Forum Home
Press F1
 
Thread ID: 68244 2006-04-22 07:32:00 Possible spyware??? The_End_Of_Reality (334) Press F1
Post ID Timestamp Content User
448467 2006-04-29 00:10:00 O4 - HKLM\ . . \Run: [NvCplDaemon] RUNDLL32 . EXE
C:\WINDOWS\System32\NvCpl . dll,NvStartup'

'O4 - HKLM\ . . \Run: [nwiz] nwiz . exe /install' this is part of the nVidia nview wizard, what is the install part mean?

Thats right they are part of Nvidia drivers, but dont need to run on startup .

I think one of these come back anyway . If u delete it .

Pass I dont know what the install bit means . Its just a command the drivers, put in startup, when u install the drivers .


I have DLed the update for

'O4 - HKLM\ . . \Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1 . 5 . 0_01\bin\jusched . exe'

Good!




'O4 - HKLM\ . . \Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic
Insight\SemanticInsight . exe' Google says this is spyware, so I will remove it

Good!




ok, I will remove 'O4 - HKCU\ . . \Run: [tbon] C:\Program Files\TBONBin\tbon . exe /r'

And good again!




She wants MSN to load with windows so, leave this?

'O4 - HKCU\ . . \Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr . Exe" /background'

Yup, u can leave that . Its just as easy putting it in the quicklaunch bar .




'O4 - Startup: MP3 Rocket (silent) . lnk = C:\Program Files\MP3
Rocket\MP3Rocket_on_startup . exe' and I will remove this .

Good again!

The ones you're removing, see if there are any entries in add/remove programs for them . Uninstall them as well .
Speedy Gonzales (78)
448468 2006-04-29 00:20:00 Ok, thanks, I will remove all except MSN...

Just need to go there and do this, or explain and get her to DL the update...

I have been into the add/remove and removed all the ones that looked suspect...
The_End_Of_Reality (334)
448469 2006-04-29 04:02:00 Hi The_End_Of_Reality

Just a final bit of fixing to do.

Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.

O4 - HKLM\..\Run: [Xujsm] C:\Program Files\Jefeb\Vbfrg.exe
O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\SemanticInsight\SemanticInsight.ex e


Open Windows Explorer and delete the following highlighted file/s
Also delete the following red folder/s

C:\Program Files\RXToolBar
C:\Program Files\Jefeb\Vbfrg.exe
Pancake (6359)
1 2 3