spyware help

Hello, I'm sorry to bother everyone again, but i was helping my friend clean up his horribly diseased computer and I was hoping some actual masters. here is the HijackThis log.

Logfile of HijackThis v1.98.2
Scan saved at 4:52:05 PM, on 11/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Explorer\Adr.EXE
C:\WINDOWS\srvany.exe
C:\WINDOWS\s4.exe
C:\WINDOWS\system32\r_server.exe
c:\Windows\system32\Dap\mssvchost.exe
c:\Windows\system32\Dap\smss.exe
c:\Windows\system32\Dap\mssvchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\Windows\system32\Dap\WindowsUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\scvhosting.exe
C:\WINDOWS\System32\386.exe
C:\WINDOWS\System32\svhosint32.exe
C:\WINDOWS\System32\spoolsvc.exe
C:\WINDOWS\System32\mstestbot.exe
C:\WINDOWS\System32\msupdatemon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\regintmon.exe
C:\WINDOWS\System32\wmmon32.exe
C:\WINDOWS\System32\systemscan.exe
C:\DOCUME~1\ADMINI~1.AND\LOCALS~1\Temp\16.tmp.exe
C:\WINDOWS\System32\sysentry32.exe
C:\WINDOWS\System32\ilka32.exe
C:\WINDOWS\System32\wincore332.exe
C:\WINDOWS\System32\ntfs16.exe
C:\WINDOWS\System32\dllmngr32.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\windows\temp\ogsFpvi6.exe
C:\windows\temp\AyzUChC.exe
C:\WINDOWS\System32\webprinter.exe
C:\WINDOWS\PASSCFG16.EXE
C:\WINDOWS\System32\winfs16.exe
C:\WINDOWS\private.exe
C:\WINDOWS\System32\mswin32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\winupdate.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\YjpWR9u0.exe
C:\WINDOWS\System32\Ohdc4.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator.ANDY\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myub.buffalo.edu/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator.ANDY\Local Settings\Temp\thSwrUMa.dll
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Configuration Loader] sysinfo.exe
O4 - HKLM\..\Run: [Registry Integrity Checker] regintmon.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\otvnoc.exe
O4 - HKLM\..\Run: [WSSAConfiguration] wmmon32.exe
O4 - HKLM\..\Run: [Automated Registry Backup] systemscan.exe
O4 - HKLM\..\Run: [AD6D69B7] C:\WINDOWS\System32\dztfmkktaxhns.exe
O4 - HKLM\..\Run: [[Ephemeral 2.5] by TreeHugger, ] C:\DOCUME~1\ADMINI~1.AND\LOCALS~1\Temp\16.tmp.exe
O4 - HKLM\..\Run: [System Uptime Server] sysentry32.exe
O4 - HKLM\..\Run: [ilka32] ilka32.exe
O4 - HKLM\..\Run: [Win32 USB2 Driver] winupdate.exe
O4 - HKLM\..\Run: [wincx] wincore332.exe
O4 - HKLM\..\Run: [starter] scvhosting.exe
O4 - HKLM\..\Run: [NTFS16] ntfs16.exe
O4 - HKLM\..\Run: [Win32 USB2.0 Driver] 386.exe
O4 - HKLM\..\Run: [Win32 Usb Driver] svhosint32.exe
O4 - HKLM\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\Run: [DLL Manager] dllmngr32.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [ogsFpvi6] C:\windows\temp\ogsFpvi6.exe
O4 - HKLM\..\Run: [AyzUChC] C:\windows\temp\AyzUChC.exe
O4 - HKLM\..\Run: [5YJYRED5JG7WSP] C:\WINDOWS\System32\Oval73H.exe
O4 - HKLM\..\Run: [Printer Monitor] C:\WINDOWS\System32\webprinter.exe
O4 - HKLM\..\Run: [Windows System Configuration] C:\WINDOWS\PASSCFG16.EXE
