Tech Support Forum banner
Status
Not open for further replies.
1 - 1 of 1 Posts

· Registered
Joined
·
1 Posts
Discussion Starter · #1 ·
INTRO :4-dontkno

My system, though older, was working fine until somehow a W32 Dropper Trojan got into the system despite having Safe and Secure and Spyware Doctor activated. It started acting slow in all phases of operation (very slow startups, sluggish online and periodic BSOD. Then one day Safe and Secure flashed that Dropper was in there but it did not apparently have capability to remove Dropper. Spyware Doctor ID’d Dropper on a full scan and I thought SD removed it (or quarantined it) but things still acted slow and in a day or so Safe and Secure indicated Dropper was still active. I checked online for solutions and it appeared that the best solution to eliminate Dropper was to run ComboFix which I did and things worked much faster afterward – for a while. I ran ComboFix several times to keep things running but the former speedy machine again became sluggish and the Internet would seize. I defragged and I started running Norton CleanSweep to keep the internet cache clean, removed duplicate DLL’s CleanSweep indicated could be removed, and even downloaded TuneXP 1.5 trying to speed things up. Now the thing runs OK for a while then seizes, won’t shutdown correctly and after sometime in use - Outlook and the internet seize causing me to do a hard shutdown as the Control/Alt/Delete won’t work.

HELP! … and thanks in advance for your assistance!

Bob

Here is my HiJackThis report and I'll try attaching sepearately the Panda and DSS Reports:

-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-11-25 11:17:52
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SafeandSecure\SafeandSecure\app\CurtainsSysSvcNt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\WINDOWS\system32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\Program Files\Dell\AccessDirect\DadApp.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Deckards System Scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.armstrongmywire.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\AUserInit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: goodsearch - {4E7BD74F-2B8D-469E-95BA-ED6DB186BE32} - C:\Program Files\goodsearch\goodsearch.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\Program Files\Spyware Doctor\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - C:\Program Files\SafeandSecure\SafeandSecure\app\AuthBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll
O3 - Toolbar: goodsearch - {4E7BD74F-2B8D-469E-95BA-ED6DB186BE32} - C:\Program Files\goodsearch\goodsearch.dll
O3 - Toolbar: Safe and Secure Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - C:\Program Files\SafeandSecure\SafeandSecure\app\AuthBHO.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] C:\PROGRA~1\NORTON~1\QDCSFS.exe /startup
O4 - HKLM\..\Run: [AuthStart] C:\Program Files\SafeandSecure\SafeandSecure\app\authstart.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU. - file://C:\Program Files\Upromise_Remind_U\UpromisesRemindU\UpromisetRemindU\uproC0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://online.musicmatch.com (HKLM)
O15 - Trusted Zone: https://turbotax.com (HKCU)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} () - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://www.homesteadhotels.com/minisite/accommodations/surround/MSSurVid.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} () - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.gamehouse.com/games/zylom/zylomplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.gamehouse.com/games/zuma/popcaploader.cab
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - Service: Anonymizer Anti-Spyware Service (AnonAswSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Curtains for Windows System Service (CurtainsSysSvc) - Authentium, Inc. - C:\Program Files\SafeandSecure\SafeandSecure\app\CurtainsSysSvcNt.exe
O23 - Service: dvpapi - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe


--
End of file - 8966 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 IFP800 (iRiver Internet Audio Player IFP-800) - c:\windows\system32\drivers\ifp800.sys <Not Verified; iRiver, Inc.; IFP-100>
R0 PenClass (Pen Class) - c:\windows\system32\drivers\penclass.sys <Not Verified; Wacom Technology Corporation; Wacom Pen Class Driver>
R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>
R2 GRTdiMon (GR TDI Mon) - c:\windows\system32\drivers\grtdimon.sys <Not Verified; Global RISC; NSX>
R3 AWINDIS5 (AWINDIS5 Protocol Driver) - c:\windows\system32\awindis5.sys <Not Verified; AMBIT Microsystems Corporation.; AMBIT WinDis32 Protocol Driver for Windows>
R3 NETGEAR_WG511_SERVICE (NETGEAR WG511T Wireless Adapter Service) - c:\windows\system32\drivers\wg511nd5.sys <Not Verified; Atheros Communications, Inc.; Atheros AR5001 Wireless Network Adapter>
R3 NETGEARUHOST (NETGEAR Network USB Host Controller) - c:\windows\system32\drivers\netgearuhost.sys <Not Verified; SerComm; NETGEAR Network USB Host Controller>

S3 catchme - c:\docume~1\monika\locals~1\temp\catchme.sys (file missing)
S3 QDFSDRV - c:\windows\system32\drivers\qdfsdrv.sys <Not Verified; Symantec Corporation; Norton CleanSweep>
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 CurtainsSysSvc (Curtains for Windows System Service) - c:\program files\safeandsecure\safeandsecure\app\curtainssyssvcnt.exe <Not Verified; Authentium, Inc.; Curtains for Windows>
R2 dvpapi - "c:\program files\common files\command software\dvpapi.exe" <Not Verified; Command Software Systems, Inc.; Command AntiVirus for Windows>
R2 TabletService - c:\windows\system32\tablet.exe <Not Verified; Wacom Technology, Corp.; Wacom Win32 Tablet Service>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2007-10-10 21:24:09 438 --a------ C:\WINDOWS\Tasks\EasyShare Registration Task.job


-- Files created between 2007-10-25 and 2007-11-25 -----------------------------

2007-11-25 11:14:48 686630 --a------ C:\Program Files\Deckards System Scanner.exe
2007-11-25 11:04:47 0 d-------- C:\Program Files\ZonedOut
2007-11-25 10:37:07 0 d-------- C:\Program Files\SpywareBlaster
2007-11-25 08:39:33 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-11-22 16:00:35 720896 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2007-11-22 16:00:34 0 d-------- C:\Program Files\TuneXP
2007-11-22 15:58:50 1045658 --a------ C:\Program Files\TuneXP_15.exe <Not Verified; Indigo Rose Corporation http://www.indigorose.com; setup>
2007-11-17 18:44:22 0 d-------- C:\Program Files\Common Files\Command Software
2007-11-14 10:24:47 0 d-------- C:\Program Files\Snapshot Viewer
2007-11-10 17:17:39 0 d-------- C:\Program Files\Spyware Doctor
2007-11-09 14:41:09 0 d-------- C:\Documents and Settings\All Users\Application Data\PopCap
2007-11-07 09:45:36 0 d--h----- C:\Documents and Settings\All Users\Application Data\{478433EB-0AFA-4B69-A2DB-9C4DA4A73909}
2007-11-07 09:45:00 0 d-------- C:\Documents and Settings\Monika\Application Data\Anonymizer
2007-11-07 09:44:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Anonymizer
2007-11-03 13:12:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Zylom
2007-10-26 05:16:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Authentium


-- Find3M Report ---------------------------------------------------------------

2007-11-25 11:04:25 240904 --a------ C:\Program Files\ZonedOut.zip
2007-11-25 10:59:42 320 --a------ C:\WINDOWS\system32\wacom.dat
2007-11-25 09:46:22 0 d-------- C:\Program Files\Google
2007-11-25 09:46:05 0 d-------- C:\Program Files\goodsearch
2007-11-25 03:14:03 222208 --a------ C:\Program Files\208th ECB website proposal draft 11-24-2007.doc
2007-11-24 13:46:35 0 d-------- C:\Documents and Settings\Monika\Application Data\WeatherBug
2007-11-23 06:37:59 17192 --a------ C:\WINDOWS\system32\nvModes.dat
2007-11-17 18:44:22 0 d-------- C:\Program Files\Common Files
2007-11-17 08:22:55 77176 --a------ C:\logfile
2007-11-16 04:18:13 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-11-16 03:56:34 0 d-------- C:\Program Files\AIM Toolbar
2007-11-16 03:45:56 0 d-------- C:\Program Files\NETGEAR
2007-11-11 06:55:34 0 d-------- C:\Program Files\Norton CleanSweep
2007-11-10 17:26:13 0 d-------- C:\Program Files\StartCop
2007-11-08 14:08:04 7063 --a------ C:\Program Files\CTC GOVT 2301 Book Order.htm
2007-11-07 10:01:57 0 d-------- C:\Program Files\Anonymizer
2007-11-07 09:45:35 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-04 23:15:53 0 d--h----- C:\Program Files\Common Files\Authentium Shared
2007-10-25 09:18:24 1977 --a------ C:\Program Files\sg_backup_2007-10-25-1018.spg
2007-10-25 09:18:24 1977 --a------ C:\Program Files\FirstBackup.spg
2007-10-24 17:22:10 0 d-------- C:\Documents and Settings\Monika\Application Data\Corel
2007-10-16 15:31:33 0 d-------- C:\Documents and Settings\Monika\Application Data\Elluminate
2007-10-10 21:58:12 0 d-------- C:\Program Files\Kodak
2007-10-10 21:55:14 0 d-------- C:\Program Files\Common Files\Kodak
2007-10-08 08:05:03 0 d-------- C:\Program Files\Microsoft Plus! Digital Media Edition
2007-10-02 16:03:01 0 d-------- C:\Program Files\User_Supported_Apps
2007-09-30 14:44:32 5632 --ahs---- C:\Program Files\Thumbs.db
2007-09-16 10:10:01 278528 --a------ C:\WINDOWS\system32\livesnth.dll <Not Verified; LiveUpdate; LiveSynth>
2007-09-14 08:20:18 79243 --a------ C:\WINDOWS\hpfins05.dat


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [06/18/2004 07:31 PM]
"nwiz"="nwiz.exe" [06/18/2004 07:31 PM C:\WINDOWS\system32\nwiz.exe]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 02:05 AM]
"BCMSMMSG"="BCMSMMSG.exe" [08/29/2003 11:59 AM C:\WINDOWS\BCMSMMSG.exe]
"AS00_Gear511"="C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe" [07/31/2003 01:52 AM]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [09/18/2002 05:52 PM]
"DadApp"="C:\Program Files\Dell\AccessDirect\dadapp.exe" [03/04/2004 12:36 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/02/2005 05:32 AM]
"QD FastAndSafe"="C:\PROGRA~1\NORTON~1\QDCSFS.exe" [04/15/1999 04:00 AM]
"AuthStart"="C:\Program Files\SafeandSecure\SafeandSecure\app\authstart.exe" [08/30/2005 12:35 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [06/07/2005 12:58 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"Spyware Doctor"="C:\PROGRA~1\SPYWAR~1\swdoctor.exe" [12/11/2006 03:35 PM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytools"=0 (0x0)
"disabletaskmgr"=0 (0x0)


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Weather"=C:\Program Files\AWS\WeatherBug\Weather.exe 1

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MimBoot"=C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"iRiver Updater"=C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\Quickset.exe
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
"DMXLauncher"=C:\Program Files\Dell\Media Experience\DMXLauncher.exe
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11aace79-b4cc-11d9-81f9-0011436a737f}]
AutoRun\command- E:\AUTORUN.EXE
 

Attachments

1 - 1 of 1 Posts
Status
Not open for further replies.
Top