Abigail
Sun Aug 24 18:58:01 PDT 2008
"Elmo" wrote:
>
> Run Msconfig, open the Startup folder and see if the entries are there.
> If so, try deselecting them there. When you restart the computer, you
> will be asked if you want to run in Diagnostic Mode. Answer yes, and
> check the box so you aren't asked at each boot.
>
> Autoruns might do something for you too, though I've never tried it.
>
> 39. AutoRuns - All Programs Running Boot/Login
>
http://www.kellys-korner-xp.com/xp_tweaks.htm
>
> --
> Joe =o)
>
I will need more directions, sorry I'm unfamiliar with it but if I do the
Msconfig thing and once I enter the Diagnostic mode, where do I go from there?
By reading at similar threads I found and tried something called
(StartupTracker3) I think is similar to what you are suggesting (Autoruns).
After runing StartupTracker3 in the resulting startuplog under Registry
Items you will notice there is a:
BMaac9df33 Rundll32.exe "C:\WINNT\system32\ojncembx.dll",s
And under running processes:
rundll32.exe "C:\WINNT\system32\Rundll32.exe"
"C:\WINNT\system32\ojncembx.dll",s
Under running Services:
None
Here is the complete part of the log report:
##############################################
8/24/2008 6:37:34 PM
-- Registry --
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
No Items Found
-- Registry --
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager mobsync.exe /logon
NvCplDaemon RUNDLL32.EXE
C:\WINNT\system32\NvCpl.dll,NvStartup
nwiz nwiz.exe /install
vptray C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
NeroFilterCheck C:\WINNT\system32\NeroCheck.exe
Adobe Reader Speed Launcher "C:\Program Files\Adobe\Reader
8.0\Reader\Reader_sl.exe"
zBrowser Launcher C:\Program Files\Logitech\iTouch\iTouch.exe
InCD C:\Program Files\Ahead\InCD\InCD.exe
QuickTime Task "C:\Program Files\QuickTime\qttask.exe"
-atboottime
NvMediaCenter RUNDLL32.EXE
C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
SystemTray SysTray.Exe
BMaac9df33 Rundll32.exe "C:\WINNT\system32\ojncembx.dll",s
TraySantaCruz C:\WINNT\system32\tbctray.exe
-- Registry --
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
No Items Found
-- Registry --
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
NBJ "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
ctfmon.exe C:\WINNT\system32\ctfmon.exe
-- Registry --
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce
^SetupICWDesktop C:\Program Files\Internet Explorer\Connection
Wizard\icwconn1.exe /desktop
-- Registry --
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run
No Items Found
-- Start Menu - Current User --
No Items Found
-- Start Menu - All Users --
Adobe Gamma Loader.lnk
Microsoft Office.lnk
-- Disabled Items --
No Items Found
-- Registry - Shell Value - HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon --
Explorer.exe
-- Running Processes --
System Idle Process
System
smss.exe \SystemRoot\System32\smss.exe
csrss.exe
winlogon.exe winlogon.exe
services.exe C:\WINNT\system32\services.exe
lsass.exe C:\WINNT\system32\lsass.exe
svchost.exe C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
svchost.exe C:\WINNT\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
spoolsv.exe C:\WINNT\system32\spoolsv.exe
DefWatch.exe "C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\DefWatch.exe"
InCDsrv.exe "C:\Program Files\Ahead\InCD\InCDsrv.exe"
Rtvscan.exe "C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\Rtvscan.exe"
nvsvc32.exe C:\WINNT\system32\nvsvc32.exe
svchost.exe C:\WINNT\system32\svchost.exe -k imgsvc
alg.exe
explorer.exe C:\WINNT\Explorer.EXE
VPTray.exe "C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe"
reader_sl.exe "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
iTouch.exe "C:\Program Files\Logitech\iTouch\iTouch.exe"
InCD.exe "C:\Program Files\Ahead\InCD\InCD.exe"
rundll32.exe "C:\WINNT\system32\RUNDLL32.EXE"
C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
rundll32.exe "C:\WINNT\system32\Rundll32.exe"
"C:\WINNT\system32\ojncembx.dll",s
tbctray.exe "C:\WINNT\system32\tbctray.exe"
ctfmon.exe "C:\WINNT\system32\ctfmon.exe"
StartupTracker3.exe "C:\StartupTracker3\StartupTracker3.exe"
wmiprvse.exe
##############################################