msconfig

Discussion in 'other anti-malware software' started by maxoblivion, Oct 8, 2007.

Thread Status:
Not open for further replies.
  1. maxoblivion

    maxoblivion Registered Member

    Joined:
    Feb 21, 2007
    Posts:
    65
    I have an entry in msconfig/Startup with a check in a box but blank space under Item and Location. Has anyone seen this sort of thing before? I'm wondering if it might be related to my win32/trojandownloader.zlob.bfl infestation. SC_Keylog has been detected by both Counterspy and Spyware Doctor (not Spysweeper or NOD32) and each time it is removed, it reappears within a day. I'm wondering if it's reinstalled at startup. Interesting to me is the detected location of SC_Keylog, a desktop shortcut to an Excel spreadsheet. Each time it reappears, the location is the same shortcut.
     
  2. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    4,761
    Location:
    New York City
    Last edited: Oct 8, 2007
  3. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    7,915
    I have seen blank entries in msconfig before also, and they're not necessarily related to anything bad. If you scan completely with a few programs and you're clean, I wouldn't worry much about it...
     
  4. maxoblivion

    maxoblivion Registered Member

    Joined:
    Feb 21, 2007
    Posts:
    65
    I'm going to uncheck it and see what happens.
     
  5. tradetime

    tradetime Registered Member

    Joined:
    Oct 24, 2006
    Posts:
    1,000
    Location:
    UK
    Best bet imho, after scanning as suggested, if that doesn't solve the problem, is to upload a HJT log to one of the sites that analyses and helps with malware removal, they will tell you if anything untoward is lurking.
     
  6. Seer

    Seer Registered Member

    Joined:
    Feb 12, 2007
    Posts:
    1,668
    Location:
    Singidunum
    Hi max.

    I have Adobe Acrobat (not Reader) installed. It creates a blank entry in HKLM\Run (msconfig startup) for [SIZE=-1]Adobe Speed Launch. I have disabled the entry, and Adobe launcher doesn't start when I boot my rig anymore. Now, why exactly is it showing as a blank entry, I have no idea o_O

    This is just an example, as your blank entry may not have anything to do with Acrobat. Anyway, I also don't feel it's anything malicious, it could very well be a remnant of an unproper uninstallation where registry 'run' keys were improperly updated/deleted.
    [/SIZE]
     
  7. HAN

    HAN Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    2,098
    Location:
    USA
    From time to time, I've had some blank entries too. In my case, I have always gone to the registry where the blank is located and if the entry is truly of no use (which to date, they have all been), I have deleted it. IMO, these entries crop up from software installations or removals.

    I'm about as sure as I can ever be that mine were never malware related. But YMMV, so my method may not work for you...
     
  8. Mrkvonic

    Mrkvonic Linux Systems Expert

    Joined:
    May 9, 2005
    Posts:
    9,367
    Hello,

    I have seen this entry the first time after I installed WGA Notification on one of the machines. As a side note, it's worth noting that WGA Notification is since long gone, but it was a lesson in legit spyware.

    I'm not sure if the two are related, but the blank entry coincided with the WU.

    Mrk
     
  9. ThunderZ

    ThunderZ Registered Member

    Joined:
    May 1, 2006
    Posts:
    2,459
    Location:
    North central Ohio, U.S.A.
    I have had them myself. In my case they were related to my HP printer.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.