Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

please watch my hijack log

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

please watch my hijack log

Unread postby rupelke » August 21st, 2009, 8:03 am

can someone look if there are any unwanted programs.
I have sometimes a BSOD.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:03:04, on 21/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\RALINK\Common\RalinkRegistryWriter.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Avant Browser\avant.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O1 - Hosts: dl22l32.rapidshare.com
O1 - Hosts: dl22cg.rapidshare.com
O1 - Hosts: dl22cg2.rapidshare.com
O1 - Hosts: dl22tl.rapidshare.com
O1 - Hosts: dl22tl2.rapidshare.com
O1 - Hosts: dl23l32.rapidshare.com
O1 - Hosts: dl23cg.rapidshare.com
O1 - Hosts: dl23cg2.rapidshare.com
O1 - Hosts: dl23tl.rapidshare.com
O1 - Hosts: dl23tl2.rapidshare.com
O1 - Hosts: dl24l32.rapidshare.com
O1 - Hosts: dl24cg.rapidshare.com
O1 - Hosts: dl24cg2.rapidshare.com
O1 - Hosts: dl24tl.rapidshare.com
O1 - Hosts: dl24tl2.rapidshare.com
O1 - Hosts: dl30l32.rapidshare.com
O1 - Hosts: dl30cg.rapidshare.com
O1 - Hosts: dl30cg2.rapidshare.com
O1 - Hosts: dl30tl.rapidshare.com
O1 - Hosts: dl30tl2.rapidshare.com
O1 - Hosts: dl31l32.rapidshare.com
O1 - Hosts: dl31cg.rapidshare.com
O1 - Hosts: dl31cg2.rapidshare.com
O1 - Hosts: dl31tl.rapidshare.com
O1 - Hosts: dl31tl2.rapidshare.com
O1 - Hosts: dl32l32.rapidshare.com
O1 - Hosts: dl32cg.rapidshare.com
O1 - Hosts: dl32cg2.rapidshare.com
O1 - Hosts: dl32tl.rapidshare.com
O1 - Hosts: dl32tl2.rapidshare.com
O1 - Hosts: dl33l32.rapidshare.com
O1 - Hosts: dl33cg.rapidshare.com
O1 - Hosts: dl33cg2.rapidshare.com
O1 - Hosts: dl33tl.rapidshare.com
O1 - Hosts: dl33tl2.rapidshare.com
O1 - Hosts: dl34l32.rapidshare.com
O1 - Hosts: dl34cg.rapidshare.com
O1 - Hosts: dl34cg2.rapidshare.com
O1 - Hosts: dl34tl.rapidshare.com
O1 - Hosts: dl34tl2.rapidshare.com
O1 - Hosts: dl40l32.rapidshare.com
O1 - Hosts: dl40cg.rapidshare.com
O1 - Hosts: dl40cg2.rapidshare.com
O1 - Hosts: dl40tl.rapidshare.com
O1 - Hosts: dl40tl2.rapidshare.com
O1 - Hosts: dl41l32.rapidshare.com
O1 - Hosts: dl41cg.rapidshare.com
O1 - Hosts: dl41cg2.rapidshare.com
O1 - Hosts: dl41tl.rapidshare.com
O1 - Hosts: dl41tl2.rapidshare.com
O1 - Hosts: dl42l32.rapidshare.com
O1 - Hosts: dl42cg.rapidshare.com
O1 - Hosts: dl42cg2.rapidshare.com
O1 - Hosts: dl42tl.rapidshare.com
O1 - Hosts: dl42tl2.rapidshare.com
O1 - Hosts: dl43l32.rapidshare.com
O1 - Hosts: dl43cg.rapidshare.com
O1 - Hosts: dl43cg2.rapidshare.com
O1 - Hosts: dl43tl.rapidshare.com
O1 - Hosts: dl43tl2.rapidshare.com
O1 - Hosts: dl44l32.rapidshare.com
O1 - Hosts: dl44cg.rapidshare.com
O1 - Hosts: dl44cg2.rapidshare.com
O1 - Hosts: dl44tl.rapidshare.com
O1 - Hosts: dl44tl2.rapidshare.com
O1 - Hosts: dl50l32.rapidshare.com
O1 - Hosts: dl50cg.rapidshare.com
O1 - Hosts: dl50cg2.rapidshare.com
O1 - Hosts: dl50tl.rapidshare.com
O1 - Hosts: dl50tl2.rapidshare.com
O1 - Hosts: dl51l32.rapidshare.com
O1 - Hosts: dl51cg.rapidshare.com
O1 - Hosts: dl51cg2.rapidshare.com
O1 - Hosts: dl51tl.rapidshare.com
O1 - Hosts: dl51tl2.rapidshare.com
O1 - Hosts: dl52l32.rapidshare.com
O1 - Hosts: dl52cg.rapidshare.com
O1 - Hosts: dl52cg2.rapidshare.com
O1 - Hosts: dl52tl.rapidshare.com
O1 - Hosts: dl52tl2.rapidshare.com
O1 - Hosts: dl53l32.rapidshare.com
O1 - Hosts: dl53cg.rapidshare.com
O1 - Hosts: dl53cg2.rapidshare.com
O1 - Hosts: dl53tl.rapidshare.com
O1 - Hosts: dl53tl2.rapidshare.com
O1 - Hosts: dl54l32.rapidshare.com
O1 - Hosts: dl54cg.rapidshare.com
O1 - Hosts: dl54cg2.rapidshare.com
O1 - Hosts: dl54tl.rapidshare.com
O1 - Hosts: dl54tl2.rapidshare.com
O1 - Hosts: dl60l32.rapidshare.com
O1 - Hosts: dl60cg.rapidshare.com
O1 - Hosts: dl60cg2.rapidshare.com
O1 - Hosts: dl60tl.rapidshare.com
O1 - Hosts: dl60tl2.rapidshare.com
O1 - Hosts: dl61l32.rapidshare.com
O1 - Hosts: dl61cg.rapidshare.com
O1 - Hosts: dl61cg2.rapidshare.com
O1 - Hosts: dl61tl.rapidshare.com
O1 - Hosts: dl61tl2.rapidshare.com
O1 - Hosts: dl62l32.rapidshare.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-606747145-842925246-839522115-1004\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/sr ... ab_srl.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.4.8.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Futuremark SystemInfo) - http://www.yougamers.com/systeminfo/FMSI.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files\RALINK\Common\RalinkRegistryWriter.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

End of file - 12627 bytes
Active Member
Posts: 1
Joined: August 21st, 2009, 7:49 am
Register to Remove

Re: please watch my hijack log

Unread postby MWR 3 day Mod » August 25th, 2009, 2:44 am


We are sorry to see your topic is over three days old and no one has yet been able to respond and offer help.

If you still require assistance, please post a link to your topic in our Waiting for help with malware removal? forum, and our staff will make an effort to assist you as promptly as possible. Only post a LINK to this topic, DO NOT post your DDS log!

Please do not reply to this topic.

If you haven't posted within two days in the "Waiting for help with malware removal?" forum, we will assume you have been able to get assistance in other ways and this topic will be closed.
MWR 3 day Mod
MRU Undergrad
MRU Undergrad
Posts: 2534
Joined: April 4th, 2008, 8:40 am

Re: please watch my hijack log

Unread postby Shaba » August 28th, 2009, 2:03 am

Due to lack of response this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
Admin/Teacher Emeritus
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

  • Similar Topics
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!

Who is online

Users browsing this forum: No registered users and 72 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware