Results 1 to 7 of 7

Thread: 'blank' items in startup [log posted]

  1. #1
    Junior Member
    Join Date
    Oct 2006
    Posts
    3

    Default 'blank' items in startup [log posted]

    My XP Pro install has started having some very strange problems over the last 48 hours and I've been trying to track it down.

    I've run Spybot S&D, AdAware SE, etc. and removed 11 Critical Items, but the item in the Startup list (via MSCONFIG) which has no text in either the the "Startup Item" or "Command" columns makes me suspicious, if not downright suspicious.

    Any ideas on what it could be, how to remove it, or if there are other things causing these problems?

    My HijackThis log is below.
    The Log from AdAware of what was Quarantined follows as well.

    Thanks!

    -- Schwa



    Logfile of HijackThis v1.99.1
    Scan saved at 11:11:05 AM, on 10/20/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS2\System32\smss.exe
    C:\WINDOWS2\system32\winlogon.exe
    C:\WINDOWS2\system32\services.exe
    C:\WINDOWS2\system32\lsass.exe
    C:\WINDOWS2\system32\svchost.exe
    C:\WINDOWS2\System32\svchost.exe
    C:\WINDOWS2\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\ccxgui\ccXservice.exe
    C:\Program Files\ccxgui\ccxstream.exe
    C:\Program Files\FileZilla Server\FileZilla Server.exe
    C:\Program Files\IRCXpro\IRCXpro.exe
    C:\WINDOWS2\system32\nvsvc32.exe
    C:\Program Files\TrippLite\PowerAlert\engine\pa.exe
    C:\Program Files\SlimServer\server\slim.exe
    C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
    C:\WINDOWS2\Explorer.EXE
    C:\WINDOWS2\system32\CTHELPER.EXE
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Online Backup\OnlineBackup.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\No-IP\DUC20.exe
    C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
    C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
    C:\Documents and Settings\Joshua.P4-ASUS\Desktop\hijackthis\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 trial.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 support.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 users.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 shop.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 195.137.236.101
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: VizController Class - {0F9CECE1-0306-4BB0-8BEF-C9EA3841E38A} - C:\Program Files\Vyooh\DiskView\VizBHO.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
    O3 - Toolbar: DiskView - {6A882320-BDD0-4ff4-BE3A-D8BAF82668E9} - C:\Program Files\Vyooh\DiskView\VizBar.dll
    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS2\UpdReg.EXE
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PAStatus] C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe
    O4 - HKLM\..\Run: [PALogView] C:\Program Files\TrippLite\PowerAlert\console\logview.exe /s
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS2\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS2\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [ZipTorrent] C:\Program Files\ZipTorrent\ZipTorrent.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS2\system32\NeroCheck.exe
    O4 - HKCU\..\Run: [@BackupScheduler] C:\Program Files\Online Backup\OnlineBackup.exe
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
    O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: SlimServer Tray Tool.lnk = C:\Program Files\SlimServer\SlimTray.exe
    O9 - Extra button: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe (file missing)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{B30FBF75-378F-4D63-89EB-A0AE68248719}: NameServer = 192.168.1.1
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS2\SYSTEM32\WgaLogon.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: ccXgui - [XC]D-Ice - C:\Program Files\ccxgui\ccXservice.exe
    O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IRCXpro - IRCXpro - C:\Program Files\IRCXpro\IRCXpro.exe
    O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS2\system32\nvsvc32.exe
    O23 - Service: PowerAlert Agent - Unknown owner - C:\Program Files\TrippLite\PowerAlert\engine/pa.exe
    O23 - Service: SlimServer (slimsvc) - Unknown owner - C:\Program Files\SlimServer\server\slim.exe
    O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe


    ArchiveData(auto-quarantine- 2006-10-20 10-39-42.bckp)
    Referencefile : SE1R128 18.10.2006
    ======================================================

    WIN32.TROJAN.DOWNLOADER
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    obj[0]=Regkey : S-1-5-21-220523388-1757981266-839522115-1003\software\classes\software\microsoft\internet explorer\toolbar
    obj[1]=Regkey : software\microsoft\internet explorer\toolbar
    obj[11]=File : C:\DOCUME~1\JOSHUA~1.P4-\LOCALS~1\Temp\5.tmp
    obj[12]=File : C:\DOCUME~1\JOSHUA~1.P4-\LOCALS~1\Temp\7.tmp

    TRACKING COOKIE
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    obj[2]=IECache Entry : Cookie:joshua@ads.pointroll.com/
    obj[3]=IECache Entry : Cookie:joshua@edge.ru4.com/
    obj[4]=IECache Entry : Cookie:joshua@tickle.com/
    obj[5]=IECache Entry : Cookie:joshua@serving-sys.com/
    obj[6]=IECache Entry : Cookie:joshua@questionmarket.com/
    obj[7]=IECache Entry : Cookie:joshua@live365.com/
    obj[8]=IECache Entry : Cookie:joshua@zedo.com/
    obj[9]=IECache Entry : Cookie:joshua@server.iad.liveperson.net/
    obj[10]=IECache Entry : Cookie:joshua@advertisingcom.122.2o7.net/

  2. #2
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Welcome

    Describe the problems your seeing ?

    For us to see the blank startups your refering to.
    Run Spybot click Mode > Advanced > tools > system startup
    Press export, save that and post it back here please
    ~~~~~~~~~~~~~~~~~~~~~~~
    Microsoft MVP Windows-Security 2006

  3. #3
    Junior Member
    Join Date
    Oct 2006
    Posts
    3

    Default

    Quote Originally Posted by LonnyRJones View Post
    Welcome

    Describe the problems your seeing ?

    For us to see the blank startups your refering to.
    Run Spybot click Mode > Advanced > tools > system startup
    Press export, save that and post it back here please
    Thanks for the reply. Having trouble connect to the net randomly from browser or games that have had zero problems.

    Export as requested:


    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2005-11-30 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2006-02-06 advcheck.dll (1.0.2.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2005-05-31 SDHelper.dll (1.4.0.0)
    2006-02-20 Tools.dll (2.0.0.2)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2006-10-13 Includes\Cookies.sbi
    2006-10-13 Includes\Dialer.sbi
    2006-10-13 Includes\DialerC.sbi
    2006-10-13 Includes\Hijackers.sbi
    2006-10-13 Includes\HijackersC.sbi
    2006-10-13 Includes\Keyloggers.sbi
    2006-10-13 Includes\KeyloggersC.sbi
    2004-11-29 Includes\LSP.sbi
    2006-10-13 Includes\Malware.sbi
    2006-10-13 Includes\MalwareC.sbi
    2003-03-16 Includes\plugin-ignore.ini
    2006-10-13 Includes\PUPS.sbi
    2006-10-13 Includes\PUPSC.sbi
    2003-11-12 Includes\QA Tests.sbi
    2006-10-13 Includes\Revision.sbi
    2006-10-13 Includes\Security.sbi
    2006-10-13 Includes\SecurityC.sbi
    2006-10-13 Includes\Spybots.sbi
    2006-10-13 Includes\SpybotsC.sbi
    2003-11-21 Includes\Temporary.sbi
    2005-02-17 Includes\Tracks.uti
    2006-10-13 Includes\Trojans.sbi
    2006-10-13 Includes\TrojansC.sbi

    Located: HK_LM:Run, AVG7_CC
    command: C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    file: C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    size: 369664
    MD5: 5ff72bb3dd3d7a206fbab530de76521a

    Located: HK_LM:Run, FileZilla Server Interface
    command: "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
    file: C:\Program Files\FileZilla Server\FileZilla Server Interface.exe
    size: 937984
    MD5: ff99e50b09256dc412d7b26d5321ac3a

    Located: HK_LM:Run, Google Desktop Search
    command: "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    file: C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    size: 166400
    MD5: d20567ad862f131ce9e80aa28f5957d8

    Located: HK_LM:Run, iTunesHelper
    command: "C:\Program Files\iTunes\iTunesHelper.exe"
    file: C:\Program Files\iTunes\iTunesHelper.exe
    size: 278528
    MD5: a8cf3f60099eaa123db72611ce7be271

    Located: HK_LM:Run, Jet Detection
    command: "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    file: C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe
    size: 28672
    MD5: 7df5f447de9e4600f8c77a00d86d210b

    Located: HK_LM:Run, Kernel and Hardware Abstraction Layer
    command: KHALMNPR.EXE
    file: C:\WINDOWS2\KHALMNPR.EXE
    size: 94208
    MD5: cacd213e5a959fdf4f8232a6b34fad43

    Located: HK_LM:Run, Logitech Hardware Abstraction Layer
    command: "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
    file: C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
    size: 94208
    MD5: cacd213e5a959fdf4f8232a6b34fad43

    Located: HK_LM:Run, NeroFilterCheck
    command: C:\WINDOWS2\system32\NeroCheck.exe
    file: C:\WINDOWS2\system32\NeroCheck.exe
    size: 155648
    MD5: 3e4c03cefad8de135263236b61a49c90

    Located: HK_LM:Run, NvCplDaemon
    command: RUNDLL32.EXE C:\WINDOWS2\system32\NvCpl.dll,NvStartup
    file: C:\WINDOWS2\system32\RUNDLL32.EXE
    size: 33280
    MD5: da285490bbd8a1d0ce6623577d5ba1ff

    Located: HK_LM:Run, NvMediaCenter
    command: RUNDLL32.EXE C:\WINDOWS2\system32\NvMcTray.dll,NvTaskbarInit
    file: C:\WINDOWS2\system32\RUNDLL32.EXE
    size: 33280
    MD5: da285490bbd8a1d0ce6623577d5ba1ff

    Located: HK_LM:Run, nwiz
    command: nwiz.exe /install
    file: C:\WINDOWS2\system32\nwiz.exe
    size: 1519616
    MD5: 66db459386d7bf62852b1bfa029fb887

    Located: HK_LM:Run, PALogView
    command: C:\Program Files\TrippLite\PowerAlert\console\logview.exe /s
    file:

    Located: HK_LM:Run, PAStatus
    command: C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe
    file: C:\Program Files\TrippLite\PowerAlert\console\pastatus.exe
    size: 299008
    MD5: faa06c2e5e42820cef3892e529f06811

    Located: HK_LM:Run, QuickTime Task
    command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
    file: C:\Program Files\QuickTime\qttask.exe
    size: 155648
    MD5: c74c7963eec07af49dce44d64819b2bf

    Located: HK_LM:Run, SunJavaUpdateSched
    command: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    file: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    size: 36975
    MD5: 61a3a9d5d98bf0331df5b716144a8100

    Located: HK_LM:Run, type32
    command: "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    file: C:\Program Files\Microsoft IntelliType Pro\type32.exe
    size: 172032
    MD5: 05e10c2c3736e52fe33d16d2f9c73c04

    Located: HK_LM:Run, UpdReg
    command: C:\WINDOWS2\UpdReg.EXE
    file: C:\WINDOWS2\UpdReg.EXE
    size: 90112
    MD5: c419df63e0121d72411285780c2fc6cc

    Located: HK_LM:Run, WINDVDPatch
    command: CTHELPER.EXE
    file: C:\WINDOWS2\system32\CTHELPER.EXE
    size: 24576
    MD5: 3c7a868402b2dd7b65ac32bed886d9e5

    Located: HK_CU:Run, @BackupScheduler
    command: C:\Program Files\Online Backup\OnlineBackup.exe
    file: C:\Program Files\Online Backup\OnlineBackup.exe
    size: 611768
    MD5: e23935a472009bf88330492f85749425

    Located: HK_CU:Run, googletalk
    command: "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
    file: C:\Program Files\Google\Google Talk\googletalk.exe
    size: 3727360
    MD5: 5e0ddd729f9dfddd9dcf4fb238028e18

    Located: HK_CU:Run, NBJ
    command: "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    file: C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
    size: 1912832
    MD5: bc9a646101e8dab2e4f484cad4996901

    Located: HK_CU:Run, Steam
    command:
    file:

    Located: HK_CU:Run, updateMgr
    command: "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
    file: C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
    size: 313472
    MD5: 43f3f6d33c793089a7c32b45da16094b

    Located: Startup (common), Adobe Reader Speed Launch.lnk
    command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    size: 29696
    MD5: 43362b96870ce8649f4f2ec893da93f0

    Located: Startup (common), Logitech SetPoint.lnk
    command: C:\Program Files\Logitech\SetPoint\SetPoint.exe
    file: C:\Program Files\Logitech\SetPoint\SetPoint.exe
    size: 671744
    MD5: 4301b51caa535510f4b45a276dc306a1

    Located: Startup (common), SlimServer Tray Tool.lnk
    command: C:\Program Files\SlimServer\SlimTray.exe
    file: C:\Program Files\SlimServer\SlimTray.exe
    size: 1183813
    MD5: 5112752017b5a6f74ca4fd8895d693c2

    Located: Startup (user), Adobe Gamma.lnk
    command: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    file: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    size: 113664
    MD5: c2ff17734176cd15221c10044ef0ba1a

    Located: Startup (user), No-IP DUC.lnk
    command: C:\Program Files\No-IP\DUC20.exe
    file: C:\Program Files\No-IP\DUC20.exe
    size: 1172992
    MD5: 74d679b8f4331e453431efb423aecece

    Located: System.ini, AtiExtEvent
    command:
    file:

    Located: System.ini, crypt32chain
    command: crypt32.dll
    file: crypt32.dll

    Located: System.ini, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll

    Located: System.ini, cscdll
    command: cscdll.dll
    file: cscdll.dll

    Located: System.ini, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, Schedule
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll

    Located: System.ini, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll

    Located: System.ini, termsrv
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, WgaLogon
    command: WgaLogon.dll
    file: WgaLogon.dll

    Located: System.ini, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll

  4. #4
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Perhaps your SlimServer and No-IP programs have something to do with your connection problems


    You can use SpyBot tools > system startup to delete this if you like
    Located: HK_CU:Run, Steam
    command:
    file:
    Any problems with you vidie card or have you recetly updated ?
    Located: System.ini, AtiExtEvent
    command:
    file:
    ~~~~~~~~~~~~~~~~~~~~~~~
    Microsoft MVP Windows-Security 2006

  5. #5
    Junior Member
    Join Date
    Oct 2006
    Posts
    3

    Default

    slim and no ip have been running for a while. i actually did update my vid card drives... and it's an nvidia not, not ati.... should i remove that ati thang?

  6. #6
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Yes it can be deleted, do you understand how to with SpyBots tools ?

    Just becouse those two programs were there before the problem started doesnt mean they might not be part of the current connection problem.
    ~~~~~~~~~~~~~~~~~~~~~~~
    Microsoft MVP Windows-Security 2006

  7. #7
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    This topic has been archived.

    If you need it re-opened please send me a private message (pm) and provide a link to the thread.
    Applies only to the original topic starter.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •