Bonjour Falu,
Wow, was I ever pleasantly surprised to find you in my email folder!
Thanks for returning.

Happy days are here again!
I read you latest instructions (3/16/07). I got through most of them. But, when I attempted to activate "fix.reg" (I named it BP fix.reg), I received the following error message:
"
Cannot import C:\Documents and Settings\RUMMY\DESKTOP\BP fix.reg: Error accessing the registry." Being unable to move forward, I stopped at that point. Details of my progress up until then are described after the following "UPDATES FROM POGO".
UPDATES FROM POGORecently I found a little new information. Perhaps some of it will prove useful.
After our last communication, I studied very closely, many of the HJT scans I had sent you. As I did so, it seemed to me that some items which should have been displayed, were not.
Back when I was running all those HJT scans, I assumed no items were being "Ignored" by HJT. But that assumption proved to be wrong. Permit me to explain.
Prior to running an HJT Scan, I viewed the IGNORE list. Most of the time the display window was completely empty or blank (hence my assumption). But once while viewing the IGNORE window, low and behold, there was a short list present. I asked myself, "How can that possibly be?" At the time I hadn't a clue. But I deleted the entire list. I said to myself, "That takes care of that", and went ahead with the HJT scan.
Attempting to develop an hypothesis that would explain these contradictory observations, I mulled over in my mind for a long time. As a result, last night I looked in the registry and found that in fact, HJT had many items listed to be IGNORED; some were listed more than once. That mystified me. So I uninstalled HJT.
With what I presumed to be a "clean" HJT application, I checked the registry to determine if there were any IGNORE entries. There were none.
Falu, I have concluded that the HJT scans I sent you for analysis, were less than fully accurate and therefore highly prone to misinterpretation; certainly not as credible nor as useful as they should have been. As such, they may have prevented you from making an accurate analysis. I apologize for that. Only you know how the faulty HJT reports may have effected your efforts.
The following is a new HJT scan ... with no "Ignore" in effect. -----------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:28:39 PM, on 3/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Merriam-Webster Online BHO - {5ADA9CAC-04F9-4DD2-ABFD-74D673BE8624} - C:\WINDOWS\_MWOLTB.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O3 - Toolbar: Merriam-Webster Online - {B7B76DD6-B6F0-4443-AF81-6A3ECF12A57D} - C:\WINDOWS\_MWOLTB.DLL
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: MWOL &Dictionary - res://C:\WINDOWS\_MWOLTB.DLL/23/219
O8 - Extra context menu item: MWOL &Thesaurus - res://C:\WINDOWS\_MWOLTB.DLL/23/220
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Offline - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - C:\WINDOWS\system32\oline.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CABO16 - DPF: {3CF32649-D1C0-4F42-AB44-ED284748920B} (Merriam-Webster Online Toolbar) -
http://www.m-w.com/downloads/toolbar/webinstall.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
------------------------------------------------------------------
Please notice:
a. Kaspersky Internet Security -- not running
b. Windows Defender -- not running
c. AVG Anti-Spyware -- not running
Are we happy?
------------------------------------------------------------------
In one of your posts you suggested that some "tweak" may have locked something in the register that prevented a change to
R3. In addition to whatever comes with Windows XP SP2, I also have
Tweak UI for Windows XP (sp1 and Higher). I have searched everything I could think of, including TweakUI, but haven't recognized anything that might solve that "Lock" situation. I must be over-looking something? Any suggestions?
While
Googling I found the following regedit file and d/l it to the Desktop.
Website: www.kellys-korner-xp.com.
File name: HomePageUnlock.reg
In EDIT mode, it looks like this:
=========================================================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage"=dword:00000000
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage"=dword:00000000
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"HomePage"=dword:00000001
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"**del.HomePage"=" "
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoSaveSettings"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoSaveSettings"=dword:00000000
===============================================================
I don't have the expertise to know if I should use this reg file or not. Might it solve the "Lock" problem?
Any advice?
New Topic: Below you will find what I did in the way of following the instructions in your most recent post (3/16/07).
If you don't mind I would like to try the following, just to be sure:
1. Please disable your realtime protection:
> Windows Defender:
Open Windows Defender.
Click on Tools, General Settings.
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender.Falu, just in case you need to update your cut & past boiler-plate Resources for WINDOWS DEFENDER, I will point out that: When I click on TOOLS, there is no "General Settings Tab". But there is a choice on the TOOLS page labeled "Options", for making changes.
I
unchecked "Turn on real-time protection", in addition I
unchecked everything there else and hit SAVE.
> AVG AntiSpyware:
* Launch AVG Anti-Spyware.
* From the "Status" menu, select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'.In my edition (Free) of AVG Anti-Spyware, the Status Page has no "Change state" option. But there are some changes that can be made on that page.
"Resident Shield" is followed by "n/a". No change to make.
"Automatic Updates" is followed by "n/a". No change to make.
I have the AVG Anti-spyware Startup disabled.
* Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".I have no AVG icon in the system tray.
* Next, go to Start > Run and type: services.msc
* Press "OK".
* Click the "Extended tab" and scroll down the list to find AVG Anti-Spyware guard.
* When you find the guard service, double-click on it.
* In the Properties Window > General Tab that opens, click the "Stop" button.
* From the drop-down menu next to "Startup Type", click on "Manual".
* Now click "Apply", then "OK" and close the Services windowAVG Anti-Spyware was already set to the "STOP" button, it was also set to "Manual" Startup. So there were no changes to made. But I didn't close the Services window yet.
The last time we went through a proceedure very similar to this, we discovered that even with WINDOWS DEFENDER disabled as a Startup Program, HJT showed
C:\Program Files\Windows Defender\MsMpEng.exe as a Running Process.
I don't know if, under that situation, Defender interferred with our "Fix" or not. But it is my belief that by using Kaspersky Internet Security, Windows Defender and it's associated parts isn't actually
required to be running." So after setting AVG Anti-Spyware "Startup Type" to MANUAL (see above), I went ahead and set the Windows Defender "Startup Type" to MANUAL. I hope this was the correct thing to do. I will change it back when we are completly finished.
Kaspersky: right click on the icon in the taskbar and select Exit. When the fixes have been done, you can reopen Kaspersky by the icon which should be on your desktop. Alternatively you may have to reboot.I changed to "Work Offline" ... then Exited Kaspersky in the taskbar.
2. Open Notepad and copy and paste the following text in the codebox into it (starting with "Windows registry Editor):CODE
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
"LinksFolderName"=-
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files".I did so. It is on the Desktop as a Registry file.
Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.I did so. This is when I received the Error Message:
Cannot import C:\Documents and Settings\RUMMY\Desktop\BP fix.reg:Error accessing the registry.Since I could not proceed, I stopped at this point.
Reboot and post a fresh HijackThis log!Falu, I tried very hard to make this as clear and coherant as I could. I hope it is useful to you.
Thanks again for stepping back into the picture.
pogo