John Scott Posted December 6, 2006 Share Posted December 6, 2006 I know we have a few gurus here. How does one delete, not just disable a startup item in sytem config? My wifes laptop was severly infected about 9 months ago. Everything has been running fine, scans all come back clean, but still see the items in the startup list. Quote Link to comment Share on other sites More sharing options...
loy Posted December 6, 2006 Share Posted December 6, 2006 hijackthis is the program's name Quote Link to comment Share on other sites More sharing options...
loy Posted December 6, 2006 Share Posted December 6, 2006 http://www.merijn.org/files/hijackthis.zip Quote Link to comment Share on other sites More sharing options...
naviathan Posted December 6, 2006 Share Posted December 6, 2006 How about going to the source yourself? Check the startup menu first of all. Next open regedit (START>RUN regedit) Start with HKEY_CURRENT_USER>software>microsoft>windows>currentversion>run Now pick the items you want to get rid of from startup and hit delete. Next go to HKEY_CURRENT_USER>SOFTWARE>microsoft>windows>currentversion>run and do the same there will be more in here. That's IT! Enjoy... I don't trust programs to do it for me as you never know what else they're doing too. Quote Link to comment Share on other sites More sharing options...
tannji Posted December 7, 2006 Share Posted December 7, 2006 Hijackthis is perfectly trustworthy and does exactly what it says and what you tell it to do. The problem with both that program and editing the registry is the user not know what THEY are doing. As long as you back up your registry properly, either way will work just fine with minimal risk. Quote Link to comment Share on other sites More sharing options...
John Scott Posted December 7, 2006 Author Share Posted December 7, 2006 How about going to the source yourself? Check the startup menu first of all. Next open regedit (START>RUN regedit) Start with HKEY_CURRENT_USER>software>microsoft>windows>currentversion>run Now pick the items you want to get rid of from startup and hit delete. Next go to HKEY_CURRENT_USER>SOFTWARE>microsoft>windows>currentversion>run and do the same there will be more in here. That's IT! Enjoy... I don't trust programs to do it for me as you never know what else they're doing too. I've confirmed what's legit and what should go on the startup items. Hmm, since I've disabled, will they show in the run? Also only see >Software> not the variables >software> or >SOFTWARE> Only shows 3 or the 14 active startup items the System Configuration Utility. Hijack this gave me quite a log I need to look over. Quote Link to comment Share on other sites More sharing options...
240zV8 Posted December 7, 2006 Share Posted December 7, 2006 Do what naviathan said, thats the only way to get the source. Be careful with hijack this, don't delete things your not sure about. and you can also use the windows search function to find a specific file to delete. If your not sure about a .exe file to delete, type it in a google search and make sure it's somthing you don't need. Quote Link to comment Share on other sites More sharing options...
(goldfish) Posted December 7, 2006 Share Posted December 7, 2006 The nice thing about hijack this is it shows other parts that the adware likes to hide in, like the browser helper objects. If you straight edit the reg. you'll miss those. I've had good luck with MS defender ( which also lets you modify the start up items) and Ewido ( now partnered with AVG). Quote Link to comment Share on other sites More sharing options...
jnjdragracing Posted December 7, 2006 Share Posted December 7, 2006 Hey John Scott, If you like I can take control of your pc and take a look at your issue. I am a computer guy and do this stuff for a living. Mainly Networks and Servers but also do pc's. Just give me a shout. You can reach me at work at 803.744.8092. This is my direct line. Hours are from 8:30am to 5:30pm eastern time. John Quote Link to comment Share on other sites More sharing options...
onlydrvsnissan Posted December 7, 2006 Share Posted December 7, 2006 edit the registry in safe mode. you'll get better results Quote Link to comment Share on other sites More sharing options...
John Scott Posted December 7, 2006 Author Share Posted December 7, 2006 Thanks for the replies and offers for help. I'm sure many of you would have it cleaned in 1/100th the time. regedit, windows defender, and Hijack This, all fail to list most of the items I find in the Msconfig System Config Utility startup items, including the legit ones. All of the risidual nasty ones that infected the computer have been disabled i.e. ibm00001, paytime, winstall, srwhost, etc, etc. Even though they are in the startup list, they seem to pose no activity, but I still disabled just because. Hijack This found some other traces in BHOs. Pretty cool program IF you know what you are looking for. Spent a lot of time looking up file names and cross checking before I deleted anything. Really no running issues, has been running fine now for months with plenty of internet activity. Regular scans turn up nothing. Never used the laptop for internet, but as soon as we had wireless my wife was on checking out music and videos, with expired protection. Kerpow! Happens fast with high speed. By the time she said John, somethings going on, it was too late. Even though its her computer, my wife is banned from Lymewire for life! Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.