Home   News  Product reviews  Website reviews  Forums   Competitions  Subscribe 

Security >> HijackThis logs help and analysis

 |  Print Thread
grahammelon
regular


Reg'd: Mon
Posts: 658
Loc: Not sure
TBUNIN ( my PC oven) not hot cross sort.
      Wed Mar 26 2008 11:10 AM

The two entries I think are the problem are the GLF2F and TBunin onspeed. After several hundred attempts to delete these entries, even from the registry, something keeps putting them back. This is not life threatening just a pain as it is slowing the startup time.
Any advice at your leisure would be much appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:32, on 26/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Stickies\stickies.exe
C:\WINDOWS\SYSTEM32\spider.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\RunOnce: [GLF2F.tmp] cmd /c "rmdir /s /q "C:\Program Files\GLF2F.tmp""
O4 - HKLM\..\RunOnce: [onspeed_toolbar] C:\DOCUME~1\teded2\LOCALS~1\Temp\TBUNIN~1.EXE -df "C:\PROGRA~1\ONSPEE~1\"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Stickies.lnk = C:\Program Files\Stickies\stickies.exe
O4 - Startup: Secunia PSI (RC1).lnk = C:\Program Files\Secunia\PSI (RC1)\psi.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsu...b?1197365085951
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BEC99AB2-DE63-4AAD-B0D9-AFA542CC1F34}: NameServer = 80.58.61.250 80.58.61.254
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 5422 bytes

--------------------
XP Home,comodo.AVG. S&D,,Mozilla,
Spywareblaster, Ccleaner and much2much time

I wish I had a mind to make up

Post Extras Print Post   Remind Me!     Notify Moderator
Rate this thread

Jump to


Entire topic
Subject Posted by Posted on
* TBUNIN ( my PC oven) not hot cross sort. grahammelon Wed Mar 26 2008 11:10 AM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Wed Mar 26 2008 01:40 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Wed Mar 26 2008 09:31 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Thu Mar 27 2008 09:51 AM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Thu Mar 27 2008 02:29 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Thu Mar 27 2008 04:34 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Thu Mar 27 2008 04:53 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Thu Mar 27 2008 06:00 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Thu Mar 27 2008 09:39 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Thu Mar 27 2008 10:15 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Fri Mar 28 2008 08:21 AM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Fri Mar 28 2008 01:41 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Fri Mar 28 2008 02:35 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Fri Mar 28 2008 09:37 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Sat Mar 29 2008 12:21 AM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Sat Mar 29 2008 04:00 AM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Sat Mar 29 2008 10:51 AM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. grahammelon   Sat Mar 29 2008 01:41 PM
. * * Re: TBUNIN ( my PC oven) not hot cross sort. Joe_LondonModerator   Sat Mar 29 2008 02:37 PM

Extra information
0 registered and 13 anonymous users are browsing this forum.

Moderator:  putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate 


Print Thread
Forum Permissions
      You cannot start new topics
      You cannot reply to topics
      HTML is disabled
      Mark-up is enabled

Rating:
Thread views: 0

Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved