Elmo said:
Run Msconfig, open the Startup folder and see if the entries are there.
If so, try deselecting them there. When you restart the computer, you
will be asked if you want to run in Diagnostic Mode. Answer yes, and
check the box so you aren't asked at each boot.
Autoruns might do something for you too, though I've never tried it.
39. AutoRuns - All Programs Running Boot/Login
http://www.kellys-korner-xp.com/xp_tweaks.htm
I will need more directions, sorry I'm unfamiliar with it but if I do the
Msconfig thing and once I enter the Diagnostic mode, where do I go from there?
By reading at similar threads I found and tried something called
(StartupTracker3) I think is similar to what you are suggesting (Autoruns).
After runing StartupTracker3 in the resulting startuplog under Registry
Items you will notice there is a:
BMaac9df33 Rundll32.exe "C:\WINNT\system32\ojncembx.dll",s
And under running processes:
rundll32.exe "C:\WINNT\system32\Rundll32.exe"
"C:\WINNT\system32\ojncembx.dll",s
Under running Services:
None
Here is the complete part of the log report:
##############################################
8/24/2008 6:37:34 PM
-- Registry --
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
No Items Found
-- Registry --
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager mobsync.exe /logon
NvCplDaemon RUNDLL32.EXE
C:\WINNT\system32\NvCpl.dll,NvStartup
nwiz nwiz.exe /install
vptray C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
NeroFilterCheck C:\WINNT\system32\NeroCheck.exe
Adobe Reader Speed Launcher "C:\Program Files\Adobe\Reader
8.0\Reader\Reader_sl.exe"
zBrowser Launcher C:\Program Files\Logitech\iTouch\iTouch.exe
InCD C:\Program Files\Ahead\InCD\InCD.exe
QuickTime Task "C:\Program Files\QuickTime\qttask.exe"
-atboottime
NvMediaCenter RUNDLL32.EXE
C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
SystemTray SysTray.Exe
BMaac9df33 Rundll32.exe "C:\WINNT\system32\ojncembx.dll",s
TraySantaCruz C:\WINNT\system32\tbctray.exe
-- Registry --
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
No Items Found
-- Registry --
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
NBJ "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
ctfmon.exe C:\WINNT\system32\ctfmon.exe
-- Registry --
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce
^SetupICWDesktop C:\Program Files\Internet Explorer\Connection
Wizard\icwconn1.exe /desktop
-- Registry --
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run
No Items Found
-- Start Menu - Current User --
No Items Found
-- Start Menu - All Users --
Adobe Gamma Loader.lnk
Microsoft Office.lnk
-- Disabled Items --
No Items Found
-- Registry - Shell Value - HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon --
Explorer.exe
-- Running Processes --
System Idle Process
System
smss.exe \SystemRoot\System32\smss.exe
csrss.exe
winlogon.exe winlogon.exe
services.exe C:\WINNT\system32\services.exe
lsass.exe C:\WINNT\system32\lsass.exe
svchost.exe C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
svchost.exe C:\WINNT\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
spoolsv.exe C:\WINNT\system32\spoolsv.exe
DefWatch.exe "C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\DefWatch.exe"
InCDsrv.exe "C:\Program Files\Ahead\InCD\InCDsrv.exe"
Rtvscan.exe "C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\Rtvscan.exe"
nvsvc32.exe C:\WINNT\system32\nvsvc32.exe
svchost.exe C:\WINNT\system32\svchost.exe -k imgsvc
alg.exe
explorer.exe C:\WINNT\Explorer.EXE
VPTray.exe "C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe"
reader_sl.exe "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
iTouch.exe "C:\Program Files\Logitech\iTouch\iTouch.exe"
InCD.exe "C:\Program Files\Ahead\InCD\InCD.exe"
rundll32.exe "C:\WINNT\system32\RUNDLL32.EXE"
C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
rundll32.exe "C:\WINNT\system32\Rundll32.exe"
"C:\WINNT\system32\ojncembx.dll",s
tbctray.exe "C:\WINNT\system32\tbctray.exe"
ctfmon.exe "C:\WINNT\system32\ctfmon.exe"
StartupTracker3.exe "C:\StartupTracker3\StartupTracker3.exe"
wmiprvse.exe
##############################################