Hi,
Looks like that entry is back - Spybot probably brought it back when you re-enabled it. Did you get any prompts for registry changes when you enabled Spybot? If so, please disable it, fix that item in HijackThis and the enable it. If it prompt a registry change, allow it. Post a new HijackThis log after that.
Everything else looks fine.
Thanks.
Actually, that registry entry only shows up in Hijackthis after I re-enable Spybot's TeaTimer, and it disappears whenever I disable it. Maybe there is a way to flush it out of TeaTimer, or should I avoid using TeaTimer completely?
If you fix the item when TeaTimer is enabled do you get a prompt from Spybot about a registry change? If so, Allow that change. If not, I will have to do some research as I am not a Spybot user.
Whenever I fix the entry in Hijackthis, close it, and run Hijack again, it pops back up. I am no longer getting any prompts from Spybot or WinPatrol, so I'm guessing the entry has either been disabled or is laying dormant for some reason.
OK, new plan, let's use Spybot to remove the entry - then it can't complain
Open Spybot. Click Mode >>Advanced Mode and hit Yes at the prompt. Click the Tools bar in the left-hand pane, and click on System Startup You see an item on the list that looks familiar, something like: HK_CU:Run (Current System) 32NFG94-H61-2SF-N1P-5M1ERH6L6 c:\recycler\s-1-5-21-2727286392-8143256373-342365730-5195\winIgn.exe
Uncheck this item. If WinPatrol prompts a change, Allow it. Click Mode >> Default Mode and then exit Spybot.