by HardCorePawn » Thu Nov 01, 2007 9:07 am
What and where is this .reg file... a .reg file is not necessarily part of the registry... you can create one (effectively a text script file) and when you double click them, they ask if you want the info added/removed from the registry depending on what the script says...
If its something like C:\tempdir\random_filename.reg (ie. xyyzsfam.reg) you'll probably be able to just delete it...
Having said that, it sounds like you have some sneaky little piece of malware that is attempting to load a reg file to 'restore' itself on startup just in case the registry entries have been cleared by an anti-spyware program...
There is a facility in windows that allows malware to load itself into memory as a kernal process during the bootup before things like antivirus/anti-spyware load, effectively making it invisible... they then restore themselves at shutdown (again, after everything else has been stopped), so anything removed by running spyware removers etc. is put back.
I spent 3 or 4 hours one afternoon trying to dig it out... finally succeeded by using a dos bootdisk with NTFS drivers and manually deleting files... I suggest using HijackThis! to try and identify exactly what malware you have and then googling for possible solutions.
good luck!
"Son, we are about the break the surly bonds of gravity, and punch the face of God." -- Homer Simpson
