Forum Home
Press F1
 
Thread ID: 80742 2007-07-03 22:15:00 Slow Boot Windows XP BlackMDK (12503) Press F1
Post ID Timestamp Content User
565515 2007-07-03 22:15:00 I'm really puzzled with this one, booting in to XP for moment I enter my username/password till explorer.exe shows up takes 4min and 15 sec. This is IBM thinkpad with Core duo 1.66 Mhz CPU and 1GB of RAM. I did all the usual stuff spyware, antivirus, turn of all unnecessary services and run hips of diagnostics but nothing helps. One interesting thing is that if I log on as a different user it is almost instantaneous. Once PC boots it is as fast as it should be with no problems.

Here is filtered boot log, showing event that take more than 0,8 sec during the time in question :

"Sequence","Time of Day","Process Name","Operation","Path","Detail","Result","Duration"
"287552","9:54:16.5267800 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.1275514"
"306312","9:54:17.6545038 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.8073646"
"306349","9:54:18.4620271 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9934919"
"306504","9:54:19.4556618 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9979025"
"306631","9:54:20.4537266 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9991181"
"306999","9:54:21.4530042 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9938067"
"308272","9:54:22.5533463 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9844706"
"308541","9:54:23.5379728 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.4046224"
"309943","9:54:25.4554037 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9968702"
"310527","9:54:26.4524293 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9983031"
"310564","9:54:27.4508754 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9985957"
"310606","9:54:28.4496163 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9990639"
"310658","9:54:29.4488182 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0022816"
"310677","9:54:30.4512386 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9989960"
"310703","9:54:31.4503742 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999992"
"310783","9:54:32.4505335 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9988124"
"310800","9:54:33.4494822 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9970005"
"310820","9:54:34.4466481 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998178"
"310855","9:54:35.4466263 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998201"
"310872","9:54:36.4465955 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998322"
"310898","9:54:37.4465754 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0013019"
"310970","9:54:38.4480600 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997664"
"311001","9:54:39.4479664 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9994080"
"311030","9:54:40.4475236 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998299"
"311056","9:54:41.4475211 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998491"
"311100","9:54:42.4475311 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997380"
"311237","9:54:43.4474482 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0017287"
"311793","9:54:44.4493400 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9983702"
"311816","9:54:45.4478482 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9994698"
"311856","9:54:46.4474512 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998296"
"311877","9:54:47.4474121 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998869"
"311928","9:54:48.4474325 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997749"
"311951","9:54:49.4473605 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0683162"
"327888","9:54:50.5157834 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9380089"
"327931","9:54:51.4539297 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9993332"
"327983","9:54:52.4534023 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9981104"
"328044","9:54:53.4516459 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9989166"
"328088","9:54:54.4507008 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0008010"
"331228","9:54:55.4516512 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9991142"
"331298","9:54:56.4509145 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9991100"
"331345","9:54:57.4501597 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9984241"
"331402","9:54:58.4487154 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9995144"
"331434","9:54:59.4483639 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0005677"
"331821","9:55:00.4490939 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9990418"
"331859","9:55:01.4482762 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9992142"
"331945","9:55:02.4476359 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997754"
"331974","9:55:03.4475406 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0023375"
"332002","9:55:04.4500231 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9996508"
"332028","9:55:05.4498278 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9989764"
"332069","9:55:06.4489447 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997844"
"332092","9:55:07.4488662 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9993125"
"332138","9:55:08.4484472 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9995751"
"332379","9:55:09.4481701 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0009473"
"332574","9:55:10.4492710 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9798260"
"334702","9:55:11.7476975 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.8438975"
"340961","9:55:13.7434257 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9544973"
"350208","9:55:16.7480948 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9983204"
"350335","9:55:17.7465747 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9993628"
"350385","9:55:18.7460741 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9987702"
"350433","9:55:19.7449960 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9989952"
"350496","9:55:20.7441378 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0005739"
"350584","9:55:21.7448857 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9990742"
"350627","9:55:22.7441063 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0029048"
"350666","9:55:23.7471684 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9991063"
"350738","9:55:24.7464351 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0027816"
"350781","9:55:25.7493944 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9959696"
"350891","9:55:26.7455307 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997760"
"350958","9:55:27.7454682 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9990443"
"350974","9:55:28.7446365 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998832"
"350990","9:55:29.7446572 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998541"
"351006","9:55:30.7446365 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0001017"
"351043","9:55:31.7449287 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9988409"
"351102","9:55:32.7439127 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0050252"
"351839","9:55:33.7491114 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9953603"
"352157","9:55:34.7446114 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999069"
"352188","9:55:35.7446709 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9986883"
"352215","9:55:36.7435305 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0007180"
"352239","9:55:37.7443887 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9989289"
"352298","9:55:38.7434548 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998092"
"352328","9:55:39.7434014 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997986"
"352346","9:55:40.7433246 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999103"
"352383","9:55:41.7433841 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997980"
"352413","9:55:42.7433165 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","2.0000123"
"352527","9:55:44.7434690 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997028"
"352563","9:55:45.7433294 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997913"
"352587","9:55:46.7432665 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998346"
"352602","9:55:47.7432458 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997897"
"352617","9:55:48.7431559 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998946"
"352646","9:55:49.7431964 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0001223"
"352708","9:55:50.7434791 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9995547"
"352740","9:55:51.7432115 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0000681"
"352760","9:55:52.7434288 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0004780"
"352802","9:55:53.7440635 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9989038"
"352832","9:55:54.7430989 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999329"
"352881","9:55:55.7431723 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0000012"
"352934","9:55:56.7433087 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9996427"
"352957","9:55:57.7430927 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997668"
"352986","9:55:58.7429838 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998824"
"353015","9:55:59.7430000 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9993111"
"353040","9:56:00.7424815 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.8852767"
"358999","9:56:02.7434126 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9995430"
"359053","9:56:03.7431148 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0023056"
"359104","9:56:04.7455699 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999446"
"359122","9:56:05.7456735 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9989345"
"359160","9:56:06.7447471 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998989"
"359199","9:56:07.7448052 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9994164"
"360702","9:56:08.7443728 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0015753"
"363109","9:56:09.7461487 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9995770"
"363149","9:56:10.7458682 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998321"
"363188","9:56:11.7458520 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9987423"
"363206","9:56:12.7447293 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0000335"
"363231","9:56:13.7449072 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.9993734"
"363702","9:56:15.7444197 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9994505"
"363726","9:56:16.7440107 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997221"
"363756","9:56:17.7438710 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997634"
"363786","9:56:18.7437649 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9993438"
"363801","9:56:19.7432447 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998363"
"363860","9:56:20.7432271 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997033"
"363896","9:56:21.7430746 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998229"
"363911","9:56:22.7430215 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9994706"
"363936","9:56:23.7426505 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998662"
"363984","9:56:24.7426619 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998587"
"364016","9:56:25.7426667 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998645"
"364133","9:56:26.7426924 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998134"
"364148","9:56:27.7426480 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997572"
"364187","9:56:28.7425365 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998869"
"364280","9:56:29.7425929 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997995"
"364295","9:56:30.7425206 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998544"
"364372","9:56:31.7425332 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999589"
"364431","9:56:32.7426237 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9996932"
"364447","9:56:33.7424524 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998522"
"364486","9:56:34.7424315 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998527"
"364516","9:56:35.7424354 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998491"
"364552","9:56:36.7424209 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998131"
"364567","9:56:37.7423709 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999547"
"364638","9:56:38.7424658 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997545"
"364668","9:56:39.7423653 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997717"
"364685","9:56:40.7422647 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999198"
"364714","9:56:41.7423337 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997885"
"364729","9:56:42.7422490 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998562"
"364759","9:56:43.7422465 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999492"
"364828","9:56:44.7423208 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997475"
"364843","9:56:45.7422052 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998676"
"364865","9:56:46.7422018 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998609"
"364894","9:56:47.7422194 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998249"
"364931","9:56:48.7421745 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998893"
"364946","9:56:49.7421976 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998738"
"364991","9:56:50.7421976 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997819"
"365027","9:56:51.7421180 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998874"
"365063","9:56:52.7421471 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998181"
"365084","9:56:53.7421177 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998003"
"365119","9:56:54.7420459 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998953"
"365154","9:56:55.7420792 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999075"
"365206","9:56:56.7421379 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997916"
"365235","9:56:57.7420680 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998081"
"365272","9:56:58.7419993 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998254"
"365290","9:56:59.7419568 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998402"
"365319","9:57:00.7419138 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0000824"
"365407","9:57:01.7421496 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997139"
"365452","9:57:02.7419862 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997502"
"365467","9:57:03.7418775 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998718"
"365491","9:57:04.7418761 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998804"
"365520","9:57:05.7419060 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998014"
"365556","9:57:06.7418406 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998737"
"365571","9:57:07.7418454 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999525"
"365624","9:57:08.7419325 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997483"
"365640","9:57:09.7418194 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998041"
"366777","9:57:11.6543152 a.m.","svchost.exe","680","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS\Tasks","Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_DIR_NAME","SUCCESS","41.9791859"
"366786","9:57:11.7416772 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","1.0003489"
"366807","9:57:12.7421524 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998841"
"366822","9:57:13.7421862 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999600"
"366881","9:57:14.7422854 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997223"
"366910","9:57:15.7421541 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998784"
"366973","9:57:16.7421826 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997667"
"366988","9:57:17.7420937 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999696"
"367026","9:57:18.7422041 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9993245"
"367059","9:57:19.7416649 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998902"
"367104","9:57:20.7416906 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998097"
"367126","9:57:21.7416470 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997933"
"367155","9:57:22.7415749 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9999037"
"367184","9:57:23.7416160 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9997709"
"367199","9:57:24.7415096 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","0.9998871"
"367229","9:57:25.7415453 a.m.","winlogon.exe","IRP_MJ_DIRECTORY_CONTROL","C:\WINDOWS","Type: NotifyChangeDirectory","SUCCESS","2.0014907"

