System32 opens on start up after spyware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by sabbath_dude, Jul 3, 2006.

  1. sabbath_dude

    sabbath_dude Private E-2

    Yesterday I managed to install virtumonde along with some other nasty stuff while updating a second hand pc I just bought. I'm pretty sure I've removed all the malware (going into safe mode, system restore off and using Spybot, Vundo Fix, Ad-Aware, AVG, Trojan Remover and HJT) and everything seems to be running smoothly however everytime I switch the pc on xp boots up with system32 folder open?. I'm guessing this it to do with an invalid registry entry left over from the spyware problems although I have no idea which one or where. I'm pretty sure all spyware problems have been dealt with but I could be wrong!. Any help with this is much appreciated!. I can submit a HJT log if needed. I'm running SP2 and everything is upto date if that makes any difference.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The system32 folder will typically open when there is a null terminated process trying to load at startup. Improper removal from startups can cause this.

    Please run the below procedure and attach the runkeys.txt log.

     
  3. sabbath_dude

    sabbath_dude Private E-2

    Thank you for replying to my post but I managed to sort it out. Thanks anyway! :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds