Virtumonde, Win32, etc.

Sadly, that doesn't fix it. One of the items that you want me to delete doesn't actually get deleted. I open HJT, I check 04 - .Default user Startup: Vongto tray.lnk.

Then I press fix checked. The HJT acts like it is deleting that item. However, when I reboot, the windows installer starts again and when I re-run HJT, it is still there. I have tried to delete it twice. Here's the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:58:46 PM, on 12/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Lexmark 7300 Series\ezprint.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\lxcicoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.stopzilla.com/director/?type=register&source=nag&AID=10136&topic=4461
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcimon.exe] "C:\Program Files\Lexmark 7300 Series\lxcimon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7300 Series\ezprint.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [HP SchedIndexer] C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppschedindexer.exe
O4 - HKLM\..\Run: [HP AutoIndexer] C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppautoindexer.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP LaserJet Director.lnk = C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppdirector.exe
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - Unknown owner - C:\Program Files\Spyware Doctor\swdsvc.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 13819 bytes
 
Hi

We'll try removing it in safe mode next.

Reboot into safe mode.

Start hjt, do a system scan, check:
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')


Fix checked.

Delete C:\Program Files\Vongo folder if it exists.

Reboot back into normal mode and post a fresh hjt log.
 
Hi --

It didn't work. But I did notice the following: when I went in in safe mode, I have two choices -- the user I always use and "administrator." The computer was my father's and he created two users. Normally, when I log in, it shows his name and mine. But in safe mode it shows my name and "administrator." When I choose administrator, Vongo is on the desktop and in the add remove files. When I try to remove the files from add/remove, I get an error message saying the installer is not available. When I look for the HJT, I can't find it.

Here's the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:02:25 PM, on 12/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Lexmark 7300 Series\lxcimon.exe
C:\Program Files\Lexmark 7300 Series\ezprint.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppdirector.exe
C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\QUICKENW\QWDLLS.EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroDist.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dwwin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.stopzilla.com/director/?type=register&source=nag&AID=10136&topic=4461
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcimon.exe] "C:\Program Files\Lexmark 7300 Series\lxcimon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7300 Series\ezprint.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [HP SchedIndexer] C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppschedindexer.exe
O4 - HKLM\..\Run: [HP AutoIndexer] C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppautoindexer.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP LaserJet Director.lnk = C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppdirector.exe
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - Unknown owner - C:\Program Files\Spyware Doctor\swdsvc.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 14099 bytes
 
Hi

Delete c:\documents and settings\Default User\start menu\programs\startup\Vongo Tray.lnk file

Note: You might have to change "Default User" to whoever is the Default User.

Let me know if you could find and delete that file. Were you able to delete C:\Program Files\Vongo folder?
 
hi --

I didn't delete the vongo folder because I couldn't find one in program files (under either user).

You should know that when I go on as Administrator in safe mode, that the computer shuts itself off. It's almost as if it doesn't want me to be in there as the Administrator.

Also, I can't see "default user" in windows explorer. Under Documents and Settings I see Administrator, All Users, Rho, Wal, Wal.YOUR-0CD4F5844.

So, I right clicked on documents and settings, searched for Vongo, and deleted the files everytime the came up.

However, even that did not fix the problem. The installer still launches.
 
Please download the Registry Search tool by clicking on the
hard drive
icon halfway down this page:
http://www.billsway.com/vbspage/
Save it to the desktop and run it. If you get an alert from your antivirus about scripting, choose to allow the script to run. Search for Vongo and click OK. Post the logfile from the tool here for me.
 
Hi

Antivirus program shouldn't interfere with Registry Search scan so you may have it enabled :)
 
Thanks. I know I must seem really dim-witted, but I am not a techie. I figure better to be safe and ask a stupid question than to be sorry (after all, I've already brought havoc unto myself by downloading . . .).

Here's the log from the registry tool:

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "vongo" 12/12/2008 11:27:11 AM

