Registered Member Joined: Apr 14, 2004 Posts: 2

This has been occurring constantly for weeks.

We recommend you to use FREE DataSpy Network X Removal Tool for guaranteed threat removal. 2. Logfile of HijackThis v1.97.7 Scan saved at 6:26:12 PM, on 14/04/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\inetsrv\inetinfo.exe Any DataSpy Network X can be used for disruptive targets. If the description states that it is a piece of malware, you should immediately run an antivirus and antispyware program.

Logfile of HijackThis v1.99.1Scan saved at 19:26:13, on 12/05/2007Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\Program Files\Belkin\F5D7051\WLService.exeC:\WINDOWS\System32\CTsvcCDA.exeC:\Program Files\Belkin\F5D7051\WLanCfgG.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\Tablet.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\CTHELPER.EXEC:\Program Files\Creative\ShareDLL\CtNotify.exeC:\Program

If in doubt, don't do anything. IMM, Nov 6, 2003 #11 darkgodessuk Thread Starter Joined: Aug 14, 2003 Messages: 37 thought we had missed something will get dad to check this out tomorrow he got a disc This file has been identified as a program that is undesirable to have running on your computer.

Then it creates new startup key with name DataSpy Network X and value expup.exe and will then load on every boot up. when i start in safe mode it is ok.

