Announcement

Collapse
No announcement yet.

My Computer always displays on startup?

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • My Computer always displays on startup?

    I've got a buddy over this evening who shows me that, every time he boots Windows XP Pro on his laptop, his "My Computer" window displays automatically.

    * http://support.microsoft.com/default.aspx?kbid=228502 doesn't apply (he's running IE6)
    * Autoruns confirms nothing relevant in any of the Startup hiding places (Run, RunOnce, etc, etc)
    * Changing (to either/both values) the "Restore previous folder windows at logon" setting in the View tab of Folder Options (and logging out and/or rebooting) does nothing
    * There's nothing in his account's StartUp folder, nor in the All Users StartUp folder
    * The window opens after both reboots and simply logging out/in

    Anyone have any idea what might be causing this to happen?
    Steam Community? Add me. | Free Remote, Encrypted Backup

    Darkilla: In short, NS is pretty much really fast chess. With guns. Apophis: I haven't seen anyone say that SM's are better than non-SMs. Nordbomber: This is THE first server I've seen where either side can comeback from out of seemingly nowhere with the right teamwork. en4rcment: I have NEVER experienced the type of gameplay that I have found here. Nightly I am amazed at the personalities and gaming talent. Zephyr: Apophis is clearly a highly sophisticated self-aware AI construct that runs on a highly modified toaster oven in Wyzcrak's basement.

  • #2
    Re: My Computer always displays on startup?

    Did you try going into safe-mode? Maybe you can spot something in there that your not getting?
    Oyee

    Comment


    • #3
      Re: My Computer always displays on startup?

      Can you export and post these two keys here?

      HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run
      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
      Battlefield Admin() ()
      [volun2][medic][defense3][eng2][support]
      [sg-c1][gchq-c1][tog-c1][ma-c1][taw-c1][tg-c2]
      | for | |

      Comment


      • #4
        Re: My Computer always displays on startup?

        Originally posted by perry
        HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run
        Empty.
        Originally posted by perry
        HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
        Code:
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
        "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
        "IgfxTray"="C:\\WINNT\\System32\\igfxtray.exe"
        "HotKeysCmds"="C:\\WINNT\\System32\\hkcmd.exe"
        "AdaptecDirectCD"="C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe"
        "vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
        "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
        "GWMDMMSG"="GWMDMMSG.exe"
        "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
        
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AutorunsDisabled]
        "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
        
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
        
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
        "Installed"="1"
        
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
        "Installed"="1"
        "NoChange"="1"
        
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
        "Installed"="1"
        Steam Community? Add me. | Free Remote, Encrypted Backup

        Darkilla: In short, NS is pretty much really fast chess. With guns. Apophis: I haven't seen anyone say that SM's are better than non-SMs. Nordbomber: This is THE first server I've seen where either side can comeback from out of seemingly nowhere with the right teamwork. en4rcment: I have NEVER experienced the type of gameplay that I have found here. Nightly I am amazed at the personalities and gaming talent. Zephyr: Apophis is clearly a highly sophisticated self-aware AI construct that runs on a highly modified toaster oven in Wyzcrak's basement.

        Comment


        • #5
          Re: My Computer always displays on startup?

          Startup data from msinfo32:

          ---

          Code:
            [Startup Programs]
            
            Program
          Command
          User Name
          Location
          
            desktop
          desktop.ini
          NT AUTHORITY\SYSTEM
          Startup
          
            desktop
          desktop.ini
          DRAGONFIRE\Owner
          Startup
          
            desktop
          desktop.ini
          .DEFAULT
          Startup
          
            desktop
          desktop.ini
          All Users
          Common Startup
          
            SynTPLpr
          c:\program files\synaptics\syntp\syntplpr.exe
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          
            SynTPEnh
          c:\program files\synaptics\syntp\syntpenh.exe
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          
            IgfxTray
          c:\winnt\system32\igfxtray.exe
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          
            HotKeysCmds
          c:\winnt\system32\hkcmd.exe
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          
            AdaptecDirectCD
          c:\program files\roxio\easy cd creator 5\directcd\directcd.exe
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          
            vptray
          c:\progra~1\symant~1\symant~1\vptray.exe
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          
            QuickTime Task
          "c:\program files\quicktime\qttask.exe" -atboottime
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          
            GWMDMMSG
          gwmdmmsg.exe
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          
            Windows Defender
          "c:\program files\windows defender\msascui.exe" -hide
          All Users
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
          Steam Community? Add me. | Free Remote, Encrypted Backup

