1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

need help restoring RegSeeker backup

Discussion in 'Other PC Software' started by rebecca, 2005/02/05.

Thread Status:
Not open for further replies.
  1. 2005/02/05
    rebecca Contributing Member

    rebecca Well-Known Member Thread Starter

    Joined:
    2004/07/31
    Messages:
    655
    Likes Received:
    1
    Let me preface this by saying MEA CULPA, loud and clear! I did a search on RegSeeker here and read everything I could find about it, and I still took the chance of running it with WindowsME, and on a computer with known "congenital" glitches, as it were. And on top of all that, I'm also totally inexperienced in registry matters - another caveat I chose to ignore. But hey, you don't move forward in life without taking chances, right?
    That having been said, here is my confession. I ran RegSeeker a couple of days ago for the first time, and it identified some 740 "questionable" items in my registry. I went through the entire list, deleting everything identified as "Invalid ActiveX" and "Obsolete entry ", along with every entry listed for programs that I no longer have on the computer. No problems with the computer immediately afterwards; add/remove programs worked fine (and still does, for that matter).
    When I booted up the computer yesterday, though, it took me half a dozen attempts before Windows would finish loading properly (it kept freezing partway through, and when I'd click on ctrl-alt-del, it was usually Explorer that was not responding, although once it was something called PCHSCHD). I opened the backup folder in RegSeeker, highlighted everything, and clicked on "merge ". A whole bunch of popups showed up, each one asking for verification on a separate item. I didn't pay attention to the number of entries in the backup folder the first time I tried this, but in all my subsequent attempts, there have been 43 files there. I'd initially deleted some 300 items -- when I run RegSeeker now, all but 43 are back in the registry. But those final 43 (or maybe just a single one of them), seem to be the key!
    I have a System Restore point created right before I ran RegSeeker, as well as several other restore points on earlier dates, but when I try to run SR, the computer reboots afterwards and says no changes were made to the computer, regardless of the date I choose. I've tried adjusting the amount of space allocated to SR (moved the slider practically all the way to minimum, rebooted, then moved it all the way to max), and I've maximized the allocated space before each of my dozen restoration attempts, but nothing's worked.
    I shut the computer down last night again, as is my habit, and had the same problem upon booting up this morning - again, five or six attempts before getting WinME to load properly. [Safe Mode always loads fine; I've tried restoring the RegSeeker backup files and running SR in both Safe mode and regular mode.]
    As far as I can tell, the system works fine once Windows DOES finally load all the way, but does anyone have any suggestions as to how I might be able to get it to load properly again every time?
    Many thanks!
     
  2. 2005/02/05
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15

  3. to hide this advert.

  4. 2005/02/06
    rebecca Contributing Member

    rebecca Well-Known Member Thread Starter

    Joined:
    2004/07/31
    Messages:
    655
    Likes Received:
    1
    No - reading the various posts on the subject in this forum left me cautious enough not to venture that far (although obviously not cautious enough for my own good!). Given that I'm having trouble just having deleted stuff that I'd gathered should be safe to get rid of, I don't think I'm ready to dig my grave any deeper at this point. Does your question imply that you think fixing everything[/] might resolve my problem?
    Thanks for the links - especially that first one (tasklist program functions and recommendations). I bookmarked that one and will undoubtedly be checking it often!
    Incidentally, for whatever it's worth, I also tried booting up from a startup diskette and running scanreg /fix. That didn't improve the situation any either.
     
    Last edited: 2005/02/06
  5. 2005/02/06
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi Rebecca,

    Yes, I was suggesting that fixing everything might solve your problem. I'm thinking that maybe in removing only some of the entries, something left behind is still trying to load and can't find the rest of the info it needs to do so, due to it being removed, so it just locks things up. I have always deleted everything it finds, and run a second and third time to cleanup leftovers, even with ME.

    Seems to me there is an option to create a bootlog, on the startup menu with the safe mode option. Might be worth creating one and posting.
     
  6. 2005/02/07
    rebecca Contributing Member

    rebecca Well-Known Member Thread Starter

    Joined:
    2004/07/31
    Messages:
    655
    Likes Received:
    1
    LOL! I've tried to create a bootlog of one of my freeze-up bootings, but now Windows seems to load okay every time. Takes longer than it used to, though (over 3 minutes), maybe that's why I kept thinking the loading process had stalled. In fact, the last time I tried restarting, I pressed ctrl-alt-del when I thought the process had stalled again, and sure enough, it said Explorer wasn't responding. But then I got sidetracked for a couple of minutes, and the next time I looked, Windows had finished loading, and everything seemed functional.
    I ran "Bootlog Analyzer ", which is how I found out about exactly how long the startup process is taking. Might someone be able to tell what's causing the slow-down by looking at my bootlog? I don't see any failure to load messages or anything...
    I'm still curious why my RegSeeker backups won't restore, and why my SR isn't working now either, despite the fact that there are a number of restore points available. Any suggestions as to how I might fix this?
     
  7. 2005/02/07
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    If you run RegSeeker again, does it find the same 740 some entries found in the first run? If so, the backups were successfully restored. Often times, System Restore will not change anything if there is nothing to fix, and if you didn't try using it until after first restoring the RegSeeker backups, it probably didn't find anything to fix. I've also seen System Restore not function properly anyway, regardless of whether or not there was something to fix, and one reason I don't rely on it for backups. :(

    There's a good possiblity that a bootlog would be helpful, but you may want to check a few other things first, as a bootlog is sometimes quite large, and time consuming/difficult to go through. I would suggest creating and posting a startup list from HijackThis, and maybe even a scan log.
     
  8. 2005/02/09
    rebecca Contributing Member

    rebecca Well-Known Member Thread Starter

    Joined:
    2004/07/31
    Messages:
    655
    Likes Received:
    1
    When I run RegSeeker now, it only comes up with 696 entries. If you add in the 43 backups that won't restore, that brings the total up to my original 740 (I may have rounded up on the original number). The fact that SR doesn't work even for restore points from a week ago (before I'd installed Trillian, for instance) tells me it's a general SR failure, not that there simply isn't anything to change. I've had SR fail on me before, too -- but somehow I got it working again the last time, following someone else's post in one of these forums (sadly, I didn't think to write down what I did. Time to start keeping a computer diary, I guess!).

    Following is my Hijack This log from today's startup; please explain to me what a "scan log" is, so that I can provide you with one of those as well. Thanks!

    Logfile of HijackThis v1.99.0
    Scan saved at 6:26:24 AM, on 2/9/2005
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v5.50 (5.50.4134.0600)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
    C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
    C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
    C:\PROGRAM FILES\GREETINGS WORKSHOP\GWREMIND.EXE
    C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
    C:\HIJACKTHIS\HIJACKTHIS.EXE

    O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEINT.DLL
    O2 - BHO: (no name) - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - (no file)
    O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
    O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TeaTimer.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
    O8 - Extra context menu item: Download with Star Downloader - C:\PROGRAM FILES\STAR DOWNLOADER\sdie.htm
    O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
    O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnview95.cab
    O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.epost.ca/printing/smsx.cab
     
  9. 2005/02/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    A scan log is what you posted. A startup log can be generated from HijackThis misc tools section. I'll look this log over tonight when I have more time, but I spotted Spybot's TeaTimer running right off. It keeps registry changes from being made. Shut it down and try remerging those reg files.
     
  10. 2005/02/09
    rebecca Contributing Member

    rebecca Well-Known Member Thread Starter

    Joined:
    2004/07/31
    Messages:
    655
    Likes Received:
    1
    OK, I think I shut down TeaTimer ( "exit Spybot S&D resident ") and tried merging the 43 files in the RegSeeker backup folder. Now when I run RegSeeker, it comes back with 705 entries - nine more than before restoring the 43 files.
    Startup is still very slow (Bootlog Analyzer reports that startup is taking 4 minutes), but at least when I click on my desktop icons, those open relatively quickly again (they'd been taking 10-15 seconds the last few days).
    Don't know if the following is of any use, but here is a list of the delays and failures reported by the Bootlog Analyzer:

    Delays:
    10:14:01 0.28 Loading Vxd = C:\PROGRA~1\GRISOFT\AVGFRE~1\AVG7CORE.VXD
    10:14:04 0.33 Loading PNP drivers of Creative Sound Blaster AudioPCI 64V (WDM) (PCI\VEN_1274&DEV_1371&SUBSYS_13711274&REV_09\48F000
    10:14:04 0.28 Loading PNP drivers of MDP3880-W(U) PCI Modem Enumerator (PCI\VEN_14F1&DEV_1033&SUBSYS_4034122D&REV_08\58F000)
    10:14:07 0.28 Starting Microsoft PS/2 Port Mouse (ACPI\*PNP0F03\0)
    10:14:09 1.33 Initing esdi_506.pdr
    10:14:10 0.28 Initing esdi_506.pdr
    10:14:10 1.06 Init Success esdi_506.pdr
    10:14:12 0.28 Dynamic load success C:\WINDOWS\system\serial.vxd
    10:14:12 1.83 INITCOMPLETE = AVGCORE
    10:14:14 0.50 Starting Creative Sound Blaster AudioPCI 64V (WDM) (PCI\VEN_1274&DEV_1371&SUBSYS_13711274&REV_09\48F000)
    10:14:15 5.83 InitDone = TSRQuery (time estimated)
    10:14:21 8.78 Enumerated Standard Floppy Disk Controller (ACPI\*PNP0700\0)
    10:14:30 17.67 Enumerated Microsoft Kernel Audio Mixer (SW\{B7EAFDC0-A680-11D0-96D8-00AA0051E51D}\{9B365890-165F-11D0-A195-0020AFD15
    10:14:48 191.00 Enumerated Microsoft Kernel System Audio Renderer (SW\{A7C7A5B0-5AF3-11D1-9CED-00A024BF0407}\{9B365890-165F-11D0-A195
    10:17:59 0.67 Started Client for Microsoft Networks (NETWORK\VREDIR\0000)

    Failure:
    10:14:05 Dynamic load failed: [000A1E83]File not found

    And last but not least, here is my Hijack This startup list log:
    StartupList report, 2/9/2005, 10:33:42 AM
    StartupList version: 1.52.2
    Started from : C:\HIJACKTHIS\HIJACKTHIS.EXE
    Detected: Windows ME (Win9x 4.90.3000)
    Detected: Internet Explorer v5.50 (5.50.4134.0600)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
    C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
    C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
    C:\PROGRAM FILES\GREETINGS WORKSHOP\GWREMIND.EXE
    C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
    C:\HIJACKTHIS\HIJACKTHIS.EXE

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\WINDOWS\Start Menu\Programs\StartUp]
    SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    SystemTray = SysTray.Exe
    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
    TaskMonitor = C:\WINDOWS\taskmon.exe
    LoadQM = loadqm.exe
    Zone Labs Client = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    AVG7_CC = C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
    AVG7_EMC = C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
    AVG7_AMSVR = C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    *StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
    TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
    SchedulingAgent = mstask.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    SpybotSD TeaTimer = C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TeaTimer.exe

    --------------------------------------------------

    File association entry for .TXT:
    HKEY_CLASSES_ROOT\txtfile\shell\open\command

    (Default) = C:\WINDOWS\NOTEPAD.EXE %1

    --------------------------------------------------

    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

    Shell=Explorer.exe
    SCRNSAVE.EXE=
    drivers=mmsystem.dll power.drv

    --------------------------------------------------

    C:\WINDOWS\WININIT.BAK listing:
    (Created 29/1/2005, 18:35:54)

    [rename]
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGLOG.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGLOG.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVG7.LNG=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVG7.LNG
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVG7CORE.VXD=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVG7CORE.VXD
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVG7RS.VXD=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVG7RS.VXD
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGAMSVR.EXE
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGCC.EXE
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCCKRN.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGCCKRN.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCFG.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGCFG.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCORE.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGCORE.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCTRL.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGCTRL.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGEMC.EXE
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGINET.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGINET.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGINET.EXE=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGINET.EXE
    C:\PROGRA~1\GRISOFT\AVGFRE~1\SETUP.LNS=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\SETUP.LNS
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGSCAN.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGSCAN.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGSET.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGSET.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGTEST.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGTEST.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGTMGR.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGTMGR.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGTRES.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGTRES.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGUNARC.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGUNARC.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGW.EXE=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVGW.EXE
    C:\PROGRA~1\GRISOFT\AVGFRE~1\CZECH.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\CZECH.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\MICROAVI.AVG=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\MICROAVI.AVG
    C:\PROGRA~1\GRISOFT\AVGFRE~1\MINIAVI.AVG=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\MINIAVI.AVG
    C:\PROGRA~1\GRISOFT\AVGFRE~1\SASLPL~1.DLL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\SASLPL~1.DLL
    C:\PROGRA~1\GRISOFT\AVGFRE~1\SETUP.DAT=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\SETUP.DAT
    C:\PROGRA~1\GRISOFT\AVGFRE~1\SETUP.EXE=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\SETUP.EXE
    C:\PROGRA~1\GRISOFT\AVGFRE~1\UPD_VERS.CFG=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\UPD_VERS.CFG
    C:\WINDOWS\SYSTEM32\DRIVERS\AVG7CORE.SYS=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\AVG7CORE.SYS
    NUL=C:\PROGRA~1\GRISOFT\AVGFRE~1\WAIT4SD
    NUL=C:\WINDOWS\ALLUSE~1\APPLIC~1\GRISOFT\AVG7DATA\AVG7UPD\INSTALL.1\U-FWD.IDX

    --------------------------------------------------

    C:\AUTOEXEC.BAT listing:

    SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
    SET windir=C:\WINDOWS
    SET winbootdir=C:\WINDOWS
    SET COMSPEC=C:\WINDOWS\COMMAND.COM
    SET PROMPT=$p$g
    SET TEMP=C:\WINDOWS\TEMP
    SET TMP=C:\WINDOWS\TEMP
    SET TVDUMPFLAGS=10

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    (no name) - C:\PROGRA~1\STARDO~1\SDIEINT.DLL - {FFFFFEF0-5B30-21D4-945D-000000000000}
    (no name) - (no file) - {387EDF53-1CF2-4523-BC2F-13462651BE8C}
    (no name) - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL - {4A368E80-174F-4872-96B5-0B27DDD11DB2}
    (no name) - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL - {53707962-6F74-2D53-2644-206D7942484F}
    (no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Tune-up Application Start.job
    PCHealth Scheduler for Data Collection.job
    Maintenance-Defragment programs.job
    Maintenance-ScanDisk.job
    Maintenance-Disk cleanup.job
    Norton SystemWorks One Button Checkup.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [CV3 Class]
    InProcServer32 = C:\WINDOWS\SYSTEM\WUV3IS.DLL
    CODEBASE = http://windowsupdate.microsoft.com/R880/V31Controls/x86/mil/en/actsetup.cab

    [{D27CDB6E-AE6D-11CF-96B8-444553540000}]
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    [Musicnotes Viewer]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MNVIEWER.DLL
    CODEBASE = http://www.musicnotes.com/download/mnview95.cab

    [Update Class]
    InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
    CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37971.1505092593

    [MeadCo ScriptX]
    InProcServer32 = C:\WINDOWS\SYSTEM\MCSCRIPX.DLL
    CODEBASE = https://www.epost.ca/printing/smsx.cab
    OSD = C:\WINDOWS\Downloaded Program Files\smsx.osd

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
    AUHook: C:\WINDOWS\SYSTEM\AUHOOK.DLL

    --------------------------------------------------
    End of report, 9,667 bytes
    Report generated in 0.394 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  11. 2005/02/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    TeaTimer is the box directly below SDHelper box, and you should also check Task Manager to be sure it's not running. I've never tried merging multiple reg files so I can't say for sure how well it works, but I would suggest merging them one at a time.

    Fix the following with HijackThis.

    O2 - BHO: (no name) - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - (no file)
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE

    http://www.infopackets.com/freenewsarticles/loadqm.exe__another+microsoft+disastrous+jewel.htm

    Reboot
     
  12. 2005/02/10
    rebecca Contributing Member

    rebecca Well-Known Member Thread Starter

    Joined:
    2004/07/31
    Messages:
    655
    Likes Received:
    1
    I'd thought that by right-clicking the Spybot S&E icon in my taskbar/system tray, I was turning off TeaTimer, but when I followed your suggestion this morning, and repeated the action and then checked Task Manager, TeaTimer was still running.
    Now I'm wondering how to tackle this next, as I already successfully merged SOME of the files yesterday (evidenced by the fact that RegSeeker now finds nine more entries than it did the day before -- yet still 34 entries fewer than originally. After turning off TeaTimer, do I just try merging everything again? Wouldn't this result in some double entries in my registry (and would this matter?)?
    In the meantime, I'll run Hijack This again and make the changes you recommended.
    FYI, my biggest problem now seems to be shutting down the computer - either Task Manager shows Rundll32 freezing up, or I simply get a blue screen with no Task Manager at all when I press ctrl-alt-del.
     
  13. 2005/05/17
    rebecca Contributing Member

    rebecca Well-Known Member Thread Starter

    Joined:
    2004/07/31
    Messages:
    655
    Likes Received:
    1
    Should've posted back the outcome back when this thread was still fresh, but better late than never, I hope.
    The outcome of it all was that noahdfear was right: I hadn't turned off TeaTimer properly. Once I did that, I was able to restore the RegSeeker backup without further ado, and everything was fine immediately thereafter.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.