Deleting a startup process... WindowsXP

Miscellaneous Forums/General Discussion/Deleting a startup process... WindowsXP

Hey guys, I have some wierd dodgy process that runs when I boot up. I've disabled it via run -> msconfig

But how do I delete it? I've deleted the "command" file in C:\WINDOWS\system32 but then there's a 'location'

which reads:

SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Anybody know where this directory is? I'm having a hell of a time trying to find it...


Thanks in advance!

run>Regedit.exe
then go through CURRENT USER and MACHINE down to the location above, and remove the offending line.


If you removed it from MSConfig, then youve removed it from the above location too so I don't think you have anything to worry about.

I would check the registry anyway.

Try the program called autoruns, it will help you clean up your registry for those sorts of things.

http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

Nice link! That'll come in handy later on.

I have some wierd dodgy process

What was it called - ie the Image Name?

use hijackthis !!!

HKEY_CURRENT_USER (Also later HKEY_LOCAL_MASCHINE)
SOFTWARE
MICROSOFT
WINDOWS
CURRENTVERSION
RUN

There you will find every startup task installed by programms. This manipulation is highter than "MSCONFIG"

bye

Well, I went to test this grass thingy for this guy here:

http://blitzbasic.com/Community/posts.php?topic=78405

And at the DL site, I got a popup that must of gave me a virus, I had blue bugs crawling across the screen, and it turned my background blue. I quickly pressed CTR+ALT+DELETE and closed the processes. Which stopped it.

I ran a virus scan and it picked nothing up, so I cleared internet cache and restarted... Well it repeated itself, but this time my Macafee antivirus picked up a trojan, I allowed it to kill the Trojan. Now i'm thinking "Ah crap". So I open msconfig and find that boot process, its some wierd mix of #s and letters .scr, I go turn it off and delete the file located at "command" which was C:/Windows/system32

And it was still disabled on the msconfig, I thought they disipear after you delete them. So I post here...

Any advice? I'm going to run a few more scans and make sure this thing is gone...

How was I infected? I didn't DL the grass thing yet.

basically you were infected due to a script kiddie putting something on the site and you probably got it via an active X call.

>Image Name?

Puki, this is what msconfig shows

Startup Item -- Command -- Location

lphc3luj0ee0a -- C:\WINDOWS\system32\lphc3luj0ee0a.exe -- SOFTWARE\Microsoft\Windows\CurrentVersion\Run




Oh and the .Exe icon was a picture of a ant :\

>via an active X call
How do I disable this in IE ?

Also, the file was shown on autoruns as 'File not found' I deleted that line. However, I still see the disabled process on msconfig... Is this permanate?

lphc3luj0ee0a.exe is certainly something odd and would appear worrying. Feel free to e-mail it to me.

You need to scan the file with whatever you can. Use 'Spybot Search and Destroy' or 'AdAware' - both are free.

uploading.com where you had a problem should be safe - I can see nothing untoward there. It is possible they were hit with something at the time you went there and they have since cleaned the threat. Various scripts will run from their site and some of those will be 3rd party scripts and links - but I see nothing wrong there now.

It is difficult to say what damage has been inflicted by that exe.

Best check for any ports that it has opened. You can do that here: https://www.grc.com/x/ne.dll?bh0bkyd2

Need to keep an eye on your firewall - if you have loads of stuff set up with automatic permissions, I'd change everything to ask for permission - then you can see what processes/applications want access. You then need to see what IPs they are heading to.

Hey, puki, Interesting website, However, I don't know what ports to check, and how to check them with that website...?

It does it all for you - Do 'Common Ports' first - then do 'All Service Ports' - do File Sharing to.

It's all automated.

Hmm, this is easyer:

http://probe.hackerwatch.org/probe/probe.asp

All seems good...

Well then, Scans are running clean, the other thing that's bugging me is that disabled image, that I posted above, still sitting in msconfig...

Ahh, I figured out yours. You have to click on preceed first... Well, done common (passed with perfect) and now doing all.

Use Spybot Search and Destroy to scan your system - make sure you run an update first. It has a built-in System Start-up tweaker that should let you disable it from running - if it is still running. It will also show you the location of the actual file.

Alright, lunch break, thanks for the help puki. I passed all the tests you said with 'perfect' all ports are running in stealth mode (I didn't even know that)

Right, I'm off to bed.

OK, I've been deleting a screensaver file created by an .exe...

The .exe I named above .. I searched for it wrong... I found it now..

It creates a .scr file with an Icon of a bug...

Do you guys think I should stick these somewhere for further investigation? Or delete them?

The screen saver switches the background for a blue one saying:

"Warning!

Spyware detected on your computer!
Install an antivirus or spyware remover to
clean your computer"

and little bugs crawl around..

Sweet, I finally knocked the thing down! Thanks for all the help guys! for those interested:

What I did to delete the virus:
-Followed the directory to the .exe and deleted it
-Deleted its sister .scr file

To delete the msconfig image thingy....
-You enable the thing on startup via msconfig
-You then do "Regedit.exe" on the run window
-You navigate to:
-HKEY_LOCAL_MACHINE
--SOFTWARE
---MICROSOFT
----WINDOWS
-----CURRENTVERSION
------RUN
-Then you delete the thing... and then bam! its finaly gone..

Ok, I'll do the port check, and a couple more virus scans, and It should be back to normal soon


Question:

How do I make it ask for promision for ActiveX on IE? where is this option? Is there such an option?