I tried using msconfig, regseeker, regcleaner, and the startup control panel - and in each of these, when I delete or disable the startup registry entry, something is immediately rewriting it in! So it appears as a second entry, under "run" instead of "run/disabled"


Here's my HijackThis logfile: any suggestions?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:59:22 AM, on 8/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\e
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: AcroIEHlprObj Cl@ss - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Cl@ss - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft

Dani AI

Generated

When a startup entry you delete is instantly recreated the problem is not the registry editor — it is whatever process is recreating that value. was right that many entries are normal vendor-supplied utilities, and is correct that manual removal can work. The practical path is: identify the owner, disable it safely, then remove or uninstall the owning program.

Start with a full autorun inventory using Autoruns (Sysinternals). Run it elevated, use the option to hide Microsoft entries, then disable suspect items rather than deleting them immediately. Use the tool's ability to jump to the file on disk so you can see which package owns the entry. If disabling stops the item, uninstall or change the program settings so it does not re-add itself.

If the entry reappears, find the writer with Process Monitor (Procmon). Capture registry write events, filter for registry-write operations and for the name or substring you removed, then reproduce the delete. Procmon will show which process performed the write. Once you know the writer, stop that process/service, remove or reconfigure the program, or uninstall it. Also check scheduled tasks and services — updaters and watchdog services often re-create startup keys.

Run an updated anti-malware scan if the writer looks suspicious. Before deleting registry data, export the key or create a restore point. If needed, post the Autoruns entry name and the Procmon process that writes it (refer to s original log) and include the full image path shown by Autoruns; that information is enough to advise the safest removal.

Recommended Answers

All 6 Replies

What is the process that you want to kill?

The things I think I want to get rid of from my startup are:

nerocheck.exe
pctspk.exe
syntplpr.exe
syntpenh.exe
ctfmon.exe
realsched.exe

Do you / Have you, tried removing them from the registry manually? (Sorry for the slow reply)

Help me out here - in RegEdit, where do I look for startup invocations?

;-b

There are many of em, but the ones you want are listed in your HT log...
Most of them are necessary. If you don't have OFFICE and wish to stop ctfmon you must uncheck Language Bar in your Taskbar properties [rclick it].
I think realsched will reload next time you use the player - check the options in it.
Leave the others alone to prevent... um... issues..
nerocheck tests for conflicting software running, pctspk is your modem, syntp... is for your touchpad..

Gerbil is right but still, the entrys can be removed without problem or complication even the removing the auto load touchpad software wont hurt.
As long as your shore that you want them gone you can do this.

Be sure to go back into msconfig and select normal startup.

Ctfmon is located in HKCU\soft\micro\windows\CurVer\RUN

The rest should be located in
HKLM\soft\micro\windows\CurVer\run


Deleting all the entries (that you want gone) in the run directory should stop the processes from running upon the next startup.

The BHO's are a diffrent story but they can still be removed.

Post if you need help.

Realplaer is a pain but I can tell you how to make it stop inside the program itself.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.