Yes without question get rid of this one. As far as I can tell the rest
looks reasonable.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run sys regedit -s sys.reg
All Users
--
Regards,
Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft MVP [Windows]
Microsoft Certified Professional [Windows 2000]
http://www.microsoft.com/protect
| Hi Dave and thanks so much again for time. I listed what
| is in the startup under each logon situation and indeed
| the command 'regedit -s sys.reg' is present in both lists.
| When I entered the command manually with restricted user
| attributes it did indeed cause the same error. Would you
| mind glancing at the contents of the 2 lists to see if you
| see anything suspicious in addition. Any reason I
| shouldn't just delete the entry from startup or is it
| providing a necessary function?
|
|
| From logon Robert attrib 'restricted user'
|
| Program Command User Name Location
| Billminder c:\progra~1\billmind.exe
| FM9Y10B\****************** Startup
| uoltray c:\program files\netzero\exec.exe regrun
| FM9Y10B\****************** HKU\S-1-5-21-
| 343818398-1708537768-1801674531-1000
| \SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| Adobe Gamma Loader c:\progra~1\common~1\adobe\calibr~1
| \adobeg~1.exe All Users Common Startup
| Synchronization Manager mobsync.exe /logon All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| Matrox Powerdesk c:\winnt\system32
| \pdesk\pdesk.exe /autolaunch All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| Ink Monitor c:\program files\epson\ink
| monitor\inkmonitor.exe All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| NeroCheck c:\winnt\system32\nerocheck.exe All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| InCD c:\program files\ahead\incd\incd.exe All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| RealJukeboxSystray "c:\program
| files\real\realjukebox\tsystray.exe" All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| sys regedit -s sys.reg All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| RealTray c:\program files\realaudio8.0\realplayer8.0
| \realplay.exe systemboothideplayer All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| ccApp "c:\program files\common files\symantec
| shared\ccapp.exe" All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
|
|
| From logon as administrator:
|
| Program Command User Name Location
| Adobe Gamma Loader c:\progra~1\common~1\adobe\calibr~1
| \adobeg~1.exe All Users Common Startup
| Synchronization Manager mobsync.exe /logon All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| Matrox Powerdesk c:\winnt\system32
| \pdesk\pdesk.exe /autolaunch All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| Ink Monitor c:\program files\epson\ink
| monitor\inkmonitor.exe All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| NeroCheck c:\winnt\system32\nerocheck.exe All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| InCD c:\program files\ahead\incd\incd.exe All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| RealJukeboxSystray "c:\program
| files\real\realjukebox\tsystray.exe" All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| sys regedit -s sys.reg All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| RealTray c:\program files\realaudio8.0\realplayer8.0
| \realplay.exe systemboothideplayer All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
| ccApp "c:\program files\common files\symantec
| shared\ccapp.exe" All Users
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
|
| Regards,
| Robert