Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Microsoft Support > Windows XP Support
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Windows XP Support Find support for Windows XP here.

Reply
 
Thread Tools
Old 09-17-2006, 04:23 PM   #1 (permalink)
Registered User
 
Fitzgig06's Avatar
 
Join Date: Dec 2004
Posts: 40
OS: XP


Question Windows XP Startup

<b>I was looking at my startup folder & noticed a bunch of square symbols as the "startup item" & the "command" with the "location" of (HKCU/SOFWARE/Microsoft/Windows NT/CurrentVersion/Windows: Load) ... does anybody know what this is? & should I take it off of my start up!? Thanks!</b>

<b>Here's my Hijack just in case...</b>


Logfile of HijackThis v1.99.1
Scan saved at 6:56:15 PM, on 9/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Gmail

Notifier\G001-1.0.25.0\gnotify.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\Keyhook.exe
C:\Program Files\iolo\System Mechanic

6\SystemGuardAlerter.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PopTray\PopTray.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\iolo\System Mechanic 6\IoloSGCtrl.exe
C:\Program Files\Common Files\Microsoft

Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL

Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Program Files\Avant Browser\avant.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

Page = http://www.freewebs.com/magichatter06/index.htm
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start

Page =

http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_C

LCID}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local

Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local

Page =
R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Window Title = Microsoft Internet Explorer
N3 - Netscape 7: user_pref("browser.startup.homepage",

"http://home.netscape.com/bookmark/7_2/home.html");

(C:\Documents and Settings\Vita Schacht\Application

Data\Mozilla\Profiles\default\mkem1hcr.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine",

"engine://C%3A%5CProgram%20Files%5CNetscape%5CN

etscape%5Csearchplugins%5CSBWeb_01.src");

(C:\Documents and Settings\Vita Schacht\Application

Data\Mozilla\Profiles\default\mkem1hcr.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat

7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) -

{53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) -

{724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program

Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: &RoboForm -

{724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program

Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run:

[{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program

Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [avast!]

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook]

C:\WINDOWS\system32\Keyhook.exe
O4 - HKLM\..\Run: [SystemGuardAlerter] C:\Program

Files\iolo\System Mechanic 6\SystemGuardAlerter.exe
O4 - HKCU\..\Run: [Weather] C:\Program

Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PopTray.lnk = C:\Program

Files\PopTray\PopTray.exe
O4 - User Startup: PopTray.lnk = C:\Program

Files\PopTray\PopTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk =

C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet

Explorer\Control Panel present
O8 - Extra context menu item: Add to AD Black List -

C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Block All Images from the

Same Server - C:\Program Files\Avant

Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Customize Menu -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3

000
O8 - Extra context menu item: Fill Forms - file://C:\Program

Files\Siber Systems\AI

RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Highlight - C:\Program

Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page...

- C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Open In New Avant Browser

- C:\Program Files\Avant Browser\OpenInNewBrowser.htm
O8 - Extra context menu item: Popup Stopper - Add to Black

List - C:\Documents and Settings\Vita

Schacht\AddToPSBlackList.htm
O8 - Extra context menu item: Popup Stopper - Add to

White List - C:\Documents and Settings\Vita

Schacht\AddToPSWhiteList.htm
O8 - Extra context menu item: RoboForm Toolbar -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Search - C:\Program

Files\Avant Browser\Search.htm
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Fill Forms -

{320AF880-6646-11D3-ABEE-C5DBF3571F46} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms -

{320AF880-6646-11D3-ABEE-C5DBF3571F46} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save -

{320AF880-6646-11D3-ABEE-C5DBF3571F49} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms -

{320AF880-6646-11D3-ABEE-C5DBF3571F49} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm -

{724d43aa-0d85-11d4-9908-00400523e39a} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar -

{724d43aa-0d85-11d4-9908-00400523e39a} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) -

{85d1f590-48f4-11d9-9669-0800200c9a66} -

%windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online

Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} -

%windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research -

{92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM -

{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -

C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger -

{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger -

{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug -

{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} -

C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet

Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF:

START_PAGE_URL=http://Www.Wintergreensys.com
O16 - DPF: Yahoo! Pool 2 -

http://download.games.yahoo.com/game...nts/y/pote_x.c

ab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE}

(SupportSoft SmartIssue) -

http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE}

(SupportSoft Script Runner Class) -

http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF:

{05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI

Object) -

http://zone.msn.com/binFrameWork/v10/StagingUI.cab4064

1.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}

(Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF:

{1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl

Class) -

http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8}

(ZoneBuddy Class) -

http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.

cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}

(MSN Photo Upload Tool) -

http://by16fd.bay16.hotmail.msn.com/...ces/MsnPUpld.c

ab
O16 - DPF:

{5736C456-EA94-4AAC-BB08-917ABDD035B3}

(ZonePAChat Object) -

http://zone.msn.com/binframework/v10/ZPAChat.cab32846.

cab
O16 - DPF:

{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}

(BDSCANONLINE Control) -

http://download.bitdefender.com/reso...scan8/oscan8.c

ab
O16 - DPF:

{5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook

Photo Uploader Control) -

http://upload.facebook.com/controls/FacebookPhotoUpload

er.cab
O16 - DPF:

{6414512B-B978-451D-A0D8-FCFDF33E833C}

(WUWebControl Class) -

http://v5.windowsupdate.microsoft.com/v5consumer/V5Cont

rols/en/x86/client/wuweb_site.cab?1102809276359
O16 - DPF:

{6C6A77C7-B4CC-4792-BB9D-5B50A211F69E}

(ProductInformation Control) -

http://www.iolo.com/app/ocx/ProductInformation.ocx
O16 - DPF:

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}

(MUWebControl Class) -

http://update.microsoft.com/microsof...v6/V5Controls/

en/x86/client/muweb_site.cab?1158418716640
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC}

(CLOActiveXInstaller Control) -

http://www.igl.net/clo/install/CLOAc...allerProj1.cab
O16 - DPF:

{7E980B9B-8AE5-466A-B6D6-DA8CF814E78A}

(MJLauncherCtrl Class) -

http://zone.msn.com/bingame/chnz/def...jolauncher.cab
O16 - DPF:

{917623D1-D8E5-11D2-BE8B-00104B06BDE3} -

http://www.ghostsandlegends.com/AxisCamControl.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}

(ActiveScan Installer Class) -

http://acs.pandasoftware.com/actives...free/asinst.ca

b
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47}

(Webshots Photo Uploader) -

http://community.webshots.com/html/WSPhotoUploader.CA

B
O16 - DPF:

{A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma

Image Uploader 3.5 Control) -

http://www.filelodge.com/ImageUploader3.cab
O16 - DPF:

{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}

(MsnMessengerSetupDownloadControl Class) -

http://messenger.msn.com/download/MsnMessengerSetupD

ownloader.cab
O16 - DPF:

{B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro

Class) -

http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab342

46.cab
O16 - DPF:

{CAC181B0-4D70-402D-B571-C596A47D0CE0}

(CBankshotZoneCtrl Class) -

http://zone.msn.com/bingame/zpagames/zpa_pool.cab42858

.cab
O16 - DPF:

{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}

(ActiveDataInfo Class) -

http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF:

{D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF}

(Facebook Photo Uploader Control) -

http://upload.facebook.com/controls/FacebookPhotoUpload

er.cab
O16 - DPF:

{D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames

Online Control) -

http://sympatico.zone.msn.com/bingam.../default/shapo.

cab
O16 - DPF:

{DA2AA6CF-5C7A-4B71-BC3B-C771BB369937}

(StadiumProxy Class) -

http://zone.msn.com/binframework/v10/StProxy.cab41227.c

ab
O16 - DPF:

{DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -

http://zone.msn.com/bingame/apop/def...opcaploader_v6

.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822}

(HeartbeatCtl Class) -

http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009}

(Live Collaboration) -

http://liveca12.custhelp.com/7530-b3.../java/RntX.cab
O16 - DPF:

{EF791A6B-FC12-4C68-99EF-FB9E207A39E6}

(McFreeScan Class) -

http://download.mcafee.com/molbin/is...cfscan/2,1,0,4

749/mcfscan.cab
O18 - Protocol: ms-help -

{314111C7-A502-11D2-BBCA-00C04F8EC294} -

C:\Program Files\Common Files\Microsoft

Shared\Help\hxds.dll
O18 - Protocol: msnim -

{828030A1-22C1-4009-854F-8E305202313F} -

"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SASWinLogon - C:\Program

Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon -

C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) -

Unknown owner - C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner -

C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner -

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe"

/service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner -

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe"

/service (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown

owner - C:\Program Files\iolo\System Mechanic

6\IoloSGCtrl.exe
O23 - Service: SQL Server (SQLEXPRESS)

(MSSQL$SQLEXPRESS) - Unknown owner - c:\Program

Files\Microsoft SQL

Server\MSSQL.1\MSSQL\Binn\sqlservr.exe"

-sSQLEXPRESS (file missing)
O23 - Service: Pml Driver HPZ12 - HP -

C:\WINDOWS\system32\HPZipm12.exe
Fitzgig06 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 09-17-2006, 04:45 PM   #2 (permalink)
Moderator, Microsoft Support, Happy to support TSF!
 
nickster_uk's Avatar
 
Join Date: Feb 2005
Location: United Kingdom
Posts: 6,548
OS: XP Pro SP3, Vista Ultimate SP1, Ubuntu v8.04

My System

Hi there..

posting this in the correct forum will get you more attention:
http://www.techsupportforum.com/forumdisplay.php?f=50

Also, the format of the log is quite difficult to read..not sure how you did it???

:)
__________________
My system:
ASUS P5K-E WiFi | Intel Core 2 Duo E6600 Conroe 2.4GHz (OC 3.60GHz) | 2GB Corsair DDR2 XMS2-6400C4 RAM (4-4-4-12) | PowerColor ATI Radeon HD 3850 Pro Xtreme 512MB GDDR3 GPU | 1xMaxtor DiamondMax 22 500GB & 4xMaxtor DiamondMax 21 250GB SATA HDDs | Zalman CNPS9500 Heatsink + 6 LED Case Fans | Corsair HX620W Modular PSU | Enermax Black Knight (CS-527) Case | Pioneer DVR-216 SATA 20x20 DVD±RW

In a world without walls or fences - who needs Windows and Gates?
nickster_uk is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 09-17-2006, 04:50 PM   #3 (permalink)
Manager Emeritus, I'm blond, James Blond
 
Zazula's Avatar
 
Join Date: Apr 2006
Location: Athens, Greece
Posts: 7,644
OS: Win XP Pro SP2


Send a message via MSN to Zazula
Yes, nickster is right, before posting again in the provided link, please in Notepad go to the Format menu and uncheck Word Wrap.
__________________

"Time is the wisest because it discovers everything" Thales of Miletus (ca.624BC-ca.546BC)
"Everything flows, nothing stands still." Heraclitus of Ephesus (ca.535BC-475BC)
"One thing I know, that I know nothing" Socrates of Athens (ca.470BC–399BC)
Zazula is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 09-17-2006, 05:04 PM   #4 (permalink)
Registered User
 
Fitzgig06's Avatar
 
Join Date: Dec 2004
Posts: 40
OS: XP


Thanks!
Fitzgig06 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 11:08 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82