dawndeimos Posted October 4, 2009 Report Share Posted October 4, 2009 Can anyone review my HijackThis log?Logfile of Trend Micro HijackThis v2.0.2Scan saved at 4:45:49 PM, on 4/10/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16791)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\COMODO\COMODO Internet Security\cmdagent.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Google\Update\GoogleUpdate.exeC:\WINDOWS\eHome\ehRecvr.exeC:\WINDOWS\eHome\ehSched.exeC:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exeC:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exeC:\WINDOWS\system32\dllhost.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\Explorer.EXEC:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exeC:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exeC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exeC:\Program Files\Toshiba\Tvs\TvsTray.exeC:\Program Files\Apoint2K\Apoint.exeC:\Program Files\TOSHIBA\TouchED\TouchED.ExeC:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exeC:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exeC:\Program Files\TOSHIBA\Touch and Launch\PadExe.exeC:\WINDOWS\AGRSMMSG.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor.exeC:\Program Files\COMODO\COMODO Internet Security\cfp.exeC:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\DAP\DAP.EXEC:\Program Files\Apoint2K\Apntex.exeC:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exeC:\Documents and Settings\All Users\Start Menu\Programs\Startup\00THotkey.exeC:\Program Files\Imation\ImationFlashDetect.exeC:\WINDOWS\system32\TPSBattM.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Windows Live\Contacts\wlcomm.exeC:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeO2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLLO4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exeO4 - HKLM\..\Run: [TOSHIBA Picture Enhancement Utility] C:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exeO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exeO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /trayO4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exeO4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exeO4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.ExeO4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exeO4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"O4 - HKLM\..\Run: [TPSMain] TPSMain.exeO4 - HKLM\..\Run: [TFncKy] TFncKy.exeO4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exeO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -hO4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exeO4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUPO4 - HKCU\..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exeO4 - HKUS\S-1-5-21-1057191722-3736638368-2841245127-1005\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe (User 'BK')O4 - HKUS\S-1-5-21-1057191722-3736638368-2841245127-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'BK')O4 - HKUS\S-1-5-21-1057191722-3736638368-2841245127-1005\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'BK')O4 - HKUS\S-1-5-21-1057191722-3736638368-2841245127-1005\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'BK')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O4 - S-1-5-21-1057191722-3736638368-2841245127-1005 Startup: ImationFlashDetect.lnk = C:\Program Files\Imation\ImationFlashDetect.exe (User 'BK')O4 - S-1-5-21-1057191722-3736638368-2841245127-1005 User Startup: ImationFlashDetect.lnk = C:\Program Files\Imation\ImationFlashDetect.exe (User 'BK')O4 - Startup: ImationFlashDetect.lnk = C:\Program Files\Imation\ImationFlashDetect.exeO4 - Global Startup: 00THotkey.exeO8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htmO8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htmO8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htmO10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dllO20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dllO23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exeO23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe--End of file - 5678 bytes Quote Link to post Share on other sites
TheTerrorist_75 Posted October 4, 2009 Report Share Posted October 4, 2009 We no longer use HJT to resolve malware issues. Please read these directions and post the required logs in the correct section of the forums.How To Post An Otl Log, Easy to Follow Guide Create a new thread and post the required logs in the following section of the forums.Malware RemovalPlease wait patiently for the experts to read your logs and guide you on removing your malware. Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.