A little help needed, please

Wednesday, June 23, 2004 by Stumpy | Discussion: WinCustomize Talk

For some strange reason, each time I boot my machine it now displays a window to My Documents which I have to close manually, does anyone know why or how I can stop it ?

I have made sure that it there is no shortcut in the Startup Folder, checked the registry, checked for spyware, all is clean, I just cannot find a reason for this to be happeneing.

Also there is now a search Toolbar that appears on the Taskbar (Toolbar is called Search Assistant), this I also have to close

I have checked with 3 Spyware programs plus an online scan by Symantec, system, is clean.

Any help would be appreciated




Powered by SkinBrowser!
First Previous Page 2 of 3 Next Last
Stumpy
Reply #21 Wednesday, June 23, 2004 12:22 PM
Here goes, I hope some can see something I missed

StartupList report, 23/06/2004, 06:18:31 PM
StartupList version: 1.52
Started from : D:\Temp\StartupList.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\Program Files\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
D:\PROGRA~1\AGNITUM\OUTPOS~1.0\outpost.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Stardock\TrayServer.exe
C:\logitech\MouseWare\system\em_exec.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
D:\My Program Files\EmailBook\EmailBook.exe
C:\Program Files\WindowsSA\omniscient.exe
D:\Program Files\SysMetrix\SysMetrix.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\Program Files\Stardock\CursorXP\CursorXP.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\PROGRA~1\INCRED~1\bin\IMAPP.EXE
D:\Utility Programs\EasyNoterPro\easynoter.exe
D:\Utility Programs\KeySound\Nkboard.exe
D:\Program Files\SpywareGuard\sgmain.exe
D:\Program Files\Rainlendar\Rainlendar.exe
D:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Stardock\sdcentral.exe
D:\Temp\StartupList.exe



Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Dennis Hallman\Start Menu\Programs\Startup]
Nkboard.lnk = D:\Utility Programs\KeySound\Nkboard.exe
SpywareGuard.lnk = D:\Program Files\SpywareGuard\sgmain.exe
Rainlendar.lnk = D:\Program Files\Rainlendar\Rainlendar.exe

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE



Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,



Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

1A:Stardock TrayMonitor = "C:\Program Files\Common Files\Stardock\TrayServer.exe"
Tweak UI = RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
Logitech Utility = Logi_MwX.Exe
LogonStudio = "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
SpeedTouch USB Diagnostics = "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
EmailBook = D:\My Program Files\EmailBook\EmailBook.exe
Windows SA = C:\Program Files\WindowsSA\omniscient.exe
SysMetrix = D:\Program Files\SysMetrix\SysMetrix.exe
jopa = C:\WINDOWS\System32\sysstartup.exe
BootSkin Startup Jobs = "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
QuickTime Task = "D:\Program Files\QuickTime\qttask.exe" -atboottime
AVG7_CC = D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
AVG7_EMC = D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
Outpost Firewall = D:\PROGRA~1\AGNITUM\OUTPOS~1.0\outpost.exe /waitservice
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit



Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

FAXPrint = C:\WINDOWS\System32\awadpr32.exe /AM



Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

CursorXP = D:\Program Files\Stardock\CursorXP\CursorXP.exe
ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe
H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
jopa = C:\WINDOWS\System32\sysstartup.exe
IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
Art Plus EasyNoter PRO 3.7 = "D:\Utility Programs\EasyNoterPro\easynoter.exe" /a



Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=wbsys.dll



Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=
SCRNSAVE.EXE=
drivers=

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\YU-GI-OH.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*




Enumerating Browser Helper Objects:

SpywareGuard Download Protection - D:\Program Files\SpywareGuard\dlprotect.dll - {4A368E80-174F-4872-96B5-0B27DDD11DB2}
(no name) - c:\windows\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}



Enumerating Task Scheduler jobs:

Tune-up Application Start.job
Uninstall Expiration Reminder.job



Enumerating Download Program Files:

[CoDetectDigitalRiver Class]
CODEBASE = http://ebot.digitalriver.com/v2.0-doc/dlwizard/wizard3.0.4.3.cab

[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
CODEBASE = http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab

[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe

[{556DDE35-E955-11D0-A707-000000521957}]
CODEBASE = http://www.xblock.com/download/xclean_micro.exe

[DASWebDownload Class]
InProcServer32 = C:\WINDOWS\DASAct.dll
CODEBASE = http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab

[Symantec RuFSI Registry Information Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

[{CEBC955E-58AF-11D2-A30A-00A0C903492B}]
CODEBASE = http://windowsupdate.microsoft.com/R824/V31Controls/x86/w98/en/actsetup.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[IMDownloader Class]
CODEBASE = http://www2.incredimail.com/contents/setup/downloader/imloader.cab

[Yahoo! Photos Easy Upload Tool Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\YDropperUK.dll
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_1uk.cab



Enumerating ShellServiceObjectDelayLoad items:

0aMCPClient: C:\Program Files\Common Files\Stardock\mcpcore.dll
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll


End of report, 9,272 bytes
Report generated in 0.250 seconds




Powered by SkinBrowser!
Essencay
Reply #22 Wednesday, June 23, 2004 12:44 PM
Holy Cow....

Essencay goes and gets this to see what starts up with his PC
yrag
Reply #23 Wednesday, June 23, 2004 12:50 PM
Stumpy - Do you have Office 2000 installed?



Powered by SkinBrowser!
PixelPirate
Reply #24 Wednesday, June 23, 2004 1:04 PM
Try going to these entries in regedit and see if there's something spooky going on:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
eieio
Reply #25 Wednesday, June 23, 2004 1:06 PM
Stumpy

See this page for jopa (one of your registry - run entries)

http://www.kephyr.com/spywarescanner/library/sysstartup.jopa/index.phtml


There's a couple of other things I need to check on.
Stumpy
Reply #26 Wednesday, June 23, 2004 1:08 PM
Yrag: Yes Office 2000 (upgraded to Office XP)

Pixel Pirate: Already checked those locations



Powered by SkinBrowser!
eieio
Reply #27 Wednesday, June 23, 2004 1:15 PM
Two more, Stumpy

This link has info on wsaupdater and omniscient, both of which are running at startup.


http://www.wilderssecurity.com/showthread.php?t=35120
yrag
Reply #28 Wednesday, June 23, 2004 1:22 PM
Stump - Stop 'Office' XP from starting anything at boot (OSA9.EXE). It should be in your Startup folder.




Powered by SkinBrowser!
PixelPirate
Reply #29 Wednesday, June 23, 2004 1:29 PM
Try to hit Win+R and type sysedit and see if there's something going on in the 2 ini files...

BE CAREFUL!
PixelPirate
Reply #30 Wednesday, June 23, 2004 1:34 PM
Or try Run - MSINFO32, go to Software Environment and Startup Programs and see if theres anything there.
PixelPirate
Reply #31 Wednesday, June 23, 2004 1:42 PM
Maybe it's this string, remember to take a backup first

Using Regedit, change the following key: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENT VERSION\WINLOGON

Change USERINIT from C:\windows\system32\userinit.exe to C:\windows\system32\userinit.exe,
Stumpy
Reply #32 Wednesday, June 23, 2004 2:02 PM
Ok!, Thank You very much guys, all is now solved, my boot is now as it was, all your help is much appreciated

Thanks Guy & Gals




Powered by SkinBrowser!
PixelPirate
Reply #33 Wednesday, June 23, 2004 2:04 PM
How did you resolve it?
Stumpy
Reply #34 Wednesday, June 23, 2004 2:07 PM
Removed all that Pictoratus said, and the Office startup, then all was well




Powered by SkinBrowser!
PixelPirate
Reply #35 Wednesday, June 23, 2004 2:13 PM
Great you got it figured out. It's a real pain to be bothered with.

In my quest for a possible solution I found the answer to a problem my father was having with Ad-Aware, also a folder that keeps popping up at startup.
SelfExiled
Reply #36 Wednesday, June 23, 2004 2:46 PM
The question is where did you get all that adware? Why wasn't it detected? And how do you protect yourself from getting it again?
Stumpy
Reply #37 Wednesday, June 23, 2004 3:07 PM
Great Security Check here

http://security.symantec.com/sscv6/default.asp?productid=symhome&langid=ie&venid=sym

Don't take long to check




Powered by SkinBrowser!
SelfExiled
Reply #38 Thursday, June 24, 2004 11:40 AM
I have Spybot and it works for me. I also have NAV and I don't have virus or trojan problems. It is just strange that you said you ran all these spyware programs and they found nothing. It seems to me that they probably weren't working. Just strange, and curious.
werewolf
Reply #39 Saturday, June 26, 2004 12:16 PM
I use AVG as my antivirus program and that Symantec checker reported that I had no virus protection running. This is odd, as Zone Alarm as reported that it couldn't find a virus checker either. I have AVG setup so that it is constantly on in the background and I have all the boot scanning options turned on as well.

Maybe that's not a bad thing. I've been reading about some of the latest virus/trojan horses which detect your virus program and turn it off. They couldn't do that if it wasn't detectable. Hmmmm.

Of course, maybe one of those pesky things has already turned it off. Double Hmmmm.


Powered by SkinBrowser!
[Message Edited]
werewolf
Reply #40 Saturday, June 26, 2004 12:35 PM
Another oddity...the Symantec virus scan said I had an infected Default.css file in c:\windows. That file doesn't exist on C:\ at all.



Powered by SkinBrowser!

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01