O4 - HKLM\..\Run: [Windows DLL Loader] C:\WINDOWS\PASSCFG16.EXE
O4 - HKLM\..\Run: [Win FS] winfs16.exe
O4 - HKLM\..\Run: [Windows SP2 Update Manager] mstestbot.exe
O4 - HKLM\..\Run: [MS Update Monitor] msupdatemon.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\private.exe
O4 - HKLM\..\Run: [Microsoft Update Service] mswin32.exe
O4 - HKLM\..\Run: [WindowsUpdatev4] C:\WINDOWS\system32\explorer.exe
O4 - HKLM\..\RunServices: [Registry Integrity Checker] regintmon.exe
O4 - HKLM\..\RunServices: [WSSAConfiguration] wmmon32.exe
O4 - HKLM\..\RunServices: [Automated Registry Backup] systemscan.exe
O4 - HKLM\..\RunServices: [5FFCD567] C:\WINDOWS\System32\dztfmkktaxhns.exe
O4 - HKLM\..\RunServices: [System Uptime Server] sysentry32.exe
O4 - HKLM\..\RunServices: [ilka32] ilka32.exe
O4 - HKLM\..\RunServices: [Win32 USB2 Driver] winupdate.exe
O4 - HKLM\..\RunServices: [wincx] wincore332.exe
O4 - HKLM\..\RunServices: [starter] scvhosting.exe
O4 - HKLM\..\RunServices: [NTFS16] ntfs16.exe
O4 - HKLM\..\RunServices: [Win32 USB2.0 Driver] 386.exe
O4 - HKLM\..\RunServices: [Win32 Usb Driver] svhosint32.exe
O4 - HKLM\..\RunServices: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\RunServices: [DLL Manager] dllmngr32.exe
O4 - HKLM\..\RunServices: [Windows Update] SysUpdate.exe
O4 - HKLM\..\RunServices: [Win FS] winfs16.exe
O4 - HKLM\..\RunServices: [Windows SP2 Update Manager] mstestbot.exe
O4 - HKLM\..\RunServices: [MS Update Monitor] msupdatemon.exe
O4 - HKLM\..\RunServices: [Microsoft Update Service] mswin32.exe
O4 - HKLM\..\RunServices: [WindowsUpdatev4] C:\WINDOWS\system32\explorer.exe
O4 - HKLM\..\RunOnce: [starter] scvhosting.exe
O4 - HKLM\..\RunOnce: [Win32 USB2.0 Driver] 386.exe
O4 - HKLM\..\RunOnce: [Win32 Usb Driver] svhosint32.exe
O4 - HKLM\..\RunOnce: [Win32 System Spool] spoolsvc.exe
O4 - HKLM\..\RunOnce: [Win32 USB2 Driver] winupdate.exe
O4 - HKLM\..\RunOnce: [Windows SP2 Update Manager] mstestbot.exe
O4 - HKLM\..\RunOnce: [MS Update Monitor] msupdatemon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [Automated Registry Backup] systemscan.exe
O4 - HKCU\..\Run: [ilka32] ilka32.exe
O4 - HKCU\..\Run: [Win32 USB2 Driver] winupdate.exe
O4 - HKCU\..\Run: [starter] scvhosting.exe
O4 - HKCU\..\Run: [Win32 USB2.0 Driver] 386.exe
O4 - HKCU\..\Run: [NTFS16] ntfs16.exe
O4 - HKCU\..\Run: [Win32 Usb Driver] svhosint32.exe
O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
O4 - HKCU\..\Run: [DLL Manager] dllmngr32.exe
O4 - HKCU\..\Run: [Printer Monitor] C:\WINDOWS\System32\webprinter.exe
O4 - HKCU\..\Run: [Win FS] winfs16.exe
O4 - HKCU\..\Run: [Windows SP2 Update Manager] mstestbot.exe
O4 - HKCU\..\Run: [MS Update Monitor] msupdatemon.exe
O4 - HKCU\..\RunOnce: [starter] scvhosting.exe
O4 - HKCU\..\RunOnce: [MS Update Monitor] msupdatemon.exe
O4 - HKCU\..\RunOnce: [Windows SP2 Update Manager] mstestbot.exe
O4 - HKCU\..\RunOnce: [Win32 USB2 Driver] winupdate.exe
O4 - HKCU\..\RunOnce: [Win32 USB2.0 Driver] 386.exe
O4 - HKCU\..\RunOnce: [Win32 Usb Driver] svhosint32.exe
O4 - HKCU\..\RunOnce: [Win32 System Spool] spoolsvc.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -


thank you again for your time.

Alex

Comments

  • SpywareShooterSpywareShooter 127.0.0.1
    edited October 2004
    O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator.ANDY\Local Settings\Temp\thSwrUMa.dll
    O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
    O4 - HKLM\..\Run: [AD6D69B7] C:\WINDOWS\System32\dztfmkktaxhns.exe
    O4 - HKLM\..\Run: [[Ephemeral 2.5] by TreeHugger, ] C:\DOCUME~1\ADMINI~1.AND\LOCALS~1\Temp\16.tmp.exe
    O4 - HKLM\..\Run: [ilka32] ilka32.exe
    O4 - HKLM\..\Run: [Win32 USB2 Driver] winupdate.exe
    O4 - HKLM\..\Run: [wincx] wincore332.exe
    O4 - HKLM\..\Run: [starter] scvhosting.exe
    O4 - HKLM\..\Run: [NTFS16] ntfs16.exe
    O4 - HKLM\..\Run: [DLL Manager] dllmngr32.exe
    O4 - HKLM\..\Run: [ogsFpvi6] C:\windows\temp\ogsFpvi6.exe
    O4 - HKLM\..\Run: [AyzUChC] C:\windows\temp\AyzUChC.exe
    O4 - HKLM\..\Run: [5YJYRED5JG7WSP] C:\WINDOWS\System32\Oval73H.exe
    O4 - HKLM\..\Run: [Windows System Configuration] C:\WINDOWS\PASSCFG16.EXE
    O4 - HKLM\..\Run: [Windows DLL Loader] C:\WINDOWS\PASSCFG16.EXE
    O4 - HKLM\..\Run: [Windows SP2 Update Manager] mstestbot.exe
    O4 - HKLM\..\Run: [MS Update Monitor] msupdatemon.exe
    O4 - HKLM\..\Run: [Printer] C:\WINDOWS\private.exe
    O4 - HKLM\..\Run: [Microsoft Update Service] mswin32.exe
    O4 - HKLM\..\RunServices: [5FFCD567] C:\WINDOWS\System32\dztfmkktaxhns.exe
    O4 - HKLM\..\RunServices: [ilka32] ilka32.exe
    O4 - HKLM\..\RunServices: [Win32 USB2 Driver] winupdate.exe
    O4 - HKLM\..\RunServices: [wincx] wincore332.exe
    O4 - HKLM\..\RunServices: [starter] scvhosting.exe
    O4 - HKLM\..\RunServices: [NTFS16] ntfs16.exe
    O4 - HKLM\..\RunServices: [Win32 USB2.0 Driver] 386.exe
    O4 - HKLM\..\RunServices: [Win32 Usb Driver] svhosint32.exe
    O4 - HKLM\..\RunServices: [Win FS] winfs16.exe
    O4 - HKLM\..\RunServices: [Windows SP2 Update Manager] mstestbot.exe
    O4 - HKLM\..\RunServices: [MS Update Monitor] msupdatemon.exe
    O4 - HKLM\..\RunServices: [Microsoft Update Service] mswin32.exe
    O4 - HKLM\..\RunOnce: [starter] scvhosting.exe
    O4 - HKLM\..\RunOnce: [Win32 USB2.0 Driver] 386.exe
    O4 - HKLM\..\RunOnce: [Win32 Usb Driver] svhosint32.exe
    O4 - HKLM\..\RunOnce: [Win32 USB2 Driver] winupdate.exe
    O4 - HKLM\..\RunOnce: [Windows SP2 Update Manager] mstestbot.exe
    O4 - HKLM\..\RunOnce: [MS Update Monitor] msupdatemon.exe
    O4 - HKCU\..\Run: [ilka32] ilka32.exe
    O4 - HKCU\..\Run: [Win32 USB2 Driver] winupdate.exe
    O4 - HKCU\..\Run: [starter] scvhosting.exe
    O4 - HKCU\..\Run: [Win32 USB2.0 Driver] 386.exe
    O4 - HKCU\..\Run: [NTFS16] ntfs16.exe
    O4 - HKCU\..\Run: [Win32 Usb Driver] svhosint32.exe
    O4 - HKCU\..\Run: [DLL Manager] dllmngr32.exe
    O4 - HKCU\..\Run: [Printer Monitor] C:\WINDOWS\System32\webprinter.exe
    O4 - HKCU\..\Run: [Win FS] winfs16.exe
    O4 - HKCU\..\Run: [Windows SP2 Update Manager] mstestbot.exe
    O4 - HKCU\..\Run: [MS Update Monitor] msupdatemon.exe
    O4 - HKCU\..\RunOnce: [starter] scvhosting.exe
    O4 - HKCU\..\RunOnce: [MS Update Monitor] msupdatemon.exe
    O4 - HKCU\..\RunOnce: [Windows SP2 Update Manager] mstestbot.exe
    O4 - HKCU\..\RunOnce: [Win32 USB2 Driver] winupdate.exe
    O4 - HKCU\..\RunOnce: [Win32 USB2.0 Driver] 386.exe
    O4 - HKCU\..\RunOnce: [Win32 Usb Driver] svhosint32.exe
    O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -

    Fix those entries with HijackThis and delete all of the files listed above, then reboot and post a new log.

    Note: This is step 1 of what might end up being many steps. Dont think your log is clean after you do this.
  • edited October 2004
    thank you very much for you help

    Alex
  • edited October 2004
    Hi again, if you have the time please, this is the new log after the changes. Thank you for your time.


