Welcome, Guest. Please login or register.
May 17, 2008, 01:29:32 PM

Login with username, password and session length

155355 Posts
19200 Topics
47349 Members

Latest Member: billzster

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Anti-Viruspyware (CAVS)
| | |-+  Virus/Malware Removal Assistance
| | | |-+  hijackthis log
« previous next »
Pages: [1] Go Down Print
Author Topic: hijackthis log  (Read 277 times)
uhohkimee
Comodo Family Member
***
Offline Offline

Posts: 74


« on: May 12, 2008, 05:23:37 AM »

I never really used this program so I guess now is the time. This is my desktop and some people are using it and sometimes they are a bit stubborn when it comes to not going to some sites or downloading stuff. So I hope you guys could check out my log and see if theres some issues. Thanks!
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4673


Life may suck, but contemplate the alternative.


« Reply #1 on: May 12, 2008, 07:29:53 AM »

G'day,

The only entry that's out of the ordinary is

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

You can safely delete this entry using Hijack This.

Cheers,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #2 on: May 12, 2008, 07:34:26 AM »

Hi uhohkimee,

02 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
(Description: File is missing. Fix it.)

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
(Description: Nvidia system tray applet. Not necessary. Removing this entry will free up a small amount of system resources.)

O4 - HKLM\..\Run: [traySantaCruz] C:\WINDOWS\system32\tbctray.exe
(Description: Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel. Removing this entry will free up a small amount of system resources.)

04 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
(Description: ctfmon.exe is a process belonging to Microsoft Office Suite. If I could not see Antivir and Spyware Doctor in your log, I could say it may be infected by Cool Web Search.)

aXes
« Last Edit: May 12, 2008, 07:37:25 AM by aXes » Logged

Don't be afraid your life will end; be afraid that it will never begin!
Ragwing
Guardian of the Light Master of the Force Invincible Legend
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2211


The Computer Mage


« Reply #3 on: May 12, 2008, 09:01:07 AM »

Since cftmon.exe is located in \WINDOWS\system32\, there's nothing to worry about. Anyways, if you want to disable it, go to Control Panel -> Regional and Language Options -> Languages -> Details -> Advanced,
and check the box that says "Turn off advanced text services."


If you don't do this, and just remove the startup entry, it'll respawn.

Cheers,
Ragwing
Logged

The Wheel of Time turns, and Ages come and pass, leaving memories that become legend. Legend fades to myth, and even myth is long forgotten when the Age that gave it birth comes again.
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #4 on: May 12, 2008, 09:48:40 AM »

Since cftmon.exe is located in \WINDOWS\system32\, there's nothing to worry about. Anyways, if you want to disable it, go to Control Panel -> Regional and Language Options -> Languages -> Details -> Advanced,
and check the box that says "Turn off advanced text services."
If you don't do this, and just remove the startup entry, it'll respawn.

Useful info, thanks Ragwing.

aXes

« Last Edit: May 12, 2008, 09:52:05 AM by aXes » Logged

Don't be afraid your life will end; be afraid that it will never begin!
uhohkimee
Comodo Family Member
***
Offline Offline

Posts: 74


« Reply #5 on: May 13, 2008, 08:43:13 PM »

Hi uhohkimee,

02 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
(Description: File is missing. Fix it.)

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
(Description: Nvidia system tray applet. Not necessary. Removing this entry will free up a small amount of system resources.)

O4 - HKLM\..\Run: [traySantaCruz] C:\WINDOWS\system32\tbctray.exe
(Description: Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel. Removing this entry will free up a small amount of system resources.)

04 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
(Description: ctfmon.exe is a process belonging to Microsoft Office Suite. If I could not see Antivir and Spyware Doctor in your log, I could say it may be infected by Cool Web Search.)

aXes

Heres an update

I deleted the BHO and I'm just making sure is deleting the nvidia thing really safe? What do you mean that you could not see spyware doctor or antivir in my log? I checked the log and it's there.

Heres an update version of the log... Sorry for the late reply I've been busy with some stuff. Thanks for taking the time to check out my log  Clapping
Logged
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #6 on: May 14, 2008, 10:52:48 AM »

1st: I checked out new log. The only difference is BHO!

2nd: There is a misunderstanding. I can see Antivir and Spyware Doctor in your log. Otherwise, I can say that your ctfmon.exe might be a spyware variant. So, no need to worry.

3rd: If you have doubt about Nvidia entry, try to fix. You can backup later if you want.

aXes
Logged

Don't be afraid your life will end; be afraid that it will never begin!
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.127 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com