This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Machine Running Slow

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello ALL, :wavey:

Need an expert to analyze my HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:00:22 AM, on 7/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\SelectRebates\SelectRebates.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\BackUp\CmdBkSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ShopAtHome Toolbar - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: OpenOffice.org 2.2.lnk.disabled
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/down…llerControl.cab
O16 - DPF: PackageCab - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/dcode/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125759480093
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://ak.imgag.com/imgag/cp/install/Crusher.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/TrueInstall.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\WINDOWS\system32\cssdll32.dll C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AG Core Services (AGCoreService) - AG Interactive - C:\Program Files\AGI\core\3.0\AGCoreService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ComodoBackupService - COMODO - C:\Program Files\COMODO\BackUp\CmdBkSvc.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

–
End of file - 10582 bytes

Thanks, Marty :unsure:
Hi MARTY1946,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

It looks like you've picked up yourself some adware.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hello Tomk, :wavey:

Thanks for your expert advice.

Malwarebytes' Anti-Malware 1.34
Database version: 1824
Windows 5.1.2600 Service Pack 3

7/17/2009 7:18:47 AM
mbam-log-2009-07-17 (07-18-47).txt

Scan type: Quick Scan
Objects scanned: 75991
Time elapsed: 5 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:53:16 AM, on 7/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\core\3.0\AGCoreService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\BackUp\CmdBkSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/down…llerControl.cab
O16 - DPF: PackageCab - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/dcode/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125759480093
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://ak.imgag.com/imgag/cp/install/Crusher.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AG Core Services (AGCoreService) - AG Interactive - C:\Program Files\AGI\core\3.0\AGCoreService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ComodoBackupService - COMODO - C:\Program Files\COMODO\BackUp\CmdBkSvc.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

–
End of file - 8695 bytes

Thanks Again,
Marty
:unsure:
MARTY1946,

I'm really not seeing anything. Let's get an online scan.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hello

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Sunday, July 19, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, July 19, 2009 14:35:28
Records in database: 2494892
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 102742
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 03:52:07


File name / Threat name / Threats count
C:\Documents and Settings\Dick\.housecall6.6\Quarantine\plusrect.exe.bac_a00804 Infected: not-a-virus:AdWare.Win32.Lop.bb 1

The selected area was scanned.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:23:29 PM, on 7/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\core\3.0\AGCoreService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\COMODO\BackUp\CmdBkSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\MICROS~3\Office12\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/down…llerControl.cab
O16 - DPF: PackageCab - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/dcode/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125759480093
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://ak.imgag.com/imgag/cp/install/Crusher.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AG Core Services (AGCoreService) - AG Interactive - C:\Program Files\AGI\core\3.0\AGCoreService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ComodoBackupService - COMODO - C:\Program Files\COMODO\BackUp\CmdBkSvc.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

–
End of file - 8726 bytes

Thanks, Marty
MARTY1946,

Let's explore that a little further.

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Hello Tomk, :pullhair:


——————–\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 2.40GHz )
BIOS : Default System BIOS
USER : Dick ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.5 (Activated)
Firewall : COMODO Firewall 3.9 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:111 Go (Free:80 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Mon 07/20/2009| 8:31 )

——————–\\ Listing folders in APPLIC~1

[01/17/2008|04:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Grisoft
[01/20/2003|09:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[09/08/2004|05:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Lavasoft
[12/25/2008|10:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Macromedia
[03/17/2009|10:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[12/21/2008|11:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Mozilla
[01/20/2003|10:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Symantec

[03/20/2009|07:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[06/02/2009|01:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[03/20/2009|07:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[05/01/2009|08:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AGI
[03/20/2009|07:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[03/20/2009|07:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[06/22/2009|11:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AVG Security Toolbar
[03/17/2009|10:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg8
[01/20/2003|10:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BVRP Software
[01/20/2009|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ comodo
[01/29/2003|07:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DelFin
[04/12/2009|07:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DriverCure
[11/11/2006|02:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[03/17/2009|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grisoft
[07/26/2004|03:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GTek
[04/20/2009|10:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Hewlett-Packard
[05/24/2009|08:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[12/21/2008|01:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[12/26/2008|10:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[01/08/2009|04:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[07/16/2009|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[01/27/2003|10:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MSN6
[01/05/2009|09:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NOS
[04/12/2009|06:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ParetoLogic
[12/16/2008|04:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PC Drivers HeadQuarters
[01/05/2009|09:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ POP VIEW TRAY 16
[01/08/2009|12:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[01/05/2009|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio
[01/20/2003|10:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[12/17/2008|09:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[07/16/2009|01:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[04/09/2009|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SupportSoft
[02/09/2008|06:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[12/21/2008|01:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[07/02/2007|11:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Trymedia
[11/26/2004|04:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ulead Systems
[02/02/2007|05:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[07/30/2005|04:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[08/14/2007|08:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo!
[05/06/2009|01:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion

[02/28/2007|07:10] C:\DOCUME~1\APPLIC~1\APPLIC~1\ Microsoft

[01/20/2003|09:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[01/20/2003|09:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[01/20/2003|10:11] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Symantec

[01/16/2009|04:08] C:\DOCUME~1\Dick\APPLIC~1\ Adobe
[06/03/2007|12:27] C:\DOCUME~1\Dick\APPLIC~1\ AdobeUM
[05/01/2009|01:23] C:\DOCUME~1\Dick\APPLIC~1\ agi
[02/09/2008|12:16] C:\DOCUME~1\Dick\APPLIC~1\ Aim
[03/06/2009|03:10] C:\DOCUME~1\Dick\APPLIC~1\ Amazon
[03/25/2005|06:13] C:\DOCUME~1\Dick\APPLIC~1\ Apple Computer
[05/20/2009|09:46] C:\DOCUME~1\Dick\APPLIC~1\ AVGTOOLBAR
[02/18/2009|02:21] C:\DOCUME~1\Dick\APPLIC~1\ Canneverbe_Limited
[04/09/2009|10:39] C:\DOCUME~1\Dick\APPLIC~1\ ComcastToolbar
[11/26/2004|07:59] C:\DOCUME~1\Dick\APPLIC~1\ Common Files
[07/09/2009|11:18] C:\DOCUME~1\Dick\APPLIC~1\ Comodo
[01/07/2009|01:27] C:\DOCUME~1\Dick\APPLIC~1\ DeepBurner
[04/12/2009|06:18] C:\DOCUME~1\Dick\APPLIC~1\ DriverCure
[02/18/2009|12:27] C:\DOCUME~1\Dick\APPLIC~1\ GetRightToGo
[02/20/2006|10:18] C:\DOCUME~1\Dick\APPLIC~1\ Google
[07/26/2004|03:37] C:\DOCUME~1\Dick\APPLIC~1\ GTek
[03/03/2003|08:12] C:\DOCUME~1\Dick\APPLIC~1\ Help
[11/26/2004|07:59] C:\DOCUME~1\Dick\APPLIC~1\ HP
[08/30/2004|03:56] C:\DOCUME~1\Dick\APPLIC~1\ Identities
[06/24/2009|08:47] C:\DOCUME~1\Dick\APPLIC~1\ Image Zone Express
[12/21/2008|03:50] C:\DOCUME~1\Dick\APPLIC~1\ InstallShield
[04/05/2005|11:46] C:\DOCUME~1\Dick\APPLIC~1\ Kazaa Lite
[04/17/2009|07:19] C:\DOCUME~1\Dick\APPLIC~1\ Kingston
[01/15/2008|05:21] C:\DOCUME~1\Dick\APPLIC~1\ Lavasoft
[04/14/2003|03:37] C:\DOCUME~1\Dick\APPLIC~1\ Leadertech
[06/21/2009|05:15] C:\DOCUME~1\Dick\APPLIC~1\ LimeWire
[09/10/2004|01:17] C:\DOCUME~1\Dick\APPLIC~1\ Macromedia
[12/26/2008|10:28] C:\DOCUME~1\Dick\APPLIC~1\ Malwarebytes
[05/19/2009|12:58] C:\DOCUME~1\Dick\APPLIC~1\ Microsoft
[10/23/2008|09:24] C:\DOCUME~1\Dick\APPLIC~1\ Mozilla
[05/10/2003|03:49] C:\DOCUME~1\Dick\APPLIC~1\ MSN6
[02/28/2007|07:10] C:\DOCUME~1\Dick\APPLIC~1\ MySpace
[07/14/2009|05:00] C:\DOCUME~1\Dick\APPLIC~1\ OpenOffice.org2
[04/20/2009|10:15] C:\DOCUME~1\Dick\APPLIC~1\ Printer Info Cache
[02/13/2004|07:20] C:\DOCUME~1\Dick\APPLIC~1\ Real
[12/27/2008|11:14] C:\DOCUME~1\Dick\APPLIC~1\ Roxio
[04/06/2005|11:32] C:\DOCUME~1\Dick\APPLIC~1\ Sun
[01/20/2003|10:11] C:\DOCUME~1\Dick\APPLIC~1\ Symantec
[08/18/2004|05:32] C:\DOCUME~1\Dick\APPLIC~1\ Systweak
[02/06/2005|11:17] C:\DOCUME~1\Dick\APPLIC~1\ Talkback
[05/01/2009|08:00] C:\DOCUME~1\Dick\APPLIC~1\ Temp
[01/08/2009|12:20] C:\DOCUME~1\Dick\APPLIC~1\ Template
[11/26/2004|04:30] C:\DOCUME~1\Dick\APPLIC~1\ Ulead Systems
[12/31/2008|01:23] C:\DOCUME~1\Dick\APPLIC~1\ Uniblue
[01/08/2009|05:00] C:\DOCUME~1\Dick\APPLIC~1\ Windows Desktop Search
[01/08/2009|05:11] C:\DOCUME~1\Dick\APPLIC~1\ Windows Search
[08/17/2007|11:17] C:\DOCUME~1\Dick\APPLIC~1\ Yahoo!

[12/27/2008|11:16] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Adobe
[06/22/2009|09:26] C:\DOCUME~1\LOCALS~1\APPLIC~1\ AVGTOOLBAR
[03/17/2009|10:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[12/20/2008|08:11] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Macromedia
[03/17/2009|10:35] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[02/28/2007|07:10] C:\DOCUME~1\Owner\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[07/19/2009 05:00 PM][–a——] C:\WINDOWS\tasks\RegCure Program Check.job
[07/19/2009 04:13 AM][–a——] C:\WINDOWS\tasks\RegCure.job
[07/19/2009 06:00 PM][–a——] C:\WINDOWS\tasks\ParetoLogic Registration.job
[07/20/2009 12:33 AM][–a——] C:\WINDOWS\tasks\ParetoLogic Update Version2.job
[07/19/2009 02:35 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/29/2002 07:00 AM][-rah—–] C:\WINDOWS\tasks\DESKTOP.INI

——————–\\ Listing Folders in C:\Program Files

[05/27/2006|03:30] C:\Program Files\ _uninstallation_info
[01/29/2005|07:01] C:\Program Files\ Abacast
[12/16/2004|10:13] C:\Program Files\ Activision
[01/05/2009|09:56] C:\Program Files\ Adobe
[03/20/2009|07:58] C:\Program Files\ Adobe Media Player
[01/05/2009|09:56] C:\Program Files\ Advanced System Optimizer
[05/01/2009|08:00] C:\Program Files\ AG Toolbar
[05/01/2009|08:00] C:\Program Files\ AGI
[02/09/2008|12:16] C:\Program Files\ AIM
[03/06/2009|03:09] C:\Program Files\ Amazon
[04/15/2009|02:56] C:\Program Files\ Analog Devices
[03/21/2007|12:22] C:\Program Files\ AOD
[07/16/2009|09:09] C:\Program Files\ Apple Software Update
[03/31/2009|09:03] C:\Program Files\ ART Inc
[02/02/2009|01:38] C:\Program Files\ AskBarDis
[01/04/2009|04:48] C:\Program Files\ Astonsoft
[03/17/2009|10:40] C:\Program Files\ AVG
[04/12/2004|11:04] C:\Program Files\ AZZ Cardfile
[08/28/2004|01:38] C:\Program Files\ BillP Studios
[03/20/2009|07:43] C:\Program Files\ Bonjour
[01/05/2009|10:00] C:\Program Files\ CCleaner
[02/18/2009|02:21] C:\Program Files\ CDBurnerXP
[08/19/2004|02:06] C:\Program Files\ cdrompollflaw
[01/08/2009|12:35] C:\Program Files\ Classic PhoneTools
[04/09/2009|10:03] C:\Program Files\ Comcast
[04/15/2009|01:51] C:\Program Files\ Common Files
[07/16/2009|01:35] C:\Program Files\ COMODO
[01/20/2003|09:07] C:\Program Files\ ComPlus Applications
[01/05/2009|09:59] C:\Program Files\ CONEXANT
[01/05/2009|09:33] C:\Program Files\ Dell
[01/20/2003|10:12] C:\Program Files\ Dell Computer
[01/20/2003|10:06] C:\Program Files\ Digital Line Detect
[04/15/2009|01:26] C:\Program Files\ DriverGuide DriverScan
[01/08/2009|12:35] C:\Program Files\ DriverGuide DriverScan(2)
[04/23/2009|10:48] C:\Program Files\ DriverGuide Toolkit
[04/12/2008|05:00] C:\Program Files\ Elsevier
[12/22/2008|10:21] C:\Program Files\ Enigma Software Group
[10/30/2005|11:42] C:\Program Files\ ER_DS
[03/20/2009|07:02] C:\Program Files\ ERUNT
[01/08/2009|12:37] C:\Program Files\ exPressit S.E. 2.2
[01/05/2009|09:56] C:\Program Files\ Flash Movie Player
[10/14/2004|09:13] C:\Program Files\ GameHouse
[07/14/2005|10:36] C:\Program Files\ GLF21.tmp
[04/21/2009|05:29] C:\Program Files\ Gold Miner Vegas
[01/08/2009|12:37] C:\Program Files\ GoldPocket
[12/21/2008|01:10] C:\Program Files\ Google
[02/09/2008|06:10] C:\Program Files\ Grisoft
[04/12/2004|11:04] C:\Program Files\ Hasbro Interactive
[04/20/2009|10:04] C:\Program Files\ Hewlett-Packard
[07/17/2009|08:43] C:\Program Files\ Hijackthis
[04/20/2009|02:20] C:\Program Files\ HP
[06/21/2009|07:47] C:\Program Files\ InstallShield Installation Information
[04/13/2009|08:20] C:\Program Files\ intel
[08/23/2004|10:41] C:\Program Files\ Intel Corporation
[11/20/2004|02:02] C:\Program Files\ InterMute
[04/20/2009|11:51] C:\Program Files\ Internet Explorer
[06/02/2009|12:47] C:\Program Files\ Java
[11/21/2004|12:54] C:\Program Files\ Lexico
[06/02/2009|01:05] C:\Program Files\ LimeWire
[02/13/2009|12:46] C:\Program Files\ Malwarebytes' Anti-Malware
[01/28/2003|08:03] C:\Program Files\ MediaLoads
[01/08/2009|12:39] C:\Program Files\ Messenger
[06/10/2007|03:49] C:\Program Files\ Microsoft AntiSpyware
[05/10/2007|02:28] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[04/12/2004|11:04] C:\Program Files\ Microsoft Encarta
[01/20/2003|09:07] C:\Program Files\ microsoft frontpage
[01/09/2009|02:28] C:\Program Files\ Microsoft IntelliPoint
[01/09/2009|01:32] C:\Program Files\ Microsoft IntelliPoint 5.5
[04/21/2009|05:39] C:\Program Files\ Microsoft Office
[01/05/2009|09:56] C:\Program Files\ Microsoft Picture It! 2002
[02/02/2004|08:24] C:\Program Files\ Microsoft Reference
[04/20/2009|11:43] C:\Program Files\ Microsoft Silverlight
[01/08/2009|12:40] C:\Program Files\ Microsoft Streets & Trips
[04/21/2009|01:18] C:\Program Files\ Microsoft Visual Studio
[05/16/2009|09:25] C:\Program Files\ Microsoft Works
[02/18/2009|12:22] C:\Program Files\ Microsoft.NET
[12/21/2008|01:32] C:\Program Files\ Modem Helper
[08/31/2008|10:01] C:\Program Files\ Movie Maker
[07/20/2009|08:11] C:\Program Files\ Mozilla Firefox
[02/25/2009|12:55] C:\Program Files\ MSBuild
[12/05/2008|10:32] C:\Program Files\ MSECache
[04/20/2009|11:44] C:\Program Files\ MSN
[01/20/2003|09:07] C:\Program Files\ MSN Gaming Zone
[04/23/2005|03:59] C:\Program Files\ MsnMusic
[11/17/2006|04:01] C:\Program Files\ MSXML 4.0
[01/28/2003|12:37] C:\Program Files\ MUSICMATCH
[01/09/2008|02:36] C:\Program Files\ MySpace
[01/20/2009|01:42] C:\Program Files\ Navilog1
[01/08/2009|12:40] C:\Program Files\ NetMeeting
[06/08/2005|01:27] C:\Program Files\ Netscape
[01/05/2009|09:56] C:\Program Files\ NOS
[01/08/2009|12:40] C:\Program Files\ Office
[04/09/2005|05:40] C:\Program Files\ Office10
[01/20/2003|09:07] C:\Program Files\ Online Services
[03/20/2009|08:26] C:\Program Files\ OpenOffice.org 2.2
[03/20/2009|08:28] C:\Program Files\ OpenOffice.org 2.4
[08/31/2008|09:54] C:\Program Files\ Outlook Express
[07/24/2004|02:27] C:\Program Files\ Overland
[01/07/2008|07:26] C:\Program Files\ Panda Security
[01/05/2009|10:00] C:\Program Files\ PC Drivers HeadQuarters
[03/07/2006|04:57] C:\Program Files\ PC MightyMax
[01/08/2009|04:04] C:\Program Files\ PC Wizard 2008
[08/04/2004|06:59] C:\Program Files\ PcBugDoctor
[12/18/2008|10:48] C:\Program Files\ PCCheckupOnline
[02/05/2008|05:06] C:\Program Files\ PCPitstop
[08/31/2004|06:51] C:\Program Files\ PCRescue
[01/29/2005|11:02] C:\Program Files\ PepiMK Software
[03/20/2009|08:40] C:\Program Files\ Perfect Uninstaller
[11/18/2005|06:24] C:\Program Files\ Prentice Hall
[04/15/2003|04:16] C:\Program Files\ Print Workshop 2003 Limited Edition
[06/02/2009|01:48] C:\Program Files\ QuickTime
[02/16/2007|10:41] C:\Program Files\ Real
[02/25/2009|12:55] C:\Program Files\ Reference Assemblies
[03/18/2006|08:56] C:\Program Files\ ReflexiveArcade
[04/15/2009|08:42] C:\Program Files\ RegCure
[01/05/2009|09:56] C:\Program Files\ Research In Motion
[11/26/2004|04:22] C:\Program Files\ Samsung
[10/29/2003|08:09] C:\Program Files\ SAT
[04/15/2009|01:52] C:\Program Files\ Seagate
[06/13/2005|01:12] C:\Program Files\ SkillJam Techologies
[06/11/2005|08:14] C:\Program Files\ SkillSoft
[12/21/2008|01:06] C:\Program Files\ SlySoft
[11/26/2004|04:29] C:\Program Files\ Sony
[07/02/2007|11:57] C:\Program Files\ Sony Online Entertainment
[04/16/2009|11:54] C:\Program Files\ Spybot - Search & Destroy
[04/09/2005|05:40] C:\Program Files\ Stationery
[12/21/2008|01:16] C:\Program Files\ support.com
[01/05/2009|09:46] C:\Program Files\ System Security Suite 1.04
[01/05/2009|09:31] C:\Program Files\ TaxCut03
[04/21/2009|05:42] C:\Program Files\ TaxCut04
[01/05/2009|10:00] C:\Program Files\ TAXCUT2003
[04/09/2005|05:40] C:\Program Files\ Templates
[11/26/2008|03:07] C:\Program Files\ Trend Micro
[11/26/2004|04:24] C:\Program Files\ Ulead Systems
[07/04/2004|09:49] C:\Program Files\ Uninstall Information
[01/05/2009|09:55] C:\Program Files\ UPHClean
[02/02/2007|05:36] C:\Program Files\ Viewpoint
[05/11/2009|01:49] C:\Program Files\ Virtools
[04/15/2009|01:27] C:\Program Files\ Visioneer OneTouch
[06/10/2009|01:00] C:\Program Files\ Windows Desktop Search
[01/08/2009|04:57] C:\Program Files\ Windows Media Connect 2
[01/08/2009|04:57] C:\Program Files\ Windows Media Player
[08/31/2008|09:54] C:\Program Files\ Windows NT
[08/12/2004|07:36] C:\Program Files\ WindowsUpdate
[01/08/2009|12:44] C:\Program Files\ WinZip
[01/20/2003|09:07] C:\Program Files\ XEROX
[08/28/2004|09:49] C:\Program Files\ XoftSpy
[05/05/2009|09:24] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[03/13/2009|05:20] C:\Program Files\Common Files\ Adobe
[03/20/2009|07:58] C:\Program Files\Common Files\ Adobe AIR
[06/02/2009|01:53] C:\Program Files\Common Files\ Apple
[01/01/2004|08:41] C:\Program Files\Common Files\ ATX
[01/20/2003|10:07] C:\Program Files\Common Files\ Designer
[07/22/2004|04:45] C:\Program Files\Common Files\ Hewlett-Packard
[04/20/2009|08:11] C:\Program Files\Common Files\ HP
[12/17/2008|09:20] C:\Program Files\Common Files\ InstallShield
[01/21/2008|12:41] C:\Program Files\Common Files\ Java
[05/16/2009|09:26] C:\Program Files\Common Files\ Microsoft Shared
[01/20/2003|09:07] C:\Program Files\Common Files\ MSSoap
[01/20/2003|09:07] C:\Program Files\Common Files\ ODBC
[06/08/2005|12:53] C:\Program Files\Common Files\ Real
[04/09/2009|10:39] C:\Program Files\Common Files\ Scanner
[12/28/2008|01:12] C:\Program Files\Common Files\ Services
[12/21/2008|01:20] C:\Program Files\Common Files\ Sonic Shared
[01/20/2003|09:07] C:\Program Files\Common Files\ SpeechEngines
[04/09/2009|10:03] C:\Program Files\Common Files\ SupportSoft
[05/16/2009|09:21] C:\Program Files\Common Files\ System
[04/15/2009|01:51] C:\Program Files\Common Files\ Wise Installation Wizard

——————–\\ Process

( 44 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-20 08:34:37
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\Dick\Desktop\Emmy\My Documents\My Pictures\crackbird.bmp


[F:1454][D:21]-> C:\DOCUME~1\Dick\LOCALS~1\Temp
[F:13][D:0]-> C:\DOCUME~1\Dick\Cookies
[F:198][D:4]-> C:\DOCUME~1\Dick\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Mon 07/20/2009| 8:36 - Option : [1]

——————–\\ Scan completed at 8:36:30
Thanks, Marty
MARTY1946,

Well that's good news. Even though Kaspersky found a LOP infected file, it is not active on your system as housecalls already removed it.

I'm still not seeing anything. I would suggest that you read this tutorial on slow running computers and Help! My computer is slow! by miekiemoes.

If nothing in those articles helps you, I suggest that you post in the Windows Forum and see if the Tech Team can help you tune things up. If you do that, please post a link back to this thread so they can see the logs you have posted here.

Log looks good :D

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

You need to create a new Clean restore point:

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

You may be asked to choose drive. Choose C: At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI