Spybot - Search and Destroy
It appears that I got rid of most of the virus but something still remains because I now get the following error message at startup:
Error loading C:\WINDOWS\system32\dgeknntu.dll
The specified module could not be found.
Here is the sequence of steps I have taken to try to fix this:
1. Using CCleaner, I found the following registry key:
Data: Rundll32.exe "C:\WINDOWS\system32\dgeknntu.dll",s
I tried to delete the key manually through CCleaner. However, when I checked the registry the key was still there.
2. Using regedit, I again tried to delete the registry key. But, when I ran regedit a second time, the key was still there.
3. I rebooted in Safe Mode and deleted the registry key using regedit. When I ran regedit a second time the key was deleted.
4. I rebooted in Safe Mode and ran regedit to verify that the key was still gone. It was still deleted!
5. I rebooted in Normal Mode and the error message did not appear.
6. I rebooted in Normal Mode and the error message did appear.
7. I checked the registry and the "BM3fad8bb3" key had been added back.
So, it appears that a startup program that loads after the registry startup programs is reloading the "BM3fad8bb3" registry key.
How do I find the program that is doing this?
Using msconfig, I've generated boot logs and reviewed them but that didn't provide me with enough information to identify the program.
Also, I've use the Autoruns tool to look at the files that load at startup but I can't identify the program that way either.
My computer is running Windows XP SP2 and is updated with the latest security patches.
Can you please provide some suggestions as to how to proceed?
Edited by jimr0707, 12 October 2008 - 09:24 PM.