This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Can anyone help me have a look at my HijackThis Logfile?

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having unusual laggings when running some games or programs lately, which it should not be happening, I suspected there is a spyware exist, could you kindly pls help me look on this? thx!



Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 3:27:48 PM, on 10/5/2009

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal


Running processes:

C:\\Windows\\system32\\taskeng.exe

C:\\Windows\\system32\\Dwm.exe

C:\\Windows\\Explorer.EXE

C:\\Windows\\RtHDVCpl.exe

C:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDSLoader.exe

C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe

C:\\Windows\\System32\\rundll32.exe

C:\\Windows\\System32\\nvraidservice.exe

C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe

C:\\Windows\\System32\\mobsync.exe

C:\\Windows\\system32\\wbem\\unsecapp.exe

C:\\Program Files\\Internet Explorer\\ieuser.exe

C:\\Program Files\\Internet Explorer\\iexplore.exe

C:\\Program Files\\Google\\Google Toolbar\\GoogleToolbarUser.exe

C:\\Windows\\system32\\Taskmgr.exe

C:\\Program Files\\Internet Explorer\\iexplore.exe

C:\\Windows\\system32\\SearchFilterHost.exe

C:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe


R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…ire_m1641 />
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896 />
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL =
http://en.us.acer.yahoo.com />
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 />
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896 />
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACAW&a…ire_m1641 />
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant =

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch =

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\\Program Files\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelper.dll

O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\\PROGRA~1\\mcafee\\msk\\mskapbho.dll

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\\PROGRA~1\\mcafee\\VIRUSS~1\\scriptsn.dll

O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\ActiveToolBand.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\\Program Files\\Google\\Google Toolbar\\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\\Program Files\\Google\\GoogleToolbarNotifier\\5.1.1309.3572\\swg.dll

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\\PROGRA~1\\mcafee\\SITEAD~1\\mcieplg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\\Program Files\\Google\\Google Toolbar\\Component\\fastsearch_A8904FB862BD9564.dll

O2 - BHO: Go!Zilla IE Helper - {E1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\\Program Files\\GoZilla\\GozCatch.dll

O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDStoolbar.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\\PROGRA~1\\mcafee\\SITEAD~1\\mcieplg.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\\Program Files\\Google\\Google Toolbar\\GoogleToolbar.dll

O4 - HKLM\\..\\Run: [Windows Defender] %ProgramFiles%\\Windows Defender\\MSASCui.exe -hide

O4 - HKLM\\..\\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\\..\\Run: [eDataSecurity Loader] C:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDSloader.exe

O4 - HKLM\\..\\Run: [LanguageShortcut] \”C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\”

O4 - HKLM\\..\\Run: [mcagent_exe] \”C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe\” /runkey

O4 - HKLM\\..\\Run: [NvCplDaemon] RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup

O4 - HKLM\\..\\Run: [NvMediaCenter] RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\\..\\Run: [NVRaidService] C:\\Windows\\system32\\nvraidservice.exe

O4 - HKCU\\..\\Run: [swg] C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe

O4 - HKUS\\S-1-5-19\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /detectMem (User \’LOCAL SERVICE\’)

O4 - HKUS\\S-1-5-19\\..\\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User \’LOCAL SERVICE\’)

O4 - HKUS\\S-1-5-20\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /detectMem (User \’NETWORK SERVICE\’)

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~2\\Office12\\ONBttnIE.dll

O9 - Extra \’Tools\’ menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~2\\Office12\\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~1\\MICROS~2\\Office12\\REFIEBAR.DLL

O13 - Gopher Prefix:

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\\PROGRA~1\\mcafee\\SITEAD~1\\mcieplg.dll

O18 - Filter: x-sdch - (no CLSID) - (no file)

O20 - AppInit_DLLs: C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL

O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\\Acer\\Empowering Technology\\ePerformance\\MemCheck.exe

O23 - Service: eDataSecurity Service - Egis Incorporated - C:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDSService.exe

O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\\Acer\\Empowering Technology\\eRecovery\\eRecoveryService.exe

O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\\Acer\\Empowering Technology\\eSettings\\Service\\capuserv.exe

O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\\Program Files\\Common Files\\LightScribe\\LSSrvc.exe

O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\\Program Files\\McAfee\\SiteAdvisor\\McSACore.exe

O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\\PROGRA~1\\McAfee\\MSC\\mcmscsvc.exe

O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\\PROGRA~1\\COMMON~1\\mcafee\\mna\\mcnasvc.exe

O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\\PROGRA~1\\McAfee\\VIRUSS~1\\mcods.exe

O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\\PROGRA~1\\COMMON~1\\mcafee\\mcproxy\\mcproxy.exe

O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\\PROGRA~1\\McAfee\\VIRUSS~1\\mcshield.exe

O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\\PROGRA~1\\McAfee\\VIRUSS~1\\mcsysmon.exe

O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\\Program Files\\McAfee\\MPF\\MPFSrv.exe

O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\\Program Files\\McAfee\\MSK\\MskSrver.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\\Windows\\system32\\nvvsvc.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\\Program Files\\CyberLink\\Shared Files\\RichVideo.exe


–

End of file - 7616 bytes

Hi AlbertLoo,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI