Auto Starts protection from

Discussion in 'Ghost Security Suite (GSS)' started by Jeremy2, Sep 24, 2005.

Thread Status:
Not open for further replies.
  1. Jeremy2

    Jeremy2 Registered Member

    Joined:
    Aug 17, 2004
    Posts:
    72
    Auto Starts protection

    Hi,

    I've an entry that has been added by windows update, at the auto start entries:
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1121291420160

    When I try to delete it through Hijackthis...Regdefend don't prompt for any action. Is this normal? Knowing that for any other entry, I have on the auto start registry, whenever I try to delete, regdefend react, by asking if I want to Allow/deny.

    Thanks
     
    Last edited: Sep 24, 2005
  2. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    I don't understand how this cab file can have been entered as an autorun. Does it appear in HJT as an 04 entry? If so what Key is it under?

    If it appears as a Global Startup, RD will not be looking for it anyway because it will be entered in a startup folder and not the Registry.

    I find that after a Windows update it is best to clear out all the Windows Temp files - have you done that?

    Are you sure this is not a piece of Active X appearing as an 016 entry in HJT? If so it is not an aurtostart at all!
     
  3. Jeremy2

    Jeremy2 Registered Member

    Joined:
    Aug 17, 2004
    Posts:
    72
    Thanks TopperID for your answer. Yes, the entry appears as 016.
    I thought that any entry appearing on the HijackThis, will be loaded as a start up entry o_O
     
Thread Status:
Not open for further replies.