This thread's last reply is from May 9, 2005, 11:58 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
'KotaGuy
No problem.... got some more instructions for you to pass on though.
Have him fire up regedit again and go to the
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Key.
Look for and delete any/all of the following entries if found:
".Prog"="%Windir%\system\services.exe"
"BuildLab"= "%Windir%\system\services.exe"
"ccApps"="%Windir%\system\services.exe"
"FriendlyTypeName"="%Windir%\system\services.exe"
"Microsoft Visual SourceSafe"="%Windir%\system\services.exe"
"RegDone"="%Windir%\system\services.exe"
"TEXTCONV"="%Windir%\system\services.exe"
"WMAudio"="%Windir%\system\services.exe"
Run and scan with HijackThis. With all other browsers and windows closed, place a check besdie the following and Fix:
O4 - HKLM\..\Run: [MsCom32Agent] C:\WINDOWS\System32\google.exe
O4 - HKLM\..\RunOnce: [*MsCom32Agent] C:\WINDOWS\System32\google.exe
O4 - HKCU\..\Run: [MsCom32Agent] C:\WINDOWS\System32\google.exe
O4 - HKCU\..\RunOnce: [*MsCom32Agent] C:\WINDOWS\System32\google.exe
Boot to Safe Mode. Search for and delete google.exe
Clean temp files, Recycle Bin, etc...
Reboot Windows normally and post a new log along with the Silent Runners log.
'KotaGuy
Have him copy/paste the contents of that link into a new text document.
Name it "SilentRunners.vbs". Save it as File Type "All Files".
He should then be able to run the script.
'KotaGuy
OK rayzer... let us know if there is a change in the situation.