. I'll be back tomorrow.

Thanks,

Joe


 o
3 Anti Virus programs!

You have 3 Anti Virus programs, Avast, Norton 360, and left overs of Norton/Symantec Anti Virus big no! no!. I strongly suggest you get rid of Norton. I am providing a link for Application Remover pleas use it to Uninstall Norton / Symantec. This will leave you with Avast and that is good. We will start with that.

Here is a link that might be useful: appremove


 o
You're infected

Go ahead and remove Norton, upon closer inspection on these items you're infected too.

O4 - HKUS\S-1-5-18\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'Default user')

You may have a possible Rootkit, don't run Malwarebytes or do anything. Go to a Malware removal forum. Link provided.

Joe

Here is a link that might be useful: malware-remova


 o
RE: Laptop Webcam

Scratch the rootkit. After you remove Norton. Please run a Malawarebytes scan,

Please download Malwarebytes' Anti-Malware to your desktop click Here
Double Click mbam-setup.exe to install the application.
•Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
•If an update is found, it will download and install the latest version.
•Once the program has loaded, select "Quick Scan", then click Scan
•The scan may take some time to finish,so please be patient.
•When the scan is complete, click OK, then Show Results to view the results.
•Make sure that everything is checked, and click Remove Selected.
•When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
•The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

click Here


 o
Edit

oops don't worry about that "Click here" at the bottom of the above post. That's an error. This forum can be difficult when your not use to html.


 o
RE: Laptop Webcam

Hey Joe. Did you see the following:

O3 - Toolbar: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll

Can be construed as malware. See link below.

Also, in the link, click on the VirusTotal scan results found under Description.

Malwarebytes may remove it though it is a nasty toolbar to get rid of. May be something lurking in the background that HJT can't see.

Here is a link that might be useful: whitesmoketoolbarX.dll


 o
RE: Laptop Webcam

Norton- huh? I just bought the internet security online, no discs. Just really want to make sure what you mean, before I remove the wrong thing.
Also, there is two choices:
I plan to reinstall a Norton product in the future. Please leave my settings behind.

Please remove all user data, including my passwords and quarantine contents.


 o
RE: Laptop Webcam

The final decision is going to have to be made by you, I would suggest getting rid of Norton and keeping avast only. If you decide to keep Norton Unistall Avast then. If you decide to uninstall Norton then yes remove all user data, including my passwords and quarantine.

Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)

The above entry is from an older version of Norton probably left over from a long time ago and there may be more Norton files left over that Hijackthis is not showing, that's a reason I wanted you to run the application remover to get rid of all the Norton files on the computer.

Let me know what you decide, having trouble, get rid of Norton take the loss. Post a malwarebytes log too.

I did see it bbbluz!


 o
RE: Laptop Webcam

I'm going to do what you think...I trust you and appreciate all the help! :) Thanks, Joe!


 o
RE: Laptop Webcam

Good morning. Run and post the Malwarebytes log after Norton is gone. I'll look at that log later today. If everything goes ok, you can then post a fresh Hijackthis log too. We will start working with that. There are quite a few deletions to be done using Hijackthis. I don't expect to be back until 4 pm est.


 o
RE: Malware removal

And thanks everyone else for all your help! I really appreciate it! :)

OK, I'm in the Malware removal forum. Dumb Question: Do I have 32 or 64 bit?


 o
RE:Malwarebytes

No reported infections in Malwarebytes:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.19.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Threas :: THREAS-PC [administrator]

2/19/2012 7:50:08 AM
mbam-log-2012-02-19 (07-50-08).txt

Scan type: Quick scan
Scan options enabled: Memory : Startup : Registry : File System : Heuristics/Extra : Heuristics/Shuriken : PUP : PUM
Scan options disabled: P2P
Objects scanned: 226392
Time elapsed: 10 minute(s), 55 second(s)

Memory Processes Detected: 2
C:\Program Files\CouponAlert_2p\bar\1.bin\2pbarsvc.exe (Adware.MyWebSearch) -> 1960 -> Delete on reboot.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrmon.exe (Adware.MyWebSearch) -> 896 -> Delete on reboot.

Memory Modules Detected: 1
C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrstub.dll (Adware.MyWebSearch) -> Delete on reboot.