    Logfile of HijackThis v1.98.2
    Scan saved at 8:09:56 PM, on 10/13/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Explorer\Adr.EXE
    C:\WINDOWS\srvany.exe
    C:\WINDOWS\s4.exe
    C:\WINDOWS\system32\r_server.exe
    c:\Windows\system32\Dap\mssvchost.exe
    c:\Windows\system32\Dap\smss.exe
    c:\Windows\system32\Dap\mssvchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    c:\Windows\system32\Dap\WindowsUpdate.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\scvhosting.exe
    C:\WINDOWS\System32\386.exe
    C:\WINDOWS\System32\AvpG.exe
    C:\WINDOWS\System32\spoolsvc.exe
    C:\WINDOWS\System32\mstestbot.exe
    C:\WINDOWS\System32\msupdatemon.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\System32\Zubyk.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\drwtsn32.exe
    C:\WINDOWS\System32\drwtsn32.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\dllmngr32.exe
    C:\WINDOWS\System32\ntfs16.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Administrator.ANDY\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myub.buffalo.edu/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Configuration Loader] sysinfo.exe
    O4 - HKLM\..\Run: [Registry Integrity Checker] regintmon.exe
    O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\otvnoc.exe
    O4 - HKLM\..\Run: [WSSAConfiguration] wmmon32.exe
    O4 - HKLM\..\Run: [Automated Registry Backup] systemscan.exe
    O4 - HKLM\..\Run: [[Ephemeral 2.5] by TreeHugger, ] C:\DOCUME~1\ADMINI~1.AND\LOCALS~1\Temp\16.tmp.exe
    O4 - HKLM\..\Run: [Win32 USB2.0 Driver] 386.exe
    O4 - HKLM\..\Run: [Win32 Usb Driver] AvpG.exe
    O4 - HKLM\..\Run: [Win32 System Spool] spoolsvc.exe
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [AyzUChC] C:\windows\temp\AyzUChC.exe
    O4 - HKLM\..\Run: [Printer Monitor] C:\WINDOWS\System32\webprinter.exe
    O4 - HKLM\..\Run: [Win FS] winfs16.exe
    O4 - HKLM\..\Run: [WindowsUpdatev4] C:\WINDOWS\system32\explorer.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [Windows Network Service] winvc32.exe
    O4 - HKLM\..\Run: [CRC Value Verifier] crsss32.exe
    O4 - HKLM\..\RunServices: [Registry Integrity Checker] regintmon.exe
    O4 - HKLM\..\RunServices: [WSSAConfiguration] wmmon32.exe
    O4 - HKLM\..\RunServices: [Automated Registry Backup] systemscan.exe
    O4 - HKLM\..\RunServices: [5FFCD567] C:\WINDOWS\System32\cdwykncfs.exe
    O4 - HKLM\..\RunServices: [Win32 Usb Driver] AvpG.exe
    O4 - HKLM\..\RunServices: [Win32 System Spool] spoolsvc.exe
    O4 - HKLM\..\RunServices: [DLL Manager] dllmngr32.exe
    O4 - HKLM\..\RunServices: [Windows Update] SysUpdate.exe
    O4 - HKLM\..\RunServices: [WindowsUpdatev4] C:\WINDOWS\system32\explorer.exe
    O4 - HKLM\..\RunServices: [Windows Network Service] winvc32.exe
    O4 - HKLM\..\RunServices: [CRC Value Verifier] crsss32.exe
    O4 - HKLM\..\RunOnce: [Win32 Usb Driver] AvpG.exe
    O4 - HKLM\..\RunOnce: [Win32 System Spool] spoolsvc.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [Automated Registry Backup] systemscan.exe
    O4 - HKCU\..\Run: [Win32 Usb Driver] AvpG.exe
    O4 - HKCU\..\Run: [Win32 System Spool] spoolsvc.exe
    O4 - HKCU\..\RunOnce: [Win32 Usb Driver] AvpG.exe
    O4 - HKCU\..\RunOnce: [Windows SP2 Update Manager] mstestbot.exe
    O4 - HKCU\..\RunOnce: [Win32 System Spool] spoolsvc.exe
    O4 - HKCU\..\RunOnce: [MS Update Monitor] msupdatemon.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe



    Thank you again.

    Alex
  • LincLinc Owner Detroit Icrontian
    edited October 2004
    Have you run AdAware, Spybot, and an anti-virus? Don't want to assume anything :)

    I recommend going to Control Panel, and choosing Add/Remove Programs. Find any programs you did not purposefully install containing words like "Search", "Rebates", "Casino", "Toolbar", and "Free".

    UNINSTALL/REMOVE all of these programs. If you feel unsure, list the programs here before you uninstall them for us to check. I've found this is sometimes a simple solution for removing some types of spyware. If the uninstall option for one of these items forwards you to a website, do NOT proceed. Close the website, and just skip that one.

    Lastly, remove any entries Shooter listed above that have returned.

    Reboot and post again...
Sign In or Register to comment.