registry changes detected at startup

Hello. I’m seeing some strange registry changes that Spybot’s TeaTimer resident task detects at startup. Every time I boot up or restart, the TeaTimer task always pops up with a registry change alert window. I forget exactly what the window says, but I do have the record entry on hand. It is:

1/31/06 1:48:17 AM Allowed value “wextract_cleanup0” (new data: "rundll32.exe C:\WINDOWS\SYSTEM\advpack.dll,DelNodeRunDLL32 “C:\WINDOWS\TEMP\IXP000.TMP"”) added in System Startup global entry!

I don’t know what’s causing it, although I have a good clue as to what it might be. Over the day I was installing and removing a few audio and video codecs, and a couple of them used some sort of installer program. It could have been one of those, but like I say, I’m not sure. The codecs I’ve been downloading have been from www.free-codecs.com.

Anybody know what would be causing this registry change and how to stop it?

Check this google search result wextract_cleanup0 there are many, many hits does it cast any light on it.
This is just one, which seems similar to yours:
http://forums.techguy.org/security/434107-solved-winfixer-vundo-infection.html

Also useful as a diagnostic tool - Download HiJackThis.zip - HJT Information HiJackThis Tutorial 1 or HiJackThis Tutorial 2
For an on-line analysis - HiJackThis Log file - On-line Analysis OR HiJackThis Log file - On-line Analysis 2
Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.
OR - Post your hijackthis-Log here for a diagnosis: tomcoyote.org/hjt

:slight_smile: Hi Heehaw :

 Why don't you ask the Spybot Experts on THEIR forums
 at :  http://forums.spybot.info