playing around with this computer someone left to be recycled; after running hjt, killing some processes that were with IE, some browser helper object with no names etc just to see if it was worth saving. For some reason the still image monitor was set to load with IE after changing websites, maybe it was normal?? or related to one of the no-name bhos?
When I vissited this site and other forum sites on that computer I found that stimon.exe was loading under internet explorer?
Found some run settings in the registry that kept bringing up still image monitor and sti_trace.log along with stimon, so I removed them from the registry, I don't hook a camera or scanner directly to the computer so I don't need stimon, so it should have been no issues to turn off the monitor for those devices.
The weird thing is, after these subtle changes there's more hard drive noise for longer periods of time durring boot up and while changing websites.
I checked out what files were being accessed and found internet explorer spending an awefull long time messing with index.bat, Couldn't get the file monitor to load before the OS so I don't know whats taking so long to boot..
Anyway I did a quick google search to check into index.bat and found it to be an ultra hidden, track everything you do on your computer, log file... so I found a utility to see what's in the index.bat files to verify if what I saw on the internet was actually true that index.bat keeps a log as detailed as the registry.. Suprized to see that yes, it tracks every site you go to on the web, every file you access, all your recently used applications, documents, downloads etc...... It's basically an INDEX like in a book of everything you did on the computer
I found a program out there that over-writes random charactors to the index.bat file but thats not my intention, I want to keep the amount of drive space used to a minimum, so I'm trying to eliminate anything other than essential files for the os, and applications "it's a small drive"
Another strange thing is shortly after seeing that there wasn't much space for a swap file and the os, I installed another drive just for the swap file and installed one or two applications into the swap file drive, then let windows manage the swap file "virtual memory" Everything was going well then I noticed a "you are running out of space on drive "something" I was like NO! it's empty!!!! I checked it out and found a new _restore folder show up on the swap file drive, even though restore had been disable before installing the swap file drive!!! the new _restore folder filled up 1.8 gigs of the swap drive and windows only had like 82 megs for a swap file! I didn't even bother to look inside the restore folder, just deleted the whole thing but still thinking that is very strange since _restore is turned off in windows. Very strange PC!
I scanned with three antivirus programs that are said to be up to date, run spybot search and destroy and hijack this and find nothing remarkable other than a proxyoverride set to local loopback... I'm guessing there's something higher up the foodchain going on with this computer and that there's a new bigbrother policy to limmit the function of certain anti-spy/anti-virus programs that used to be independant applications that are now part of a consortium in cahoots with microsoft... oh yeah love the conspiracy theory stuff :P


Reply With Quote