Registry Keys Detected: 90
HKLM\SYSTEM\CurrentControlSet\Services\CouponAlert_2pService (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(23b38049-323f-443d-9732-f454e5b15b72) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(d7ce22af-ccb3-423f-84d5-4d77152181f3) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(004EB151-885B-4A9E-A22D-CA98DD998D75) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.SettingsPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.SettingsPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\(23B38049-323F-443D-9732-F454E5B15B72) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CouponAlert_2pbar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(3a421c8f-e238-4aeb-8874-b8b5f2cc4772) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\(3A421C8F-E238-4AEB-8874-B8B5F2CC4772) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\(3A421C8F-E238-4AEB-8874-B8B5F2CC4772) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(60e91567-ef8a-4520-bce2-83aba5256799) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\(60E91567-EF8A-4520-BCE2-83ABA5256799) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\(60E91567-EF8A-4520-BCE2-83ABA5256799) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(1f0a2185-da7e-4614-91c0-dd5f4a76cb1b) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(16fe2505-f2a0-4782-b035-af0e5188c02c) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(79583de9-d0c2-44ef-ae0d-cbfa16c2a785) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(1116A14B-F6A3-4FD9-A00E-FF8CF270EE48) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\(16FE2505-F2A0-4782-B035-AF0E5188C02C) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(3462c343-be19-4143-af70-cefb56f46fc6) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(7717f4b3-397f-4ce5-9192-6effde3ac999) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(4d8eacbc-e293-4462-b91e-42ea5b54b743) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.Radio.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.Radio (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(3276e8a8-a233-449b-a7eb-fcee21246018) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(A0636D37-97D0-4DC4-95A6-93AABA07437F) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.RadioSettings.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.RadioSettings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(7b9f8c21-46ec-4c0b-8683-e755ef84577a) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(cf9d6d4e-5496-438e-ba24-5a580a59f5a3) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.PseudoTransparentPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\(CF9D6D4E-5496-438E-BA24-5A580A59F5A3) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\(66D8FBA6-D90F-40A9-AC55-84896F79CA69) (Trojan.BHO) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\(66D8FBA6-D90F-40A9-AC55-84896F79CA69) (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.DynamicBarButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.DynamicBarButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.FeedManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.FeedManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.HTMLMenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.HTMLMenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.HTMLPanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.HTMLPanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.MultipleButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.MultipleButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.ScriptButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.ScriptButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.SkinLauncher (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.SkinLauncher.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.SkinLauncherSettings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.SkinLauncherSettings.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.ThirdPartyInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.ThirdPartyInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.UrlAlertButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.UrlAlertButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.XMLSessionPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2p.XMLSessionPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\CouponAlert_2p (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\MozillaPlugins\@CouponAlert_2p.com/Plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(def07acd-bcea-4269-933a-4087d20842bb) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(411b1946-3277-4a7f-9f60-745266360613) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(ebaf2b4f-510a-47c7-86ba-e7d94d1162f6) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(860AF5D1-0735-409D-8E5F-E3E99356D7E9) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(84576f6e-0660-4b4f-8918-bc6c975044d4) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(60fc9013-4a5a-4306-9695-fce0a6617f22) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(D244EAC5-A0F5-4859-A1F8-18ABC0AC3A00) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(86d02bcf-0e0e-444f-8a8d-2d5c4a9e6578) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(2d205adf-c992-4eda-99c3-096e13f38ab4) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(20bcce5a-c687-46ff-8dd2-ad8235f5f2b4) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(041278C7-DF92-486D-AE85-921BDFC75A43) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(0bdf6c42-132c-45f5-92de-dc13f40c6dab) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(a4116f8c-a634-4536-b9ef-6b9ebcc5bae1) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(65D8E17B-312E-4E12-913B-A841A8631143) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\(0BDF6C42-132C-45F5-92DE-DC13F40C6DAB) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(95B3F577-D54A-4831-B2B4-8AACEEDA85CF) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\(95B3F577-D54A-4831-B2B4-8AACEEDA85CF) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(457a4cb8-0391-409d-98b4-c4ccb2849670) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(7924fd2b-877c-4395-a063-a88ab887ea6d) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(36A7148B-639E-423C-90BB-30B6E1A40BD7) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(c2df3856-676c-41dc-a73b-facbdf8e81e9) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(8542e415-0e53-4261-8be4-0d1598229d90) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(56965DCF-718F-4148-BECF-5A2B466F4556) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\(C2DF3856-676C-41DC-A73B-FACBDF8E81E9) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(ebbc4e43-292a-40df-88e3-3262b7521460) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(13119113-0854-469d-807A-171568457991) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(8867ac9b-4426-44a2-a693-c95850d3405c) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\(53ca18e7-5223-4358-9fd9-97c62c66c5bd) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\(61DAB0AD-AD23-4E40-84AC-7C6CE64D4EB3) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\(8867AC9B-4426-44A2-A693-C95850D3405C) (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\(23b0ae65-17d2-4491-98e5-b1aa6228dda2) (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Detected: 7
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run:CouponAlert_2p Browser Plugin Loader (Adware.MyWebSearch) -> Data: C:\PROGRA~1\COUPON~2\bar\1.bin\2pbrmon.exe -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run:Coupon Alert Search Scope Monitor (Adware.MyWebSearch) -> Data: "C:\PROGRA~1\COUPON~2\bar\1.bin\2psrchmn.exe" /m=2 /w /h -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar:(3462C343-BE19-4143-AF70-CEFB56F46FC6) (Adware.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks:(7B9F8C21-46EC-4C0B-8683-E755EF84577A) (Adware.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\(7b9f8c21-46ec-4c0b-8683-e755ef84577a) (Adware.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\(3462c343-be19-4143-af70-cefb56f46fc6) (Adware.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions:2pffxtbr@CouponAlert_2p.com (Adware.MyWebSearch) -> Data: C:\Program Files\CouponAlert_2p\bar\1.bin -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 8
C:\Program Files\CouponAlert_2p (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\CouponAlert_2p\bar (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\CouponAlert_2p\bar\1.bin (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\CouponAlert_2p\bar\1.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\gen1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\IE9Mesg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Detected: 44
C:\Program Files\CouponAlert_2p\bar\1.bin\2pbarsvc.exe (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrstub.dll (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrmon.exe (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pSrchMn.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pbar.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pSrcAs.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pskin.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pradio.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pmlbtn.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pauxstb.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pdatact.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pdlghk.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pdyn.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pfeedmg.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2phighin.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2phkstub.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2phtml.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2phtmlmu.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2phttpct.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pidle.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pieovr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pimpipe.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pmedint.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pmsg.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pPlugin.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pregfft.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2preghk.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pregiet.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pscript.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2psknlcr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2pskplay.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2ptpinst.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\2puabtn.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\CHROME.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\installKeys.js (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\LOGO.BMP (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\NP2pStub.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\T8RES.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\1.bin\chrome\2pffxtbr.jar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\gen1\COMMON.T8S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\IE9Mesg\COMMON.T8S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\Message\COMMON.T8S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\CouponAlert_2p\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.

(end)

I'm going to run Hijack This again.


 o
RE: Hijack This

I did restart my computer after I posted the above log. Don't know if that makes a difference or not. Here are the results of Hijack This:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:06:11 PM, on 2/19/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Norton 360\Engine\5.2.0.13\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\YouCam\YouCamService.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Threas\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler.exe
C:\Program Files\CyberLink\YouCam\YouCam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\SpyZooka\spyzooka.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O2 - BHO: Symantec NCO BHO - (602ADB0E-4AFF-4217-8AA1-95DAC4DFA408) - C:\Program Files\Norton 360\Engine\5.2.0.13\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - (6D53EC84-6AAE-4787-AEEE-F4628F01010C) - C:\Program Files\Norton 360\Engine\5.2.0.13\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O2 - BHO: SkypeIEPluginBHO - (AE805869-2E5C-4ED4-8F7B-F1F7851A4497) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: WeCareReminder - (D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: ShopAtHomeIEHelper - (E8DAAA30-6CAA-4b58-9603-8E54238219E2) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: Microsoft Live Search Toolbar - (1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: ShopAtHome Toolbar - (98279C38-DE4B-4bcf-93C9-8EC26069D6F4) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O3 - Toolbar: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O3 - Toolbar: Norton Toolbar - (7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA) - C:\Program Files\Norton 360\Engine\5.2.0.13\coIEPlg.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [YouCam Service] "C:\Program Files\CyberLink\YouCam\YouCamService.exe" /s
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Threas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'Default user')
O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - (91774881-D725-4E58-B298-07617B9B86A8) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - (8C7461EF-2B13-11d2-BE35-3078302C2030) - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: cyberbackup.Service - Cyberlab - C:\Program Files\Cyberbackup\CyberbackupService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdx_device - - C:\Windows\system32\lxdxcoms.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.2.0.13\ccSvcHst.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10497 bytes


 o
RE: Laptop Webcam

Scan saved at 10:06:11 PM, on 2/19/2012 Are you sure that's a new log.

Hi we will delete some hijackthis entries, please follow all instructions carefully. If you van view these instructions on another computer that would be best or print them out.

Double click the hijackthis Icon or however you have been getting it open.

Do a System Scan only In other we are not saving a log file. Once the scan opens place a check mark in the following entries be sure to get them all and no others.

O2 - BHO: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O2 - BHO: WeCareReminder - (D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll
O2 - BHO: ShopAtHomeIEHelper - (E8DAAA30-6CAA-4b58-9603-8E54238219E2) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: Microsoft Live Search Toolbar - (1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: ShopAtHome Toolbar - (98279C38-DE4B-4bcf-93C9-8EC26069D6F4) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O3 - Toolbar: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O4 - HKUS\S-1-5-18\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'Default user')

Once you have all the check marks in place.

Click Fix Checked.
Close Hijackthis.
Reboot the computer.
Post a Fresh hijackthis log.

Why Is Norton still there, need to uninstall it soon.


 o
More7

Ok. Maybe norton's still there cause that's an older log. It's easy to do post an old log.


 o
RE: Laptop Webcam

Sorry, guess I used the old log. Should I post the newer one first?


 o
RE: Laptop Webcam

No. But you might not see all the entries i have asked you to delete in the above post. Don't worry about that. Just check the ones you see. You're doing a great job here it's nice working with you. Take your time.


 o
Updated Hijack This Log

I needed to go into Hijack This and run as admin. again, I didn't do that with above log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:25:08 PM, on 2/20/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\YouCam\YouCamService.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Threas\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O2 - BHO: SkypeIEPluginBHO - (AE805869-2E5C-4ED4-8F7B-F1F7851A4497) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: WeCareReminder - (D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: ShopAtHomeIEHelper - (E8DAAA30-6CAA-4b58-9603-8E54238219E2) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: Microsoft Live Search Toolbar - (1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: ShopAtHome Toolbar - (98279C38-DE4B-4bcf-93C9-8EC26069D6F4) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O3 - Toolbar: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [YouCam Service] "C:\Program Files\CyberLink\YouCam\YouCamService.exe" /s
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Threas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'Default user')
O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - (91774881-D725-4E58-B298-07617B9B86A8) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - (8C7461EF-2B13-11d2-BE35-3078302C2030) - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: cyberbackup.Service - Cyberlab - C:\Program Files\Cyberbackup\CyberbackupService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdx_device - - C:\Windows\system32\lxdxcoms.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9773 bytes


 o
RE: Laptop Webcam

Good Norton is gone. But all these entries are still there, it's imperative we get rid of them: Follow my instructions above. That is do a SYSTEM SCAN ONLY, place a check mark in the following entries, the little box to the left of each entry. You may have to be running as administrator. Then click fix checked (etc) as "explained" in above post with instructions for this exercise. Then do a system scan and save a log file. Check to see if those entries below are gone in the next log. Some can be stubborn. If that is the case, do it safe mode.

O2 - BHO: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O2 - BHO: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O2 - BHO: WeCareReminder - (D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll
O2 - BHO: ShopAtHomeIEHelper - (E8DAAA30-6CAA-4b58-9603-8E54238219E2) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: Microsoft Live Search Toolbar - (1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: ShopAtHome Toolbar - (98279C38-DE4B-4bcf-93C9-8EC26069D6F4) - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: PageRage Toolbar - (9565115d-c7d6-46d3-bd63-b67b481a4368) - C:\Program Files\PageRage\tbPage.dll
O3 - Toolbar: Conduit Engine - (30F9B915-B755-4826-820B-08FBA6BD249D) - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: WhiteSmoke Toolbar - (52794457-af6c-4c50-9def-f2e24f4c8889) - C:\Program Files\whitesmoketoolbar\whitesmoketoolbarX.dll
O4 - HKUS\S-1-5-18\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [454D5A46_ 0] C:\Windows\TEMP\uegsg.exe (User 'Default user')
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\SymcPCCULaunchSvc.exe


 o
RE: Hijack This Log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:55:50 PM, on 2/20/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\YouCam\YouCamService.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Threas\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - (AE805869-2E5C-4ED4-8F7B-F1F7851A4497) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [YouCam Service] "C:\Program Files\CyberLink\YouCam\YouCamService.exe" /s
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Threas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [kcokydps] C:\Windows\TEMP\xyikkeqfd\tjddjodlajb.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [kcokydps] C:\Windows\TEMP\xyikkeqfd\tjddjodlajb.exe (User 'Default user')
O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - (91774881-D725-4E58-B298-07617B9B86A8) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - (8C7461EF-2B13-11d2-BE35-3078302C2030) - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: cyberbackup.Service - Cyberlab - C:\Program Files\Cyberbackup\CyberbackupService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdx_device - - C:\Windows\system32\lxdxcoms.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 8505 bytes


 o
RE: Laptop Webcam

Good job! Something else appeared,

O4 - HKUS\S-1-5-18\..\Run: [kcokydps] C:\Windows\TEMP\xyikkeqfd\tjddjodlajb.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [kcokydps] C:\Windows\TEMP\xyikkeqfd\tjddjodlajb.exe (User 'Default user')

Again DO A SYSTEM SCAN ONLY, Place a check mark in those 2 entries. Click fix check, you know the drill.

Post a fresh log


 o
RE: Laptop Webcam

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:09:02 PM, on 2/20/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\YouCam\YouCamService.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Threas\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - (AE805869-2E5C-4ED4-8F7B-F1F7851A4497) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [YouCam Service] "C:\Program Files\CyberLink\YouCam\YouCamService.exe" /s
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Threas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User 'Default user')
O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - (91774881-D725-4E58-B298-07617B9B86A8) - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - (8C7461EF-2B13-11d2-BE35-3078302C2030) - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: cyberbackup.Service - Cyberlab - C:\Program Files\Cyberbackup\CyberbackupService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdx_device - - C:\Windows\system32\lxdxcoms.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 8480 bytes


 o
clear temp

Next

Clean out your temporary internet files and temp files.

Download TFC by OldTimer From here click Here
to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programswhen run, so make sure you have saved all your work before you begin

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.


 o
RE:Laptop Webcam

OK, I ran TFC... Now what?
Another thing I noticed is Windows Security Alerts keeps popping up, saying I am vulnerable. I click on the bubble and the virus protection is off. When I click on turn on, it doesn't do anything. I'm pretty sure I tried to get rid of Avast awhile ago. Should I reinstall it. And under Spyware and Malware protection is says Windows Defender is out of date. Nothing happens when I try to "Update Now".


 o
Avast

First of all you're running Avast Anti Virus, that's what we decided on. Can you see the avast Icon down by the clock, if so right click on it and see if there is an option to scan the computer. See if avast will do a scan for you. If right clicking does not work just double click it. For Windows Defender we may need to visit the windows up-date page. Lets try Avast first though.


 o
RE:Laptop Webcam

No icon for Avast.


 o
RE: Laptop Webcam

Hi,
If you continue to have issues with avast lets uninstall it and reinstall it by following my directions below:

Hi lets install Avast again just download it to the desktop, don't double click the install Icon yet. click Here To download Avast free first one on the left for home use click download at bottom.

Next
Download the Avast uninstall utility, save the file to the desktop, once there double click it and choose run.
click Here

Once the Avast uninstall utility has completed, go back to the Avast install Icon that you downloaded first and double click it. This will start to install Avast.


 o
RE: Avast

ok, did the above steps. I now have an Avast icon.... :)


 o
RE: Laptop Webcam

Ok. Let me know if you're still getting "Windows Security Alerts keeps popping up" and how things are in general with the computer. Back later today.

Joe


 o
RE: Windows Security Alerts

No security alerts... In general, seems good....thank you. Have a good day! See you later. :)

Theresa


 o
RE: Laptop Webcam

Hi Theresa,

Glad things are little better for you with the computer.

I'd like you to clear all the restore points when you get a chance. Instructions below:

delete all system restore points

1. In Control Panel / System, click System Protection (on the left of the window).

2. Under automatic restore points, uncheck all the boxes in the list of disks available. This is to disable the System Restore.

