You will want to abandon your Spybot and AdAware...

Sander said:
And yet another lesson is: use Linux, Firefox and other such things.
Hell, use MacOS X if you prefer. It beats Windows.
Would love to, but electrodes operated by several Windows system DLLs have been plugged into my brain, so if I even think about uninstalling Windows, I will die.
Ashmo said:
I also suspect that it's capable of crashing Explorer, like most Windows-integrated applications are.
"Looking at it funny" is capable of crashing Explorer.
The problem is that Linux requires far more effort than I am willing to expend and you have to join a cult to use a Mac. Well, apparently.
Ratty said:
I want my membership on this forum revoked.
D'ya hear that Odin?
The_Vault_Dweller said:
I use internet explorer.

Seriously, switch to Firefox.
And Adblock. You will wonder how you put up with all those ads.
I have a machine here though that lags intermittently when using Firefox but not when using IE. Old one, maybe 500 MHz, Win98. Whoa, there's another lag wave.
Per said:
I have a machine here though that lags intermittently when using Firefox but not when using IE. Old one, maybe 500 MHz, Win98. Whoa, there's another lag wave.
So, the lag is constant with IE?

Meh, I don't know.
Ratty, Ratty...

I wanted to EAT one of your children. Can't one just have some roasted rat once in a while?
Hmm, it seems to work fine on my machine. Found three things spybot S&D couldn't find, and fixed them faster.
Ratty is espousing buying into the Microsoft conspiracy to take over the world.


note to all comrades- Ratty has sold out the capitalist imperialists. He must be among the first taken to the wall when the revolution begins. Death to Traitors!
When your looking at sketchy websites goto Internet Options, Security and set it on High.

Then customize it to enable prompting for downloads and enable downloads.

This easily prevents any problem you could think of. Unless the user was dumb enough to download and install the Trojan.
NPR just had a bit on this.

Seems like Microsoft is trying to wipe out the anti- spy-ware companies.

The irony is that most of the spyware comes from Microsoft sloppiness.

Ratty, you sure you are not mole for the global capitalist conspiracy (aka New World Order)?
welsh said:
Ratty, you sure you are not mole for the global capitalist conspiracy (aka New World Order)?
Well, some decades ago my experimental flyer crashed near some shithole in New Mexico and I got busted by FBI and detained in Area 51, so there is a realistic, albeit far-fetched possibility that they conditioned me to work at their advantage under certain circumstances. But even if my betrayal is real, it exists on an entirely subconscious level and is therefore beyond my ability to control.
Hey guys... I've been removing malware from my Windows XP Pro system, and I wanted to consult you.

I found the trojan "msc32.exe" and boy is this fucker annoying. Seems to have infected ipconfig.exe and winhlp32.exe... Also, it kept shutting down my system.

Anyway, a long fight it was, but I think I finally managed to remove the fucker. But I couldn't find an exact manual for its removal . I've executed a deletion of most suspect files on startup, and it seems it's gone, but I'm not sure (I was a few times and it just kept crawling back...)

So, does any of you have info regarding the exact list of the files this virus infects or uses?

I don't know if my system's clean and operational...

Here's a hijackthis log if you're curious...

C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\BOINC\boinc_gui.exe
C:\Program Files\BOINC\projects\\mfoldB125_4.22_windows_intelx86.exe
C:\Program Files\Outlook Express\msimn.exe

O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: BOINC.lnk = C:\Program Files\BOINC\boinc_gui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office\Office\OSA9.EXE

Sorry for cluttering up the forum, but this was really a nuisance, and any info you could provide would be appreciated.

Or, oyu could chaek if you're not it's prey...