Also here is hijaxkThis output just in case:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:18:22 a.m., on 4/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService. exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Village Tronic VTBook\Driver\VTBookGauge.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Hotspot Shield\AnchorFree\ctrl\AFController.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\VideoMate\ComproSchedulerDTV.exe
C:\Program Files\Evoluent\VMouse\EvoMouExec.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE
C:\Program Files\Borland\Delphi6\Bin\delphi32.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\IDM Computer Solutions\UltraEdit-32\uedit32.exe
C:\Download\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://appserver01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://appserver01
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CEventSink Class - {B7154C4D-87C0-4A2C-AB64-DA132BAC2EE6} - C:\Program Files\Hotspot Shield\AnchorFree\ie\AFBho.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrB kGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBa ttLog
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [VTBookGauge] "C:\Program Files\Village Tronic VTBook\Driver\VTBookGauge.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AFProg] C:\Program Files\Hotspot Shield\AnchorFree\ctrl\AFController.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: ComproSchedulerDTV.lnk = ?
O4 - Global Startup: Evoluent Mouse Manager.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O14 - IERESET.INF: START_PAGE_URL=http://appserver01
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - www.kaspersky.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = tvdint.co.nz
O17 - HKLM\Software\..\Telephony: DomainName = tvdint.co.nz
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = tvdint.co.nz
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService. exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Unknown owner - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (file missing)

Any ideas?:badpc: :help:
BlackMDK (12503)
565516 2007-07-03 22:52:00 Run HJT again tick these entries and tick fix checked.

Close browser/s.

Do you know what this is??

C:\Program Files\Village Tronic VTBook\Driver\VTBookGauge.exe - This could be the reason you're slow.

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"

O4 - HKLM\..\Run: [VTBookGauge] "C:\Program Files\Village Tronic VTBook\Driver\VTBookGauge.exe"

I would run these manually

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized

I would get Rogueremover and trojan remover in my sig below.

Update both then click on scan.
Speedy Gonzales (78)
565517 2007-07-04 00:07:00 till explorer.exe shows up takes 4min and 15 sec. I did all the usual stuff spyware, antivirus, turn of all unnecessary services and run hips of diagnostics but nothing helps.

I'd say theres a heap of stuff loading along with Windows as well as Speedys advice.

STart - Run - type in MSCONFIG.
Click the startup tab and untick the piles of unnecessary things you have loading up at the same time.
pctek (84)
565518 2007-07-04 00:40:00 corrupted profile! SolMiester (139)
565519 2007-07-04 00:41:00 And using Bittorent / P2P programs doesnt help..

I would also install an AV program and a firewall.
Speedy Gonzales (78)
565520 2007-07-04 00:47:00 This is frustrating, I removed those few apps as per suggestion above and also had run Rogue remover and Trojan Remover they didn’t find anything. There is nothing much to un tick in msconfig either. I guess I did not mention that this is brand new rebuild of machine. Thing is that according to the boot log nothing is really loading in to memory during the time in question, no drivers no services nothing, there is no CPU or disk activity it is just Winlogon process preparing to load my user profile and according to the log above calls to disk take about 1 sec each with one taking whooping 47 sec. My best guess is that problem lies with particular user profile but what can be done about it?

Ah and by the way VTBookGauge.exe is part of the VGA driver for third and fourth monitor that allows hot plug and unplug.
BlackMDK (12503)
565521 2007-07-04 00:49:00 corrupted profile!

So how do i go about it, i don't want to loose or application settings
BlackMDK (12503)
565522 2007-07-04 00:50:00 And using Bittorent / P2P programs doesnt help..

I would also install an AV program and a firewall.


I have AV and firewall but currently they are uninstalled until i figure out what is the problem
BlackMDK (12503)
565523 2007-07-04 00:51:00 Lates Hijack output

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:53:34 a.m., on 4/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService. exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hotspot Shield\AnchorFree\ctrl\AFController.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Evoluent\VMouse\EvoMouExec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Download\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://appserver01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://appserver01
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CEventSink Class - {B7154C4D-87C0-4A2C-AB64-DA132BAC2EE6} - C:\Program Files\Hotspot Shield\AnchorFree\ie\AFBho.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrB kGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBa ttLog
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [AFProg] C:\Program Files\Hotspot Shield\AnchorFree\ctrl\AFController.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Evoluent Mouse Manager.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O14 - IERESET.INF: START_PAGE_URL=http://appserver01
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - www.kaspersky.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = tvdint.co.nz
O17 - HKLM\Software\..\Telephony: DomainName = tvdint.co.nz
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = tvdint.co.nz
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - (no file)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService. exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - (no file)

--
BlackMDK (12503)
565524 2007-07-04 01:00:00 So how do i go about it, i don't want to loose or application settings

Read this (support.microsoft.com)
Speedy Gonzales (78)
1 2