Thread: Svchost.exe?
View Single Post
Old 01-16-2008, 08:30 AM   #5 (permalink)
Osiris
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 25,891
Default Re: Svchost.exe?

I sure hate to be the bearer of bad news but SVCHOST.EXE is the problem. If it was all lowercase, then it wouldn't be, 99% of the time, but this computer is a mess so here I go
Uninstall Radar Sync Toolbar

Remove these entries manually or is safemode

D:\WINDOWS\SVCHOST.EXE

Remove these entries using hijackthis


Remove all of the O1 - Hosts: There are a lot so don't forget any

O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - D:\Program Files\iPacific Turbo Web Accelerator\PBHelper.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - D:\Program Files\iPacific Turbo Web Accelerator\components\NOWImaging.dll (file missing)

O3 - Toolbar: TelPacific Turbo Web Accelerator - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - D:\Program Files\iPacific Turbo Web Accelerator\Toolband.dll (file missing)

O3 - Toolbar: RadarSync - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - D:\Program Files\RadarSync\RSToolbar.dll

O4 - HKUS\S-1-5-18\..\Run: [Tok-Cirrhatus] "D:\WINDOWS\system32\config\systemprofile\Loca l Settings\Application Data\smss.exe" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [Tok-Cirrhatus] "D:\WINDOWS\system32\config\systemprofile\Loca l Settings\Application Data\smss.exe" (User 'Default user')

O4 - Startup: Microsoft Office.lnk = C:\WINDOWS\svchost.exe

O9 - Extra button: RadarSync Website - {29F02F90-D4AE-4c9a-82D2-D8DCDD507F33} - D:\Program Files\RadarSync\RadarSync Website.lnk

O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - D:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)

O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - D:\Documents and Settings\Tony\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)



If you havne't go thru my guide, please do so now and then post a new guide

Are you running a proxy? I see some unusual but safe entries in your LSP, if you are running one, why are you?
__________________

www.MasterB365.com
www.Tech-Dump.com


"On 10-3-08 Obama Supporters Vandalized-Tresspassed and STOLE My Palin-McCain Sign Violating My First Amendment Right To Free Speech. Do It Again And You Will Find Out What The 2nd Amendment Is All ABOUT!"
Osiris is online now   Reply With Quote