Read the links in the following Google search for more info on the " O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe" problem:
http://www.google.com/search?hl=en&ie=UTF-8&q=sysupd.exe&btnG=Google+Search
Have HJT fix the following entries:
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKLM\..\Run: [ONhcKo] C:\documents and settings\rob\local settings\temp\ONhcKo.exe
Reboot into safe mode and:
- Delete C:\WINDOWS\sysupd.exe
- Delete the entire contents of C:\documents and settings\rob\local settings\temp\ (do this for any other user accounts you might have as well)
- In your Internet Options control panel:
Delete all cookies
Delete all Temporary Internet filess, including "offline content"
- Empty your Recycle Bin
- reboot
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
I don't see anything suspicious in your new log; is there a chance the problem is not malware-related? It could be something going on with your network/Internet connection, a problem on your ISP's end, etc.
You could try downloading a different browser (Netscape, Opera, or Firefox) to see if the problem is specific to IE or not.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
When I try to access my itunes.com music store, it comes up empty as well; with an error message.
What is theexact error?
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
This needs to go. O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE will be in either C:\Windows or C:\Windows\system32 folder. Make sure all programs are set to run in Msconfig, reboot then rescan with HJT (Get the latest version first) & post back.
Start/Run & type in *Msconfig* go to startup tab & *check* all boxes.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
The " O4 - HKLM\..\Run:" entries that you see in the HJT log are programs that have inserted themselves into your system's registry in such a way that they are automagically started each time you boot your computer. To find/view/edit/delete these entries:
Choose "run" under your Start menu and type "regedit" (omit the quotes) in the resulting dialog box; this will open the registry editor. In the registry editor, navigate to HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run. Do not make any deletes/changes here unless you know what you're doing or have been given specific instructions! Many of these "autostarted" programs will be legit, but "malware" programs can insert themselves there as well.
When you ask HJT to fix "04" entries, it will only remove the registry values which start these programs, but it will not delete the offending programs themselves- hence the need to "fix" the entries with HJT and then reboot. In other words, HJT will remove the "autostart" registry entries so that the program will not start the next time you boot, which should (because the program has not been "asked" to run at startup) allow you to delete it.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
This needs to go. O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE...
Not sure about that Chris- that particular file is a valid part of the Realtek AC97 sound driver package.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Based on the following info, I always remove it. Maybe I should insert that it be a user's choice??
From sysinfo:
ALCXMNTR.EXE
Realtek AC97 Audio - Event Monitor. Sypware file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but is being used by Realtek to gather data about customers
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Ah, I see.
I've never seen a description of that little piece of its functionality before. I knew it was an optional component, but I didn't know it "phoned home" to Realtek. If true, I guess that does make it spyware.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370