Author Topic: Documents and Settings problems again/still  (Read 3810 times)

Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« on: October 14, 2007, 11:45:31 PM »
Me yet again,

I had written about a problem that nobody seemed to know anything about and it seems to be spreading.  Previously, when I would go into the Documents and Settings folder and open the All Users folder, it would open then almost immediately I would get the error report telling me IE has to shut down.  Now it is doing it when I open the Home folder.  I am running Windows XP home edition with SP2 and have gotten all the updates that I know about.  I also update and run Spybot Seek and Destroy weekly.  I also used to like House Call, but lately its getting on my nerves...its listing problems with two of my Office Suite programs (Word and Publisher) but tells me I have to manually remove them, when I click on the link to learn how to do that, my pop-up blocker is activated.  when I click to allow the pop-up, the whole damn thing starts over again and I am expected to wait another 45 minutes for it to run through its scan!  In any event, it doesn't seem to find any viruses!

So back to the main problem, this is getting real irritating...I want it to stop and don't want to have to resort to a total re-load of Windows.  I've also gotten a few Dr. Watson error reports when this happens.  i finally discovered that Dr. Watson is an actual Microsoft product but don't ever remember loading it.  I also checked running processes and the thing is listed 3 times!  Is there a reason that thing seems to have 3 seperate runing processes???  Also:  I was told by a friend that AVG free Ant-Virus is itself spyware.  any truth to that story?

Here is my latest hijack this report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:51:34 PM, on 10/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.Email Removed.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1191534961265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downl...eCallButton.CAB
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Email Removed Attachments Control) - http://by9fd.bay9.Email Removed.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF7420D7-D241-4731-A40D-69C2ECB429F0}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

--
End of file - 4848 bytes
« Last Edit: October 15, 2007, 12:00:46 AM by djkwik »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #1 on: October 15, 2007, 12:44:14 AM »
Quote
AVG free Ant-Virus is itself spyware
I've never heard that before, I would like to see proof
I have it installed on one of my computers and never here arguments from my spyware scanners that AVG is spyware?

Is that why you no longer have it installed?
I would go back and immediately reinstall the free version if that's what you used

Also, can you post a different log
If you have an older version of Combofix>>delete it
Download this file - Combofix.exe and save it ONLY to your desktop
Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Post the log from Combofix please
It's default location is C:\Combofix.txt

Also, what happened when you went to safe mode and signed in with the Adminstrator account
Did you have problems accessing your folders?
Any other user profiles on this computer?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #2 on: October 19, 2007, 09:58:57 AM »
[quote name=\'guestolo\' post=\'397032\' date=\'Oct 15 2007, 12:44 AM\']I've never heard that before, I would like to see proof
I have it installed on one of my computers and never here arguments from my spyware scanners that AVG is spyware?

Is that why you no longer have it installed?
I would go back and immediately reinstall the free version if that's what you used

Also, can you post a different log
If you have an older version of Combofix>>delete it
Download this file - Combofix.exe and save it ONLY to your desktop
Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Post the log from Combofix please
It's default location is C:\Combofix.txt

Also, what happened when you went to safe mode and signed in with the Adminstrator account
Did you have problems accessing your folders?
Any other user profiles on this computer?[/quote]

I did reinstall the latest version of AVG and ran the full system scan...it found nothing.

Please remind me how to log in under safe mode.

Here is the Combo-fix log....

ComboFix 07-10-19.1 - home 2007-10-19  9:49:26.1 - NTFSx86
Script execution time was exceeded on script "C:\ComboFix\osid.vbs".
Script execution was terminated.
Running from: C:\Documents and Settings\home\Desktop\ComboFix.exe
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com

.
(((((((((((((((((((((((((   Files Created from 2007-09-19 to 2007-10-19  )))))))))))))))))))))))))))))))
.

2007-10-19 09:48   51,200   --a------   C:\WINDOWS\NirCmd.exe
2007-10-15 00:23   <DIR>   d--------   C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-15 00:23   <DIR>   d--------   C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-15 00:23   <DIR>   d--------   C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-15 00:23   <DIR>   d--------   C:\Documents and Settings\home\Application Data\AVG7
2007-10-15 00:22   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-14 23:51   <DIR>   d--------   C:\Program Files\Trend Micro
2007-10-09 14:45   <DIR>   d--------   C:\Program Files\Windows Media Connect 2
2007-10-09 14:43   <DIR>   d--------   C:\WINDOWS\system32\LogFiles
2007-10-09 14:43   <DIR>   d--------   C:\WINDOWS\system32\drivers\UMDF
2007-10-09 13:55   582,656   -----c---   C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-04 20:31   271,224   --a------   C:\WINDOWS\system32\mucltui.dll
2007-10-03 22:37   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Avg7
2007-10-03 22:30   <DIR>   d----c---   C:\WINDOWS\system32\DRVSTORE

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-16 19:51   ---------   d-----w   C:\Documents and Settings\home\Application Data\AdobeUM
2007-10-09 19:29   ---------   d-----w   C:\Program Files\SpywareBlaster
2007-10-04 03:45   ---------   d-----w   C:\Program Files\Lavasoft
2007-10-04 03:45   ---------   d-----w   C:\Documents and Settings\home\Application Data\Lavasoft
2007-10-04 03:08   ---------   d-----w   C:\Program Files\Yahoo!
2007-10-04 03:08   ---------   d-----w   C:\Documents and Settings\home\Application Data\Yahoo!
2007-10-04 03:08   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-01 13:00   ---------   d-----w   C:\Program Files\Java
2007-10-01 12:08   ---------   d-----w   C:\Program Files\Napster
2007-03-24 20:23   5,037,072   ----a-w   C:\Program Files\spybotsd14.exe
2006-02-19 20:12   2,566,736   ----a-w   C:\Program Files\spywareblastersetup351.exe
2005-03-11 14:19   2,177,752   ----a-w   C:\Program Files\radius.td3
2005-02-07 19:10   68,080   ----a-w   C:\Documents and Settings\home\Application Data\GDIPFONTCACHEV1.DAT
2004-03-05 18:37   15,228,464   ----a-w   C:\Program Files\j2re-1_4_2_03-windows-i586-p.exe
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-02-10 11:55]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-10 11:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-04-07 17:48]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-02-11 18:08]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-15 00:22]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"= C:\WINDOWS\system32\ieframe.dll [2007-08-20 05:04 6058496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
C:\Program Files\Browser MOUSE\mouse32a.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWBKEYBOARD]
C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
c:\Program Files\Microsoft Works\WkDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
C:\Program Files\Napster\napster.exe /systray

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ScsiAccess"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)


*Newly Created Service* - AVG7ALRT
*Newly Created Service* - AVG7CORE
*Newly Created Service* - AVG7RSXP
*Newly Created Service* - AVG7UPDSVC
*Newly Created Service* - AVGCLEAN
*Newly Created Service* - AVGEMS
*Newly Created Service* - AVGTDI
*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-19 09:53:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-19  9:55:01
.
   --- E O F ---

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #3 on: October 20, 2007, 03:19:16 PM »
combofix removed some files
Are you still having problems with your folders?

Let's see another couple logs please
Download [color=\"#008000\"]Deckard's System Scanner (dss.exe)[/color] to your desktop.
Close all applications and windows.
Double-click on dss.exe to run it and follow the prompts.
When the scan is complete, two text files will open; main.txt, which will be maximized and extra.txt, which will be minimized.

Post the contents of  main.txt and extra.txt

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #4 on: October 22, 2007, 01:16:20 PM »
[quote name=\'guestolo\' post=\'399103\' date=\'Oct 20 2007, 03:19 PM\']combofix removed some files
Are you still having problems with your folders?

Let's see another couple logs please
Download [color=\"#008000\"]Deckard's System Scanner (dss.exe)[/color] to your desktop.
Close all applications and windows.
Double-click on dss.exe to run it and follow the prompts.
When the scan is complete, two text files will open; main.txt, which will be maximized and extra.txt, which will be minimized.

Post the contents of  main.txt and extra.txt[/quote]


Yes, I still get the "windows Explorer Encountered a Problem and needs to shut down" when I went into Documents & Settings > Home.  Also, this time (and it's happened before) some of my desktop icons got moved around when it "refreshed" the desktop after closing the page.  Note:  I logged on in Safe Mode and was given a choice of Home or Administrator.  I chose Home...went to Documents & Settings > Home and did not get the error report.  When I turned off and logged back on in regular mode, I got an update notice immediately (even though I was no longer online) for Adobe reader.  I went online and downloaded the update, ran Windows Clean-Up and then came here.  This is driving me nuts.  i swear I am near ready to dump the PC altogether and get a Mac!  Bill Gates needs to be shot!  Here is the dss report:

Deckard's System Scanner v20071014.68
Run by home on 2007-10-22 13:05:08
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
67: 2007-10-22 18:05:27 UTC - RP1009 - Deckard's System Scanner Restore Point
66: 2007-10-22 17:09:37 UTC - RP1008 - System Checkpoint
65: 2007-10-21 16:17:13 UTC - RP1007 - System Checkpoint
64: 2007-10-20 15:09:38 UTC - RP1006 - System Checkpoint
63: 2007-10-19 14:48:48 UTC - RP1005 - ComboFix created restore point


-- First Restore Point --
1: 2007-08-27 15:38:15 UTC - RP943 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

[color=\"red\"]Total Physical Memory: 254 MiB (512 MiB recommended).[/color]


-- HijackThis (run as home.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:07:08 PM, on 10/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\home\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\home.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB0_0_0
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - <a href="http://by102fd.bay102.Email Removed.msn.com/resources/MsnPUpld.cab" target="_blank" rel="nofollow">http://by102fd.bay102.Email Removed.msn.com/resources/MsnPUpld.cab</a>
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1191534961265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downl...eCallButton.CAB
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Email Removed Attachments Control) - <a href="http://by9fd.bay9.Email Removed.msn.com/activex/HMAtchmt.ocx" target="_blank" rel="nofollow">http://by9fd.bay9.Email Removed.msn.com/activex/HMAtchmt.ocx</a>
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF7420D7-D241-4731-A40D-69C2ECB429F0}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

--
End of file - 5779 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 ATMhelpr - c:\windows\system32\drivers\atmhelpr.sys <Not Verified; Adobe Systems Incorporated; Adobe Type Manager Deluxe>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S4 ScsiAccess - c:\windows\system32\scsiaccess.exe


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2007-09-22 and 2007-10-22 -----------------------------

2007-10-15 00:23:23         0 d-------- C:\Documents and Settings\home\Application Data\AVG7
2007-10-15 00:23:06         0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-15 00:22:17         0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-14 23:51:03         0 d-------- C:\Program Files\Trend Micro
2007-10-09 14:45:35         0 d-------- C:\Program Files\Windows Media Connect 2
2007-10-09 14:43:05         0 d-------- C:\WINDOWS\system32\LogFiles
2007-10-09 14:43:05         0 d-------- C:\WINDOWS\system32\drivers\UMDF
2007-10-03 22:37:37         0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-10-03 22:30:18         0 d------c- C:\WINDOWS\system32\DRVSTORE


-- Find3M Report ---------------------------------------------------------------

2007-10-16 14:51:49         0 d-------- C:\Documents and Settings\home\Application Data\AdobeUM
2007-10-09 14:29:45         0 d-------- C:\Program Files\SpywareBlaster
2007-10-03 22:45:07         0 d-------- C:\Program Files\Lavasoft
2007-10-03 22:45:06         0 d-------- C:\Documents and Settings\home\Application Data\Lavasoft
2007-10-03 22:08:54         0 d-------- C:\Documents and Settings\home\Application Data\Yahoo!
2007-10-03 22:08:44         0 d-------- C:\Program Files\Yahoo!
2007-10-01 08:00:24         0 d-------- C:\Program Files\Java
2007-10-01 07:08:43         0 d-------- C:\Program Files\Napster
2007-08-26 15:15:30         8 --a------ C:\WINDOWS\system32\CtSACKey.sys


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [02/10/2004 11:55 AM]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [02/10/2004 11:51 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 04:00 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/07/2004 05:48 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/11/2005 06:08 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [10/15/2007 12:22 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:56 AM]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 04:45 PM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"= C:\WINDOWS\system32\ieframe.dll [08/20/2007 05:04 AM 6058496]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
C:\Program Files\Browser MOUSE\mouse32a.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWBKEYBOARD]
C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
c:\Program Files\Microsoft Works\WkDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
C:\Program Files\Napster\napster.exe /systray

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ScsiAccess"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)

*Newly Created Service* - AVG7ALRT
*Newly Created Service* - AVG7CORE
*Newly Created Service* - AVG7RSXP
*Newly Created Service* - AVG7UPDSVC
*Newly Created Service* - AVGCLEAN
*Newly Created Service* - AVGEMS
*Newly Created Service* - AVGTDI
*Newly Created Service* - CATCHME



-- End of Deckard's System Scanner: finished at 2007-10-22 13:09:12 ------------
« Last Edit: October 22, 2007, 01:41:20 PM by djkwik »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #5 on: October 23, 2007, 09:54:10 PM »
You never posted the contents of Extra.txt
A copy of it should be found in the folder
C:\Deckard\System Scanner

Can you post it please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #6 on: October 30, 2007, 10:04:25 AM »
[quote name=\'guestolo\' post=\'400053\' date=\'Oct 23 2007, 09:54 PM\']You never posted the contents of Extra.txt
A copy of it should be found in the folder
C:\Deckard\System Scanner

Can you post it please[/quote]

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Celeron® CPU 2.60GHz
Percentage of Memory in Use: 77%
Physical Memory (total/avail): 253.98 MiB / 57.23 MiB
Pagefile Memory (total/avail): 625.11 MiB / 383.74 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1928.18 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 37.27 GiB total, 20.87 GiB free.
D: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - WDC WD400EB-11CPF0 - 37.27 GiB - 1 partition
  \PARTITION0 (bootable) - Installable File System - 37.27 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

AntiVirusDisableNotify is set.

AV: AVG 7.5.488 v7.5.488 (GRISOFT)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\home\Application Data
CLASSPATH=C:\Program Files\PhotoDeluxe 2.0\AdobeConnectables
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=YOUR-KGOHY9AU97
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\home
LOGONSERVER=\\YOUR-KGOHY9AU97
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Adaptec Shared\System
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0209
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\home\LOCALS~1\Temp
TMP=C:\DOCUME~1\home\LOCALS~1\Temp
USERDOMAIN=YOUR-KGOHY9AU97
USERNAME=home
USERPROFILE=C:\Documents and Settings\home
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI


-- User Profiles ---------------------------------------------------------------

home (admin)
Administrator (new local, admin)


-- Add/Remove Programs ---------------------------------------------------------

 --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{836612F0-1571-4C65-A4B7-58A39AA578EE}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{836612F0-1571-4C65-A4B7-58A39AA578EE}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9104A09A-EC83-11D8-8469-00D0B726B56E}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9104A09A-EC83-11D8-8469-00D0B726B56E}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9744AE38-1CC6-414F-96CE-0643AEE30A9B}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9744AE38-1CC6-414F-96CE-0643AEE30A9B}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB14DF5-3B04-4E3B-9969-695DBA7F2008}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB14DF5-3B04-4E3B-9969-695DBA7F2008}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D42EFA6C-0553-45F7-AD03-6D36207CA6D4}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D42EFA6C-0553-45F7-AD03-6D36207CA6D4}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D524239C-FD5C-4183-A49C-7930915A9C0A}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D524239C-FD5C-4183-A49C-7930915A9C0A}\setup.exe" -l0x9  /remove
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD2D9012-E5A1-4717-8EE9-8DB3F36E2F8C}\setup.exe" -l0x9
 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD2D9012-E5A1-4717-8EE9-8DB3F36E2F8C}\setup.exe" -l0x9  /remove
 --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
3D Home Architect --> C:\WINDOWS\uninst.exe -fC:\3dhome\DeIsL1.isu
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe PhotoDeluxe 2.0 --> C:\WINDOWS\uninst.exe -f"C:\Program Files\PhotoDeluxe 2.0\DeIsL1.isu"
Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Adobe Type Manager 4.0 --> C:\WINDOWS\uninst.exe -f"C:\Program Files\Adobe Type Manager\DeIsL1.isu" -c"C:\Program Files\Adobe Type Manager\UNINST.DLL"
aspi --> MsiExec.exe /I{015E4B8A-29B5-4AE3-BD08-38220FADFF4C}
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
Browser MOUSE --> C:\Program Files\Browser MOUSE\uninst00.exe
CCHelp --> MsiExec.exe /I{9D1CF8B6-17B3-4832-B062-2C2DD0B57B04}
CCScore --> MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
CleanUp! --> C:\Program Files\CleanUp!\uninstall.exe
Conexant SoftK56 Modem(M) --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F00&SUBSYS_8D8B155D\HXFSETUP.EXE -U -IVEN_14F1&DEV_2F00&SUBSYS_200214F1
CR2 --> MsiExec.exe /I{432C3720-37BF-4BD7-8E49-F38E090246D0}
Creative Jukebox Driver --> C:\Program Files\Creative\Jukebox 3 Drivers\DrvUnins.exe /s
Creative MediaSource --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}\setup.exe" -l0x9  /remove
Creative Removable Disk Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9  /remove
Creative System Information --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9  /remove
Creative Zen Micro --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime91\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D944236D-7992-41D6-8257-930B5832F1CC}\SETUP.EXE" -l0x9  /remove
Easy CD Creator 5 Basic --> MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}
ESSAdpt --> MsiExec.exe /I{D15E9DB5-6BEB-4534-901E-80C0A29BAB97}
ESSANUP --> MsiExec.exe /I{A6F18A67-B771-4191-8A33-36D2E742D6D9}
ESSBrwr --> MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCAM --> MsiExec.exe /I{469730CC-78DF-4CD3-B286-562D459EA619}
ESSCDBK --> MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore --> MsiExec.exe /I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}
ESSCT --> MsiExec.exe /I{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}
ESSgui --> MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESShelp --> MsiExec.exe /I{87843A41-7808-4F2E-B13F-25C1E67CF2FD}
ESSini --> MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD --> MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSPDock --> MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091}
ESSTUTOR --> MsiExec.exe /I{CA60320D-6A16-49C8-A34F-84EEF4799567}
ESSvpaht --> MsiExec.exe /I{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}
ESSvpot --> MsiExec.exe /I{48C82F7A-F100-4DAB-A310-8E18BF2159E1}
HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HLPCCTR --> MsiExec.exe /I{F2D0C1B1-80FF-46F9-BA61-33B01A07FAFC}
HLPIndex --> MsiExec.exe /I{78F79C84-BFD5-4D79-A07D-F39A3CF428DC}
HLPPDOCK --> MsiExec.exe /I{154508C0-07C5-4659-A7A0-E49968750D21}
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Intel® Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
Java(tm) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(tm) SE Runtime Environment 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Kodak EasyShare software --> C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_3d001c_1edae1f3\Setup.exe /APR-REMOVE
KSU --> MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}
Learn2 Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Money 2003 --> MsiExec.exe /I{01F9D88C-3C86-4E82-840A-101A3221F67A}
Microsoft Money 2003 System Pack --> MsiExec.exe /I{02B42D23-10F2-4862-ADA4-3DF1EA0021B2}
Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft Publisher 2002 --> MsiExec.exe /I{90190409-6000-11D3-8CFE-0050048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Windows Journal Viewer --> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA7}
Microsoft Works 6.0 --> MsiExec.exe /I{F8D0829C-9C6F-11D3-8080-00C04FA329AA}
MP3 Update --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA1C5F22-D1AF-484F-B28A-85FA4E3CAC5A}\setup.exe" -l0x9
MultiMedia Keyboard 1.1 --> C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\unins000.EXE
Napster --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBBCAE4B-B416-4182-A6F2-438180894A81}\setup.exe" -l0x9  -removeonly
Napster Burn Engine --> MsiExec.exe /I{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}
Netscape 6 (6.2.1) --> C:\WINDOWS\N6Uninst.exe /ua "6.2.1 (en)"
Notifier --> MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
OTtBP --> MsiExec.exe /I{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}
PCDLNCH --> MsiExec.exe /I{69BD6399-3D8F-45B7-81D9-819361F5101D}
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek AC'97 Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
SFR --> MsiExec.exe /I{C354C9B6-A4E0-4BB0-A368-6DC6BCA0E314}
SFR2 --> MsiExec.exe /I{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}
Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster v3.5.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"
VCAMCEN --> MsiExec.exe /I{10E98E14-832C-4AF7-A4D1-6A9EF83B282E}
Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Backup Utility --> MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG


-- Application Event Log -------------------------------------------------------

Event Record #/Type5274 / Error
Event Submitted/Written: 10/22/2007 01:03:27 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2900.3156, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00031c6b.
Processing media-specific event for [explorer.exe!ws!]

Event Record #/Type5271 / Error
Event Submitted/Written: 10/16/2007 10:32:29 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.

Event Record #/Type5267 / Error
Event Submitted/Written: 10/14/2007 11:26:29 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2900.3156, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00031c6b.
Processing media-specific event for [explorer.exe!ws!]

Event Record #/Type5264 / Error
Event Submitted/Written: 10/14/2007 10:59:30 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2900.3156, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00031c6b.
Processing media-specific event for [explorer.exe!ws!]

Event Record #/Type5262 / Error
Event Submitted/Written: 10/14/2007 10:55:27 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application explorer.exe, version 6.0.2900.3156, hang module hungapp, version 0.0.0.0, hang address 0x00000000.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type32570 / Error
Event Submitted/Written: 10/22/2007 08:36:11 AM
Event ID/Source: 1002 / Dhcp
Event Description:
The IP address lease 192.168.100.11 for the Network Card with network address 00402B74A717 has been
denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).

Event Record #/Type32568 / Error
Event Submitted/Written: 10/22/2007 08:00:10 AM
Event ID/Source: 1002 / Dhcp
Event Description:
The IP address lease 24.209.176.103 for the Network Card with network address 00402B74A717 has been
denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).

Event Record #/Type32567 / Warning
Event Submitted/Written: 10/22/2007 08:00:00 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00402B74A717.  The following
error occurred:
%%121.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Event Record #/Type32566 / Warning
Event Submitted/Written: 10/22/2007 07:58:57 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00402B74A717.  The following
error occurred:
%%121.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Event Record #/Type32565 / Warning
Event Submitted/Written: 10/22/2007 07:56:49 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00402B74A717.  The following
error occurred:
%%121.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.



-- End of Deckard's System Scanner: finished at 2007-10-22 13:09:12 ------------

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #7 on: November 01, 2007, 11:05:07 AM »
It could be that your profile got corrupt somehow

Can you try making a new profile and see if the problem persists with opening folders, etc..

1.   Click Start, and then click Control Panel.
2.   Click User Accounts.
3.   Under Pick a task, click Create a new account.
4.   Type a name for the user information, and then click Next.
5.   Click an account type (Admin)  and then click Create Account.

Log off your account then log into your new account, any problems?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #8 on: November 03, 2007, 06:05:44 AM »
[quote name=\'guestolo\' post=\'402110\' date=\'Nov 1 2007, 11:05 AM\']It could be that your profile got corrupt somehow

Can you try making a new profile and see if the problem persists with opening folders, etc..

1.   Click Start, and then click Control Panel.
2.   Click User Accounts.
3.   Under Pick a task, click Create a new account.
4.   Type a name for the user information, and then click Next.
5.   Click an account type (Admin)  and then click Create Account.

Log off your account then log into your new account, any problems?[/quote]


Amazingly enough, No I had no problems under the new account.  Now, last question:  can I copy all of the contents from the "home" account that I want to keep (documents, etc) into the new account (I have already gone into documents and settings, copied all of the the favorites list into the new account so I am assuming I can do the same to everything else).  After setting up the new account with everything I want to keep, can I change the name of "home" to something else, then change the new account's name to "home" and delete the old one so I only have the one?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #9 on: November 03, 2007, 09:33:26 AM »
Here's the instructions from Microsoft
http://support.microsoft.com/kb/811151

Personally, this is what I like to do
You have 2 Profiles right now, plus Administrator account seen in safe mode

Leave the Admin account alone
Try the following
Create another user account and give it Admin privileges

So now you have 3 accounts + Admin

You have the corrupt account>>Home
Your new account>>Let's call this "djkwik" < or whatever you named it
And another new account you just made>>Let's say you call it "Transfer"

Log off of your Home and djkwik and log into the newly created account>>Transfer
Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

Locate the C:\Documents and Settings\Home folder,
   Press and hold down the CTRL key while you click each file and subfolder in this folder, EXCEPT the following files:
•   Ntuser.dat
•   Ntuser.dat.log
•   Ntuser.ini

   On the Edit menu, click Copy.

Locate the C:\Documents and Settings\djkwik folder <-or whatever you called it
On the Edit menu, click Paste.

Log off the Transfer account and log into the djkwik account
Ensure everything is working fine

Don't delete the other accounts yet, you may still need them
Take note at the Microsoft link
You must import your e-mail messages and addresses to the new user profile before you delete the old profile. For more information, click the following article number to view the article in the Microsoft Knowledge Base:
313055 (http://support.microsoft.com/kb/313055/) OLEXP: Mail folders, address book, and e-mail messages are missing after you upgrade to Microsoft Windows XP

You need to transfer you email
Personally, I just set up a new account in the new profile with same account info if your using Outlook Express
If you can't remember passwords to your mail accounts, I use a little tool to refresh my memory
Let me know what route you want to take

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #10 on: November 03, 2007, 12:05:07 PM »
[quote name=\'guestolo\' post=\'402617\' date=\'Nov 3 2007, 09:33 AM\']Here's the instructions from Microsoft
http://support.microsoft.com/kb/811151

Personally, this is what I like to do
You have 2 Profiles right now, plus Administrator account seen in safe mode

Leave the Admin account alone
Try the following
Create another user account and give it Admin privileges

So now you have 3 accounts + Admin

You have the corrupt account>>Home
Your new account>>Let's call this "djkwik" < or whatever you named it
And another new account you just made>>Let's say you call it "Transfer"

Log off of your Home and djkwik and log into the newly created account>>Transfer
Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

Locate the C:\Documents and Settings\Home folder,
   Press and hold down the CTRL key while you click each file and subfolder in this folder, EXCEPT the following files:
•   Ntuser.dat
•   Ntuser.dat.log
•   Ntuser.ini

   On the Edit menu, click Copy.

Locate the C:\Documents and Settings\djkwik folder <-or whatever you called it
On the Edit menu, click Paste.

Log off the Transfer account and log into the djkwik account
Ensure everything is working fine

Don't delete the other accounts yet, you may still need them
Take note at the Microsoft link
You must import your e-mail messages and addresses to the new user profile before you delete the old profile. For more information, click the following article number to view the article in the Microsoft Knowledge Base:
313055 (http://support.microsoft.com/kb/313055/) OLEXP: Mail folders, address book, and e-mail messages are missing after you upgrade to Microsoft Windows XP

You need to transfer you email
Personally, I just set up a new account in the new profile with same account info if your using Outlook Express
If you can't remember passwords to your mail accounts, I use a little tool to refresh my memory
Let me know what route you want to take[/quote]


I am willing to try that, but have already realized I will have a problem with my Outlook Express.  i cannot for the life of me remember the password to my LAN email account.  Since that is the account that Oulook Express uses, I figured I could just go into their home site and follow the instructions to the "can't remember password".  From your reply above, I see there is a way to just export the account into my new windows profile?  Is that correct?  Let me know.  Also, as I was trying to move some files around today, I got a Windows Live ID sign-in prompt.  I googled it and found one place where someone had asked how to get rid of it, but there was no response to their question.  I am hoping once i establish a good user profile on Windows and get rid of all of the other's (especially the corrupt one) all of these problems will disappear with that corrupt profile.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #11 on: November 03, 2007, 12:15:59 PM »
Move the files/folders as I described above

See if this helps in remembering passwords
Download SIW.exe from here
http://www.gtopala.com/siw-download.html

Save it to your Local Disk C: folder
Go to MyComputer>>Local Disk C:
open SIW.exe
Click on Secrets on the left hand side
See if that helps

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #12 on: November 03, 2007, 02:39:57 PM »
[quote name=\'guestolo\' post=\'402649\' date=\'Nov 3 2007, 12:15 PM\']Move the files/folders as I described above

See if this helps in remembering passwords
Download SIW.exe from here
http://www.gtopala.com/siw-download.html

Save it to your Local Disk C: folder
Go to MyComputer>>Local Disk C:
open SIW.exe
Click on Secrets on the left hand side
See if that helps[/quote]


Well, I have everything moved and everything seems to be working ok except one thing.  under the "home" profile, some windows would always open at their maximized size and some wouldn't..I never found a way to fix that....now however, under the new profile, the windows that used to open fully maximized under "home" profile now do not open fully maximized.  I have maximized the window, then exited the window (and have tried several different ways of doing both) and I still get the same crap.  Do YOU have any idea of how to fix it so that every window I open does so in its fully maximized size?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #13 on: November 03, 2007, 03:56:35 PM »
Try this, see if it's any help

Close down all windows
Go to Start>>MyComputer>>Tools>>Folder Options>>View

Select "Reset All Folders"
Yes to the prompt

Open a Window such as "My Documents">>Maximize it
Close then reopen it, does it stay maximized?

NOTE: I seen this in your log from dss.exe
Total Physical Memory: 254 MiB (512 MiB recommended).
Is it possible to add more Ram to this computer, you are running on minimal for XP in my opinion
another 256 mb would make an improvement
« Last Edit: November 03, 2007, 04:09:19 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #14 on: November 03, 2007, 05:12:52 PM »
[quote name=\'guestolo\' post=\'402708\' date=\'Nov 3 2007, 03:56 PM\']Try this, see if it's any help

Close down all windows
Go to Start>>MyComputer>>Tools>>Folder Options>>View

Select "Reset All Folders"
Yes to the prompt

Open a Window such as "My Documents">>Maximize it
Close then reopen it, does it stay maximized?

NOTE: I seen this in your log from dss.exe
Total Physical Memory: 254 MiB (512 MiB recommended).
Is it possible to add more Ram to this computer, you are running on minimal for XP in my opinion
another 256 mb would make an improvement[/quote]


Well, that worked for all of my folders...now what about Internet Explorer windows.  I would like to be able to go to a page on the web and not have to expand each and every one I go to.  Are there any settings to open all web pages in full expanded view?  Also, everything seems to be working, can I get rid of the old "home" profile now to free up space on the hard drive?  I will get more memory when I can afford it, but as for speed, the computer works fine for what I use it for.  I just really hate that all the internet explorer windows won't open in full view.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #15 on: November 04, 2007, 05:35:39 PM »
Try this
Open IE window
Click on TOOLS>>Menu bar

Ensure the IE windows is maximized
Next click on FILE>>New Window
Drag the corners of the new Window to fill the whole screen
Then minimize it to the taskbar
The original IE window, click on FILE>>Exit
Open the minimized window and click File>>Exit

Does that help?
I don't use IE that much, so I hope so  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/wink.gif\' class=\'bbc_emoticon\' alt=\';)\' />

Don't forget about IE7 tabbed browsing
You can set up options to suit your needs
In IE go to TOOLS>>Internet Options>>Under the General page
Select Settings under Tabs
You may like to set :: These are all optional
Always swith to new tab when created
Open new tab next to current tab
Open new tab in current window

Regarding the Home account

This is what I like to do
Shut down the computer
This is to ensure every profile is logged out
Restart the computer and sign in Only with your new account you are going to hold onto

Go into User Accounts in Control Panel and delete the Home account and the Transfer account
You can Delete files at prompt now that you have everything running smooth and in order
Up to you

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #16 on: November 04, 2007, 05:49:52 PM »
[quote name=\'guestolo\' post=\'402994\' date=\'Nov 4 2007, 04:35 PM\']Try this
Open IE window
Click on TOOLS>>Menu bar

Ensure the IE windows is maximized
Next click on FILE>>New Window
Drag the corners of the new Window to fill the whole screen
Then minimize it to the taskbar
The original IE window, click on FILE>>Exit
Open the minimized window and click File>>Exit

Does that help?
I don't use IE that much, so I hope so  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/wink.gif\' class=\'bbc_emoticon\' alt=\';)\' />

Don't forget about IE7 tabbed browsing
You can set up options to suit your needs
In IE go to TOOLS>>Internet Options>>Under the General page
Select Settings under Tabs
You may like to set :: These are all optional
Always swith to new tab when created
Open new tab next to current tab
Open new tab in current window

Regarding the Home account

This is what I like to do
Shut down the computer
This is to ensure every profile is logged out
Restart the computer and sign in Only with your new account you are going to hold onto

Go into User Accounts in Control Panel and delete the Home account and the Transfer account
You can Delete files at prompt now that you have everything running smooth and in order
Up to you[/quote]

Thanks.  I somehow managed to get the explorer windows to open fully maximized (can't remember what I did, but every window I try fresh opens fully...but links from those windows dont...not a problem)

New problem:  I am trying to make sure all my things are updated before getting rid of the extra profiles.  I went to Windows Update and it once again is prompting me to download and install the Office XP SP3.  I tried this before and it failed...I am apparently missing s file called PUB.MSI  I have already run repair on Publisher, I only have one version of Publisher on here.  i do not have the disc that I installed it with either.  Isn't there ANY way i can get that file without having to go an buy a disc for it?  I have been browsing and it seems there are a LOT of people having this problem.  I downloaded the previous service pack and update for Office XP just last month, so i don't know how or why the PUB.MSI file is now missing.  I've done a complete search including hidden and program files and still nothing.  You would think that with so many people experiencing this problem that someone out there would be able to provide a free download of that file.  Any suggestions?  Again, its the PUB.MSI file for MS Publisher 2002 as part of MS Office XP.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #17 on: November 04, 2007, 06:29:57 PM »
I'm not sure if this will help
As it may prompt for the CD also, even though it claims it won't

Try the full download of SP3 from here
http://www.microsoft.com/downloads/details...;displaylang=en
OfficeXpSp3-kb832671-fullfile-enu.exe
It's 57.5 MB in size

Edit>>Did office come preinstalled on your system?
Do you need Publisher?
Can you borrow a Office XP Cd from a friend/coworker?
« Last Edit: November 04, 2007, 06:56:18 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline djkwik

  • Jr. Member
  • **
  • Posts: 87
  • Karma: +0/-0
    • View Profile
Documents and Settings problems again/still
« Reply #18 on: November 05, 2007, 12:23:24 PM »
[quote name=\'guestolo\' post=\'403015\' date=\'Nov 4 2007, 05:29 PM\']I'm not sure if this will help
As it may prompt for the CD also, even though it claims it won't

Try the full download of SP3 from here
http://www.microsoft.com/downloads/details...;displaylang=en
OfficeXpSp3-kb832671-fullfile-enu.exe
It's 57.5 MB in size

Edit>>Did office come preinstalled on your system?
Do you need Publisher?
Can you borrow a Office XP Cd from a friend/coworker?[/quote]


i don't know anyone with the XP disc that I can borrow..its on my home computer and was installed by a friend that I no longer have contact with.  I used to use Publisher a great deal, but lately it has been acting strange...everytime I try to put a picture in it...even from the publisher clip art file, it shows up very blurry once in the publication.  I've run the repair for publisher itself and nothing.  The Office XP download that Microsoft is labeling a critical upgrade for security reasons will not install without it.  I will try the link you supplied and see if that works.  I may just end up having to go and shell otu hundreds of $$$$ for a new Office XP program....of course...knowing Microsoft, that will be outdated within a year and require more hundreds of $$$ to replace.  In any event, I at least need Word, since the business world does not recognize Microsoft Works documents...anytime I apply for a job online, they require a resume done only in Word format.  One of the Office SP3 critical downloads is also for Word...but if I don't have all of Office XP, I guess I don't get the security updates...more of the typical Microsoft Bullsh--!

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Documents and Settings problems again/still
« Reply #19 on: November 05, 2007, 10:38:10 PM »
Your going to have trouble getting updates without a full legal version of Office Xp
You can try manually downloading individual updates from here
http://office.microsoft.com/en-us/download...0224911033.aspx

Or try Open Office, it's not a bad Office suite
Take a look
http://www.openoffice.org/

and/or for Publishing program, also take a look at
http://www.scribus.net/
« Last Edit: November 06, 2007, 12:26:50 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here