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Vongo\\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\00408BC11A533A04996F4F4110676430]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\03706BE699FFAC54E8D7DDEF21B60CDE]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaPolMgr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\06974588BF55B71469B8A3AC82302BAB]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\ssleay32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\1339E3D20784EBD4A8C723673836AB5C]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\1D74CE3AEFF56AE4B8A3B7BB325A5400]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaDal.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\20ADCF8A960F7A048AE188EC7BDF775A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\260C711AAE9D6B649BC732CACE113B45]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\29CEA8A7F9927324B936C770A0FCCE88]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaUninstall.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\331752FA4CA84194BA9F88C11567EE78]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaWinSys.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\3653017FA5F4248408D76923E34F521A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaDnlMgr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\365E265429F7F7844B4598D174849C2B]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\Content\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\3AED3044E3C8E75419492A88AC51DE9A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaSoapV.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\4119CCBCE57E9CE4C9B82684FBCC68D7]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\VongoService.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\439C29A42453A6A4D9E1E2239078F909]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\54D4D48FE7FAD714DA6BB718451BD467]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\VongoPortable.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\5A255152CF25BC54F87E9434E67D1C65]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\5E6A695AB93D68843B3A7F07CFCF3F48]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaSysMgr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\637B701D8BF6BF747B4796A1B9A16AA5]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\Tray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\66D289AA5C497E543AF531C4E22A9F46]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaCmn.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\675B206F3A6A7154CA2F03B5495D5256]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\6B4687B1CA9D63545824D2C6FA41DDB6]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\VongoPlayer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\6EC22DB8FE83E384CB3665CBE395F934]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\785E9640D08874041A5002701193326A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\qt-mt335.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\829A20E0C9F0B6E419B00C3A8A62CEF8]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\msvcp71.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\883A7D602339AF34580C2CD8DAF6E4D5]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\libeay32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\99E170480F9DFCD48ABBCDD4786F875A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaLibMgr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\9E94FF97C40EA6442B25C229370C3CE2]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\A6FF334CE9AAD4C488376C20185A3212]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\Data\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\BC118EFC9D0317F46A48E94718844956]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\CC4D3433E02B28842B321F9AE2974A97]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\Vongo.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\CE668C03B927F614882A3D53126C5D09]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\D5A3BDC1FD25A9941B55C4ED6146D1D5]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\F1EF5086ACDC2B74AA041E1902611623]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\sqldrivers\\qsqlite.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\F68706DAED654BB4D86E03641CE4937B]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\msvcr71.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Components\FEDF2315F1DDF3D43BC58DCB2E8148FA]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

"VongoClient"="D3ixT'&[6?[V2UeMSGg91M'(haVTT@BBnt!=pC`-oGWA=W.XA?(juQ,0`8ObTHNo_ZweO=1lAN@WzTNH~S4c]}J^?A{Zk9e2gL*!t5RJx],&7?DF!=4xDIl[lXqLRfTg!AbG,%ApeT3^XG%V2B2r}@(O$~M6XeVhUFWB_k,Dk8FV6HkPuK3^*lRYK~`aL=g!_vzTR,KuGB+r9b4SD=z.fvSJN4]_F$d6^g[EB?900BLE0.gRW)gHOkFx?9U&SJ%xM_!TL3m@a%)PQ?sLV2,gDRcS%Qo5OY`*~9AT@}VNQW%3i}jnkH+?UAg2vPMAh%`HZD)w..]dL='P9^9,J,tCD-?+B]NGo@yQ&deWjuJaXA={?T7xv?D_r-4=AyPVD0P3l=8P.?(CVQ+07L.EM`g(xzpT5=S_8BEst8SHW2jE5@1)%=yYi^n=^L..YSsj[?$pf=)._C`)5u6CcTC?,=Xh`?ZyxMpsNlwEuscb38m]%9]AQA5wEgVV@cRP4_.vA?D7^]_Cf.+O'wNo+%qq8=0~=jJ1eeaJVPDmxky.'90qD]QG8w$Ng*XRj,cKCAPSP=?d}8EP-_w4%'!,q9jQhWUFD%~E`]hR'4IA5A$?P^]t6m9VtIOf`^i1D@i}UW=$7Ptc_HmLIfJf&?,Y?tVGyA44X}XK$E^&a8K5`@%8+dI^0aHnS2_t&9OOa~ilKB!eV-X7,46oj8m,Tg)=NP'$2q[quy2Ig(cA.0(K'p{sLJ(qcD!Rb8ay`$FWId-6=R~St`)Ng(jV.0(K'p{sGs}ilFf4g(Xy-0(K'p{spA-GLh'5g(Y}-0(K'p{sqA-GLh'5g(Y}-0(K'p{sPnt?)~rIg(eG.0(K'p{sts-nEC(rBAISqO!c'$DYG]&zc^f7g(['.0(K'p{s(R!HiU'Zl9xdeQ6Jot*n=[FmE=v`X@msw6g.5+T3cFr}+QG^K?([Cad[,nF)dz9*gom`NAQjBMjIVD$]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Products\9C00E7BDFED6A98418218D8F61414FA5\InstallProperties]
"InstallLocation"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Products\9C00E7BDFED6A98418218D8F61414FA5\InstallProperties]
"URLInfoAbout"="http://www.vongo.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Products\9C00E7BDFED6A98418218D8F61414FA5\InstallProperties]
"DisplayName"="Vongo"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-1006\Products\9C00E7BDFED6A98418218D8F61414FA5\Usage]
"VongoClient"=dword:39892014

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\00408BC11A533A04996F4F4110676430]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\03706BE699FFAC54E8D7DDEF21B60CDE]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaPolMgr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\06974588BF55B71469B8A3AC82302BAB]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\ssleay32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\1339E3D20784EBD4A8C723673836AB5C]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\1D74CE3AEFF56AE4B8A3B7BB325A5400]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaDal.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\20ADCF8A960F7A048AE188EC7BDF775A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\260C711AAE9D6B649BC732CACE113B45]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\29CEA8A7F9927324B936C770A0FCCE88]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaUninstall.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\331752FA4CA84194BA9F88C11567EE78]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaWinSys.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\3653017FA5F4248408D76923E34F521A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaDnlMgr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\365E265429F7F7844B4598D174849C2B]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\Content\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\3AED3044E3C8E75419492A88AC51DE9A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaSoapV.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\4119CCBCE57E9CE4C9B82684FBCC68D7]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\VongoService.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\439C29A42453A6A4D9E1E2239078F909]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\54D4D48FE7FAD714DA6BB718451BD467]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\VongoPortable.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\5A255152CF25BC54F87E9434E67D1C65]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\5E6A695AB93D68843B3A7F07CFCF3F48]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaSysMgr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\637B701D8BF6BF747B4796A1B9A16AA5]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\Tray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\66D289AA5C497E543AF531C4E22A9F46]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaCmn.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\675B206F3A6A7154CA2F03B5495D5256]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\6B4687B1CA9D63545824D2C6FA41DDB6]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\VongoPlayer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\6EC22DB8FE83E384CB3665CBE395F934]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\785E9640D08874041A5002701193326A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\qt-mt335.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\829A20E0C9F0B6E419B00C3A8A62CEF8]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\msvcp71.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\883A7D602339AF34580C2CD8DAF6E4D5]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\libeay32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\99E170480F9DFCD48ABBCDD4786F875A]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\CaLibMgr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\9E94FF97C40EA6442B25C229370C3CE2]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\A6FF334CE9AAD4C488376C20185A3212]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\Data\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\BC118EFC9D0317F46A48E94718844956]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\CC4D3433E02B28842B321F9AE2974A97]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\Vongo.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\CE668C03B927F614882A3D53126C5D09]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\D5A3BDC1FD25A9941B55C4ED6146D1D5]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\F1EF5086ACDC2B74AA041E1902611623]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\sqldrivers\\qsqlite.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\F68706DAED654BB4D86E03641CE4937B]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\msvcr71.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Components\FEDF2315F1DDF3D43BC58DCB2E8148FA]
"9C00E7BDFED6A98418218D8F61414FA5"="C:\\Program Files\\Vongo\\"

"VongoClient"="D3ixT'&[6?[V2UeMSGg91M'(haVTT@BBnt!=pC`-oGWA=W.XA?(juQ,0`8ObTHNo_ZweO=1lAN@WzTNH~S4c]}J^?A{Zk9e2gL*!t5RJx],&7?DF!=4xDIl[lXqLRfTg!AbG,%ApeT3^XG%V2B2r}@(O$~M6XeVhUFWB_k,Dk8FV6HkPuK3^*lRYK~`aL=g!_vzTR,KuGB+r9b4SD=z.fvSJN4]_F$d6^g[EB?900BLE0.gRW)gHOkFx?9U&SJ%xM_!TL3m@a%)PQ?sLV2,gDRcS%Qo5OY`*~9AT@}VNQW%3i}jnkH+?UAg2vPMAh%`HZD)w..]dL='P9^9,J,tCD-?+B]NGo@yQ&deWjuJaXA={?T7xv?D_r-4=AyPVD0P3l=8P.?(CVQ+07L.EM`g(xzpT5=S_8BEst8SHW2jE5@1)%=yYi^n=^L..YSsj[?$pf=)._C`)5u6CcTC?,=Xh`?ZyxMpsNlwEuscb38m]%9]AQA5wEgVV@cRP4_.vA?D7^]_Cf.+O'wNo+%qq8=0~=jJ1eeaJVPDmxky.'90qD]QG8w$Ng*XRj,cKCAPSP=?d}8EP-_w4%'!,q9jQhWUFD%~E`]hR'4IA5A$?P^]t6m9VtIOf`^i1D@i}UW=$7Ptc_HmLIfJf&?,Y?tVGyA44X}XK$E^&a8K5`@%8+dI^0aHnS2_t&9OOa~ilKB!eV-X7,46oj8m,Tg)=NP'$2q[quy2Ig(cA.0(K'p{sLJ(qcD!Rb8ay`$FWId-6=R~St`)Ng(jV.0(K'p{sGs}ilFf4g(Xy-0(K'p{spA-GLh'5g(Y}-0(K'p{sqA-GLh'5g(Y}-0(K'p{sPnt?)~rIg(eG.0(K'p{sts-nEC(rBAISqO!c'$DYG]&zc^f7g(['.0(K'p{s(R!HiU'Zl9xdeQ6Jot*n=[FmE=v`X@msw6g.5+T3cFr}+QG^K?([Cad[,nF)dz9*gom`NAQjBMjIVD$]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Products\9C00E7BDFED6A98418218D8F61414FA5\InstallProperties]
"InstallLocation"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Products\9C00E7BDFED6A98418218D8F61414FA5\InstallProperties]
"URLInfoAbout"="http://www.vongo.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Products\9C00E7BDFED6A98418218D8F61414FA5\InstallProperties]
"DisplayName"="Vongo"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2349546400-2988384400-1043169116-500\Products\9C00E7BDFED6A98418218D8F61414FA5\Usage]
"VongoClient"=dword:3550001a

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DB7E00C9-6DEF-489A-8112-D8F81614F45A}]
"InstallLocation"="C:\\Program Files\\Vongo\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DB7E00C9-6DEF-489A-8112-D8F81614F45A}]
"URLInfoAbout"="http://www.vongo.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DB7E00C9-6DEF-489A-8112-D8F81614F45A}]
"DisplayName"="Vongo"

[HKEY_LOCAL_MACHINE\SOFTWARE\Trolltech\Qt Plugins 3.3\C:\Program Files\Vongo]

[HKEY_LOCAL_MACHINE\SOFTWARE\Trolltech\Qt Plugins 3.3\C:\Program Files\Vongo\sqldrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VONGO_SERVICE]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VONGO_SERVICE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VONGO_SERVICE\0000]
"Service"="Vongo Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VONGO_SERVICE\0000]
"DeviceDesc"="Vongo Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Vongo Service]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Vongo Service]
"DisplayName"="Vongo Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Vongo Service]
"Description"="Vongo Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Vongo Service\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\\Program Files\\Vongo\\VongoService.exe"="C:\\Program Files\\Vongo\\VongoService.exe:*:enabled:VongoService"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\\Program Files\\Vongo\\VongoService.exe"="C:\\Program Files\\Vongo\\VongoService.exe:*:enabled:VongoService"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\\Program Files\\Vongo\\VongoService.exe"="C:\\Program Files\\Vongo\\VongoService.exe:*:enabled:VongoService"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Microsoft\Installer\Features\9C00E7BDFED6A98418218D8F61414FA5]
"VongoClient"=""

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Microsoft\Installer\Products\9C00E7BDFED6A98418218D8F61414FA5]
"ProductName"="Vongo"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Microsoft\Installer\Products\9C00E7BDFED6A98418218D8F61414FA5\SourceList]
"PackageName"="Vongo.msi"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Microsoft\Search Assistant\ACMru\5603]
"000"="vongo"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Vongo]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\AppID\{8721C831-834D-43fc-B26A-B8C469DD5A2A}]
@="Vongo Portable"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\Vongo.HWEventHandler]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\Vongo.HWEventHandler\CLSID]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\Vongo.HWEventHandler\CurVer]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\Vongo.HWEventHandler\CurVer]
@="Vongo.HWEventHandler.1"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}]
@="Vongo Portable"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\LocalServer32]
@="C:\\Program Files\\Vongo\\VongoPortable.exe"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\ProgID]
@="Vongo.HWEventHandler.1"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\VersionIndependentProgID]
@="Vongo.HWEventHandler"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\Vongo.HWEventHandler.1]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006\Software\Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\Vongo.HWEventHandler.1\CLSID]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\AppID\{8721C831-834D-43fc-B26A-B8C469DD5A2A}]
@="Vongo Portable"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\Vongo.HWEventHandler]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\Vongo.HWEventHandler\CLSID]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\Vongo.HWEventHandler\CurVer]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\Vongo.HWEventHandler\CurVer]
@="Vongo.HWEventHandler.1"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}]
@="Vongo Portable"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\LocalServer32]
@="C:\\Program Files\\Vongo\\VongoPortable.exe"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\ProgID]
@="Vongo.HWEventHandler.1"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\VersionIndependentProgID]
@="Vongo.HWEventHandler"

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\Vongo.HWEventHandler.1]

[HKEY_USERS\S-1-5-21-2349546400-2988384400-1043169116-1006_Classes\CLSID\{362296A1-BA71-4f15-BFC8-849426DF39E4}\Vongo.HWEventHandler.1\CLSID]
 
It's always better to ask first if something is unclear :)


We need to execute an OTMoveIt3 script
  1. Please download OTMoveIt3 by OldTimer and save it to your desktop.
  2. Double click theOTMoveIt3 icon on your desktop.
  3. Paste the following code under the Paste Fix Here area. Do not include the word
    Code
    .
    Code:
    :Files
    C:\Documents and Settings\Administrator\Start Menu\Programs\Vongo
    C:\Program Files\Vongo
  4. Push the large MoveIt button.
  5. OTMI3 may ask to reboot the machine. Please do so if asked.
  6. Copy/Paste the contents under the Results line here in your next reply.
  7. If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Then you have to download and run Windows Installer CleanUp Utility by following instructions given here to get rid of Vongo.
 
Now you tell me not to type "code." You have no idea how long I wrestled with whether I should type it the first time you had me put in a code. I was too ashamed to ask the question (I wasn't sure if you had a policy against helping the unreasonably stupid :sad:).

Here's what I got from move it:

FILES ==========
File/Folder C:\Documents and Settings\Administrator\Start Menu\Programs\Vongo not found.
File/Folder C:\Program Files\Vongo not found.

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12122008_123019
 
Ok. Looks like the folders no more exist. Please try Installer CleanUp Utility next :)
 
Hi

I gave you link to download and instructions on the last line of post #30 of this thread ;)
 
My bad. Totally missed it. You must think I'm smarter than I am because you didn't tell me exactly how to run the installer utility . . . maybe I screwed it up. This is what I did: I downloaded it to my desk top, double clicked it, accepted the license, and I don't remember what next. i just followed it through and it seemed to run. I rebooted and the windows installer still launched . . .

Here's a new hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:37:57 PM, on 12/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Lexmark 7300 Series\ezprint.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\lxcicoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.stopzilla.com/director/?type=register&source=nag&AID=10136&topic=4461
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcimon.exe] "C:\Program Files\Lexmark 7300 Series\lxcimon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7300 Series\ezprint.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [HP SchedIndexer] C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppschedindexer.exe
O4 - HKLM\..\Run: [HP AutoIndexer] C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppautoindexer.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP LaserJet Director.lnk = C:\Program Files\Hewlett-Packard\LaserJet All-in-one\hppdirector.exe
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - Unknown owner - C:\Program Files\Spyware Doctor\swdsvc.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 13680 bytes
 
Now there isn't anything Vongo related at least on the log. Could you post a screenshot of the installer window that you see when the system starts up?
 
Hi --

I have figured out how to save a screenshot, but I'm having trouble figuring out how to paste it into this post.

I have taken to screenshots: The first is the way the computer looks immediately as the installer begins, and the second is the point at which it says that it is "vongo" that is installing. I'm quite sure that I did not manage to paste the images. Could you please tell me how to do this?


Screenshot%20First.jpg



Screenshot%20Vongo.jpg
 
Hi

You're refering to pictures on your local hard drive while you should had used manage attachments -option which comes up when you click reply and scroll down a bit (Additional Options -section).

Anyway, I'd like to know if you ran Installer CleanUp Utility properly or if you just installed it and left Vongo removal undone.

1.Start CleanUp Utility (Click 'Start', click 'All Programs' (or 'Programs' on some operating systems), and then click the shortcut for the Windows Installer Clean Up Utility).
2. From installed products list select Vongo related items.
3. Click remove and then ok.
 
Hi -- yes, that was the problem, I installed the program, but I didn't run it. I thought clicking on the license and following the steps was somehow running it. In the past when I've been directed to download a program from another site, I haven't had to follow the instructions listed on that site. I missed where you said download AND follow the instructions from here.

I had figured out how to add an attachment, but my image was larger than the allowed size. Under manage attachments, I couldn't find additional options.

Anyway, at least now that annoying vongo launcher is gone. What should I do now?
 
What I mean is, am I cured?? Do I have to run anything or turn anything off/on (I remember something about tea timers, but I don't remember what those were).
 
Back
Top