This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Undeletable Registry Files

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please could someone help me with some problems with my computer? I am just about tearing my hair out. Is there anyone out there that could explain to me what I have to do to remove some Registry entries and stop some files loading at startup please ? :unsure: In days gone past I have had MusicMatch JukeBox, AVG 6 (free), Trend Micro PC Cillin installed but have uninstalled them and used a Registry Cleaner to remove any other Registry Entries not removed by the uninstall program. :huh: I have tried to delete "nwiz.exe/install" which is supposedly an NVidia program for my monitor but it keeps coming back. However, every time I log on I still have these programs showing as running but the folders no longer exist. :scratch: I have run HiJackThis and Registry Cleaner and deleted the files each time but they still come back ! :rant: Is there something that I am missing ? I used to have Attune/Aveo which came with CorelDraw, and, although the program folder and all the relevant files have gone when I go to Control Panel/Add & Remove Programs the program name Attune is still there but there is no program to remove. I also have Acronis folder in the registry at HKEY_LOCAL_MACHINE/SOFTWARE/Acronis which cannot be deleted. I would be grateful for any help in clearing these entries. Or, is a complete reinstallation the only solution ? :thumbdown: :rant2: Regards Leith Friend
first place to look is in the software itself. some may have options/preferences etc to not at startup when windows start. might want to check msconfig utility and the startup tab. i would be careful what i uncheck though……….
Hi Shelf Life :wavey: Thanks for your reply. I have already tried removing the entries on several occasions using regedit and msconfig as well HiJackThis but they keep on coming back. :rant2: They are as follows from the HiJackThis Log File: O4 - HKLM\..\Run: [AVG_CC] C:\AVG6\avgcc32.exe /startup O4 - HKLM\..\Run: [MMTray] C:\MUSIC\MusicMatch Jukebox\mm_tray.exe O4 - HKLM\..\Run: [pccguide.exe] "C:\UTILITIES\Trend Micro\Internet Security 2005\pccguide.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Spybot - Search & Destroy\TeaTimer.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup The directories of the first four entries no longer exist on the computer - they were deleted when I uninstalled the applications weeks or months ago. I still have Spybot TeaTimer but I did a reinstall into another directory which does not show up - only the old entry. The second group of 2 entries are NVidia Monitor Settings which are not required and I have tried to delete the entries without success using all of the 3 methods above. When I did a web search of the files I found on some virus websites like McAfee and Symantec that some of these files like mm_tray.exe, pccguide.exe, nwiz.exe and NvCpl.dll were regarded as possible viruses (worms) - on the basis that some form of virus replicated itself using the names of those legitimate files. Sometimes even the file explorer.exe was used in some cases. When I have run Trojan Hunter there have been some files with NTFS Streams showing up but I do not know what to do with them. I do not know whether they would be valid or could be virus things. I do wonder if there is some program hidden on my computer which works like the HiJack BOs starting up the programs each time I reboot. If there is one how do I find it ? Do you have any other options ? Regards Leith Friend :weee:
ok now iam confused, you said you deleted some programs via add/remove programs panel but they keep coming back?

However, every time I log on I still have these programs showing as running


you mean there showing up in the hjt log? or are there icons down near the clock that show the prog is actually running after having been uninstalled?

what version of hjt are you using?
Hi Shelf Life :wavey:

Sorry if I am confusing you - I am confused enough on my own !! :D

They are showing up in the HJT log not in the tray near the clock.

I am using HJT 1.99.0

In the information section of HJT it says for those entries "O4 - Enumeration of suspicious autoloading Registry entries". I now realise from looking at the HJT log that it is not showing them as running processes. But, everytime I try to get rid of the entries using HJT or Reg Clean or going into regedit or msconfig and deleting the entries they keep coming back when I reboot. I just do not understand why that is or what I can do to rid the registry entries completely.

In case there is something else that should not be there the full HJT log is as follows:

Logfile of HijackThis v1.99.0
Scan saved at 10:01:03 p.m., on 12/03/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\UTILIT~1\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\UTILIT~1\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTSvcCDA.exe
c:\progra~1\mcafee\MCAFEE~2\MssSrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\UTILITIES\FlashGet\flashget.exe
C:\WINDOWS\explorer.exe
E:\Program Files\Drivo\Drivo.exe
C:\WINDOWS\system32\ntvdm.exe
C:\UTILIT~1\AVGFRE~1\avgw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\UTILITIES\HiJack This 199\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.slingshot.co.nz/mailman.cgi
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\UTILIT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\UTILIT~1\FlashGet\jccatch.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\UTILIT~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [KeyMaestro] C:\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Ahead\In CD\InCD.exe
O4 - HKLM\..\Run: [AWMON] "C:\UTILIT~1\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~2\MssCli.exe
O4 - HKLM\..\Run: [PopUpInspector.exe] "C:\PopUp Inspector\PopUpInspector.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG_CC] C:\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\MUSIC\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\UTILITIES\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [PopUpInspector] C:\PopUp Inspector\PopUpInspector.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Runner.EXE
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Allow popups from this web page - C:\PopUp Inspector\allowsite.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\ADOBE PROGRAMS\Adobe Acrobat 7 Pro\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download All by FlashGet - C:\UTILITIES\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\UTILITIES\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O8 - Extra context menu item: Stop popups from this web page - C:\PopUp Inspector\denysite.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\UTILIT~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\UTILIT~1\FlashGet\flashget.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: PopUp Inspector - {D216B74A-9A2F-4025-9690-86780AA75F6E} - C:\PopUp Inspector\PopUpInspector.exe (HKCU)
O9 - Extra 'Tools' menuitem: PopUp Inspector - {D216B74A-9A2F-4025-9690-86780AA75F6E} - C:\PopUp Inspector\PopUpInspector.exe (HKCU)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .psd: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O15 - Trusted Zone: http://www.bdm.nsw.gov.au
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\ADOBE PROGRAMS\Adobe Creative Suite\Adobe Version Cue\service\VersionCue.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\UTILIT~1\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\UTILIT~1\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~2\MssSrv.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee SpamKiller Server - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe


Regards and many thanks for your help

Leith Friend :weee:
It appears you are running Ad-Watch on your system on system start up. I had the same problem and it was driving me nuts also. I finally figured out that I had the "Lock Start-Up Section" running in Ad-WAtch. On removal, I could eliminate everything….what a relief!!! If Ad-Watch is running on Start-Up: 1. R Click on Ad-Watch Syatem Tray Icon. 2. Click "Ad-Watch Settings." 3. Scroll to "Blocking Options." 4. Uncheck "Lock Start-Up Section." 5. Now use MSCONFIG or Registry or whatever you did and all should work. God, I hope this works for you. I'll feel like I'm a contributor to a great site and a great bunch of people. Good luck,

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI