Interesting!
by joebjo - 4/7/07 3:39 AM
In Reply to: startup control by Daniel32
Thanks for that Daniel32. I was just cruising the posts and read what you had to say about Spybot start up utility.....I had a look at it and it is saying that I have a system32.exe file which has the HK_LM:RunOnceEx registry key that was supposedly added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field. No other anti spyware/virus/malware proggies I have seemed to have picked that up. I checked it out on the http://www.sysinfo.org/startuplist.php site posted above. I have disabled it, but have since noticed that I have several similar entries in my registry....those being...HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx-, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices, and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce. None of these have any values in the data colum on the right hand side interface (Windows 2000 SP4). Do you know if any of these are legitimate registry key entries (ie not from the worm or any other malware etc)?
Thanks,
Jo

Moderator
CNET Staff
Samsung Staff
Dell Staff