Re: Spyware



Ankur wrote:

A spyware has registered itself to my system and its was not cleaned
by any software known to me Windows defender, Norton , System Mechanic
etc.

it runs an exe msyuc.exe and few other exes ,everytime i login .
i checked registry, and there is an entry under winlogon:

Shell=Explorer.exe, C:\WINDOWS\system32\msyuc.exe
UserInit=C:\WINDOWS\system32\userinit.exe,xofxmvg.exe

I tried to remove both these exes, but they are not getting deleted
from registry.
Also i tried to delete these file manually under safe mode, but they
are not there under these direcotries, i have no hidden files etc.

i dont know how to clean up my registry, any advice will be helpful.

You need to change the userinit registry entry to:

C:\WINDOWS\system32\userinit.exe,

This assumes your Windows installation is on the C: drive. Be sure to
include the trailing comma.

I'll give you a link to systematic malware cleanup steps, but you will
probably need to run HijackThis and post your log at one of the
specialty forums (not here, please) listed at the link below:

http://www.elephantboycomputers.com/page2.html#Removing_Malware

If the procedures look too complex - and there is no shame in admitting
this; we all have our areas of expertise - then take your computer to a
professional computer repair shop (not your local version of
BigStoreUSA).

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
.



Relevant Pages

  • NewestShareware.com Issue #89
    ... FileBoss for Windows ... Program Homepage/Download url ... In general users make a program execute at window startup by ... Adding programs to the Registry and WIN.INI file protects the program. ...
    (comp.software.shareware.announce)
  • Re: Windows XP home login/off
    ... How to Perform an In-Place Upgrade of Windows XP ... Click on How To Run a Repair Install ... registry has worked the 5 or 6 times I have seen this problem. ... The script will stop and ask you to hit enter to continue to load SCSI ...
    (microsoft.public.windowsxp.wmi)
  • RE: Windows 2000 RRAS and ipSEC /L2TP VPN
    ... How to Configure a L2TP/IPSec Connection Using Pre-shared Key Authentication ... This article contains information about modifying the registry. ... , Windows 2000 is compliant with IKE RFC ...
    (microsoft.public.win2000.networking)
  • RE: Networking and DOS attacks
    ... Windows has found 55 Critical System Errors... ... Install Repair Registry Pro. ... I have tracked all of these UDP port hits since 2001. ...
    (Security-Basics)
  • RE: Problems to create a new internet conection
    ... You Cannot Create a Network Connection After You Restore Windows XP ... This article contains information about modifying the registry. ... You cannot create a remote access or Dial-Up Networking connection. ...
    (microsoft.public.windowsxp.help_and_support)