This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

svchost.exe in C:\WINDOWS

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

the window is a file folder full of other files including SpyBot, AdAware, M$ Antispyware Beta, and many more. A lot of the file folders were empty, left over from old downloads. I removed them. The program folder window that opens with the desktop extends from Local Disk (C:)\ NVidia\ I also get a notification saying Invalid BackLite Web 447682. The notification appears for 5-10 seconds but not on every boot.

the window is a file folder full of other files including SpyBot, AdAware, M$ Antispyware Beta, and many more. A lot of the file folders were empty, left over from old downloads. I removed them. The program folder window that opens with the desktop extends from Local Disk (C:)\ NVidia\

I also get a notification saying Invalid BackLite Web 447682. The notification appears for 5-10 seconds but not on every boot.

172137



NVidia is your Video Card, so that should be OK.

Invalid BackLite Web 447682 is from most likely F-Secure.
I am sure it is OK. The window never opened each time with desktop until I was deleting all the items you instructed. I must have done something to cause it but don't know how to change it back so I don't have to close it each time I boot.

The forum is here if you are interested in seeing an example of the way key words are automaticlly highlighted and advertisements attatched to them. 10-30 items will be listed for sale on ebay (that I know were not listed previosly) shortly after a key word is picked up from the text without searching for anything. The small popup advertisements that are listed as resources change according to words used in the text.

http://www.automotiveforums.com/t414847-damn_____intake.ht

I'm not sure about the BackWeb Lite. I think it may be connected to SpyBot or it could be F-Secure. SpyBot shows two BackWeb lite problems that can not be fixed.

Thank You, I know you are busy. The spyware is controlled. I'm sure I can email M$ to get rid of the file folder window.

I'm not sure about the BackWeb Lite. I think it may be connected to SpyBot or it could be F-Secure. SpyBot shows two BackWeb lite problems that can not be fixed

I think you can add those to the ignore list in SpyBot.

The link you post doesn't work.
Great job :thumbup:

You're more then welcome.
Glad we were able to help

Peace be with you :wavey:





If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.
Topic reopened at user's request.

I am JustSayGo
I spent many hours on my computer for more than two days after spyware
removal. I did not notice any flashing or noise from my monitor. My system
was quiet and stable. While working on a word doc. possibly when I keyed the
first uppercase "H", there was a loud crackling noise and my monitor nearly
went off. Since that time there have been periodic minor noises and flashes
like I used to have before following your instruction. Some how F-Secure
became unregistered and wouldn't update (same thing happened one time
earlier this week). I reinstalled F-Secure and scanned for viruses and
spyware using SpyBot, AdAware, M$, F-Secure, CWShredder, spyblaster, and
HouseCall. Their were virus and spyware. Everything showed clear and removed
The occasional flashes continued. I don't think they are caused by external
power supply surges. The flashes are not related to A/C starting or running.
I have 550w power supply.

This morning I ran HouseCall and it detected a Trojan Worm virus that
releases spyware. Repairs show complete and the flashes have continued.

M$ said that spyware probably caused the Program Files folder to become
attached to startup. The programs folder is currently removed using MSCONFIG
M$ hasn't told me how to fix it yet. The folder was not listed individually
in the registry where they told me to look. The contents of the programs
folder F-secure and PCHealth are at the location .

F-Secure is updated and working. I read a page that says spyware can hide with PCHealth. System
Restore is still disabled during all the scans

there was a loud crackling noise and my monitor nearly went off.


JustSayGo, I can't say I've ever heard of any virus doing that.

Have you heard back from M$ yet?

You can post a new HJT log.
M$ instructions are confusing me. If I unmark the program files entry under the startup tab in MSCONFG it switches to selective startup under the general tab. M$ says mark normal start up and unmark the program files and everthing is done. What I am understanding them to say is that both can be done. They should answer again in a few hours. M$ has had nothing more to add as far as spyware. HouseCall identified four info miner cookies yesterday and two today. The noise continues but seems like less noise and lighter flashes.

Logfile of HijackThis v1.99.1
Scan saved at 2:20:24 PM, on 6/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Creative\ShareDLL\MediaDet.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSMB32.EXE
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\fspex.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\F-Secure Anti-Virus\Common\FCH32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\F-Secure Anti-Virus\Common\FAMEH32.EXE
C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsav32.exe
C:\Program Files\F-Secure Anti-Virus\FSGUI\fsguiexe.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Extensis\Portfolio 7\Portfolio Express.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.cox.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cox.net/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Anti-Virus\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Anti-Virus\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\SBLive\RemoteCenter\Rc\Rcman.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Portfolio Express.lnk = C:\Program Files\Extensis\Portfolio 7\Portfolio Express.exe
O4 - Global Startup: SATARaid.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: F-Secure Anti-Virus 2005 (BackWeb Plug-in - 4476822) - Unknown owner - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

M$ instructions are confusing me. If I unmark the program files entry under the startup tab in MSCONFG it switches to selective startup under the general tab. M$ says mark normal start up and unmark the program files and everthing is done

. What programs are they telling you to uncheck?



Lets look at what's in the startup.

click Start> Run> type in Msconfig tap enter key.
look in the Startup. List everything there and point out which ones have a check next to it.
They are telling me to un check an entry that says program files. When program files folder is unchecked, the program files folder does not open with the desk top when I restart. That is what I want but how can Program files folder be removed from the start up list, so that I can use normal startup? Is there any way to transfer a printscreen copy of MSCONFIG to this post.

Is there any way to transfer a printscreen copy of MSCONFIG to this post.

Not that I know of.

That is what I want but how can Program files folder be removed from the start up list

After you uncheck it, you'll be using Selective startup.
When you see the box popup that tells you that, just put a Check in the Box to not show that when you startup. That's how I run mine.
Ok I did that. I didn't know we just use selective startup after this. :unsure: :ph34r: any Ideas on the cookies returning. Are they generated every time i go to a website that is accociated with the cookie miner? Now that I have several antispyware tools what sould I do? You Said run SpyBot and AdAware once each week. Are the low risk cookies a problem? Why does HCall pick them out and remove them if they come back? Is there any reason for me to be concerned about anything else. Any idea on the screen flashes?
The best tool for scanning the system for malware is mwavscan.
It won't fix anything (unless you buy it) but it will give us a report.
If you want, run it. It will take awhile to run.


Click here http://www.mwti.net/download/tools/mwav.exe to download mwavscan.
Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane.
Highlight it, CTRL C and paste it in your next reply.
It's going to take a while to scan and if you get a pop-up to buy the program, just X it out.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI