PDA

View Full Version : What is this on my desktop? (WXP-Home)



kristinwilson
05-12-2006, 12:11 PM
Yesterday, I did a refresh of my desktop and suddenly there was this bar on the left of my desktop screen. I don't know what it is, how it got there, or how to get rid of it. I did a screenshot:

http://img.villagephotos.com/p/2005-9/1078542/Desktop.jpg

How do I get rid of this thing???

HELP!

Kristin Wilson
Miss Know It All - NOT!

kristinwilson
05-12-2006, 04:35 PM
I just wanted to quick add that I when I right click on my recycle bin, it won't let me empty that way. I still can with disc cleanup but not by right clicking. don't know if this helps identify the problem or not.

Kristin Wilson
Miss Know It All - NOT!

Brf
05-12-2006, 07:07 PM
That is the "common tasks" pane that shows on the left of Explorer when Folder-View is turned off. I have never seen it show on desktop before though...

josefz
05-13-2006, 12:40 AM
Hi kristinwilson,
the same as Brf - I have never seen it show on desktop before, so I can't delight you. However, I have been looking for a procedure to show on desktop this <a target="_blank" href=http://www.geekgirls.com/windowsxp_best_guide.htm> task pane </a> - in vain.

A question: are these doubled up- and down- arrows clickable? What do you see when clicking double downarrow at "Details" row? Does it change to double uparrow?

If the arrows are clickable, then copy and paste your fresh HijackThis log here, please.
In other case (when the picture of common task pane stays static) check your desktop wall-paper picture in some image-viewing program.

In any case, let us know your advance.

kristinwilson
05-13-2006, 09:43 AM
Well, I wanted to see if I could change the folder options, but it won't let me into that from my control panel. Other options work in the control panel though, as far as I can see.

The double arrows are clickable and give me the options of making a new folder, share this folder, and links to my computer and my documents. It depends on what I have highlighted on my desktop as to what it offers for options when I click on them. I'll run my Highjack This and post it in a minute. Thanks folks!!!

Kristin Wilson
Miss Know It All - NOT!

kristinwilson
05-13-2006, 10:12 AM
Here's the Hijack This log:



Logfile of HijackThis v1.99.1
Scan saved at 12:11:05 PM, on 5/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb1 0.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Instant Buzz\IBDaemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\PrintScreen31\PrintScreen\PrintScreen.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTML
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kwe.buildreferrals.com/homerotator.cgi
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;&lt;local&gt;
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~1\COPERN~1.DLL (file missing)
R3 - URLSearchHook: SearchHook Class - {D94AAA2A-C415-42E3-82B6-49FAB4EBFFE9} - C:\PROGRA~1\HALFLE~1\HALFLE~1.DLL (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3950E0E8-58DC-467E-9EE4-21A0E0B142C4} - (no file)
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {79A002FB-C126-462D-B4A7-81D6B42D1666} - (no file)
O2 - BHO: (no name) - {8B50176C-DD6E-4C14-A603-727A859337CD} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O2 - BHO: XBTBPos00 - {E552EEFC-DE97-45D4-BA1A-F534A1B4A579} - C:\PROGRA~1\MORPHE~1\MORPHE~1.DLL
O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll (file missing)
O3 - Toolbar: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb1 0.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe
O4 - HKLM\..\Run: [MyPointsPointAlert0] "C:\Program Files\MyPoints_PointAlert\MyPointsPointAlert0.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\PrintScreen31\PrintScreen\PrintScreen.exe /nosplash
O4 - Startup: FavoriteSync.lnk = C:\Program Files\FavoriteSync\FavoriteSync.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MyPoints - file://C:\Program Files\MyPoints_PointAlert\Sy800\Tp800\scri800a.htm
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bv9zzqha.Kristin\ext ensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: Search Using Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bv9zzqha.Kristin\ext ensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O9 - Extra 'Tools' menuitem: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE (file missing)
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE (file missing)
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Customize - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra 'Tools' menuitem: Customize Menu - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker\partypokernet.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: TM Scan - {03D188B9-3997-4361-A9FB-A2318B1D02ED} - http://housecall.trendmicro.com/housecall/start_corp.asp (file missing) (HKCU)
O9 - Extra button: Panda Scan - {03F56B66-CB98-406D-980B-DC20FC5B8884} - http://www.pandasoftware.com/activescan/activescan.asp?Language=2&Country=63&Partner=1&Ref=EN-PR-AS-107 (file missing) (HKCU)
O9 - Extra button: Dictionary - {08E702D6-834F-4420-8C02-8EF8FB81F05D} - http://encarta.msn.com/encnet/features/dictionary/dictionaryhome.aspx (file missing) (HKCU)
O9 - Extra button: Music - {4FCD9C0F-719F-468C-91CC-5D81BCEFFD3B} - http://www.panoramicit.com/radio (file missing) (HKCU)
O9 - Extra button: Help - {59331B17-4E0E-45A2-B546-A3D3BBF3478B} - http://www.panoramicit.com/techsupport (file missing) (HKCU)
O9 - Extra button: Point Alert - {67B50696-04BA-48ea-A697-28AA0EAA9C26} - file://C:\Program Files\MyPoints_PointAlert\Sy800\Tp800\scri800a.htm (file missing) (HKCU)
O9 - Extra button: Atlas - {B5E34E7C-90E3-4C30-8B11-CEB1237DCFEB} - http://encarta.msn.com/encnet/features/mapcenter/map.aspx (file missing) (HKCU)
O9 - Extra button: IE Update - {D2A9762B-DBF1-4D62-8278-6DB61820B062} - http://www.panoramicit.com/DOWNLOAD/WIN32/EN/ie6setup.exe (file missing) (HKCU)
O9 - Extra button: Software - {D668DD02-D0C6-4CAD-BC50-26CED0208EF1} - http://111things.com/apf4/amazon.cgi?SearchIndex=Software (file missing) (HKCU)
O9 - Extra button: Shopping - {D6DD2729-B589-48FA-8779-8D9372CF3350} - http://www.111things.com (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.com
O15 - Trusted Zone: http://www.adpost.com
O15 - Trusted Zone: http://www.ahcppo.com
O15 - Trusted Zone: http://www.bottomlinewholesaler.com
O15 - Trusted Zone: http://jobs.brassring.com
O15 - Trusted Zone: http://pub44.bravenet.com
O15 - Trusted Zone: www.bravenet.com
O15 - Trusted Zone: http://onwisconsin.careercast.com
O15 - Trusted Zone: www.classiccloseouts.com
O15 - Trusted Zone: http://www.clixgalore.com
O15 - Trusted Zone: http://www.common-knowledge.net
O15 - Trusted Zone: www.e-rewards.com
O15 - Trusted Zone: http://www.e-rewards.com
O15 - Trusted Zone: www.elance.com
O15 - Trusted Zone: http://members.esdinternational.org
O15 - Trusted Zone: http://www.esdinternational.org
O15 - Trusted Zone: http://screensaver.freeze.com
O15 - Trusted Zone: http://www.gozingsurveys.com
O15 - Trusted Zone: http://free.grisoft.com
O15 - Trusted Zone: http://bfc.iwon.com
O15 - Trusted Zone: http://btrack.iwon.com
O15 - Trusted Zone: http://www.linkshare.com
O15 - Trusted Zone: http://flipdog.monster.com
O15 - Trusted Zone: http://my.monster.com
O15 - Trusted Zone: www.monster.com
O15 - Trusted Zone: http://www.monsterworldwide.com
O15 - Trusted Zone: http://www.MyPoints.com
O15 - Trusted Zone: my.net-temps.com
O15 - Trusted Zone: www.net-temps.com
O15 - Trusted Zone: www.onwisconsin.com
O15 - Trusted Zone: http://survey.otxresearch.com
O15 - Trusted Zone: www.realtor.com
O15 - Trusted Zone: www.ripway.com
O15 - Trusted Zone: *.Safer products for home, personal, and pet use.
O15 - Trusted Zone: http://www.serve-you-rx.com
O15 - Trusted Zone: http://www.shutterfly.com
O15 - Trusted Zone: www.surveysavvy.com
O15 - Trusted Zone: http://www.weather.com
O15 - Trusted Zone: www.wisconsinjobnetwork.com
O15 - Trusted Zone: www.workathomeagent.com
O16 - DPF: ConferenceRoom Java Client -
O16 - DPF: Yahoo! Chat -
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} -
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {0D136D67-D293-4626-8C93-D12CF78E4590} (tcConference Setup) - http://67.19.231.218/ivocalize/tc4.cab
O16 - DPF: {0F1B982D-C18E-4F2F-8ADB-91C12D858A08} -
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} -
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) -
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} -
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {3DECE173-1936-4387-B641-D0F96567C36B} -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} -
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} -
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_02) -
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp.coupons.com/r3302/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} -
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} -
O16 - DPF: {C2F38867-251C-4216-9B1C-BBE89B8700E2} -
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} -
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Plug-in 1.4.2_06) -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v13/ticker.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} -
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\FYPWPP.DLL (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe



Kristin Wilson
Miss Know It All - NOT!

josefz
05-13-2006, 01:02 PM
I am afraid I did not find a culprit of your problem. However, you have some uninvited guests.
Here is short analysis of your HijackThis log with some my suggestions (most of pest/not_pest confirmed at http://castlecops.com/ or http://www.pestpatrol.com/spywarecenter/ or http://www.liutilities.com/ or http://research.pestpatrol.com/Analyses/).
For full analysis see <a target="_blank" href=http://www.hijackthis.de/>http://www.hijackthis.de/</a>.

Key to my suggestions:
fix - fix with HijackThis (be careful, consider and decide yourself)
let - let it be
??? - I do not know
!!! - should be fixed (but not with HijackThis): Check your hard disc drive with Spybot S&D from Kolla.de or LSPFix from Cexx.org.

??? R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTML - Nasty
??? R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;; - Possibly nasty
fix R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~1\COPERN~1.DLL (file missing) - Possibly nasty
fix R3 - URLSearchHook: SearchHook Class - {D94AAA2A-C415-42E3-82B6-49FAB4EBFFE9} - C:\PROGRA~1\HALFLE~1\HALFLE~1.DLL (file missing) - Possibly nasty
let F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe - Unknown
fix O2 - BHO: (no name) - {3950E0E8-58DC-467E-9EE4-21A0E0B142C4} - (no file) - Unknown
fix O2 - BHO: (no name) - {79A002FB-C126-462D-B4A7-81D6B42D1666} - (no file) - Nasty
fix O2 - BHO: (no name) - {8B50176C-DD6E-4C14-A603-727A859337CD} - (no file) - Nasty
fix O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~2\IBBar.dll - Nasty
??? O2 - BHO: XBTBPos00 - {E552EEFC-DE97-45D4-BA1A-F534A1B4A579} - C:\PROGRA~1\MORPHE~1\MORPHE~1.DLL - Unknown
fix O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~2\IBBar.dll - Nasty
??? O3 - Toolbar: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll - Unknown
let O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE - Unknown
fix O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe - Unknown
??? O4 - HKLM\..\Run: [MyPointsPointAlert0] "C:\Program Files\MyPoints_PointAlert\MyPointsPointAlert0.exe" - Unknown
??? O4 - HKCU\..\Run: [Yahoo! Pager] 1 - Unknown
??? O4 - Startup: FavoriteSync.lnk = C:\Program Files\FavoriteSync\FavoriteSync.exe - Unknown
??? O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe - Unknown
??? O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe - Unknown
let O8 - Extra context menu item: MyPoints - file://C:\Program Files\MyPoints_PointAlert\Sy800\Tp800\scri800a.htm - Possibly nasty
??? O8 - Extra context menu item: Search Using Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT - Nasty
fix O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~2\IBBar.dll - Possibly nasty
??? O9 - Extra button: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll - Possibly nasty
??? O9 - Extra 'Tools' menuitem: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll - Possibly nasty
fix O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE (file missing) - Possibly nasty
let O9 - Extra button: Customize - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html - Possibly nasty
let O9 - Extra 'Tools' menuitem: Customize Menu - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html - Possibly nasty
fix O9 - Extra button: TM Scan - {03D188B9-3997-4361-A9FB-A2318B1D02ED} - http://housecall.trendmicro.com/housecall/start_corp.asp (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: Panda Scan - {03F56B66-CB98-406D-980B-DC20FC5B8884} - http://www.pandasoftware.com/activescan/activescan.asp?Language=2&Country=63&Partner=1&Ref=EN-PR-AS-107 (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: Dictionary - {08E702D6-834F-4420-8C02-8EF8FB81F05D} - http://encarta.msn.com/encnet/features/dictionary/dictionaryhome.aspx (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: Music - {4FCD9C0F-719F-468C-91CC-5D81BCEFFD3B} - http://www.panoramicit.com/radio (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: Help - {59331B17-4E0E-45A2-B546-A3D3BBF3478B} - http://www.panoramicit.com/techsupport (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: Point Alert - {67B50696-04BA-48ea-A697-28AA0EAA9C26} - file://C:\Program Files\MyPoints_PointAlert\Sy800\Tp800\scri800a.htm (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: Atlas - {B5E34E7C-90E3-4C30-8B11-CEB1237DCFEB} - http://encarta.msn.com/encnet/features/mapcenter/map.aspx (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: IE Update - {D2A9762B-DBF1-4D62-8278-6DB61820B062} - http://www.panoramicit.com/DOWNLOAD/WIN32/EN/ie6setup.exe (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: Software - {D668DD02-D0C6-4CAD-BC50-26CED0208EF1} - http://111things.com/apf4/amazon.cgi?SearchIndex=Software (file missing) (HKCU) - Possibly nasty
fix O9 - Extra button: Shopping - {D6DD2729-B589-48FA-8779-8D9372CF3350} - http://www.111things.com (file missing) (HKCU) - Possibly nasty
!!! O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll - Nasty
!!! O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll - Nasty
!!! O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll - Nasty
!!! O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll - Nasty
!!! O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll - Nasty
!!! O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll - Nasty
??? O15 - Trusted Zone: www.bravenet.com - Possibly nasty
??? O15 - Trusted Zone: www.classiccloseouts.com - Possibly nasty
??? O15 - Trusted Zone: www.e-rewards.com - Possibly nasty
??? O15 - Trusted Zone: www.elance.com - Possibly nasty
??? O15 - Trusted Zone: www.monster.com - Possibly nasty
??? O15 - Trusted Zone: my.net-temps.com - Possibly nasty
??? O15 - Trusted Zone: www.net-temps.com - Possibly nasty
??? O15 - Trusted Zone: www.onwisconsin.com - Possibly nasty
??? O15 - Trusted Zone: www.realtor.com - Possibly nasty
??? O15 - Trusted Zone: www.ripway.com - Possibly nasty
fix O15 - Trusted Zone: *.Safer products for home, personal, and pet use. - Nasty
??? O15 - Trusted Zone: www.surveysavvy.com - Possibly nasty
??? O15 - Trusted Zone: www.wisconsinjobnetwork.com - Possibly nasty
??? O15 - Trusted Zone: www.workathomeagent.com - Possibly nasty
??? O16 - DPF: ConferenceRoom Java Client - - Possibly nasty
??? O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} - - Possibly nasty
??? O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - - Possibly nasty
??? O16 - DPF: {0D136D67-D293-4626-8C93-D12CF78E4590} (tcConference Setup) - http://67.19.231.218/ivocalize/tc4.cab - Possibly nasty
??? O16 - DPF: {0F1B982D-C18E-4F2F-8ADB-91C12D858A08} - - Possibly nasty
??? O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} - - Possibly nasty
??? O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - - Possibly nasty
??? O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - - Possibly nasty
??? O16 - DPF: {3DECE173-1936-4387-B641-D0F96567C36B} - - Possibly nasty
??? O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - - Possibly nasty
??? O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} - - Possibly nasty
??? O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - - Possibly nasty
??? O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} - - Possibly nasty
??? O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - - Possibly nasty
fix O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp.coupons.com/r3302/cpbrkpie.cab - Nasty
??? O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - - Possibly nasty
??? O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} - - Possibly nasty
??? O16 - DPF: {C2F38867-251C-4216-9B1C-BBE89B8700E2} - - Possibly nasty
??? O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} - - Possibly nasty
??? O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Plug-in 1.4.2_06) - - Possibly nasty
??? O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - - Possibly nasty
let O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx - Possibly nasty
??? O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} - - Possibly nasty
fix O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\FYPWPP.DLL (file missing) - UnknownO20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\FYPWPP.DLL (file missing) - Unnecessarily
let O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe - Unknown
let O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe - Unknown

josefz
05-13-2006, 02:03 PM
Useful link: <a target="_blank" href=http://www.bleepingcomputer.com/tutorials/tutorial42.html> HijackThis Tutorial & Guide </a>.

Perhaps the task pane on your desktop results from one of ActiveX Objects (otherwise known as Downloaded Program Files), as listed in "O16" section of your HijackThis log file?

kristinwilson
05-13-2006, 03:52 PM
Thank you both for responding with such great information. I'm at the tutorial you linked to and doing as it says ... running Spybot and AdAware first. Then I'll run HiJackThis again and post that new log. Maybe we'll see things differently, maybe it'll just fix the issue, or who knows. I'll post on the other forum the tutorial is on if we can't figure it out here. Watch for the log posting shortly.

Thank you again, so very much!!!

Kristin Wilson
Miss Know It All - NOT!

kristinwilson
05-13-2006, 08:21 PM
Ok folks. I ran the Spybot and Adaware and stinger too. I also noticed that when I go to folder options, there is a check on the folder. It's locked so that I can't do anything with it. I did a screenshot of this and you can view it at:

http://img.villagephotos.com/p/2005-9/1078542/FolderOptionsLocked.jpg

====================
Here is the new HiJackThis log:
====================

Logfile of HijackThis v1.99.1
Scan saved at 10:14:35 PM, on 5/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb1 0.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Instant Buzz\IBDaemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\PrintScreen31\PrintScreen\PrintScreen.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\RSS Reader\RssReader.exe
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTML
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kwe.buildreferrals.com/homerotator.cgi
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;&lt;local&gt;
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~1\COPERN~1.DLL (file missing)
R3 - URLSearchHook: SearchHook Class - {D94AAA2A-C415-42E3-82B6-49FAB4EBFFE9} - C:\PROGRA~1\HALFLE~1\HALFLE~1.DLL (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3950E0E8-58DC-467E-9EE4-21A0E0B142C4} - (no file)
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {8B50176C-DD6E-4C14-A603-727A859337CD} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O2 - BHO: XBTBPos00 - {E552EEFC-DE97-45D4-BA1A-F534A1B4A579} - C:\PROGRA~1\MORPHE~1\MORPHE~1.DLL
O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll (file missing)
O3 - Toolbar: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb1 0.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe
O4 - HKLM\..\Run: [MyPointsPointAlert0] "C:\Program Files\MyPoints_PointAlert\MyPointsPointAlert0.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\PrintScreen31\PrintScreen\PrintScreen.exe /nosplash
O4 - Startup: FavoriteSync.lnk = C:\Program Files\FavoriteSync\FavoriteSync.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MyPoints - file://C:\Program Files\MyPoints_PointAlert\Sy800\Tp800\scri800a.htm
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bv9zzqha.Kristin\ext ensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: Search Using Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bv9zzqha.Kristin\ext ensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O9 - Extra 'Tools' menuitem: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE (file missing)
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE (file missing)
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Customize - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra 'Tools' menuitem: Customize Menu - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker\partypokernet.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: TM Scan - {03D188B9-3997-4361-A9FB-A2318B1D02ED} - http://housecall.trendmicro.com/housecall/start_corp.asp (file missing) (HKCU)
O9 - Extra button: Panda Scan - {03F56B66-CB98-406D-980B-DC20FC5B8884} - http://www.pandasoftware.com/activescan/activescan.asp?Language=2&Country=63&Partner=1&Ref=EN-PR-AS-107 (file missing) (HKCU)
O9 - Extra button: Dictionary - {08E702D6-834F-4420-8C02-8EF8FB81F05D} - http://encarta.msn.com/encnet/features/dictionary/dictionaryhome.aspx (file missing) (HKCU)
O9 - Extra button: Music - {4FCD9C0F-719F-468C-91CC-5D81BCEFFD3B} - http://www.panoramicit.com/radio (file missing) (HKCU)
O9 - Extra button: Help - {59331B17-4E0E-45A2-B546-A3D3BBF3478B} - http://www.panoramicit.com/techsupport (file missing) (HKCU)
O9 - Extra button: Point Alert - {67B50696-04BA-48ea-A697-28AA0EAA9C26} - file://C:\Program Files\MyPoints_PointAlert\Sy800\Tp800\scri800a.htm (file missing) (HKCU)
O9 - Extra button: Atlas - {B5E34E7C-90E3-4C30-8B11-CEB1237DCFEB} - http://encarta.msn.com/encnet/features/mapcenter/map.aspx (file missing) (HKCU)
O9 - Extra button: IE Update - {D2A9762B-DBF1-4D62-8278-6DB61820B062} - http://www.panoramicit.com/DOWNLOAD/WIN32/EN/ie6setup.exe (file missing) (HKCU)
O9 - Extra button: Software - {D668DD02-D0C6-4CAD-BC50-26CED0208EF1} - http://111things.com/apf4/amazon.cgi?SearchIndex=Software (file missing) (HKCU)
O9 - Extra button: Shopping - {D6DD2729-B589-48FA-8779-8D9372CF3350} - http://www.111things.com (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.com
O15 - Trusted Zone: http://www.adpost.com
O15 - Trusted Zone: http://www.ahcppo.com
O15 - Trusted Zone: http://www.bottomlinewholesaler.com
O15 - Trusted Zone: http://jobs.brassring.com
O15 - Trusted Zone: http://pub44.bravenet.com
O15 - Trusted Zone: www.bravenet.com
O15 - Trusted Zone: http://onwisconsin.careercast.com
O15 - Trusted Zone: www.classiccloseouts.com
O15 - Trusted Zone: http://www.clixgalore.com
O15 - Trusted Zone: http://www.common-knowledge.net
O15 - Trusted Zone: www.e-rewards.com
O15 - Trusted Zone: http://www.e-rewards.com
O15 - Trusted Zone: http://mailer.ebates.com
O15 - Trusted Zone: www.elance.com
O15 - Trusted Zone: http://members.esdinternational.org
O15 - Trusted Zone: http://www.esdinternational.org
O15 - Trusted Zone: http://screensaver.freeze.com
O15 - Trusted Zone: http://www.gozingsurveys.com
O15 - Trusted Zone: http://free.grisoft.com
O15 - Trusted Zone: http://bfc.iwon.com
O15 - Trusted Zone: http://btrack.iwon.com
O15 - Trusted Zone: http://www.linkshare.com
O15 - Trusted Zone: http://flipdog.monster.com
O15 - Trusted Zone: http://my.monster.com
O15 - Trusted Zone: www.monster.com
O15 - Trusted Zone: http://www.monsterworldwide.com
O15 - Trusted Zone: http://www.MyPoints.com
O15 - Trusted Zone: my.net-temps.com
O15 - Trusted Zone: www.net-temps.com
O15 - Trusted Zone: www.onwisconsin.com
O15 - Trusted Zone: http://survey.otxresearch.com
O15 - Trusted Zone: www.realtor.com
O15 - Trusted Zone: www.ripway.com
O15 - Trusted Zone: *.Safer products for home, personal, and pet use.
O15 - Trusted Zone: http://www.serve-you-rx.com
O15 - Trusted Zone: http://www.shutterfly.com
O15 - Trusted Zone: www.surveysavvy.com
O15 - Trusted Zone: http://www.weather.com
O15 - Trusted Zone: www.wisconsinjobnetwork.com
O15 - Trusted Zone: www.workathomeagent.com
O16 - DPF: ConferenceRoom Java Client -
O16 - DPF: Yahoo! Chat -
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} -
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {0D136D67-D293-4626-8C93-D12CF78E4590} (tcConference Setup) - http://67.19.231.218/ivocalize/tc4.cab
O16 - DPF: {0F1B982D-C18E-4F2F-8ADB-91C12D858A08} -
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} -
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) -
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} -
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {3DECE173-1936-4387-B641-D0F96567C36B} -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} -
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} -
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_02) -
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp.coupons.com/r3302/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} -
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} -
O16 - DPF: {C2F38867-251C-4216-9B1C-BBE89B8700E2} -
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} -
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Plug-in 1.4.2_06) -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v13/ticker.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} -
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\FYPWPP.DLL (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe



Kristin Wilson
~ I'm here because I know just enough to get myself in trouble ... HELP ME!!!

josefz
05-13-2006, 10:13 PM
Can you access Folder Options from Tools menu in Windows Explorer at least? Read <a target="_blank" href=http://www.winguides.com/registry/display.php/619/> Disable Folder Options Menu</a>. (The check mark on this folder in Control Panel is there intentionally, by default).

Disable Active Desktop in Display control panel, please.

About HijackThis: IMHO you can feel safe in fixing all of these entries, where words (file missing) or (no file) appears in analysis.

Also check all your trusted zone settings in Internet Explorer settings (cf. "O15" Section in HijackThis log).

kristinwilson
05-14-2006, 08:08 AM
Okay. I did a search in help and found it has something to do with IE no options. I do have that listed in my recent run programs list in the start list. I don't get it though. I did a search for the registry entry shown in the thread you linked to but I'm not finding it. I'm going to keep looking though and disable the active desktop too. I'll be back to let you know if I figure this out.

Oh, in the search/help section, I came across this:

Internet Explorer NoBrowserOptions Restriction Blocks Access to Folder Options
View products that this article applies to.
Article ID : 293848
Last Review : September 26, 2005
Revision : 3.1
This article was previously published under Q293848
SYMPTOMS
Setting a group policy to restrict access to the Internet Explorer Internet Options command also blocks access to the Folder Options command in Explorer windows.
Back to the top

RESOLUTION
To resolve this problem, obtain the latest service pack for Internet Explorer 5.01 for Windows 2000 or Internet Explorer 5.5. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
267954 (http://support.microsoft.com/kb/267954/EN-US/) How to Obtain the Latest Internet Explorer 5.01 Service Pack
276369 (http://support.microsoft.com/kb/276369/EN-US/) How to Obtain the Latest Service Pack for Internet Explorer 5.5
The English version of this fix should have the following file attributes or later:
Date Time Version Size File name
-------------------------------------------------------
09/04/2001 16:02 5.0.3216.600 810,768 Browseui.dll

My problem is running IE7 beta! Will this fix work then??? I'm afraid to run it and have it do more damage than good.

Kristin Wilson
~ I'm here because I know just enough to get myself in trouble ... HELP ME!!!

kristinwilson
05-14-2006, 08:32 AM
Here's the latest HiJackThis log after deleting the file missing and such. I did check the trusted zones, nothing new there.

Logfile of HijackThis v1.99.1
Scan saved at 10:27:30 AM, on 5/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb1 0.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Instant Buzz\IBDaemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\PrintScreen31\PrintScreen\PrintScreen.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Webshots\webshots.scr
C:\Program Files\HiJackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTML
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kwe.buildreferrals.com/homerotator.cgi
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1;;&lt;local&gt;
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O2 - BHO: XBTBPos00 - {E552EEFC-DE97-45D4-BA1A-F534A1B4A579} - C:\PROGRA~1\MORPHE~1\MORPHE~1.DLL
O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb1 0.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe
O4 - HKLM\..\Run: [MyPointsPointAlert0] "C:\Program Files\MyPoints_PointAlert\MyPointsPointAlert0.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\PrintScreen31\PrintScreen\PrintScreen.exe /nosplash
O4 - Startup: FavoriteSync.lnk = C:\Program Files\FavoriteSync\FavoriteSync.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MyPoints - file://C:\Program Files\MyPoints_PointAlert\Sy800\Tp800\scri800a.htm
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bv9zzqha.Kristin\ext ensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: Search Using Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~2\IBBar.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O9 - Extra 'Tools' menuitem: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\opls.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.com
O15 - Trusted Zone: http://www.adpost.com
O15 - Trusted Zone: http://www.ahcppo.com
O15 - Trusted Zone: http://www.bottomlinewholesaler.com
O15 - Trusted Zone: http://jobs.brassring.com
O15 - Trusted Zone: http://pub44.bravenet.com
O15 - Trusted Zone: www.bravenet.com
O15 - Trusted Zone: http://onwisconsin.careercast.com
O15 - Trusted Zone: www.classiccloseouts.com
O15 - Trusted Zone: http://www.clixgalore.com
O15 - Trusted Zone: http://www.common-knowledge.net
O15 - Trusted Zone: www.e-rewards.com
O15 - Trusted Zone: http://www.e-rewards.com
O15 - Trusted Zone: http://mailer.ebates.com
O15 - Trusted Zone: www.elance.com
O15 - Trusted Zone: http://members.esdinternational.org
O15 - Trusted Zone: http://www.esdinternational.org
O15 - Trusted Zone: http://screensaver.freeze.com
O15 - Trusted Zone: http://www.gozingsurveys.com
O15 - Trusted Zone: http://free.grisoft.com
O15 - Trusted Zone: http://bfc.iwon.com
O15 - Trusted Zone: http://btrack.iwon.com
O15 - Trusted Zone: http://www.linkshare.com
O15 - Trusted Zone: http://flipdog.monster.com
O15 - Trusted Zone: http://my.monster.com
O15 - Trusted Zone: www.monster.com
O15 - Trusted Zone: http://www.monsterworldwide.com
O15 - Trusted Zone: http://www.MyPoints.com
O15 - Trusted Zone: my.net-temps.com
O15 - Trusted Zone: www.net-temps.com
O15 - Trusted Zone: www.onwisconsin.com
O15 - Trusted Zone: http://survey.otxresearch.com
O15 - Trusted Zone: www.realtor.com
O15 - Trusted Zone: www.ripway.com
O15 - Trusted Zone: *.Safer products for home, personal, and pet use.
O15 - Trusted Zone: http://www.serve-you-rx.com
O15 - Trusted Zone: http://www.shutterfly.com
O15 - Trusted Zone: www.surveysavvy.com
O15 - Trusted Zone: http://www.weather.com
O15 - Trusted Zone: www.wisconsinjobnetwork.com
O15 - Trusted Zone: www.workathomeagent.com
O16 - DPF: ConferenceRoom Java Client -
O16 - DPF: Yahoo! Chat -
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} -
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {0D136D67-D293-4626-8C93-D12CF78E4590} (tcConference Setup) - http://67.19.231.218/ivocalize/tc4.cab
O16 - DPF: {0F1B982D-C18E-4F2F-8ADB-91C12D858A08} -
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} -
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) -
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} -
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {3DECE173-1936-4387-B641-D0F96567C36B} -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} -
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} -
O16 - DPF: {74F5614A-8A8C-43B4-8CC2-4B4EFAF4A6C5} -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_02) -
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp.coupons.com/r3302/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} -
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} -
O16 - DPF: {C2F38867-251C-4216-9B1C-BBE89B8700E2} -
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} -
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Plug-in 1.4.2_06) -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v13/ticker.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} -
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe


Nope, cannot access folder options from the tools menu. It shows a check on it and I'm locked out of it. I am using the user that supposedly has access to it though. Weird. It's not letting me do anything with it.

Kristin Wilson
~ I'm here because I know just enough to get myself in trouble ... HELP ME!!!

josefz
05-14-2006, 12:30 PM
Do not try fix your problems of MSIE7 with fixes intended for lower versions of MSIE.
Check if the value NoBrowserOptions (http://www.winguides.com/registry/display.php/442/>NoBrowserOptions</a>) does not exist, create it, and set the value to "0" to disable the restriction (in both User Key and System Key).

josefz
05-14-2006, 01:09 PM
Please read something about reason for completely uninstalling some pest software (or, fixing those entries by HijackThis, if unistalling fails):

O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe
<a target="_blank" href=http://www.pestpatrol.com/spywarecenter/pest.aspx?id=453097283>Instant Buzz Daemon at pestpatrol.com</a>
<a target="_blank" href=http://castlecops.com/s10527-IBDaemon_exe.html>Instant Buzz Daemon at castlecops.com</a>.

O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~2\IBBar.dll
<a target="_blank" href=http://www.pestpatrol.com/spywarecenter/pest.aspx?id=453097283>Instant Buzz Helper at pestpatrol.com</a>
<a target="_blank" href=http://castlecops.com/clsid-1717.html>Instant Buzz Helper at castlecops.com</a>.

kristinwilson
05-14-2006, 08:18 PM
Okey dokey. I'm not very understanding about the registry. You need to tell me exactly where to put it and how. I'm very afraid of doing things in the registry without exact direction on how. Please?!?! Thanks again.

Oh, I don't want to take out the IB. That's a marketing program I've never had a problem with.

Kristin Wilson
~ I'm here because I know just enough to get myself in trouble ... HELP ME!!!

josefz
05-15-2006, 12:09 AM
Your decision about IB - acknowledged.

I am afraid I am not able to direct and conduct you in registry editing exactly enough, because of I am on czech-localised Windows (and localising persons had not known either English or Computer Science or both). However, I feel my English language skills insufficient, too.

So read <a target="_blank" href=http://www.winguides.com/article.php?id=1&page=1&guide=registry>Windows Registry Tutorial</a> carefully.

Be wary: any change in Registry by Registry editor is irreversible simply, because of no default backups of Registry are made.
Therefore: before launchig Regedit
1. Close all runnig programs
2. <a target="_blank" href=http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx>Create Restore Point Manually</a>

---

Next part has only been tested on my computer which uses XP Pro, but I am sure it will be the same in XP Home.
If you want then copy and paste this reg file info into Notepad, save it as a .reg file elsewhere (e.g. onto your Desktop).
When saving:
1. Use SaveAs... dialog, instead of Save dialog
2. Be sure you have choosed "All file types" instead of "Text documents".
3. Name it including file extension ".reg", e.g. something.reg

Finally, double-click your something.reg file:

--------------------Copy and Paste within the lines---------------------------
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Inte rnet Explorer\Restrictions]
"NoBrowserOptions"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Int ernet Explorer\Restrictions]
"NoBrowserOptions"=dword:00000000

-------------------End Copy and Paste---------------------------------

HTH.

kristinwilson
05-15-2006, 09:45 AM
I did do that, found the instructions elsewhere in these forums. Didn't do anything different though. I could still see the folder options, they are still locked though. This is just so weird!!!! Any other ideas, since editing the registry didn't do it?

Kristin Wilson
~ I'm here because I know just enough to get myself in trouble ... HELP ME!!!

josefz
05-15-2006, 10:12 AM
Try this one (instructions are the same as previously).

--------------------Copy and Paste within the lines---------------------------
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer]
"NoFolderOptions"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\Explorer]
"NoFolderOptions"=dword:00000000


-------------------End Copy and Paste---------------------------------

Let me repeat last question: Can you access Folder Options from Tools menu in Windows Explorer at least?

kristinwilson
05-15-2006, 02:13 PM
Well, kind of. I can see it but it won't let me in to actually access it and make any changes.

Kristin Wilson
~ I'm here because I know just enough to get myself in trouble ... HELP ME!!!

josefz
05-15-2006, 03:41 PM
Try download trial version of <a target="_blank" href=http://www.winguides.com/tweak/>Tweak Manager™ 2.1 for Windows</a>.
It may appear convenient for you - need not edit the registry directly.

DownRiver
05-21-2006, 04:20 PM
Here's an easy fix. Go here and download "unlocker" http://www.snapfiles.com/reviews/Unlocker/Unlocker.html

Go into explorer and find the item you want to delete and delete it. That will at least get rid of it.

irishlady
03-16-2007, 08:14 PM
I've searched this form but don't see if any of the suggestions made fix the problem. I am having the same problem with this blue strip, I guesss you call it a task pane, on my desk top. Under the control panel there is a check mark on the folders icon and I cannot get in. I'm not sure how this happened. It may have been a result of my toddler pushing many buttons :mad: and I figured out how to get my icons back on the desktop but this I can't get rid of...... Anybody know how to get rid of.............. Thank you