          Darkilla: In short, NS is pretty much really fast chess. With guns. Apophis: I haven't seen anyone say that SM's are better than non-SMs. Nordbomber: This is THE first server I've seen where either side can comeback from out of seemingly nowhere with the right teamwork. en4rcment: I have NEVER experienced the type of gameplay that I have found here. Nightly I am amazed at the personalities and gaming talent. Zephyr: Apophis is clearly a highly sophisticated self-aware AI construct that runs on a highly modified toaster oven in Wyzcrak's basement.

          Comment


          • #6
            Re: My Computer always displays on startup?

            You can try Silent Runners. That will list all startup items, even the «hidden» ones.

            DB
            Last edited by Dick Blonov; 06-01-2006, 11:27 AM. Reason: Added ref to Autoruns entry

            «That looks like a really nice house except for that horrible bathroom.» Donrhos

            | |





            Comment


            • #7
              Re: My Computer always displays on startup?

              Here's the Silent Runners output. Man, that's a lot to look at:
              Code:
              "Silent Runners.vbs", revision 45, http://www.silentrunners.org/
              Operating System: Windows XP SP2
              Output limited to non-default values, except where indicated by "{++}"
              
              
              Startup items buried in registry:
              ---------------------------------
              
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
              "SynTPLpr" = "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" ["Synaptics, Inc."]
              "SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]
              "IgfxTray" = "C:\WINNT\System32\igfxtray.exe" ["Intel Corporation"]
              "HotKeysCmds" = "C:\WINNT\System32\hkcmd.exe" ["Intel Corporation"]
              "AdaptecDirectCD" = ""C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"" ["Roxio"]
              "vptray" = "C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" ["Symantec Corporation"]
              "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
              "GWMDMMSG" = "GWMDMMSG.exe" ["GTW"]
              "Windows Defender" = ""C:\Program Files\Windows Defender\MSASCui.exe" -hide" [MS]
              
              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
              {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
                -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                                 \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
              
              HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
              "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
                -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                                 \InProcServer32\(Default) = "C:\WINNT\System32\hticons.dll" ["Hilgraeve, Inc."]
              "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
                -> {HKLM...CLSID} = "Outlook File Icon Extension"
                                 \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
              "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
                -> {HKLM...CLSID} = (no title provided)
                                 \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
              "{5E44E225-A408-11CF-B581-008029601108}" = "Adaptec DirectCD Shell Extension"
                -> {HKLM...CLSID} = "Adaptec DirectCD Shell Extension"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\Roxio\EASYCD~1\DirectCD\Shellex.dll" ["Roxio"]
              "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
                -> {HKLM...CLSID} = "RealOne Player Context Menu Class"
                                 \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshellext.dll" ["RealNetworks"]
              "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
                -> {HKLM...CLSID} = "WinRAR"
                                 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
              "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
                -> {HKLM...CLSID} = "WinZip"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
              "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
                -> {HKLM...CLSID} = "WinZip"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
              "{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
                -> {HKLM...CLSID} = "WinZip"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
              "{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
                -> {HKLM...CLSID} = "WinZip"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
              "{BDA77241-42F6-11d0-85E2-00AA001FE28C}" = "LDVP Shell Extensions"
                -> {HKLM...CLSID} = "VpshellEx Class"
                                 \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
              "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
                -> {HKLM...CLSID} = "Portable Media Devices"
                                 \InProcServer32\(Default) = "C:\WINNT\system32\Audiodev.dll" [MS]
              "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
                -> {HKLM...CLSID} = "Portable Media Devices Menu"
                                 \InProcServer32\(Default) = "C:\WINNT\system32\Audiodev.dll" [MS]
              "{E8FAF807-ABD4-11D2-B14E-00C04F72C182}" = "Remote Computers"
                -> {HKLM...CLSID} = "Remote Computers"
                                 \InProcServer32\(Default) = "c:\program files\intuit\track-it! 6.5\technician client\Remote\\ircftran.dll" ["Intuit Track-It!"]
              "{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
                -> {HKLM...CLSID} = "Shell Search Band"
                                 \InProcServer32\(Default) = "C:\WINNT\system32\browseui.dll" [MS]
              "{e82a2d71-5b2f-43a0-97b8-81be15854de8}" = "ShellLink for Application References"
                -> {HKLM...CLSID} = "ShellLink for Application References"
                                 \InProcServer32\(Default) = "C:\WINNT\system32\dfshim.dll" [MS]
              "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}" = "Shell Icon Handler for Application References"
                -> {HKLM...CLSID} = "Shell Icon Handler for Application References"
                                 \InProcServer32\(Default) = "C:\WINNT\system32\dfshim.dll" [MS]
              
              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
              INFECTION WARNING! "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" = "Microsoft AntiMalware ShellExecuteHook"
                -> {HKLM...CLSID} = "Microsoft AntiMalware ShellExecuteHook"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\WINDOW~4\MpShHook.dll" [MS]
              
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
              INFECTION WARNING! "Shell" = "explorer.exe                                                                                                    "" [MS], [file not found]
              
              HKLM\System\CurrentControlSet\Control\Session Manager\
              INFECTION WARNING! "BootExecute" = "autocheck autochk * sprestrt" [file not found], [MS], [file not found], [file not found]
              
              HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
              INFECTION WARNING! igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]
              INFECTION WARNING! NavLogon\DLLName = "C:\WINNT\System32\NavLogon.dll" [null data]
              INFECTION WARNING! WgaLogon\DLLName = "WgaLogon.dll" [MS]
              
              HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
              LDVPMenu\(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}"
                -> {HKLM...CLSID} = "VpshellEx Class"
                                 \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
              WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                -> {HKLM...CLSID} = "WinRAR"
                                 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
              WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
                -> {HKLM...CLSID} = "WinZip"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
              
              HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
              WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                -> {HKLM...CLSID} = "WinRAR"
                                 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
              WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
                -> {HKLM...CLSID} = "WinZip"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
              
              HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
              LDVPMenu\(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}"
                -> {HKLM...CLSID} = "VpshellEx Class"
                                 \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"]
              WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                -> {HKLM...CLSID} = "WinRAR"
                                 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
              WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
                -> {HKLM...CLSID} = "WinZip"
                                 \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
              
              
              Default executables:
              --------------------
              
              HKLM\Software\Classes\.hta\(Default) = (value not set)
              
              
              Active Desktop and Wallpaper:
              -----------------------------
              
              Active Desktop is disabled at this entry:
              HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
              
              HKCU\Control Panel\Desktop\
              "Wallpaper" = "C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp"
              
              
              Enabled Screen Saver:
              ---------------------
              
              HKCU\Control Panel\Desktop\
              "SCRNSAVE.EXE" = "C:\WINNT\System32\logon.scr" [MS]
              
              
              Enabled Scheduled Tasks:
              ------------------------
              
              "MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]
              
              
              Winsock2 Service Provider DLLs:
              -------------------------------
              
              Namespace Service Providers
              
              HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
              000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
              000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
              000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
              
              Transport Service Providers
              
              HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
              0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
              %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 35
              %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
              
              
              Toolbars, Explorer Bars, Extensions:
              ------------------------------------
              
              Explorer Bars
              
              HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\
              {4528BBE0-4E08-11D5-AD55-00010333D0AD}\(Default) = (no title provided)
                -> {HKLM...CLSID} = "&Yahoo! Messenger"
                                 \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll" ["Yahoo! Inc."]
              
              HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
              {4528BBE0-4E08-11D5-AD55-00010333D0AD}\(Default) = (no title provided)
                -> {HKLM...CLSID} = "&Yahoo! Messenger"
                                 \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll" ["Yahoo! Inc."]
              
              Extensions (Tools menu items, main toolbar menu buttons)
              
              HKLM\Software\Microsoft\Internet Explorer\Extensions\
              {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
              "MenuText" = "Sun Java Console"
              "CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}"
                -> {HKLM...CLSID} = "Web Browser Applet Control"
                                 \InProcServer32\(Default) = "C:\WINNT\System32\msjava.dll" [MS]
              
              {4528BBE0-4E08-11D5-AD55-00010333D0AD}\
              "ButtonText" = "Messenger"
              "MenuText" = "Yahoo! Messenger"
              "CLSIDExtension" = "{4C171D40-8277-11D5-AD55-00010333D0AD}"
                -> {HKLM...CLSID} = (no title provided)
                                 \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll" ["Yahoo! Inc."]
              
              {AC9E2541-2814-11D5-BC6D-00B0D0A1DE45}\
              "ButtonText" = "AIM"
              "Exec" = "C:\Program Files\AIM\aim.exe" ["America Online, Inc."]
              
              {CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\
              
              {FB5F1910-F110-11D2-BB9E-00C04F795683}\
              "ButtonText" = "Messenger"
              "MenuText" = "Windows Messenger"
              "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
              
              
              Running Services (Display Name, Service Name, Path {Service DLL}):
              ------------------------------------------------------------------
              
              Belkin 54g Wireless USB Network Adapter, Belkin 54g Wireless USB Network Adapter Service, "C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe" [null data]
              DefWatch, DefWatch, "C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe" ["Symantec Corporation"]
              Machine Debug Manager, MDM, ""C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"" [MS]
              PrismXL, PrismXL, "C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS" ["Lanovation"]
              Retrospect Launcher, RetroLauncher, "C:\Program Files\Dantz\Retrospect\retrorun.exe" ["Dantz Development Corporation"]
              Retrospect WD Service, RetroWDSvc, "C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe" ["Dantz Development Corporation"]
              Symantec AntiVirus Client, Norton AntiVirus Server, "C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe" ["Symantec Corporation"]
              Windows Defender Service, WinDefend, ""C:\Program Files\Windows Defender\MsMpEng.exe"" [MS]
              Windows User Mode Driver Framework, UMWdf, "C:\WINNT\system32\wdfmgr.exe" [MS]
              
              
              Print Monitors:
              ---------------
              
              HKLM\System\CurrentControlSet\Control\Print\Monitors\
              PrimoMon\Driver = "Primomonnt.dll" [null data]
              
              
              ----------
              + This report excludes default entries except where indicated.
              + To see *everywhere* the script checks and *everything* it finds,
                launch it from a command prompt or a shortcut with the -all parameter.
              + The search for DESKTOP.INI DLL launch points on all local fixed drives
                took 167 seconds.
              + The search for all Registry CLSIDs containing dormant Explorer Bars
                took 17 seconds.
              ---------- (total run time: 244 seconds)
              Steam Community? Add me. | Free Remote, Encrypted Backup

              Darkilla: In short, NS is pretty much really fast chess. With guns. Apophis: I haven't seen anyone say that SM's are better than non-SMs. Nordbomber: This is THE first server I've seen where either side can comeback from out of seemingly nowhere with the right teamwork. en4rcment: I have NEVER experienced the type of gameplay that I have found here. Nightly I am amazed at the personalities and gaming talent. Zephyr: Apophis is clearly a highly sophisticated self-aware AI construct that runs on a highly modified toaster oven in Wyzcrak's basement.

              Comment


              • #8
                Re: My Computer always displays on startup?

                That registry entry :HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
                INFECTION WARNING! "Shell" = "explorer.exe "" [MS], [file not found]

                Is wrong (that is why it is flagged as infection warning). This value is not supposed to appear in the report.

                The correct value is:"Shell"="Explorer.exe"

                Registry corruption maybe ?

                Also, can you look for the following file: sprestrt.exe in c:\windows\system32. Should be an MS file, 9278 bytes in length.

                While you're at it, could you do a search for files called «explorer». Legit places are \c:windows, c:\windows\system32\dllcache and C:\WINDOWS\$NtServicePackUninstall$.


                DB
                Last edited by Dick Blonov; 06-01-2006, 02:54 PM.

                «That looks like a really nice house except for that horrible bathroom.» Donrhos

                | |





                Comment


                • #9
                  Re: My Computer always displays on startup?

                  c:\winnt\system32\sprestrt.exe 9728 bytes in length.

                  explorer.exe is found only in:
                  c:\winnt
                  c:\winnt\ServicePackFiles\i386

                  interesting existances:
                  c:\winnt\prefetch\explorer.exe-28ce6f94.pf
                  c:\i386\explorer.ex_
                  Steam Community? Add me. | Free Remote, Encrypted Backup

                  Darkilla: In short, NS is pretty much really fast chess. With guns. Apophis: I haven't seen anyone say that SM's are better than non-SMs. Nordbomber: This is THE first server I've seen where either side can comeback from out of seemingly nowhere with the right teamwork. en4rcment: I have NEVER experienced the type of gameplay that I have found here. Nightly I am amazed at the personalities and gaming talent. Zephyr: Apophis is clearly a highly sophisticated self-aware AI construct that runs on a highly modified toaster oven in Wyzcrak's basement.

                  Comment


                  • #10
                    Re: My Computer always displays on startup?

                    It is a laptop you say, could it have something to do with Hibernation and it messing up and saving the my computer? Worth a check

                    |TG-12th| Troublesome4u

                    Comment


                    • #11
                      Re: My Computer always displays on startup?

                      How would one check that?
                      Steam Community? Add me. | Free Remote, Encrypted Backup

                      Darkilla: In short, NS is pretty much really fast chess. With guns. Apophis: I haven't seen anyone say that SM's are better than non-SMs. Nordbomber: This is THE first server I've seen where either side can comeback from out of seemingly nowhere with the right teamwork. en4rcment: I have NEVER experienced the type of gameplay that I have found here. Nightly I am amazed at the personalities and gaming talent. Zephyr: Apophis is clearly a highly sophisticated self-aware AI construct that runs on a highly modified toaster oven in Wyzcrak's basement.

                      Comment


                      • #12
                        Re: My Computer always displays on startup?

                        Originally posted by Wyzcrak
                        c:\winnt\system32\sprestrt.exe 9728 bytes in length.

                        explorer.exe is found only in:
                        c:\winnt
                        c:\winnt\ServicePackFiles\i386

                        interesting existances:
                        c:\winnt\prefetch\explorer.exe-28ce6f94.pf
                        c:\i386\explorer.ex_
                        That looks OK.

                        Have you changed HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ "Shell"


                        ( I don't think this is what is causing the problem, but it should be corrected) ?

                        «That looks like a really nice house except for that horrible bathroom.» Donrhos

                        | |





                        Comment


                        • #13
                          Re: My Computer always displays on startup?

                          That happens to me occasionally, I think it just opens up whatever you were working on when you shut down. If I have the explorer window open when I shutdown, the next time I start, it pops up.

                          Comment


                          • #14
                            Re: My Computer always displays on startup?

                            bd5, that doesn't apply here. See first post.

                            Dick, yes. The change affected nothing.
                            Steam Community? Add me. | Free Remote, Encrypted Backup

                            Darkilla: In short, NS is pretty much really fast chess. With guns. Apophis: I haven't seen anyone say that SM's are better than non-SMs. Nordbomber: This is THE first server I've seen where either side can comeback from out of seemingly nowhere with the right teamwork. en4rcment: I have NEVER experienced the type of gameplay that I have found here. Nightly I am amazed at the personalities and gaming talent. Zephyr: Apophis is clearly a highly sophisticated self-aware AI construct that runs on a highly modified toaster oven in Wyzcrak's basement.

                            Comment


                            • #15
                              Re: My Computer always displays on startup?

                              Originally posted by Wyzcrak
                              bd5, that doesn't apply here. See first post.

                              Dick, yes. The change affected nothing.
                              This is the next one that I would fix:

                              HKLM\System\CurrentControlSet\Control\Session Manager\
                              INFECTION WARNING! "BootExecute" = "autocheck autochk * sprestrt" [file not found], [MS], [file not found], [file not found]

                              Normally, the value BootExecute is: "autocheck autochk *"



                              Can you check it again ?

                              DB

                              «That looks like a really nice house except for that horrible bathroom.» Donrhos

                              | |





                              Comment

                              Connect

                              Collapse

                              TeamSpeak 3 Server

                              Collapse

                              Advertisement

                              Collapse

                              Twitter Feed

                              Collapse

                              Working...
                              X