Mysterious RunOnce Startup Registries

Sunrise12

New member
Member
Local time
8:05 PM
Messages
62
Something strange thing happened to my computer today, and I am hoping for feedback from techies here.

WinPatrol alerted me of new RunOnce Startup items and then my computer froze. I was offline when this happened and do not use that computer to go online for surfing or anything.

I was able to get back into my computer but unable to delete the "hidden" registry files that were still appearing in WinPatrol.

I tried to log in as the admin -- still offline -- and the screen was frozen and black; no luck.

But I was able to log in with another account and discovered that the mysterious registries were gone. When I logged in again under my usual account, WinPatrol even alerted me that they were gone.

My security programs did not find anything suspicious. Everything appears to be fine.

I found the following snippet on patchmanagement.org that matched my situation:

The RunOnce registry key is getting populated with the following content on some computers:

MSPCLOCK=rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
MSPQM=rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
MSKSSRV=rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
MSTEE.CxTransform=rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install
MSTEE.Splitter=rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install
WDM_DRMKAUD=rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD.Interface.Install
 

My Computer My Computer

OS
Win 7 64
Okay, thanks. But why would all of that suddenly populate like that and crash my computer?

When it happened, I was testing a basic web page locally in Firefox while offline but that should not have caused any issues. Perhaps something in Firefox triggered the problem.

The closest thing that I found on Google was here but (that does not really clarify it for me):

http://permalink.gmane.org/gmane.comp.security.patch-managment/2659

I do not use Gmane, which I guess is a program or OS, unless I am missing something and it is a kernel or something that is used in Windows 7.

Should I move on and hope it never happens again or get other software to evaluate whether something bad happened?
 

My Computer My Computer

OS
Win 7 64
Do you use any other Security Software ? ....
 

My Computer My Computer

Computer Manufacturer/Model Number
W530-3630QM1
OS
windows 7 home 64bit
CPU
INTEL-CORE I7
Memory
16GB
Hard Drives
750GB
Browser
Chrome
I am trying not to panic and assume it was some kind of malware (that was not picked up my antivirus software).

I found an article that makes me feel a little about it on a forum at thewindowsclub.com that claimed it is related to a MS security patch from October 2008. It described the exact same issue that I ran into with the WinPatrol alerts.

Not sure why it suddenly was triggered again in November 2014.
 

My Computer My Computer

OS
Win 7 64
See if Malwarebytes finds any thing ... There is not much Information about the issue on the Web ... There is a couple of Members here that use WinPatrol do not think they have has any issues though ..
 

My Computer My Computer

Computer Manufacturer/Model Number
W530-3630QM1
OS
windows 7 home 64bit
CPU
INTEL-CORE I7
Memory
16GB
Hard Drives
750GB
Browser
Chrome
I used to use Malwarebytes and have an old version of it and should update it and use it again. That is a good suggestion and would not hurt.

I did not like how I have to give Malwarebytes permission to run with my Admin account every time I want to use it. The other programs never ask me to do that. (Other than that, I liked it.)
 

My Computer My Computer

OS
Win 7 64
Yes i have that issue also ... Have not had any Problems with the new Version of Malwarebytes either ...
 

My Computer My Computer

Computer Manufacturer/Model Number
W530-3630QM1
OS
windows 7 home 64bit
CPU
INTEL-CORE I7
Memory
16GB
Hard Drives
750GB
Browser
Chrome
Some times this helps.

Right tick on program.
Select Properties/Advanced and you will see a box for Run as Administrator.
Some time when you install a program it will give a option for all users.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
I don't remember but maybe it's different with the old Malwarebytes version, and the free new version, but I never get UAC prompts with the latest premium version. mbam.exe starts automatically at startup with Integrity = High, and not Medium like most other programs.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
I don't have that problem with Malwarebytes either but some might for what ever reason.
That is why I gave other things one may try.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
I have not tried it in a long time and should install the newest version and run it.
 

My Computer My Computer

OS
Win 7 64
I running version 2.0.3.1025 on three systems and they are working as they should.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
I ran Malwarebytes and it did not find anything suspicious.
 

My Computer My Computer

OS
Win 7 64
That would seem to be good news ...
 

My Computer My Computer

Computer Manufacturer/Model Number
W530-3630QM1
OS
windows 7 home 64bit
CPU
INTEL-CORE I7
Memory
16GB
Hard Drives
750GB
Browser
Chrome
Because you found this on the internet about someone else computer means absolutely nothing. Every computer is different and different circumstances.

You can find millions of such things on the internet about someone else computer.
We need to make sure you are clean.

Did you run Malwarebytes and have rootkit selected?
If not I would suggest doing so. The scan does take some time.

I would also recommend going into msconfig/Start and Services (non Microsoft services) and see if you have programs that might be scanning or updating on boot.

If you need instructions how to do these things just ask.
We have many members that can give guidance.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Yes, I know how to view the services to view the Startup programs.

I can also view them from WinPatrol that shows me Startup programs and Delayed Start programs and Hidden Files as well as services, etc.

There are some non-MS programs in the list but they do not look suspicious.

I ran Malwarebytes with the rootkit scan and it was clean.

I also ran AVG and and SuperAntiSpyware and the results were clean with them too.

I think something quirky happened that might have been triggered by one of my actions. So, I am betting -- and hoping -- that it is nothing to worry about.
 

My Computer My Computer

OS
Win 7 64
After running all those security scans I agree that your system is clean.
I haven't used WinPatrol in so many years I can't remember what all the program does.

You are happy with your system that's all that counts.
If you have anymore problems we are open 24-7-365
Happy computing.
 
Last edited:

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Back
Top