My desktop is changed into a message "Warning: Spyware", and I can't fix it. Below you find my Hijackthis logfile. Can someone tell me what I should do?
Thanks
Logfile of HijackThis v1.99.1
Scan saved at 15:56:40, on 26/03/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijack this\HijackThis.exe
C:\WINDOWS\notepad.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PSDrvCheck] "c:\program files\liquid.silver\program\PSDrvCheck.exe" -CheckReg
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Echo Fire Server] "C:\Program Files\Synthetic Aperture\Echo Fire\Support\Echo Fire Server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Kdu] C:\WINDOWS\Upt.exe
O4 - HKLM\..\Run: [Spr] C:\WINDOWS\System32\Spa.exe
O4 - HKLM\..\Run: [Aqp] C:\WINDOWS\Auj.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\System32\Services\{52DEABA4-071D-4AF9-A6C5-8FA9AA24FBB8}\SVCHOST.EXE
O4 - HKLM\..\Run: [Jla] C:\WINDOWS\System32\Cjv.exe
O4 - HKLM\..\Run: [Abe] C:\WINDOWS\System32\Cvq.exe
O4 - HKLM\..\Run: [Hqq] C:\WINDOWS\System32\Jgm.exe
O4 - HKLM\..\Run: [Jek] C:\WINDOWS\Gcg.exe
O4 - HKLM\..\Run: [Tlm] C:\WINDOWS\System32\Gnr.exe
O4 - HKLM\..\Run: [Mav] C:\WINDOWS\Kth.exe
O4 - HKLM\..\Run: [Qoa] C:\WINDOWS\System32\Uld.exe
O4 - HKLM\..\Run: [Ois] C:\WINDOWS\Gng.exe
O4 - HKLM\..\Run: [Fcj] C:\WINDOWS\System32\Nee.exe
O4 - HKLM\..\Run: [Grg] C:\WINDOWS\Afg.exe
O4 - HKLM\..\Run: [Kmd] C:\WINDOWS\Vcr.exe
O4 - HKLM\..\Run: [Csn] C:\WINDOWS\System32\Nvf.exe
O4 - HKLM\..\Run: [Tem] C:\WINDOWS\Ken.exe
O4 - HKLM\..\Run: [Feq] C:\WINDOWS\System32\Amg.exe
O4 - HKLM\..\Run: [Ncf] C:\WINDOWS\Vlf.exe
O4 - HKLM\..\Run: [Rmp] C:\WINDOWS\Psq.exe
O4 - HKLM\..\Run: [Lce] C:\WINDOWS\Lno.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O9 - Extra button: IBM Internet Explorer Helper console - {6B07CF02-CF48-438E-BA4C-9F657A85B58B} - C:\WINDOWS\System32\iegfxfrw.dll
O9 - Extra 'Tools' menuitem: IBM Internet Explorer Helper console - {6B07CF02-CF48-438E-BA4C-9F657A85B58B} - C:\WINDOWS\System32\iegfxfrw.dll
O20 - Winlogon Notify: drct16 - C:\WINDOWS\SYSTEM32\drct16.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Thanks
Logfile of HijackThis v1.99.1
Scan saved at 15:56:40, on 26/03/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijack this\HijackThis.exe
C:\WINDOWS\notepad.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PSDrvCheck] "c:\program files\liquid.silver\program\PSDrvCheck.exe" -CheckReg
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Echo Fire Server] "C:\Program Files\Synthetic Aperture\Echo Fire\Support\Echo Fire Server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Kdu] C:\WINDOWS\Upt.exe
O4 - HKLM\..\Run: [Spr] C:\WINDOWS\System32\Spa.exe
O4 - HKLM\..\Run: [Aqp] C:\WINDOWS\Auj.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\System32\Services\{52DEABA4-071D-4AF9-A6C5-8FA9AA24FBB8}\SVCHOST.EXE
O4 - HKLM\..\Run: [Jla] C:\WINDOWS\System32\Cjv.exe
O4 - HKLM\..\Run: [Abe] C:\WINDOWS\System32\Cvq.exe
O4 - HKLM\..\Run: [Hqq] C:\WINDOWS\System32\Jgm.exe
O4 - HKLM\..\Run: [Jek] C:\WINDOWS\Gcg.exe
O4 - HKLM\..\Run: [Tlm] C:\WINDOWS\System32\Gnr.exe
O4 - HKLM\..\Run: [Mav] C:\WINDOWS\Kth.exe
O4 - HKLM\..\Run: [Qoa] C:\WINDOWS\System32\Uld.exe
O4 - HKLM\..\Run: [Ois] C:\WINDOWS\Gng.exe
O4 - HKLM\..\Run: [Fcj] C:\WINDOWS\System32\Nee.exe
O4 - HKLM\..\Run: [Grg] C:\WINDOWS\Afg.exe
O4 - HKLM\..\Run: [Kmd] C:\WINDOWS\Vcr.exe
O4 - HKLM\..\Run: [Csn] C:\WINDOWS\System32\Nvf.exe
O4 - HKLM\..\Run: [Tem] C:\WINDOWS\Ken.exe
O4 - HKLM\..\Run: [Feq] C:\WINDOWS\System32\Amg.exe
O4 - HKLM\..\Run: [Ncf] C:\WINDOWS\Vlf.exe
O4 - HKLM\..\Run: [Rmp] C:\WINDOWS\Psq.exe
O4 - HKLM\..\Run: [Lce] C:\WINDOWS\Lno.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O9 - Extra button: IBM Internet Explorer Helper console - {6B07CF02-CF48-438E-BA4C-9F657A85B58B} - C:\WINDOWS\System32\iegfxfrw.dll
O9 - Extra 'Tools' menuitem: IBM Internet Explorer Helper console - {6B07CF02-CF48-438E-BA4C-9F657A85B58B} - C:\WINDOWS\System32\iegfxfrw.dll
O20 - Winlogon Notify: drct16 - C:\WINDOWS\SYSTEM32\drct16.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe