PDA

View Full Version : Items under Startup Tab in the System Config Utility



a-10tankkiller
01-01-2011, 09:51 AM
I hope this takes this time as it is my 2nd time trying to post.
One of my sons went and looked at naked women via his facebook, and then to YouTube for the same. I have the Virus scan running and will do AntiMalwareBytes after, but my question for now is with entries I found in the System Configuration Utility under the Startup tab.
2 entries intially showed with a series of 8 squares under the 1st 2 columns(Startup Item, and Command). Then in the location column were the following entries:
HKCU\SOFTWARE\MICROSOFT\Windows NT\CUrrentversion\Windows:run
and
HKCU\SOFTWARE\MICROSOFT\Windows NT\CUrrentversion\Windows:load

I unchecked them and closed, but didn't restart as I am running the virus scan. When I reopened they were unchecked still, but 2 more entries appeared with only 2 squares in each of the first 2 columns, and the following for location for both:
SOFTWARE\MICROSOFT\Windows NT\Currentversion\Windows
I unchecked these, and they have stayed unchecked so far and the 8 Square entries are now gone.
I did a search of the Location descriptions, but that gave me nothing specific that helped. I have no idea how to search by describing the squares in the Startup Item and Command columns.
If anyone has an idea of how, or what this crap maybe I'd appreciate it greatly, as would my son right now.
Thank you, and Happy New Year!

Markel
01-01-2011, 05:54 PM
Found some recent discussion here (http://www.techsupportalert.com/freeware-forum/security/5864-please-help-virus-or-trojan-squares-in-msconfig-startup-2.html) that sounds like it might be a similar infection. There are also some links in that thread that might help.

gwilks98
01-01-2011, 06:51 PM
http://www.sysinternals.com, download the suite and use ProcExp.exe to look at what's running and autoruns.exe to view everything that's starting up.

You said Antimalwarebytes, but I want to make sure you meant "malwarebytes" as that is a great program.

I would use spybot as well. (Don't turn on the immunizer or teatime as they will slow your system down.)

a-10tankkiller
01-01-2011, 08:42 PM
Thank you for the link, I will get through it tommorow. I did a quick scan and it sounds almost identical. I know I also have had a full update for MalwareBytes recently.
Yes, I did mean Malwarebytes Anti malware program. I had a feeling when I typed it I was mixing up the company and program name.
Nothing came up on the virus scan or the Malwarebytes scan, so not sure what is going on. I did find a note about the squares could have resulted from removing a program that I had previously unchecked it from the Startup menu in the Sys Config Util. Then when it wasn't found after removal it caused it to be identified with the squares. Why it would switch from 8 squares to 2 in each column, and then the 8 square entries disappear after unchecking is a mystery for now.
Hopefully the computer will start up tommorrow, and not send all my info to some clown in Russia or China.

Thanks again, and if anyone else has any thoughts I would still appreciate the input.

gwilks98
01-04-2011, 04:57 PM
Could you take a screenshot of these squares? I'm not sure I know what you mean.

a-10tankkiller
01-05-2011, 05:27 AM
I'm not seeing where to attach a jpeg image of the squares. I saw in the instructions there should be a browse button, but I am not seeing it. I won't deny I maybe staring right at it.

gwilks98
01-06-2011, 01:03 PM
I'm not seeing where to attach a jpeg image of the squares. I saw in the instructions there should be a browse button, but I am not seeing it. I won't deny I maybe staring right at it.

step 1 is take a screenshot and make it a bmp or jpb.
step 2 is to go to a hosting site like http://imageshack.us and upload it.
step 3 is to insert a link to the image using the buttons above the text box where you're typing your post here.

Does that help?

a-10tankkiller
01-06-2011, 03:39 PM
Thank you. Here it goes.
http://img534.imageshack.us/i/sysconfigjpeg.jpg/

gwilks98
01-07-2011, 03:49 PM
Thank you. Here it goes.
http://img534.imageshack.us/i/sysconfigjpeg.jpg/
That looks like a corruption or invalid character in the value. What version of windows is this?

a-10tankkiller
01-08-2011, 04:27 AM
Win XP Pro SP3, and all the 50,000+ updates.:))
As I mentioned I did read it maybe due to removing a program that had a Startup FUnction, but I had unchecked it as a Startup Process before I Removed the program, so the line ended up an orphan in the Startup menu. I don't understand why there was originally 2 lines with ~8 squares and those two entries are now gone completely. After unchecking them they were there at the first reboot along with the new 2 square lines. After unchecking the 2 square lines the 8 square lines disappeared completely form the list.

gwilks98
01-10-2011, 09:59 PM
I'd suggest running Glary Utilities "Registry Cleaner" and see if that removes those bad entries.

a-10tankkiller
01-17-2011, 05:12 AM
Thanks for the help! Everything seems to be running fine and I have run numerous scans and seem to be clean. I also have spent too much time trying out the various apps in sysinternals. Cool applications all in one place.