Can not get rid of startup entry after malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kareltje538, Aug 10, 2008.

Thread Status:
Not open for further replies.
  1. Kareltje538

    Kareltje538 Private E-2

    Hello all,

    after years of sometimes visiting this site (mainly for some downloads to find) now I finally registered because I ran into a problem i can not solve.

    Yesterday I reinstalled my Vista Ultimate and I added some programs that made my avast antivirus "scream" ;)

    So I shutted avast down and installed the program. 9 out of 10 times it isn't a virus,but this one was. Cmd's flying all over the screen,so I hit the resetbutton. But not quickly enough,apparently,so I ended up with removing Virtumonde and something called "Vista AntiVirus" and some other things.

    All ends well,everything's gone now and safe,accept for one little startup-entry I can't get rid of. When I boot up I run into this :

    http://img515.imageshack.us/img515/251/68719680ye6.jpg

    and Windows stays there and won't go further until I click OK.
    ( the text says : Cannot load or execute the file "C...." which is entered in the registry.Check if this file exists on you computer or remove the file's entry from the register).

    But the problem is : I searched through the entire registry and came up with nothing ! I cleaned up the registry with Regcleaner (my favourite) and with the cleaner from TuneUp 2008. Both came up with a lot of wrong entries in the register,but not this one. And I looked in MSConfig,but no entry there either.

    Funny thing is : I had nothing from Adobe installed when this happened and that's why I assume it had something to do with the malware I had (because I had like 10 startup-entries that had all names from reliable companies after the infection and those were all gone after the virus-scan and use of Spybot).

    Does anyone have any idea how to get rid of this warning ?

    I think it's strange by the way that the window-title of the warning is
    Desktop....(having a Dutch Windows)
     
  2. Kareltje538

    Kareltje538 Private E-2

    Just adding another post to tell that the problem is solved.

    Maybe someone else is having the same trouble and that could be
    a reason not to mod mine posts away,but I'll leave that to the mods.

    Here's how I eventually solved it :

    In addition to the things I already tried I used CCleaner's Register Integrety
    option and also none results there. HiJack-log didn't show anything useful either,but on their site (or actually I downloaded it here) I found the program
    StartupList. And with the logfile it created I could finally find the location
    of the startup-entry that was bothering me.

    I still am baffled that the search-function in the Windows Regedit and
    the one in TuneUp's Regedit didn't come up with that entry,but anyway,
    now it's solved and I certainly keep the program StartupList in my
    "emergency" - program-folder.

    So without having to thank anyone here,but I hope that someone
    finds my little "quest" useful in case they have the same problem.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds