Multiple instances of iexplore.exe show up in task manager upon start up

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

evilmike

Thread Starter
Joined
Mar 27, 2008
Messages
1
For the last few weeks I have noticed that when I restart windows, several iexplore.exe processes are running - even before I've had a chance to do anything. These take up a lot of CPU space and will multiple if I don't close them in Task Manager. They are mostly listed as MIKE under User Name but there is one that is listed as SYSTEM which seems strange. I believe that these processes are actually going to ad related websites because I can notice them in my history - on some occasions I believe that they are on a radio station site because I can hear radio being broadcast even though no windows are open.

If anybody knows what I can do to get rid of this, please let me know. I am not able to do a system restore to before the problem either for some reason. I have tried numerous spyware programs and online virus scans but the problem persists. I have attached the DSS report below. Thanks!



Deckard's System Scanner v20071014.68
Run by Mike on 2008-03-27 00:20:09
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
50: 2008-03-27 04:20:40 UTC - RP924 - Deckard's System Scanner Restore Point
49: 2008-03-27 01:43:41 UTC - RP923 - Software Distribution Service 3.0
48: 2008-03-27 01:33:33 UTC - RP922 - Software Distribution Service 3.0
47: 2008-03-27 01:10:09 UTC - RP921 - Restore Operation
46: 2008-03-27 00:14:56 UTC - RP920 - Restore Operation


-- First Restore Point --
1: 2008-02-07 02:46:33 UTC - RP875 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 77% (more than 75%).
Total Physical Memory: 256 MiB (512 MiB recommended).


-- HijackThis (run as Mike.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:22:38 AM, on 3/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\EzButton\CplBCL50.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mike\Desktop\dss.exe
C:\DOCUME~1\Mike\MYDOCU~1\Mike.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theweathernetwork.com/weather/CAON0696
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CplBCL50] C:\Program Files\EzButton\CplBCL50.EXE
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [xydzyh] C:\WINDOWS\system32\xydzyh.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103w.bay103.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.pestpatrol.com/pestscan/pestscan.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136898693750
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://bain.webex.com/client/T25L/webex/ieatgpc.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Indexing Helps (Indexingbox) - Unknown owner - C:\WINDOWS\system\svchest.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: OESH (Office Source Engine Help) - Unknown owner - C:\Program.exe (file missing)

--
End of file - 7049 bytes

-- HijackThis Fixed Entries (C:\DOCUME~1\Mike\MYDOCU~1\backups\) ---------------

backup-20080303-203819-151 O2 - BHO: (no name) - {8FC234D4-D636-8EB4-1E82-FC5A103841C7} - C:\WINDOWS\system32\vcjeipw.dll (file missing)
backup-20080303-203819-371 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20080303-203819-423 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
backup-20080303-203819-454 R3 - URLSearchHook: (no name) - {8FC234D4-D636-8EB4-1E82-FC5A103841C7} - C:\WINDOWS\system32\vcjeipw.dll (file missing)
backup-20080303-203819-609 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080303-203820-196 O23 - Service: OESH (Office Source Engine Help) - Unknown owner - C:\Program.exe (file missing)
backup-20080303-203820-202 O23 - Service: Indexing Helps (Indexingbox) - Unknown owner - %WINDIR%\system\svchest.exe (file missing)
backup-20080303-203820-409 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
backup-20080303-203820-520 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
backup-20080303-203820-584 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

-- File Associations -----------------------------------------------------------

.js - JSFile - DefaultIcon - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe",2


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R3 ElbyDelay - c:\windows\system32\drivers\elbydelay.sys <Not Verified; Elaborate Bytes AG; CDRTools>

S3 NAL (Nal Service ) - c:\windows\system32\drivers\iqvw32.sys <Not Verified; Intel Corporation; Intel(R) iQVW32.SYS>
S3 NPF (Netgroup Packet Filter) - c:\windows\system32\drivers\npf.sys <Not Verified; CACE Technologies; WinPcap Netgroup Packet Filter Driver>
S3 vaxscsi - c:\windows\system32\drivers\vaxscsi.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>

S2 Indexingbox (Indexing Helps) - c:\windows\system\svchest.exe
S2 Office Source Engine Help (OESH) - c:\program files\netmeeting\msmsgs


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) PRO/Wireless LAN 2100 3B Mini PCI Adapter
Device ID: PCI\VEN_8086&DEV_1043&SUBSYS_25278086&REV_04\4&16793A72&0&10F0
Manufacturer: Intel(R) Corporation
Name: Intel(R) PRO/Wireless LAN 2100 3B Mini PCI Adapter
PNP Device ID: PCI\VEN_8086&DEV_1043&SUBSYS_25278086&REV_04\4&16793A72&0&10F0
Service: w70n51

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\WEC0518\4&32D50C2&0
Manufacturer:
Name:
PNP Device ID: ACPI\WEC0518\4&32D50C2&0
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Modem
Device ID: PCI\VEN_8086&DEV_24C6&SUBSYS_001214C0&REV_03\3&61AAA01&0&FE
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_8086&DEV_24C6&SUBSYS_001214C0&REV_03\3&61AAA01&0&FE
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-03-21 19:22:09 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


-- Files created between 2008-02-27 and 2008-03-27 -----------------------------

2008-03-26 23:34:20 0 d-------- C:\WINDOWS\LastGood
2008-03-26 21:50:36 0 d-------- C:\Program Files\RegVac Registry Cleaner
2008-03-26 21:07:30 0 d-------- C:\Program Files\Common Files\xing shared
2008-03-26 20:01:03 116 --a------ C:\myDelm.bat
2008-03-24 18:33:09 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-03-24 18:21:29 0 d-------- C:\WINDOWS\pss
2008-03-13 20:53:25 0 d---s---- C:\WINDOWS\system32\%SystemDrive%
2008-03-13 19:54:32 2566 --a------ C:\WINDOWS\system\svchest.reg
2008-03-13 19:54:32 123889 --a------ C:\WINDOWS\system\svchest.exe
2008-03-13 19:46:56 79872 -----n--- C:\WINDOWS\system32\winsys32_061230.dll
2008-03-13 19:41:21 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-13 19:40:04 0 d-------- C:\Program Files\Windows Live
2008-03-13 19:38:33 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-13 17:52:05 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-03-12 23:18:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-03 23:32:19 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-03 23:31:03 0 d-------- C:\Program Files\Spyware Doctor
2008-03-03 19:08:30 0 d-------- C:\Documents and Settings\Mike\.housecall6.6
2008-03-02 23:58:27 691545 --a------ C:\WINDOWS\unins000.exe
2008-03-02 23:58:23 2536 --a------ C:\WINDOWS\unins000.dat
2008-03-02 23:37:11 63488 ---hs---- C:\WINDOWS\system32\xydzyh.exe
2008-03-02 20:45:40 30720 -r-hs---- C:\WINDOWS\system32\winsys16_061230.dll
2008-03-02 20:45:40 30720 -r-hs---- C:\WINDOWS\system32\scrsys16_061230.scr
2008-03-02 20:45:38 175616 -r-hs---- C:\WINDOWS\system32\scrsys061230.scr
2008-03-02 20:45:37 175616 -r-hs---- C:\WINDOWS\system32\AlxRes061230.exe


-- Find3M Report ---------------------------------------------------------------

2008-03-26 23:17:33 0 d-------- C:\Documents and Settings\Mike\Application Data\uTorrent
2008-03-26 21:07:20 0 d-------- C:\Program Files\Common Files\Real
2008-03-26 21:06:28 0 d-------- C:\Program Files\Google
2008-03-26 21:06:14 0 d-------- C:\Program Files\MSN Messenger
2008-03-24 19:24:13 0 d-------- C:\Program Files\iTunes
2008-03-24 19:22:18 0 d-------- C:\Program Files\EzButton
2008-03-24 19:22:06 0 d-------- C:\Program Files\Easy CD-DA Extractor 9
2008-03-24 19:18:23 0 d-------- C:\Program Files\Apoint2K
2008-03-23 21:26:24 0 d-------- C:\Program Files\Common Files
2008-02-22 20:50:30 0 d-------- C:\Program Files\iPod
2008-02-19 00:49:33 0 d-------- C:\Documents and Settings\Mike\Application Data\vlc
2008-02-18 23:53:49 0 d-------- C:\Program Files\VideoLAN
2008-02-15 20:39:08 0 d-------- C:\Program Files\QuickTime
2008-02-13 00:56:03 0 d-------- C:\Program Files\LimeWire
2008-02-11 09:07:03 0 d-------- C:\Documents and Settings\Mike\Application Data\Adobe
2008-02-06 23:43:01 0 d-------- C:\Documents and Settings\Mike\Application Data\webex
2008-02-06 23:41:17 202827 --a------ C:\WINDOWS\system32\atasnt40.dll <Not Verified; WebEx Communications, Inc; WebEx Application Sharing>
2008-01-29 19:51:55 0 d-------- C:\Program Files\Gabest
2008-01-29 09:36:53 0 d-------- C:\Program Files\DirectVobSub


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [11/19/2002 09:01 AM C:\WINDOWS\SOUNDMAN.EXE]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [12/18/2002 05:20 PM]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"ATIModeChange"="Ati2mdxx.exe" [09/04/2001 03:24 AM C:\WINDOWS\system32\Ati2mdxx.exe]
"CplBCL50"="C:\Program Files\EzButton\CplBCL50.EXE" [01/29/2003 03:19 AM]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [10/20/2001 12:46 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
"NWEReboot"="" []
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [10/12/2002 09:00 PM]
"xydzyh"="C:\WINDOWS\system32\xydzyh.exe" [02/13/2008 10:18 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:56 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [03/13/2008 09:08 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 09:05 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
"C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"C:\Program Files\Winamp\winampa.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f340303-7b49-11db-92b0-00023fb8d11b}]
AutoRun\command- G:\AUTORUN.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{edfc12d2-e933-11da-925d-00023fb8d11b}]
AutoRun\command- F:\RunGame.exe




-- End of Deckard's System Scanner: finished at 2008-03-27 00:23:38 ------------
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Members online

Top