247fixes PC Help Forum: C:\documents - 247fixes PC Help Forum

Jump to content

Welcome to 247fixes PC Help Forum

Welcome to 247fixes PC Help Forum, like most online communities you must register to view or post in our community, but don't worry this is a simple free process that requires minimal information. Take advantage of it immediately, Register Now or Sign In.

  • Start new topics and reply to others
  • Subscribe to topics and forums to get automatic updates
  • Add events to our community calendar
  • Get your own profile and make new friends
  • Customize your experience here
Guest Message © 2010 DevFuse
  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

C:\documents

#1 User is offline   Fuser77 

  • Full Member
  • PipPip
  • Group: Member+
  • Posts: 12
  • Joined: 27-July 09

Posted 28 July 2009 - 10:57 AM

Good Morning,

I was having this problem with my PC during the last two weeks:

http://i979.photobucket.com/albums/ae278/Fuser77/SystemMessage1.jpg

The message appears at start-up, before Windows shows any activity.

I don't think it is an actual System Message...

I posted this problem in Spyware Beware and got help from Rorschach112, who referred me here...

Rorschach112 had me performing a series of tasks and now my system appears to be clean... though I still get the C:\Documents message...

Could someone help me out with this? What can I do to get rid of the problem?

Many thanks!
0

#2 User is offline   Artellos 

  • Bionic Boy
  • Icon
  • Group: Tech Helper
  • Posts: 689
  • Joined: 02-July 08
  • Gender:Male
  • Location:Steenwijk, The Netherlands

Posted 28 July 2009 - 12:23 PM

Hello Fuser77,

Rorschach112 told me you were coming so I did some thinking on the issue before you posted ;)
I would actually like to try a program I wrote.

Please download SINO by Artellos from here

  • Save SINO to a place you can remember and run SINO.exe.
  • Then please check the following checkboxes:
    Startup Items
    System Info

  • Once checked, hit the Run Scan! button and wait for the program to finish the scan.
  • A notepad file will pop up, Please copy and paste the content of the notepad into your next reply.


Note: If you try to interact with the program once it's started scanning it might appear to hang. The scan however will continue.

Regards,
Olrik
0

#3 User is offline   Fuser77 

  • Full Member
  • PipPip
  • Group: Member+
  • Posts: 12
  • Joined: 27-July 09

Posted 28 July 2009 - 12:33 PM

Hello Olrik!

It's fine by me, I will try your software in the afternoon once at home and then will let you know.

Thanks for the thinking around!
0

#4 User is offline   Extremeboy 

  • Da 247 Malware Disintegrator Instructor
  • Icon
  • Group: Academy Instructor
  • Posts: 2680
  • Joined: 19-February 09
  • Gender:Male

Posted 28 July 2009 - 01:24 PM

-Edit Out-

Sorry.. Wrong member. Mist-post. Please ignore.

This post has been edited by Extremeboy: 28 July 2009 - 01:26 PM

0

#5 User is offline   Fuser77 

  • Full Member
  • PipPip
  • Group: Member+
  • Posts: 12
  • Joined: 27-July 09

Posted 30 July 2009 - 03:21 AM

Hello Olrik!

(Sorry, it's been a very long working day...!)

Here's the log from your software:
---------------------------------------------------------------------------------------------------------------------
System Investigator by Olrik
Log Created On: 2318_29-07-2009
C: | 183488 MB out of 305168 MB Free | Local Fixed Disk
D: | None | CD-ROM Disc
E: | None | CD-ROM Disc
F: | None | Removable Disk

<<<< System Information >>>>

Computer Name: OWNER-CEBD65DA7
Username: Alf
Language Setting: ENU
Windows Directory: C:\WINDOWS
Windows Version: Windows XP Service Pack 3

<<<< Startup Items >>>>

[desktop] - <Startup> - desktop.ini
[desktop] - <Startup> - desktop.ini
[OpenOffice.org 3.0] - <Startup> - C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
[ERUNT AutoBackup] - <Startup> - C:\PROGRA~1\ERUNT\AUTOBACK.EXE %SystemRoot%\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow
[SpywareGuard] - <Startup> - C:\PROGRA~1\SPYWAR~2\sgmain.exe
[ctfmon.exe] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\system32\ctfmon.exe
[WeatherEye] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
[Google Update] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Documents and Settings\Alf.OWNER-CEBD65DA7\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
[IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
[SpybotSD TeaTimer] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[MSMSGS] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Messenger\msmsgs.exe" /background
[Run[0]] - <*HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\Windows> -
[Load[0]] - <*HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\Windows> -
[desktop] - <Startup> - desktop.ini
[OpenOffice.org 3.0] - <Startup> - C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
[BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
[ctfmon.exe] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\system32\ctfmon.exe
[MSMSGS] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Messenger\msmsgs.exe" /background
[QuickTime Task] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\QuickTime\qttask.exe" -atboottime
[desktop] - <Startup> - desktop.ini
[desktop] - <Common Startup> - desktop.ini
[BOC-427] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
[Adobe Reader Speed Launcher] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[SSBkgdUpdate] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
[PaperPort PTD] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[IndexSearch] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
[NBKeyScan] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[NeroFilterCheck] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[SunJavaUpdateSched] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Java\jre6\bin\jusched.exe"
[avast!] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[Run[0]] - <win.ini> -
[Load[0]] - <win.ini> -



END OF LOG FILE, Date of Completion: 2318_29-07-2009----------
---------------------------------------------------------------------------------------------------------------------

The scan was completed in no time!

Kind regards.
0

#6 User is offline   Artellos 

  • Bionic Boy
  • Icon
  • Group: Tech Helper
  • Posts: 689
  • Joined: 02-July 08
  • Gender:Male
  • Location:Steenwijk, The Netherlands

Posted 30 July 2009 - 03:26 AM

Hello Fuser77,

Can you open up Start, then go to Run.
In the box type msconfig
Once msconfig is open, go to the startup page.
Look for Google Update and remove the tickbox in front of it.
Close msconfig by clicking OK.

Reboot your PC and see if the Error message still pops up.

Regards,
Olrik
0

#7 User is offline   Fuser77 

  • Full Member
  • PipPip
  • Group: Member+
  • Posts: 12
  • Joined: 27-July 09

Posted 31 July 2009 - 09:21 PM

Good Day, Olrik

I did, and C:\Documents is still there...

Then right after I get this one:

http://i979.photobucket.com/albums/ae278/Fuser77/SystemConfig1.jpg

Then System Configuration window pops-up and finally I am requested to reboot the system...

http://i979.photobucket.com/albums/ae278/Fuser77/SystemConfig2.jpg

What's next?

Thank you!
0

#8 User is offline   Artellos 

  • Bionic Boy
  • Icon
  • Group: Tech Helper
  • Posts: 689
  • Joined: 02-July 08
  • Gender:Male
  • Location:Steenwijk, The Netherlands

Posted 31 July 2009 - 09:34 PM

Hello there,

Please see if you have the same issues in safe mode:
  • Reboot your machine.
  • After you hear the first beep keep tapping F8.
  • You'll get a menu up and should be able to select safe mode.


Regards,
Olrik
0

#9 User is offline   Fuser77 

  • Full Member
  • PipPip
  • Group: Member+
  • Posts: 12
  • Joined: 27-July 09

Posted 05 August 2009 - 04:46 AM

Dear Olrik,

Sorry for the late reply.

C:\Documents does not show up in Safe Mode, but I forgot to specify that it does appears on normal mode only when accessing user accounts with administrator rights... it does not show up in accounts with no rights...

Question: what should I do with System Config? Should I put it back as it was or leave it like that?
In case that I leave it like it is now, how can I avoid System Configuration Messages at startup?

Again, thank you so much for your help!
0

#10 User is offline   Artellos 

  • Bionic Boy
  • Icon
  • Group: Tech Helper
  • Posts: 689
  • Joined: 02-July 08
  • Gender:Male
  • Location:Steenwijk, The Netherlands

Posted 05 August 2009 - 09:09 AM

Hello Fuser77,

Quote

Sorry for the late reply.

Don't worry about it :) Take everything at YOUR pace.
We are here to help you! :thumbup:

Quote

C:\Documents does not show up in Safe Mode, but I forgot to specify that it does appears on normal mode only when accessing user accounts with administrator rights... it does not show up in accounts with no rights...

Ok, thanks for the extra bit of information. I will be playing around with some virtual machines to try and reproduce your problem.

Quote

Question: what should I do with System Config? Should I put it back as it was or leave it like that?
In case that I leave it like it is now, how can I avoid System Configuration Messages at startup?

You can enable the google updater again.
To get rid of the System Config screen at bootup, tick the box in the warning window, then press OK :)

I would like a copy of your win.ini, To do that, follow these instructions:
  • Open start and select Run...
  • In the box, type: type win.ini > C:\winini.txt
  • Then go to your C:\ drive and open the file winini.txt
  • Please copy and paste the contents of that file into your next reply.


Regards,
Olrik
0

#11 User is offline   Fuser77 

  • Full Member
  • PipPip
  • Group: Member+
  • Posts: 12
  • Joined: 27-July 09

Posted 06 August 2009 - 02:12 AM

Dear Olrik,

I believe this is the one...

---------------------------------------------------------------------------------------------------------------------

; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1
[MCI Extensions.BAK]
aif=MPEGVideo
aifc=MPEGVideo
aiff=MPEGVideo
asf=MPEGVideo
asx=MPEGVideo
au=MPEGVideo
m1v=MPEGVideo
m2v=MPEGVideo
m3u=MPEGVideo
mod=MPEGVideo
mp2=MPEGVideo
mp2v=MPEGVideo
mp3=MPEGVideo
mpa=MPEGVideo
mpe=MPEGVideo
mpeg=MPEGVideo
mpg=MPEGVideo
mpv2=MPEGVideo
snd=MPEGVideo
wax=MPEGVideo
wm=MPEGVideo
wma=MPEGVideo
wmv=MPEGVideo
wmx=MPEGVideo
wpl=MPEGVideo
wvx=MPEGVideo
---------------------------------------------------------------------------------------------------------------------

Thank you!
0

#12 User is offline   Artellos 

  • Bionic Boy
  • Icon
  • Group: Tech Helper
  • Posts: 689
  • Joined: 02-July 08
  • Gender:Male
  • Location:Steenwijk, The Netherlands

Posted 08 August 2009 - 12:56 PM

Hello Fuser77,

That is indeed the one.
Could you re-run SINO for me, please? (the same options)

Regards,
Olrik
0

#13 User is offline   Fuser77 

  • Full Member
  • PipPip
  • Group: Member+
  • Posts: 12
  • Joined: 27-July 09

Posted 14 August 2009 - 12:31 PM

Good day to you, Olrik!

Hope you're doing well...

Her's the SINO log:

---------------------------------------------------------------------------------------------------------------------


System Investigator by Olrik
Log Created On: 0828_14-08-2009
C: | 169385 MB out of 305168 MB Free | Local Fixed Disk
D: | None | CD-ROM Disc
E: | None | CD-ROM Disc
I: | None | Removable Disk

<<<< System Information >>>>

Computer Name: OWNER-CEBD65DA7
Username: Alf
Language Setting: ENU
Windows Directory: C:\WINDOWS
Windows Version: Windows XP Service Pack 3

<<<< Startup Items >>>>

[desktop] - <Startup> - desktop.ini
[desktop] - <Startup> - desktop.ini
[OpenOffice.org 3.0] - <Startup> - C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
[ERUNT AutoBackup] - <Startup> - C:\PROGRA~1\ERUNT\AUTOBACK.EXE %SystemRoot%\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow
[SpywareGuard] - <Startup> - C:\PROGRA~1\SPYWAR~2\sgmain.exe
[ctfmon.exe] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\system32\ctfmon.exe
[WeatherEye] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
[IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
[SpybotSD TeaTimer] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[MSMSGS] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Messenger\msmsgs.exe" /background
[Run[0]] - <*HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\Windows> -
[Load[0]] - <*HKU\S-1-5-21-1482476501-1035525444-1801674531-1005\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\Windows> -
[desktop] - <Startup> - desktop.ini
[OpenOffice.org 3.0] - <Startup> - C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
[BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
[ctfmon.exe] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\system32\ctfmon.exe
[MSMSGS] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Messenger\msmsgs.exe" /background
[QuickTime Task] - <HKU\S-1-5-21-1482476501-1035525444-1801674531-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\QuickTime\qttask.exe" -atboottime
[desktop] - <Startup> - desktop.ini
[desktop] - <Common Startup> - desktop.ini
[BOC-427] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
[Adobe Reader Speed Launcher] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[SSBkgdUpdate] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
[PaperPort PTD] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[IndexSearch] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
[NBKeyScan] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[NeroFilterCheck] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[avast!] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[Acrobat Assistant 8.0] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
[] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> -
[Adobe_ID0EYTHM] - <HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
[Run[0]] - <win.ini> -
[Load[0]] - <win.ini> -



END OF LOG FILE, Date of Completion: 0828_14-08-2009----------


---------------------------------------------------------------------------------------------------------------------

Kindest regards.
0

#14 User is offline   Artellos 

  • Bionic Boy
  • Icon
  • Group: Tech Helper
  • Posts: 689
  • Joined: 02-July 08
  • Gender:Male
  • Location:Steenwijk, The Netherlands

Posted 14 August 2009 - 01:37 PM

Hello Fuser77,

I'm going to do some testing on a virtual machine.
I'll get back to you later. :)

Regards,
Olrik
0

#15 User is offline   Artellos 

  • Bionic Boy
  • Icon
  • Group: Tech Helper
  • Posts: 689
  • Joined: 02-July 08
  • Gender:Male
  • Location:Steenwijk, The Netherlands

Posted 14 August 2009 - 02:25 PM

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :reg
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

EDIT: You can throw away SINO.exe and the folder C:\SINO :)

Regards,
Olrik

This post has been edited by Artellos: 14 August 2009 - 02:26 PM
Reason for edit: Forgot to add extra info.

0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users