i have a question......can't i just do a start, run, regedit and manually find and delete the files? Or is it not that easy??
That was going to be the next move. I try not to send people into the registry unless necessary. I forget you are a Tech. so we probably should have done this sooner.
You may not find all of them, but they need to be checked anyway.
---------------
Go to
My Computer->Tools->Folder Options->View tab:
- Under the Hidden files and folders heading:
- Select Show hidden files and folders.
- Uncheck Hide protected operating system files (recommended) option.
- Also, make sure there is no checkmark beside Hide file extensions for known file types.
- Click OK
---------------
Follow these steps to create a backup of the registry.
- Click the Start button, then click Run. The Run window opens.
- Type REGEDIT, then click OK. The Registry Editor opens.
- Choose Registry, Export Registry File.
- Verify the following entries in the Export Registry File Dialog Box:
- Save in: Desktop
- File Name: Registry Backup
- Export Range: All
- Click Save.
- Exit the Registry Editor.
- Verify you have an icon titled REGISTRY BACKUP.REG on the Desktop.
CAUTION:
Do not double-click the REGISTRY BACKUP.REG file on your Desktop unless you intend to undo your changes. Immediately verify the effect of your changes. When you have verified that the changes to the registry produce the desired result, delete the REGISTRY BACKUP.REG file from the desktop, otherwise restore it immediately.
Do not allow the REGISTRY BACKUP.REG file to remain on the desktop beyond the testing period to avoid inadvertently double-clicking it.
Delete the registry backup after an hour or so of normal computer functions---------------
Look for these File, Folders and Registry keys.
Folder::
C:\WINDOWS\i34yuc387
File::
C:\WINDOWS\awcofznA.exe
C:\Documents and Settings\brainiak\Application Data\Microsoft\Windows\rayiou.exe
C:\Program Files\?ppPatch\?serinit.exe
C:\Program Files\WinPop\winpop.exe
Registry::
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\awcofznA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fkgswssg
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\i34yuc387
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6w
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Umvjiuyd
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPop
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTouch
Let me know how it went.