3.Vista will ask you to confirm this.

4. Confirm by clicking the Disable System Restore. All restore points existing system will be abolished

5. Click OK to close the window.

6. Click System Protection, recheck all the boxes in the list of available disks and then click OK.

7. This will thus put the system restore to function.

8. You can then create a restore point total of nine by clicking the Create button. The system will then create other at regular intervals.

Joe


 o
RE: Laptop Webcam

Hi Joe, I followed your above instruction. Still get the error message, when I try to create a Restore Point:

Error message reads:

The restore point could not be created for the following reason: Insufficient storage available to create either the shadow copy or other shadow copy(0x8004231F)

Please try again.


 o
RE: Laptop Webcam

I tried shutting down the computer after unchecking boxes. I unchecked one box at a time. Nothing.
There is a lot of lag when I'm playing games on Facebook and watching videos also...


 o
RE: Laptop Webcam

Hi if you have time, could you post the following logs for me.

Download DDS download here click Here

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open 2 logs:

1 DDS.txt
2 Attach.txt

* Save both logs to your desktop.
* Please include the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.


 o
dds

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by Threas at 14:11:10 on 2012-02-23
Microsoft� Windows Vista� Home Premium 6.0.6002.2.1252.1.1033.18.2814.1593 [GMT -5:00]
. AV: avast! Antivirus *Enabled/Updated* (2B2D1395-420B-D5C9-657E-930FE358FC3C)
SP: avast! Antivirus *Enabled/Updated* (904CF271-6431-DA47-5FCE-A87D98DFB681)
SP: Windows Defender *Enabled/Updated* (D68DDC3A-831F-4fae-9E44-DA132C1ACF46)
. ============== Running Processes ===============
. svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
C:\Program Files\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\YouCam\YouCamService.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\Threas\AppData\Local\Google\Update\1.3.21.99\GoogleCrashHandler.exe
svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
. ============== Pseudo HJT Report ===============
. uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
mStart Page = http
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
mSearchAssistant =
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: (18df081c-e8ad-4283-a596-fa578c2ebdc3) - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: avast! WebRep: (8e5e2654-ad2d-48bf-ac2d-d17f00898d06) - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Skype Browser Helper: (ae805869-2e5c-4ed4-8f7b-f1f7851a4497) - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Microsoft Live Search Toolbar Helper: (d2ce3e00-f94a-4740-988e-03dc2f38c34f) - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: (dbc80044-a445-435b-bc74-9c25c1c588a9) - c:\program files\java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: (8e5e2654-ad2d-48bf-ac2d-d17f00898d06) - c:\program files\avast software\avast\aswWebRepIE.dll
TB: (604BC32A-9680-40D1-9AC6-E06B23A1BA4C) - No File
TB: (9565115D-C7D6-46D3-BD63-B67B481A4368) - No File
TB: ShopAtHome Toolbar: (98279c38-de4b-4bcf-93c9-8ec26069d6f4) - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
TB: (472734EA-242A-422B-ADF8-83D1E48CC825) - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Google Update] "c:\users\threas\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [YouCam Service] "c:\program files\cyberlink\youcam\YouCamService.exe" /s
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: (2670000A-7350-4f3c-8081-5663EE0C6C49) - (48E73304-E1D6-4330-914C-F5F514E3486C) - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - (898EA8C8-E7FF-479B-8935-AEC46303B9E5) - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: (92780B25-18CC-41C8-B9BE-3C9C571A8263) - (FF059E31-CC5A-4E2E-BF3B-96E929D65503) - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: (8AD9C840-044E-11D1-B3E9-00805F499D93) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: (CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA) - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 208.59.247.45 208.59.247.46 192.168.1.1
TCP: Interfaces\(C53262C3-4621-4DE4-9D5D-414D410C4238) : DhcpNameServer = 208.59.247.45 208.59.247.46 192.168.1.1
Handler: skype-ie-addon-data - (91774881-D725-4E58-B298-07617B9B86A8) - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - c:\progra~1\common~1\skype\SKYPE4~1.DLL
mASetup: (10880D85-AAD9-4558-ABDC-2AB1552D831F) - "c:\program files\common files\lightscribe\LSRunOnce.exe"
. ================= FIREFOX ===================
. FF - ProfilePath - c:\users\threas\appdata\roaming\mozilla\firefox\profiles\iqp42yjh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.startsearcher.com/?q=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.startsearcher.com/?src=kw&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\programdata\norton\(0c55c096-0f1d-4f28-aaa2-85ef591126e7)\nis_18.1.0.37\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\(0c55c096-0f1d-4f28-aaa2-85ef591126e7)\nis_18.1.0.37\ipsffplgn\components\IPSFFPl.dll
FF - component: c:\users\threas\appdata\roaming\mozilla\firefox\profiles\iqp42yjh.default\extensions\(8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94)\components\RadioWMPCoreGecko19.dll
FF - component: c:\users\threas\appdata\roaming\mozilla\firefox\profiles\iqp42yjh.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol500.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\users\threas\appdata\local\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\users\threas\appdata\local\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\users\threas\appdata\roaming\mozilla\firefox\profiles\iqp42yjh.default\extensions\(ab91efd4-6975-4081-8552-1b3922ed79e2)\plugins\npAclmPlugin.dll
FF - plugin: c:\users\threas\appdata\roaming\mozilla\firefox\profiles\iqp42yjh.default\extensions\(ab91efd4-6975-4081-8552-1b3922ed79e2)\plugins\npProductDetectPlugin.dll
. ---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
. R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2010-6-21 15328]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-2-20 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-2-20 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-2-20 20568]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-2-20 55128]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-2-20 44768]
R2 cyberbackup.Service;cyberbackup.Service;c:\program files\cyberbackup\CyberbackupService.exe [2012-1-17 13824]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service --> c:\windows\system32\lxdxcoms.exe -service [?]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\engine\2.0.17.20\SymcPCCULaunchSvc.exe [2012-2-17 135608]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.17.20\ccSvcHst.exe [2012-2-17 126392]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-4-20 365952]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\macrium\reflect\ReflectService.exe [2010-6-21 220128]
R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\drivers\clwvd.sys [2012-2-15 27760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Norton Internet Security;Norton Internet Security;"c:\program files\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 --> c:\program files\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-1-31 158856]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-4-20 193840]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [2010-6-21 44512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-1-20 16896]
. =============== Created Last 30 ================
. 2012-02-21 07:06:25 6552120 ----a-w- c:\programdata\microsoft\windows defender\definition updates\(6167fd3a-aa70-411b-9e4e-0d8e6f78bf39)\mpengine.dll
2012-02-21 05:02:28 6557240 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2012-02-21 04:18:57 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-02-21 04:18:54 55128 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-02-21 04:17:30 -------- d-----w- c:\programdata\AVAST Software
2012-02-21 04:17:30 -------- d-----w- c:\program files\AVAST Software
2012-02-19 23:11:58 388096 ----a-r- c:\users\threas\appdata\roaming\microsoft\installer\(45a66726-69bc-466b-a7a4-12fcba4883d7)\HiJackThis.exe
2012-02-19 23:11:54 -------- d-----w- c:\program files\Trend Micro
2012-02-19 12:44:50 -------- d-----w- c:\users\threas\appdata\roaming\Malwarebytes
2012-02-19 12:44:32 -------- d-----w- c:\programdata\Malwarebytes
2012-02-18 03:57:26 -------- d-----w- c:\windows\system32\drivers\nortonpccheckup\0200110.014
2012-02-18 03:57:26 -------- d-----w- c:\windows\system32\drivers\NortonPCCheckup
2012-02-18 03:57:24 -------- d-----w- c:\program files\Norton PC Checkup
2012-02-18 00:57:23 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2012-02-17 14:45:49 2048 ----a-w- c:\program files\internet explorer\iecompat.dll
2012-02-15 21:53:59 -------- d-----w- c:\users\threas\appdata\local\CyberLink
2012-02-15 21:49:04 27760 ----a-w- c:\windows\system32\drivers\clwvd.sys
2012-02-15 20:25:29 -------- d-----w- c:\programdata\install_clap
2012-02-15 17:23:21 -------- d-----r- c:\program files\Skype
2012-02-15 00:31:51 2044416 ----a-w- c:\windows\system32\win32k.sys
2012-02-15 00:31:48 680448 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-15 00:31:35 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2012-02-01 21:36:20 -------- d-----w- c:\program files\iPod
2012-02-01 21:36:17 -------- d-----w- c:\program files\iTunes
2012-01-31 11:45:27 9728 ----a-w- c:\windows\system32\lsass.exe
2012-01-31 11:45:27 72704 ----a-w- c:\windows\system32\secur32.dll
2012-01-31 11:45:27 440192 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-31 11:45:27 377344 ----a-w- c:\windows\system32\winhttp.dll
2012-01-31 11:45:27 278528 ----a-w- c:\windows\system32\schannel.dll
2012-01-31 11:45:27 1259008 ----a-w- c:\windows\system32\lsasrv.dll
. ==================== Find3M ====================
. 2012-02-21 09:01:41 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-29 10:10:42 237072 ------w- c:\windows\system32\MpSigStub.exe
2011-12-22 00:52:12 55168 ----a-w- c:\windows\help\oem\scripts\HPSAUpdaterObj.exe
2011-12-14 21:29:18 876928 ----a-w- c:\windows\help\oem\scripts\HP.SupportFramework.dll
2011-12-10 20:24:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-08 20:58:12 22528 ----a-w- c:\windows\help\oem\scripts\PWAlertEnable.exe
2011-12-07 16:29:22 49152 ----a-w- c:\windows\help\oem\scripts\Interop.TaskScheduler.dll
2011-11-30 21:20:08 21048 ----a-w- c:\windows\help\oem\scripts\HPSADeployer.exe
2011-11-28 18:01:25 41184 ----a-w- c:\windows\avastSS.scr
. ============= FINISH: 14:13:30.05 ===============


 o
RE: Laptop Webcam

Hi Theresa,
Norton Bootable Recovery Tool Wizard (Version: 4.1.0.15)
Norton PC Checkup (Version: 2.0.17.20)
Norton Utilities (Version: 14.5)

Boot the computer to safe mode and try uninstalling those entries above from your programs an Features list.

You also may consider running Application Remover again and see if it can remove any left over Norton files.

Let me know.

Joe


 o
More 14

I want you to run this tool too, Norton remover. Please scroll down to Step # 2. Look for the yellow Download button / tab. Download it and run it.

See link.

Here is a link that might be useful: Norton remover.


 o
RE: Laptop Webcam

Thanks Joe! I did what you suggested above. What's next?


 o
RE: Laptop Webcam

Were any files removed? I hope so.

See if you can create a restore point now. I provided a link for you.

Here is a link that might be useful: restore-point-for-windows-vistas


 o
RE: Laptop Webcam

Joe, yes the files for Norton were removed.
Still can't create a restore point.Still get the error message, when I try to create a Restore Point:

Error message reads:

The restore point could not be created for the following reason: Insufficient storage available to create either the shadow copy or other shadow copy(0x8004231F)

Please try again.


 o
more 12

Ok. It looks like possible registry corruption but that's a guess. Only because I saw a reg cleaner installed on your machine that we removed. I am working from this link below. There talking about creating a new user account, they also ran SFC and we did that already. Take a look a the link. In the mean time I'm still thinking.

Here is a link that might be useful: (0x8004231F)


 o
RE: Laptop Webcam

I read the info.Thanks! I don't know if this means anything or not, but, I looked in my user accounts and I am listed as the Admin.(Threas)and (Alex) as Guest, but in the Minitoolbox log ran earlier, is has (Alex) as Admin. and (Threas)as Guest. While I was in user accounts I deleted (Alex)account. That account doesn't get used any more. I hope I didn't further screw things up...

User accounts for \\THREAS-PC

Administrator Alex Guest
Threas

**** End of log ****


 o
RE: Laptop Webcam

No that should not hurt. I'm not sure how to change your user account. I have never given instructions on that. Someone else here may know and it may be worth a shot. I'm still looking around.

Do you have a Vista operating disk?

Joe


 o
RE: Laptop Webcam

I do not have a Vista operating disk. I do have back up discs thru Macrium Reflect..Does that help?

Do you think the link you gave above"(0x8004231F)",is worth a shot creating a new admin. account? Here's what it says:

"If the above step does not fix the issue I would suggest that you create a new administrator user account on the computer.

Login to the new user account and check if you can create system restore point.

Open User Accounts by clicking the Start button, clicking Control Panel, clicking User Accounts and Family Safety, and then clicking User Accounts.
Click Manage another account. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
Click Create a new account.
Type the name you want to give the user account, click an account type, and then click Create Account.

http://windows.microsoft.com/en-US/windows-vista/Create-a-user-account"


 o
RE: Laptop Webcam

I'd be curious ;
What's the newest restore point.
What's the oldest restore point.
About how many restore points are there.

You can easily look at that with CCleaner options.

Sounds like you've changed so much from reading parts of the above, its not much good to you anyways.
What I might do is schedule a check disk, turn off system restore & restart the computer before turning it back on & trying to make a new restore point. Be nice feeling to run defrag before making any restore point.

Did you get the web camera working ?


 o
RE: Laptop Webcam

I didn't create a new Administrator account. Should I try that?
Should I install CCleaner?

Didn't really play with camera yet. But I'm pretty sure, no go.


 o
RE: Laptop Webcam

If your comfortable creating an account by all means do it.

Yes install CCleaner.

Funny I see what I think is your camera running at start up:

mRun: [YouCam Service] "c:\program files\cyberlink\youcam\YouCamService.exe" /s


 o
RE: Laptop Webcam

The camera must be running,because, I tried to do an uninstall of Cyberlink YouCam 5, and it says YouCam is using this program, please close and retry. I don't know how to turn it off...????

I installed CCleaner. Right now I'm running a Drive Wiper on both Drives. C & D.


 o
RE: Administrator account

Okay, I created a new Administrator account. Now what? Joe, have I told you lately how much I appreciate all your help? :)


 o
hello

Anytime we make a change we want to go back and see if we can create a system restore point. See if you can.

Do you have a Vista disk? Not a recovery disk, but a retail version of Vista.


 o
edit

Back to hijackthis,

When you get a chance, do System Scan only, place a check mark in this entry:
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"

Fix checked.
Close hijackthis
Reboot.

That will stop Youcam from running


 o
RE: Laptop Webcam

I don't have a retail version of Vista...
I tried to create a restore point again, no luck. Same message as above.
I ran hijackthis scan. Rebooted. What should I try next?


 o
RE: Laptop Webcam

If you fixed that entry above you could see if the camera works now.

Lets also turn System restore off and on see link. Then see if a restore point can be created.

Here is a link that might be useful: Turn-System-Restore-on-or-off


 o
Also

Lets try this too.

Delete Shadow Copies Using "Disk Clean"

Please use OPTION ONE See link.

Here is a link that might be useful: Delete Shadow Copies


 o
RE: Elevated Command Prompt

When I open the Elevated Command Prompt, is says to go to "General" tab click on "unblock" next to Security, under "Advanced" button. I don't have that part....???


 o
RE: Laptop Webcam

Scroll down to option one on that page where it says all this stuff below.

*********************************************************
OPTION ONE
Delete Shadow Copies Using "Disk Cleanup"

NOTE: Disk Cleanup will delete all shadow copies and restore points saved to the selected hard drive letter except the most recent copy.
1. Open the Start Menu, type cleanmgr into the search box, and press Enter.
2. Select the drive/volume letter that you want to delete shadow copies on, and click on OK. (see screenshot below)
NOTE: You will not see this window unless you have more than one drive or partition on your computer.
******************************************************


 o
RE: Laptop Webcam

Doh! Sorry about that. I didn't read far enough down...:? Ok, I did the disk clean up for Drive C should I also do one for Drive D "Recovery"?


 o
RE: Laptop Webcam

NO! Don't do that. There may be recovery files there that will be needed someday. Try to create a restore point again after cleaning up those files and see what happens.


 o
RE:Laptop Webcam

Nope...still won't create recovery point...


 o
RE: Laptop Webcam

Try visiting the windows up-date page. Let the computer scan for up-dates. Windows up-date should be in Start> All Programs list.


 o
RE: Laptop Webcam

Windows Update : Latest Scan Yesterday 8:30AM. When I scan for updates, the scan doesn't stop.....?


 o
RE: Laptop -Slow Down

My laptop is really lagging now... like something is running in the background...?


 o
RE: Laptop Webcam

Maybe we should restore it to factory settings, like it was new. Do you have any recovery disks?


 o
RE: Laptop Webcam

I have Disks from Macrium Reflect. Will that do?


 o
RE: Laptop Webcam

I have no idea what they are. Where did you get them?

You should have made recovery disks when you got the computer, ha ha no one does. You do have a recovery partition I saw it so you may be able to make disks.

Do me a favor reboot the computer and hold the F11 KEY down, tell me what comes up if anything.

See link for reference on hp recovery.

http://h10025.www1.hp.com/ewfrf/wc/document?docname=c00810334&cc=us&lc=en&dlc=en

http://h10025.www1.hp.com/ewfrf/wc/document?docname=c01895783&tmp_task=useCategory&cc=us&dlc=en&lc=en&product=3979133


 o
RE: Recovery Disk

I have a Disk that I made. It's marked Recovery Disk. Is this good?


 o
more23

I can't guarantee anything sometimes things can go wrong when you make a disk. Your computer was pretty messed up when you first got here, no restore, no camera, sluggish,etc ect. We have covered a lot of bases and not getting anywhere. I would review the links I gave above about recovery above. There for your model. Then strongly consider doing a recovery. You will loose all your files, pictures, and that sort of thing. You would need to back up pictures etc that you wanted to save.

Check out the links so you have some knowledge about it.

Joe


 o
RE: Laptop Webcam

"Do me a favor reboot the computer and hold the F11 KEY down, tell me what comes up if anything."

The Recovery Manager comes up.

Thanks, Joe...


 o
RE: Laptop Webcam

Hey Joe, I restored my computer to factory settings. I still can't find the integrated webcam. Any advice?

Theresa


 o
RE: Laptop Webcam

No! I give up on that for now HA HA ! More importantly did you install an Anti Virus program? Did you go to windows up-date in install all up-dates including service packs. You will need to reinstall flash, java too.

Tell me where you are with it.


 o
More 56

Make sure the computer is up to date with windows up date, service pack, Anti Virus like Avast. Then deal with the Webcam issue.

Fixing Webcam Problems in Windows Vista

http://h10025.www1.hp.com/ewfrf/wc/document?docname=c01560721&cc=us&dlc=en&lc=en&product=3979133#N1100

Joe


 o
RE: Laptop Webcam

Thanks Joe! I did all the above... I cannot fond the webcam in device manager. I went through the above posts and researched a lot... still at a loss....???


 o
webcam issue

Click Start , type Device Manager , and select Device Manager from the list provided.
If there is no Imaging devices entry in the listing, highlight any topic (for example: Keyboards), and then on the Action menu, click Scan for hardware changes .

If the Device Manager does not recognize the existence of the webcam after the scan, there may be a hardware issue.

Did you try the above exercise?


 o
RE: Laptop Webcam

Did the above....more than once...:/


 o
RE: Laptop Webcam

I would conclude then a hardware issue. Broken Intergrated Circuit chip, broken connection, bad diode, resistor or anything like that. An alternative might be to consider a USB webcam as listed in the link provided.

http://www.newegg.com/Store/SubCategory.aspx?SubCategory=152


 o
RE: Laptop Webcam

I have a HP laptop with windows 7 so it may not be the same but if I click on the start button and type webcam in the search programs and files box my webcam is the first thing listed in the search result. I can right click on the name of the webcam and select send to and choose desktop. it will make a shortcut on the desktop. Or I can choose pin to taskbar or pin to start menu from the drop down list. This may not help you at all but thought I would suggest trying.


 o
RE: Laptop Webcam

Joe, i think you are right... thank you for all your help... :)
Bob, thank you for the tip. Unfortunately, I did that and there is no webcam device detected.
I'm probably going to buy one.
Thank again for all your help.

Theresa


 o Post a Follow-Up

Please Note: Only registered members are able to post messages to this forum.

    If you are a member, please log in.

    If you aren't yet a member, join now!


Return to the Computer Help Forum

Information about Posting

  • You must be logged in to post a message. Once you are logged in, a posting window will appear at the bottom of the messages. If you are not a member, please register for an account.
  • Please review our Rules of Play before posting.
  • Posting is a two-step process. Once you have composed your message, you will be taken to the preview page. You will then have a chance to review your post, make changes and upload photos.
  • After posting your message, you may need to refresh the forum page in order to see it.
  • Before posting copyrighted material, please read about Copyright and Fair Use.
  • We have a strict no-advertising policy!
  • If you would like to practice posting or uploading photos, please visit our Test forum.
  • If you need assistance, please Contact Us and we will be happy to help.


Learn more about in-text links on this page here