Welcome, Guest. Please login or register.
July 25, 2008, 07:40:50 PM

Login with username, password and session length

177085 Posts
20940 Topics
50767 Members

Latest Member: Jero

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Anti-Viruspyware (CAVS)
| | |-+  Virus/Malware Removal Assistance
| | | |-+  hijackthis log
« previous next »
Pages: [1] Go Down Print
Author Topic: hijackthis log  (Read 990 times)
uhohkimee
Comodo Family Member
***
Offline Offline

Posts: 85


« on: May 12, 2008, 05:23:37 AM »

I never really used this program so I guess now is the time. This is my desktop and some people are using it and sometimes they are a bit stubborn when it comes to not going to some sites or downloading stuff. So I hope you guys could check out my log and see if theres some issues. Thanks!
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5163


... and I say to myself, "What a wonderful world"


« Reply #1 on: May 12, 2008, 07:29:53 AM »

G'day,

The only entry that's out of the ordinary is

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

You can safely delete this entry using Hijack This.

Cheers,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #2 on: May 12, 2008, 07:34:26 AM »

Hi uhohkimee,

02 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
(Description: File is missing. Fix it.)

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
(Description: Nvidia system tray applet. Not necessary. Removing this entry will free up a small amount of system resources.)

O4 - HKLM\..\Run: [traySantaCruz] C:\WINDOWS\system32\tbctray.exe
(Description: Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel. Removing this entry will free up a small amount of system resources.)

04 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
(Description: ctfmon.exe is a process belonging to Microsoft Office Suite. If I could not see Antivir and Spyware Doctor in your log, I could say it may be infected by Cool Web Search.)

aXes
« Last Edit: May 12, 2008, 07:37:25 AM by aXes » Logged

Don't be afraid your life will end; be afraid that it will never begin!
Ragwing
Guardian of the Light Master of the Force Invincible Legend
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2794



« Reply #3 on: May 12, 2008, 09:01:07 AM »

Since cftmon.exe is located in \WINDOWS\system32\, there's nothing to worry about. Anyways, if you want to disable it, go to Control Panel -> Regional and Language Options -> Languages -> Details -> Advanced,
and check the box that says "Turn off advanced text services."


If you don't do this, and just remove the startup entry, it'll respawn.

Cheers,
Ragwing
Logged

"The closer you get to the light, the greater your shadow becomes"

XP SP3 2.1 GHz 768 MB RAM
5 services / 12 processes
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #4 on: May 12, 2008, 09:48:40 AM »

Since cftmon.exe is located in \WINDOWS\system32\, there's nothing to worry about. Anyways, if you want to disable it, go to Control Panel -> Regional and Language Options -> Languages -> Details -> Advanced,
and check the box that says "Turn off advanced text services."
If you don't do this, and just remove the startup entry, it'll respawn.

Useful info, thanks Ragwing.

aXes

« Last Edit: May 12, 2008, 09:52:05 AM by aXes » Logged

Don't be afraid your life will end; be afraid that it will never begin!
uhohkimee
Comodo Family Member
***
Offline Offline

Posts: 85


« Reply #5 on: May 13, 2008, 08:43:13 PM »

Hi uhohkimee,

02 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
(Description: File is missing. Fix it.)

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
(Description: Nvidia system tray applet. Not necessary. Removing this entry will free up a small amount of system resources.)

O4 - HKLM\..\Run: [traySantaCruz] C:\WINDOWS\system32\tbctray.exe
(Description: Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel. Removing this entry will free up a small amount of system resources.)

04 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
(Description: ctfmon.exe is a process belonging to Microsoft Office Suite. If I could not see Antivir and Spyware Doctor in your log, I could say it may be infected by Cool Web Search.)

aXes

Heres an update

I deleted the BHO and I'm just making sure is deleting the nvidia thing really safe? What do you mean that you could not see spyware doctor or antivir in my log? I checked the log and it's there.

Heres an update version of the log... Sorry for the late reply I've been busy with some stuff. Thanks for taking the time to check out my log  Clapping
Logged
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #6 on: May 14, 2008, 10:52:48 AM »

1st: I checked out new log. The only difference is BHO!

2nd: There is a misunderstanding. I can see Antivir and Spyware Doctor in your log. Otherwise, I can say that your ctfmon.exe might be a spyware variant. So, no need to worry.

3rd: If you have doubt about Nvidia entry, try to fix. You can backup later if you want.

aXes
Logged

Don't be afraid your life will end; be afraid that it will never begin!
3xist
Guest
« Reply #7 on: May 31, 2008, 11:50:44 PM »

Topic Locked.

Reason: Out-Dated post.

Josh
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in -0 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com