msconfig

Discussion in 'other anti-malware software' started by maxoblivion, Oct 8, 2007.

Thread Status:
Not open for further replies.
  1. maxoblivion

    maxoblivion Registered Member

    Joined:
    Feb 21, 2007
    Posts:
    65
    I have an entry in msconfig/Startup with a check in a box but blank space under Item and Location. Has anyone seen this sort of thing before? I'm wondering if it might be related to my win32/trojandownloader.zlob.bfl infestation. SC_Keylog has been detected by both Counterspy and Spyware Doctor (not Spysweeper or NOD32) and each time it is removed, it reappears within a day. I'm wondering if it's reinstalled at startup. Interesting to me is the detected location of SC_Keylog, a desktop shortcut to an Excel spreadsheet. Each time it reappears, the location is the same shortcut.
     
  2. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    3,737
    Location:
    New York City
    Last edited: Oct 8, 2007
  3. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    7,786
    I have seen blank entries in msconfig before also, and they're not necessarily related to anything bad. If you scan completely with a few programs and you're clean, I wouldn't worry much about it...
     
  4. maxoblivion

    maxoblivion Registered Member

    Joined:
    Feb 21, 2007
    Posts:
    65
    I'm going to uncheck it and see what happens.
     
  5. tradetime

    tradetime Registered Member

    Joined:
    Oct 24, 2006
    Posts:
    1,000
    Location:
    UK
    Best bet imho, after scanning as suggested, if that doesn't solve the problem, is to upload a HJT log to one of the sites that analyses and helps with malware removal, they will tell you if anything untoward is lurking.
     
  6. Seer

    Seer Registered Member

    Joined:
    Feb 12, 2007
    Posts:
    1,596
    Location:
    Singidunum
    Hi max.

    I have Adobe Acrobat (not Reader) installed. It creates a blank entry in HKLM\Run (msconfig startup) for [SIZE=-1]Adobe Speed Launch. I have disabled the entry, and Adobe launcher doesn't start when I boot my rig anymore. Now, why exactly is it showing as a blank entry, I have no idea o_O

    This is just an example, as your blank entry may not have anything to do with Acrobat. Anyway, I also don't feel it's anything malicious, it could very well be a remnant of an unproper uninstallation where registry 'run' keys were improperly updated/deleted.
    [/SIZE]
     
  7. HAN

    HAN Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    2,080
    Location:
    USA
    From time to time, I've had some blank entries too. In my case, I have always gone to the registry where the blank is located and if the entry is truly of no use (which to date, they have all been), I have deleted it. IMO, these entries crop up from software installations or removals.

    I'm about as sure as I can ever be that mine were never malware related. But YMMV, so my method may not work for you...
     
  8. Mrkvonic

    Mrkvonic Linux Systems Expert

    Joined:
    May 9, 2005
    Posts:
    8,698
    Hello,

    I have seen this entry the first time after I installed WGA Notification on one of the machines. As a side note, it's worth noting that WGA Notification is since long gone, but it was a lesson in legit spyware.

    I'm not sure if the two are related, but the blank entry coincided with the WU.

    Mrk
     
  9. ThunderZ

    ThunderZ Registered Member

    Joined:
    May 1, 2006
    Posts:
    2,459
    Location:
    North central Ohio, U.S.A.
    I have had them myself. In my case they were related to my HP printer.
     
Thread Status:
Not open for further replies.