1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Multiple instances of iexplore.exe show up in task manager upon start up

Discussion in 'Virus & Other Malware Removal' started by evilmike, Mar 27, 2008.

Thread Status:
Not open for further replies.
  1. evilmike

    evilmike Thread Starter

    Joined:
    Mar 27, 2008
    Messages:
    1
    For the last few weeks I have noticed that when I restart windows, several iexplore.exe processes are running - even before I've had a chance to do anything. These take up a lot of CPU space and will multiple if I don't close them in Task Manager. They are mostly listed as MIKE under User Name but there is one that is listed as SYSTEM which seems strange. I believe that these processes are actually going to ad related websites because I can notice them in my history - on some occasions I believe that they are on a radio station site because I can hear radio being broadcast even though no windows are open.

    If anybody knows what I can do to get rid of this, please let me know. I am not able to do a system restore to before the problem either for some reason. I have tried numerous spyware programs and online virus scans but the problem persists. I have attached the DSS report below. Thanks!



    Deckard's System Scanner v20071014.68
    Run by Mike on 2008-03-27 00:20:09
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 5 Restore Point(s) --
    50: 2008-03-27 04:20:40 UTC - RP924 - Deckard's System Scanner Restore Point
    49: 2008-03-27 01:43:41 UTC - RP923 - Software Distribution Service 3.0
    48: 2008-03-27 01:33:33 UTC - RP922 - Software Distribution Service 3.0
    47: 2008-03-27 01:10:09 UTC - RP921 - Restore Operation
    46: 2008-03-27 00:14:56 UTC - RP920 - Restore Operation


    -- First Restore Point --
    1: 2008-02-07 02:46:33 UTC - RP875 - System Checkpoint


    Backed up registry hives.
    Performed disk cleanup.

    Percentage of Memory in Use: 77% (more than 75%).
    Total Physical Memory: 256 MiB (512 MiB recommended).


    -- HijackThis (run as Mike.exe) ------------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:22:38 AM, on 3/27/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\EzButton\CplBCL50.EXE
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Mike\Desktop\dss.exe
    C:\DOCUME~1\Mike\MYDOCU~1\Mike.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theweathernetwork.com/weather/CAON0696
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [CplBCL50] C:\Program Files\EzButton\CplBCL50.EXE
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [xydzyh] C:\WINDOWS\system32\xydzyh.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103w.bay103.mail.live.com/mail/resources/MsnPUpld.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.pestpatrol.com/pestscan/pestscan.cab
    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136898693750
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://bain.webex.com/client/T25L/webex/ieatgpc.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Indexing Helps (Indexingbox) - Unknown owner - C:\WINDOWS\system\svchest.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: OESH (Office Source Engine Help) - Unknown owner - C:\Program.exe (file missing)

    --
    End of file - 7049 bytes

    -- HijackThis Fixed Entries (C:\DOCUME~1\Mike\MYDOCU~1\backups\) ---------------

    backup-20080303-203819-151 O2 - BHO: (no name) - {8FC234D4-D636-8EB4-1E82-FC5A103841C7} - C:\WINDOWS\system32\vcjeipw.dll (file missing)
    backup-20080303-203819-371 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    backup-20080303-203819-423 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    backup-20080303-203819-454 R3 - URLSearchHook: (no name) - {8FC234D4-D636-8EB4-1E82-FC5A103841C7} - C:\WINDOWS\system32\vcjeipw.dll (file missing)
    backup-20080303-203819-609 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    backup-20080303-203820-196 O23 - Service: OESH (Office Source Engine Help) - Unknown owner - C:\Program.exe (file missing)
    backup-20080303-203820-202 O23 - Service: Indexing Helps (Indexingbox) - Unknown owner - %WINDIR%\system\svchest.exe (file missing)
    backup-20080303-203820-409 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    backup-20080303-203820-520 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    backup-20080303-203820-584 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    -- File Associations -----------------------------------------------------------

    .js - JSFile - DefaultIcon - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe",2


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R3 ElbyDelay - c:\windows\system32\drivers\elbydelay.sys <Not Verified; Elaborate Bytes AG; CDRTools>

    S3 NAL (Nal Service ) - c:\windows\system32\drivers\iqvw32.sys <Not Verified; Intel Corporation; Intel(R) iQVW32.SYS>
    S3 NPF (Netgroup Packet Filter) - c:\windows\system32\drivers\npf.sys <Not Verified; CACE Technologies; WinPcap Netgroup Packet Filter Driver>
    S3 vaxscsi - c:\windows\system32\drivers\vaxscsi.sys (file missing)


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>

    S2 Indexingbox (Indexing Helps) - c:\windows\system\svchest.exe
    S2 Office Source Engine Help (OESH) - c:\program files\netmeeting\msmsgs


    -- Device Manager: Disabled ----------------------------------------------------

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Intel(R) PRO/Wireless LAN 2100 3B Mini PCI Adapter
    Device ID: PCI\VEN_8086&DEV_1043&SUBSYS_25278086&REV_04\4&16793A72&0&10F0
    Manufacturer: Intel(R) Corporation
    Name: Intel(R) PRO/Wireless LAN 2100 3B Mini PCI Adapter
    PNP Device ID: PCI\VEN_8086&DEV_1043&SUBSYS_25278086&REV_04\4&16793A72&0&10F0
    Service: w70n51

    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description:
    Device ID: ACPI\WEC0518\4&32D50C2&0
    Manufacturer:
    Name:
    PNP Device ID: ACPI\WEC0518\4&32D50C2&0
    Service:

    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: PCI Modem
    Device ID: PCI\VEN_8086&DEV_24C6&SUBSYS_001214C0&REV_03\3&61AAA01&0&FE
    Manufacturer:
    Name: PCI Modem
    PNP Device ID: PCI\VEN_8086&DEV_24C6&SUBSYS_001214C0&REV_03\3&61AAA01&0&FE
    Service:


    -- Scheduled Tasks -------------------------------------------------------------

    2008-03-21 19:22:09 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


    -- Files created between 2008-02-27 and 2008-03-27 -----------------------------

    2008-03-26 23:34:20 0 d-------- C:\WINDOWS\LastGood
    2008-03-26 21:50:36 0 d-------- C:\Program Files\RegVac Registry Cleaner
    2008-03-26 21:07:30 0 d-------- C:\Program Files\Common Files\xing shared
    2008-03-26 20:01:03 116 --a------ C:\myDelm.bat
    2008-03-24 18:33:09 0 d-------- C:\WINDOWS\system32\ActiveScan
    2008-03-24 18:21:29 0 d-------- C:\WINDOWS\pss
    2008-03-13 20:53:25 0 d---s---- C:\WINDOWS\system32\%SystemDrive%
    2008-03-13 19:54:32 2566 --a------ C:\WINDOWS\system\svchest.reg
    2008-03-13 19:54:32 123889 --a------ C:\WINDOWS\system\svchest.exe
    2008-03-13 19:46:56 79872 -----n--- C:\WINDOWS\system32\winsys32_061230.dll
    2008-03-13 19:41:21 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
    2008-03-13 19:40:04 0 d-------- C:\Program Files\Windows Live
    2008-03-13 19:38:33 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-03-13 17:52:05 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
    2008-03-12 23:18:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-03-03 23:32:19 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
    2008-03-03 23:31:03 0 d-------- C:\Program Files\Spyware Doctor
    2008-03-03 19:08:30 0 d-------- C:\Documents and Settings\Mike\.housecall6.6
    2008-03-02 23:58:27 691545 --a------ C:\WINDOWS\unins000.exe
    2008-03-02 23:58:23 2536 --a------ C:\WINDOWS\unins000.dat
    2008-03-02 23:37:11 63488 ---hs---- C:\WINDOWS\system32\xydzyh.exe
    2008-03-02 20:45:40 30720 -r-hs---- C:\WINDOWS\system32\winsys16_061230.dll
    2008-03-02 20:45:40 30720 -r-hs---- C:\WINDOWS\system32\scrsys16_061230.scr
    2008-03-02 20:45:38 175616 -r-hs---- C:\WINDOWS\system32\scrsys061230.scr
    2008-03-02 20:45:37 175616 -r-hs---- C:\WINDOWS\system32\AlxRes061230.exe


    -- Find3M Report ---------------------------------------------------------------

    2008-03-26 23:17:33 0 d-------- C:\Documents and Settings\Mike\Application Data\uTorrent
    2008-03-26 21:07:20 0 d-------- C:\Program Files\Common Files\Real
    2008-03-26 21:06:28 0 d-------- C:\Program Files\Google
    2008-03-26 21:06:14 0 d-------- C:\Program Files\MSN Messenger
    2008-03-24 19:24:13 0 d-------- C:\Program Files\iTunes
    2008-03-24 19:22:18 0 d-------- C:\Program Files\EzButton
    2008-03-24 19:22:06 0 d-------- C:\Program Files\Easy CD-DA Extractor 9
    2008-03-24 19:18:23 0 d-------- C:\Program Files\Apoint2K
    2008-03-23 21:26:24 0 d-------- C:\Program Files\Common Files
    2008-02-22 20:50:30 0 d-------- C:\Program Files\iPod
    2008-02-19 00:49:33 0 d-------- C:\Documents and Settings\Mike\Application Data\vlc
    2008-02-18 23:53:49 0 d-------- C:\Program Files\VideoLAN
    2008-02-15 20:39:08 0 d-------- C:\Program Files\QuickTime
    2008-02-13 00:56:03 0 d-------- C:\Program Files\LimeWire
    2008-02-11 09:07:03 0 d-------- C:\Documents and Settings\Mike\Application Data\Adobe
    2008-02-06 23:43:01 0 d-------- C:\Documents and Settings\Mike\Application Data\webex
    2008-02-06 23:41:17 202827 --a------ C:\WINDOWS\system32\atasnt40.dll <Not Verified; WebEx Communications, Inc; WebEx Application Sharing>
    2008-01-29 19:51:55 0 d-------- C:\Program Files\Gabest
    2008-01-29 09:36:53 0 d-------- C:\Program Files\DirectVobSub


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMan"="SOUNDMAN.EXE" [11/19/2002 09:01 AM C:\WINDOWS\SOUNDMAN.EXE]
    "PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [12/18/2002 05:20 PM]
    "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
    "ATIModeChange"="Ati2mdxx.exe" [09/04/2001 03:24 AM C:\WINDOWS\system32\Ati2mdxx.exe]
    "CplBCL50"="C:\Program Files\EzButton\CplBCL50.EXE" [01/29/2003 03:19 AM]
    "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [10/20/2001 12:46 AM]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
    "NWEReboot"="" []
    "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [10/12/2002 09:00 PM]
    "xydzyh"="C:\WINDOWS\system32\xydzyh.exe" [02/13/2008 10:18 PM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:56 AM]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [03/13/2008 09:08 PM]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 09:05 PM]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableRegistryTools"=0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @="Volume shadow copy"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
    "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "C:\Program Files\iTunes\iTunesHelper.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
    "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    C:\WINDOWS\system32\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    "C:\Program Files\Winamp\winampa.exe"


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f340303-7b49-11db-92b0-00023fb8d11b}]
    AutoRun\command- G:\AUTORUN.EXE

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{edfc12d2-e933-11da-925d-00023fb8d11b}]
    AutoRun\command- F:\RunGame.exe




    -- End of Deckard's System Scanner: finished at 2008-03-27 00:23:38 ------------
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - Multiple instances iexplore
  1. Dano2
    Replies:
    0
    Views:
    409
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/697485

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice