Thread: hijackthis help
View Single Post
Old 20-08-2004, 01:13 PM   #12 (permalink)
dpm
Member
 
Join Date: Aug 2003
Posts: 115
Thanks: 0
Thanked 0 Times in 0 Posts
In addition to the entries Apex has flagged up, it looks like you are infected with (at least) a couple of viruses.

You've got three run instances of 'svchosts.exe' (as opposed to svchost.exe, which is a legitimate Microsoft process). svchosts.exe is a trojan, and very bad news - your anti-virus should have picked up on it.

O4 - HKLM\..\RunServices: [Microsoft DirectX] PDSched.exe
(also three instances) is also a trojan/worm, and needs to be removed.

I don't recognize "O4 - HKLM\..\Run: [WindowsReg% update] wvmgtxagfum.exe" , but it looks very suspicious - The registry doesn't need updating every time windows starts, and the randomised file name is a hallmark of viruses.

If you aren't already running one, you need to run (and keep updated) a good antivirus as well as adaware and spybot. If you are running one then you should check that it has the latest updates.

If you don't have one then Avast antivirus and AVG antivirus are both good, free, antivirus tools.

when you've scanned for viruses and removed them, run hijack this again, and post your log
dpm is offline   Reply With Quote