Finally I found how that virus started again and again secretly after reboot!

@ronney47 (109)
Nepal
November 4, 2007 12:34am CST
Yes, it was so difficult. I looked at the registry Run key. There was none, I looked at Startup folder in the Start Menu. There was nothing as well. No matter how many times I killed that process and guarded the registry, it popped up again and again. Then on one of the computer blogs http://robite.blogspot.com/2007/11/secret-startup-methods.html , I found there are other keys for secret startups as well. The keys are userinit and shell under HKLM/software/microsoft/windowsnt/winlogon. So difficult to notice!
1 response
@nesher (237)
• United States
4 Nov 07
Congratulations, man! I know, how difficult is to hunt for the virus or trojan. Last time, after two days of search, I found trojan, hiding under the innocent name Notepad.exe. Not easy to suspect this stupid, but official software file...