Okay, looks good.
Please reopen HijackThis to 'do system scan only'.
Check each of the following if present> Don't click on 'Fix Checked' until all are done:
C:\Program Files\Viewpoint\Common\ViewpointService.exe
O4 - HKLM\..\Run: [gcasDtServ] gcasDtServ.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [VF0560Inst] RunDll32.exe C:\WINDOWS\system32\V0560Pin.dll,RunDLL32EP 515 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [VF0560Inst] RunDll32.exe C:\WINDOWS\system32\V0560Pin.dll,RunDLL32EP 515 (User 'Default user')
O4 - HKLM\..\Run: [igivm] "C:\Program Files\iGive__Shopping__Window\iGiveShoppingWindowv.exe"
O8 - Extra context menu item: iGive Shopping Window - file://C:\Program Files\iGive__Shopping__Window\igivt\igivC5.htm
O9 - Extra button: iGive Shopping Window - {9B7E79AC-A646-4e45-A70F-1B3981FE370E} - file://C:\Program Files\iGive__Shopping__Window\igivt\igivC5.htm (file missing) (HKCU)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Close all Windows except HijackThis and click on
'Fix Checked.'
Boot into Safe Mode
[*] Restart your computer and start pressing the F8 key on your keyboard.
[*] Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.
[1] Right click on the Taskbar> Task Manager> Highlight each of the processes below and 'End Task':
- VIEWMGR.EXE
- iGive
- iGive Shopping Window
[2]Start> Run> tytpe in misconfig> enter> Selective Startup> Startup tab> UNCHECK each of the following if present:
- Viewpoint Manager
- Viewpoint Media Player
- Viewpoint Toolbar
- iGive Shopping Windows
[3] Click on Start> Control Panel> Add/Remove Programs> UNINSTALL any of the following if found:
- Viewpoint Manager
- Viewpoint Media Player
- Viewpoint Toolbar
- "iGive Shopping Window"
[4]Right click on Start> Explore> Programs> find each of the following if present> right click on the folder> Delete:
- Viewpoint
- iGive Shopping Window (see my note at the bottom)
[5]Start> Run> type in services.msc> right click> Properties on each of the Service below and reset the Startup Type to Disabled> Stop the Service:
- Viewpoint
- iGive Shopping Window.
Reboot into Normal Mode: NOTE: ignore the nag message and close it after checking 'don't show this message again.' Stay in Selective Startup.
Note: We encourage users to remove Viewpoint. It is not malware. It is considered 'foistware'. What is foistware?
[o]Foistware or Bundler is software bundled with completely unrelated programs. This means you didn't ask for it- it came bundled with another program.
Warning: If you install AOL © Instant Messenger, Adobe Atmosphere plugin, or another program that requires Viewpoint, it will download and install again.
Please download ComboFix
HERE:
- With ComboFix, at the download window, please rename it to Combo-Fix(.exe) before downloading it.
- Please disable all security programs, such as antiviruses, antispywares, and firewalls. Also disable your internet connection. This will include the AV and the firewall.
- Run Combo-Fix.exe and follow the prompts.
(Understand that things like your system clock changing and your desktop disappearing might happen. Do not worry, because all will be restored later.)
- Wait for the scan to be completed.
- If it requires a reboot, please do it.
• After the scan has completed entirely, please attach the log here. The log will be located at C:\ComboFix(.txt)
Do not click on the ComoboFix window, as it may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Then follow wit a full system scan with the antivirus program. Save log and attach to new post.
Logs and Reports to attach to next reply:
1. Combofix report
2. AV log
3. Rescan wit HJT and include new log.
Please be more specific with the problem you're having, if you find them any better since we started and if there are any new problems. There are a few System 32 files I might have you delete, but want to wain until after Combofix.
I am not a hardware person so hopefully Raybay can assist with the sound issue.