Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works

System hammered by MSServer and other likes

  • Please log in to reply



    New Member

  • Member
  • Pip
  • 2 posts
Okay, it's my first post here.. found about the forum from google....

I will quickly give brief on the issue I am facing..

On one of my friends' desktop (which runs on Vista), some registry entries are causing problems. I found the stuff in msconfig, some entries like MSServer, CMDS etc.. are not allowing to use google or any search engine. Also, it masks adsense ads with their own fake anti-spyware software ads. (Names like WinAnonymous, AntiSpyWareMaster etc..)

I tried scanning the machine using Nod32, Ad-Aware and Spybot but they could not fix anything but using Spybot I managed to block those registry entries.

Basically these things are controlled by dll files located under user's temp folder (Under Appdata/Local) but the system is not allowing me to delete those dll files.

I ran Combofix, it did manage to fix up few things but the files are still present.. I have attached following files:

Screenshot of MSConfig screen
ComboFix Log File
Hijackthis Log File (Ran after ComboFix)

Any kind of help is appreciated.


Attached Thumbnails

  • msconfig.gif

Attached Files

Edited by DeepXP, 01 June 2008 - 03:36 AM.

  • 0




    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
Any idea guys?
  • 0

Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP