PDA

View Full Version : Good or bad



VoiceofJest
2008-03-24, 07:31
I'm sorry if this is in the wrong place, I think I've only been here once before.

I got the teatimer dialog today while my brother was online. I don't think he was downloading anything at the time (as it's my computer and I don't allow it)although automatic updates may have been going.

I denied whatever it was as I saw temp in it (assuming a lot of the nasties hop into the temp folder) and checked the log and the same thing happened a couple months back.
I'm just wondering if this is something I should of allowed (so when it comes up again I can) or if it's because I have something hiding on here.

17/01/2008 2:01:39 AM Denied value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\TEMP\IXP000.TMP\"") added in System Startup global entry!
23/03/2008 8:12:56 PM Denied value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IXP000.TMP\"") added in System Startup global entry!


I still have version 1.4 of spybot if that makes any difference

PiCoPi
2008-03-24, 13:37
I'm sorry if this is in the wrong place, I think I've only been here once before.

I got the teatimer dialog today while my brother was online. I don't think he was downloading anything at the time (as it's my computer and I don't allow it)although automatic updates may have been going.

I denied whatever it was as I saw temp in it (assuming a lot of the nasties hop into the temp folder) and checked the log and the same thing happened a couple months back.
I'm just wondering if this is something I should of allowed (so when it comes up again I can) or if it's because I have something hiding on here.

17/01/2008 2:01:39 AM Denied value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\TEMP\IXP000.TMP\"") added in System Startup global entry!
23/03/2008 8:12:56 PM Denied value "wextract_cleanup0" (new data: "rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IXP000.TMP\"") added in System Startup global entry!


I still have version 1.4 of spybot if that makes any difference
Let it run! It's safe.

More info here: http://forums.techguy.org/windows-nt-2000-xp/356553-wextract_cleanup0.html