I've got a PC that's been infected with some sort of spyware. I'm going to format, but this has me completely stumped. What I've got is:
I can rename/delete the file, but then half of my programs error with "Cannot find C:\Windows\System32\mspygps.dll" or "mspygps.dll is a bad image", something to that effect. I searched the registry for the filename and came up with nothing.
Based on file size I was able to get to this page: MSLVVWBK.DLL - Trojan.Agent/Gen-Uphov-B | SUPERAntiSpyware
but that doesn't help and searching google/bing for Trojan.Agent/Gen-Uphov-B returns essentially nothing.
McAfee, Kaspersky, and a couple others won't find anything, even recovery boot CDs.
Any idea how this thing is launching on every exe? Also, if the file is deleted and I reboot, userinit.exe and the other EXE's that run before even the login screen come up error about the missing DLL, so its not an infected explorer.exe I don't think.
- randomly named filename mspygps.dll in the System32 folder that is launching after every EXE (not affected .bat, .pif or .com files)
- no bad startup items, no bad services
- nothing in win.ini/system.ini out of the ordinary
- HKCR\exefile looks fine, as does HKLM\ exefile reg entry
I can rename/delete the file, but then half of my programs error with "Cannot find C:\Windows\System32\mspygps.dll" or "mspygps.dll is a bad image", something to that effect. I searched the registry for the filename and came up with nothing.
Based on file size I was able to get to this page: MSLVVWBK.DLL - Trojan.Agent/Gen-Uphov-B | SUPERAntiSpyware
but that doesn't help and searching google/bing for Trojan.Agent/Gen-Uphov-B returns essentially nothing.
McAfee, Kaspersky, and a couple others won't find anything, even recovery boot CDs.
Any idea how this thing is launching on every exe? Also, if the file is deleted and I reboot, userinit.exe and the other EXE's that run before even the login screen come up error about the missing DLL, so its not an infected explorer.exe I don't think.