Hi.....Last week I discovered 3 trojan/spyware files on my computer. They were msshed32.exe, atiupdate.exe and moneyspj.exe. I found all 3 files in safe mode and deleted them. However, when I use msconfig and go to my startup, I still see msshed32 as an option to check if I want it to start up when I turn on my computer. Did I fully get rid of these files by just deleting them? Why is msshed32 still an option in my startup? I have XP Home with SP1. I have run NAV 2003, Ad-Aware and Spybot Search & Destroy. They are not picking up any of these files. I also ran TrojanHunter with no luck. Thanks.

Dani AI

Generated

Brief expert note tying the thread together: the persistent "msshed32" line seen in msconfig after the EXE was deleted is almost always an orphaned autostart entry (registry value or Startup shortcut) rather than a running copy of the program. was correct to point toward a startup scanner; 's observation about running a tool from a temp/extraction area explains the HijackThis warning that saw. A safe, conservative cleanup workflow is below.

A safe cleanup workflow (XP-era paths shown)

  1. Protect the system first: create a System Restore point and export the registry (Regedit → File → Export).
  2. Search the registry for leftover entries named like the executable and remove only values that explicitly point to that filename. Important locations to check:
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
    HKLM\SYSTEM\CurrentControlSet\Services
  3. Check Startup folders and scheduled tasks:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    C:\Documents and Settings\<username>\Start Menu\Programs\Startup
    C:\WINDOWS\Tasks
  4. Use Regedit’s Find for the string "msshed32" and delete matching Value entries only when the value data references that file path. Remove shortcut files in Startup folders that reference it. If a service is present under Services, set it to Disabled first, then remove the service entry only after confirming it refers to the malware.

Troubleshooting tips and cautions

  • If tools complain they're being run from a temporary folder, fully extract them to a normal folder (for example C:\HJT) before running.
  • To locate any stray copies from the command line: dir C:\*msshed32* /s /a and remove any found files from Safe Mode.
  • Run modern, up‑to‑date AV/anti‑malware definitions (preferably both online/offline or a bootable rescue scanner) to catch self‑recreating components.
  • Registry edits are risky—when unsure, leave the startup item disabled in msconfig until an offline scan or a professional cleanup can be performed.

Recommended Answers

All 6 Replies

Possibly it is still in the registry as an orphaned entry. You can try a scan with hijackthis and if you see it delete it using the fix button.

Download HijackThis from & unzip it into it's own, permanent folder, (Not a temporary folder or the desktop (in a folder on the desktop is fine) & not directly on your hard drive).

Hi.....and thanks. I downloaded Hijack This and created a new folder on my desktop and put it in that folder. However, when I open it, I got the message that it appears that I am trying to open it in a temporary file. I then placed it under Program Files and opened it there and got the same message. Sorry if this is a silly question, but where should I place it so that it is in a permanent folder?

In a folder on the desktop should be fine :). Shouldn't get that message there.
You can also do the following;

Click My Computer, then C:\
In the menu bar, File->New->Folder.
That will create a folder named New Folder, which you can rename to "HJT" or "HijackThis". Now you have C:\HJT\ folder. Put your HijackThis.exe there, and double click to run it.

Hi.....and thanks. I downloaded Hijack This and created a new folder on my desktop and put it in that folder. However, when I open it, I got the message that it appears that I am trying to open it in a temporary file. I then placed it under Program Files and opened it there and got the same message. Sorry if this is a silly question, but where should I place it so that it is in a permanent folder?

Have you unzipped it completely ,some folks run winzip ,but don't finish the unzip and try to run it from the winzip temp folder .?? just a thought

I am not using Winzip but no matter how I save it (to a folder in my program files) it still says that it is coming from a temporary folder when I try to run it??????

Don't worry, it must be a glitch :).

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.