Leftover malware problems

Discussion in 'Software' started by Neil Jones, Jun 16, 2011.

  1. Neil Jones

    Neil Jones Private E-2

    When I use msconfig I see what probably are 100 Startup Items like:

    mmfhjhoj,
    mmfhjhoj0
    mmfhjhoj1

    Etc...

    Location is listed as: SOFTWARE\Microsoft\Windows\CurrentVersion\Run Is this a registry location?

    I'd like to remove this crap from the Startup tab of the System Configuration Utility. How do I go about doing this?
     
  2. thisisu

    thisisu Malware Consultant

    you should head over to the malware forum
     
  3. thisisu

    thisisu Malware Consultant

    yes it is, it controls what runs on startup.

    http://majorgeeks.com/Startup_CPL_d619.html is a great program for that.

    you should still go through the READ & RUN ME FIRST. Malware Removal Guide over in the malware removal forum
     
  4. Neil Jones

    Neil Jones Private E-2

    Controlling isn't the problem. I've unchecked them all. Now I want them removed from the Startup tab of the System Configuration Utility. Is the program you recommended going to do this? If this crap is in the Registry shouldn't I just delete the keys that this Malware created?

    I started another thread in the Malware forum and it got moved to Software so that's why I started this one here.
     
  5. tgell

    tgell Major Geek Extraordinaire

    You can use Autoruns to look at things in the registry during startup. But, be very careful what you delete.

    [​IMG]
     
  6. Neil Jones

    Neil Jones Private E-2

    I used Autoruns. I deleted all the crap plus a ton of other stuff where it said it couldn't find the program. I figured if it couldn't find the program it shouldn't be on my machine. Don't know if that's the right way to think or not. Everything seems to work and the machine sure boots faster.

    Autoruns is a very powerful application and I'm really impressed. It sure saves a lot of time.

    I'm left wondering why applications don't fully uninstall themselves?
     
  7. satrow

    satrow Major Geek Extraordinaire

    If you use Autoruns to 'blindly' delete entries that appear to be missing their files, you could actually be breaking some legitimate installed software. Online games often use protection against hacking or other unfair/illegal interference by loading security software that is quite rootkit-like on first examination, ie, the file(s) can't be 'seen' by Explorer or even Autoruns. It is quite possible that other software also uses, or could use, a similar technique to secure the legitimacy of expensive software.
     
  8. thisisu

    thisisu Malware Consultant

    http://majorgeeks.com/Startup_CPL_d619.html - either program would work, but yes it can delete those reg entries which will affect what you see in msconfig. you have to be careful with it, just like AUTORUNS which has even more options (services / drivers)


    tip with autoruns, if you go to Find , type in "not found", without the quotation marks, and you can safely delete all the missing File not found entries.

    Slight PC boost especially if the PC was still looking for those files on startup.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds