Okay, the system is clean of malware. But I think I have found the CPU users. You don't need any of the following to start on boot. I have given a short description where applicable. These are all considered optional removals- they aren't malware, foistware or adware. But some are high resource users and most will be accessing the internet multiple times a day:
If you would like to take the\e off of Startup or remove nt of the programs follow below:
Please reopen HijackThis to 'do system scan only. Check each of the following if present:
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
yahooauservice.exe uses excessive system and memory resources with no corresponding benefit.
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
HP software updates.
The following processes are all for the Logitech web cam and are loading at startup. None need to start on boot. Web cam is user invoked- you can access it through All Programs when wanted/needed.
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
(Found on Acer laptops with webcams and Logitech webcams. Reports indicate that this process can use up a great deal of memory)
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
(Video effects for web cam)
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe> high resource user
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
-------------------------------------------
The following are Google related. None need to start on boot:
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe> auto update
O4 - HKUS\S-1-5-21-2025429265-963894560-682003330-1004\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (User 'Mom')
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
(If you never asked for the "Google Quick Search Box", and neither need nor want it: Then uninstall it
O23 - Service: Google Update Service (gupdate1c9bf1be359a036) (gupdate1c9bf1be359a036) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe> [on my laptop,this Service contacted the internet twice yesterday- I disabled it)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe>> t(on my laptop this Services contacted the internet 13 times yesterday- I have disabled it.
Close all Windows except HijackThis and click on "Fix Checked".
Boot into Safe Mode
- Restart your computer and start pressing the F8 key on your keyboard.
- Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.
Go to
Add/ remove Programs in the Control Panel> if you decided to uninstall the Logitech web cam> uninstall all related entries.
If you want to keep the web cam, but take it off of Startup> do this:
Start> Run> type in msconfig> enter> Selective Startup> Startup tab> Uncheck all processes related to the web cam:
QuickCam10.exe
COCIManager.exe
LComMgr or Communications_Helper.exe
LVComSX.exe
Logitech Vid or vid.exe
LVPrcSrv.exe
SrvLnch\SrvLnch.exe
Click on Apply> OK
Start> Run> type in
services.msc> find the following 2 Services> if uninstalling the program, change Startup Type to Disabled. If keeping but removing from Startup> change Startup Type to Manual.
LVPrcSrv
LVSrvLauncher
The extra Google entries do not appear in Add/Remove Programs. To disable the Service, find the 2 entries below and change Startup type to Disabled:
gupdate
gusvc
Close the Services. Reboot into Normal Mode. NOTE: the first time you reboot after making changes using msconfig, you will get a nag message. It can be ignored and closed after checking 'do not show this message again.'
Empty the Recycle Bin
Let me know if you notice and improvement. Then I'll have you remove the clenaing tools and old restore points.