|  | 
 
															
															
	
			
			
				| Too Many Applications At Startup? |  |  
					
					
				 
						| Member 
   | 14. March 2006 @ 14:15 |  Link to this message   |  
						| 
							
							I was wondering if the programs listed below would be causing my system resources to be "eaten up". 
 HiJackThis:
 
 StartupList report, 15/03/2006, 00:09:02
 StartupList version: 1.52.2
 Started from : C:\Documents and Settings\Brett Rigby\Desktop\HijackThis.EXE
 Detected: Windows XP SP2 (WinNT 5.01.2600)
 Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 * Using default options
 ==================================================
 
 Running processes:
 
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 C:\Program Files\Alwil Software\Avast4\ashServ.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
 C:\Program Files\Steam\Steam.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\Messenger\Msmsgs.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
 C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
 C:\Program Files\Nero\Nero 7\Nero Recode\Recode.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Documents and Settings\Brett Rigby\Desktop\HijackThis.exe
 
 --------------------------------------------------
 
 Listing of startup folders:
 
 Shell folders Common Startup:
 [C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
 Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 MA111 Configuration Utility.lnk = ?
 
 --------------------------------------------------
 
 Checking Windows NT UserInit:
 
 [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
 UserInit = C:\WINDOWS\system32\userinit.exe,
 
 --------------------------------------------------
 
 Autorun entries from Registry:
 HKLM\Software\Microsoft\Windows\CurrentVersion\Run
 
 ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 SoundMan = SOUNDMAN.EXE
 NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
 ATICCC = "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
 iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
 Windows Defender = "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 avast! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 
 --------------------------------------------------
 
 Autorun entries from Registry:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Run
 
 CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
 BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} = "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
 Steam = "C:\Program Files\Steam\Steam.exe" -silent
 MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 MSMSGS = "C:\Program Files\Messenger\Msmsgs.exe" /background
 
 --------------------------------------------------
 
 Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
 
 Shell=*INI section not found*
 SCRNSAVE.EXE=*INI section not found*
 drivers=*INI section not found*
 
 Shell & screensaver key from Registry:
 
 Shell=Explorer.exe
 SCRNSAVE.EXE=*Registry value not found*
 drivers=*Registry value not found*
 
 Policies Shell key:
 
 HKCU\..\Policies: Shell=*Registry key not found*
 HKLM\..\Policies: Shell=*Registry value not found*
 
 --------------------------------------------------
 
 
 Enumerating Browser Helper Objects:
 
 (no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
 (no name) - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
 
 --------------------------------------------------
 
 Enumerating Task Scheduler jobs:
 
 MP Scheduled Scan.job
 
 --------------------------------------------------
 
 Enumerating Download Program Files:
 
 [QuickTime Object]
 InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
 CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab
 
 [MetaStreamCtl Class]
 InProcServer32 = C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
 
 [Windows Genuine Advantage Validation Tool]
 InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
 CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204
 
 [Office Update Installation Engine]
 InProcServer32 = C:\WINDOWS\opuc.dll
 CODEBASE = http://office.microsoft.com/officeupdate/content/opuc3.cab
 
 [WUWebControl Class]
 InProcServer32 = C:\WINDOWS\system32\wuweb.dll
 CODEBASE = http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 
 [MUWebControl Class]
 InProcServer32 = C:\WINDOWS\system32\muweb.dll
 CODEBASE = http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 
 [PhotoPickConvert Class]
 InProcServer32 = C:\WINDOWS\Downloaded Program Files\PhtPkMSN.dll
 CODEBASE = http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSw...
 
 [Aurigma Image Uploader 3.5 Control]
 InProcServer32 = C:\WINDOWS\Downloaded Program Files\ImageUploader3.ocx
 CODEBASE = http://www.filelodge.com/ImageUploader3.cab
 
 [BatchDownloader Class]
 InProcServer32 = C:\WINDOWS\Downloaded Program Files\DigWXMSN.dll
 CODEBASE = http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSw...
 
 [MsnMessengerSetupDownloadControl Class]
 InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
 CODEBASE = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 
 [Shockwave Flash Object]
 InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx
 CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
 
 --------------------------------------------------
 
 Enumerating ShellServiceObjectDelayLoad items:
 
 PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
 CDBurn: C:\WINDOWS\system32\SHELL32.dll
 WebCheck: C:\WINDOWS\system32\webcheck.dll
 SysTray: C:\WINDOWS\system32\stobject.dll
 
 --------------------------------------------------
 End of report, 7,480 bytes
 Report generated in 0.282 seconds
 
 Command line options:
 /verbose  - to add additional info on each section
 /complete - to include empty sections and unsuspicious data
 /full     - to include several rarely-important sections
 /force9x  - to include Win9x-only startups even if running on WinNT
 /forcent  - to include WinNT-only startups even if running on Win9x
 /forceall - to include all Win9x and WinNT startups, regardless of platform
 /history  - to list version history only
 
 
 3.2Ghz P4 775, ATi X700 Pro 256mb, 1GB DDR2,Asrock 775Twins-HDTV S/L, Maxtor 10 160GB SATA, NEC 4571 DVD±RW DL/RAM, Pioneer 110 DL/RAM, Hiper Type R 480W.
----------------------------------------------
 Satin Silver Ltd. Ed. PS2, 200GB Maxtor HDD, Swap Magic 3.3, Slide Card, HD Advance 3
 |  
						| Advertisement   |   |  
						|  |  
						| Senior Member 
   | 14. March 2006 @ 19:41 |  Link to this message   |  
						| 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 14. March 2006 @ 20:55 |  
						| Member 
   | 15. March 2006 @ 00:16 |  Link to this message   |  
						| 
							
							Thanks. I cant do a HJT log at the moment, im at school :/
 I dont really have a problem with boot / start times as such, just checking up on things.
 
 I was pretty sure my Cable Router has a firewall enabled, maybe i disabled it for some reason ?
 
 Im not going to install Zone Alarm, i have had problems with that in the past (on my other machine) but I personally dont like that program.
 
 Im pretty happy with the setup I have, i was just wondering if I had to many apps starting.
 
 I checked my hijackthis log yesterday anyway, all is good :)
 I check my HJT log myself, and use online checkers (i know, there not relyable) but i do research the file names and processes thati do not know.
 
 
 3.2Ghz P4 775, ATi X700 Pro 256mb, 1GB DDR2,Asrock 775Twins-HDTV S/L, Maxtor 10 160GB SATA, NEC 4571 DVD±RW DL/RAM, Pioneer 110 DL/RAM, Hiper Type R 480W.
----------------------------------------------
 Satin Silver Ltd. Ed. PS2, 200GB Maxtor HDD, Swap Magic 3.3, Slide Card, HD Advance 3
 |  
						| Senior Member 
   | 15. March 2006 @ 08:40 |  Link to this message   |  
						| 
							
							Ok, a firewall in your router it is not visible in the logs. Usually those router firewalls don't have an inbound protection so that is one reason why it would be good to have a software based firewall too.
 Running two antivirus programs is not recommended. This may cause freezes, hangs, lockups and other problems. But your choise....
 
 I just ment that if you could post a normal HijackThis log, it would be the easiest way to check/remove those unnessesary startups.
 
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Member 
   | 15. March 2006 @ 09:09 |  Link to this message   |  
						| 
							
							ok, here is the log:
 As you can probably tell, i was running a few apps when i ran HJT.
 I just cant fit everything into my timescale!
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 19:06:11, on 15/03/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 C:\Program Files\Alwil Software\Avast4\ashServ.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
 C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\Msmsgs.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\MSN Messenger\msnmsgr.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
 C:\Program Files\DVD Decrypter\DVDDecrypter.exe
 C:\Program Files\Shareaza\Shareaza.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Documents and Settings\Brett Rigby\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://www....
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: MA111 Configuration Utility.lnk = ?
 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://automobiles.honda.com/models/mov_iframe_viewpt.asp?path=/i...
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSw...
 O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.filelodge.com/ImageUploader3.cab
 O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSw...
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 
 
 
 
 I'll get a software based firewall soon!
 
 
 3.2Ghz P4 775, ATi X700 Pro 256mb, 1GB DDR2,Asrock 775Twins-HDTV S/L, Maxtor 10 160GB SATA, NEC 4571 DVD±RW DL/RAM, Pioneer 110 DL/RAM, Hiper Type R 480W.
----------------------------------------------
 Satin Silver Ltd. Ed. PS2, 200GB Maxtor HDD, Swap Magic 3.3, Slide Card, HD Advance 3
 This message has been edited since posting. Last time this message was edited on 15. March 2006 @ 09:20 |  
						| Senior Member 
   | 15. March 2006 @ 09:37 |  Link to this message   |  
						| 
							
							Ok, move HijackThis.exe to its own folder C:\HJT
 These are unnessessary startups and you can fix these with HijackThis:
 
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 
 
 Have you locked the Internet Explorer settings?
 If you have not, fix this entry:
 
 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 
 
 It is clean like you said =)
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 15. March 2006 @ 09:44 |  
						| Member 
   | 15. March 2006 @ 09:59 |  Link to this message   |  
						| 
							
							Locked the Internet settings?
 I have installed FireFox and made it the default if thats what you mean?
 
 
 3.2Ghz P4 775, ATi X700 Pro 256mb, 1GB DDR2,Asrock 775Twins-HDTV S/L, Maxtor 10 160GB SATA, NEC 4571 DVD±RW DL/RAM, Pioneer 110 DL/RAM, Hiper Type R 480W.
----------------------------------------------
 Satin Silver Ltd. Ed. PS2, 200GB Maxtor HDD, Swap Magic 3.3, Slide Card, HD Advance 3
 |  
						| Senior Member 
   | 15. March 2006 @ 10:01 |  Link to this message   |  
						| 
							
							I ment that have you blocked the access to internet explorer settings.
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Member 
   | 15. March 2006 @ 10:05 |  Link to this message   |  
						| 
							
							Not that i know of. I'll fix that.
 I'm going to leave MSN to startup, i'll fix the rest.
 
 Just downloaded Sunbelt Kerio Personal Firewall, see how it goes!
 
 Thanks for the help!
 
 
 3.2Ghz P4 775, ATi X700 Pro 256mb, 1GB DDR2,Asrock 775Twins-HDTV S/L, Maxtor 10 160GB SATA, NEC 4571 DVD±RW DL/RAM, Pioneer 110 DL/RAM, Hiper Type R 480W.
----------------------------------------------
 Satin Silver Ltd. Ed. PS2, 200GB Maxtor HDD, Swap Magic 3.3, Slide Card, HD Advance 3
 |  
						| Advertisement   |   |  
						| 
 |  
						| Senior Member 
   | 15. March 2006 @ 10:06 |  Link to this message   |  
						| 
							
							You are welcome :)
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  |