Upon restart Windows Server 2003 r2 w/ SP2 is unable to load my local profile. It logs me on with a temporary profile that is devoid of 'Favorites", data files, and some apps.
I will post a HijackThis log below.
Logfile of HijackThis v1.99.1
Scan saved at 7:00:27 AM, on 5/14/2008
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\csrss.
exe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\msdtc.
exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\inetsr
v\inetinfo
.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSMSI\SSEE\MSS
QL.2005\MS
SQL\Binn\s
qlservr.ex
e
C:\Program Files\Microsoft SQL Server\MSSQL$PCTOOLS\Binn\
sqlservr.e
xe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\BIN\wsstraci
ng.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter
.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\ThreatFire\TFService
.exe
C:\Program Files\UPHClean\uphclean.ex
e
C:\WINDOWS\system32\Search
Indexer.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\alg.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\soundman.exe
C:\Program Files\ThreatFire\TFTray.ex
e
C:\Program Files\Microsoft Office2003\Office12\Groove
Monitor.ex
e
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\Program Files\Java\jre1.6.0_06\bin
\jusched.e
xe
C:\Program Files\BillP Studios\WinPatrol\winpatro
l.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Microsoft Office2003\OFFICE11\ONENOT
EM.EXE
C:\Program Files\Microsoft Office2003\Office12\ONENOT
EM.EXE
C:\WINDOWS\system32\wbem\w
miprvse.ex
e
C:\Program Files\Microsoft Office2003\Office12\OUTLOO
K.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Microsoft Office2003\Office12\WINWOR
D.EXE
C:\DOCUME~1\ADMINI~1\LOCAL
S~1\Temp\T
emporary Directory 8 for hijackthis_199.zip\HijackT
his.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://shdoclc.dll/hardAdmi
n.htm
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: IEToolbarBHO Class - {1A1DAC8C-074D-440F-8707-7
009A672D7D
1} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\Linkedi
nIEToolbar
.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0
BBC1D38A37
E} - C:\Program Files\Microsoft Office2003\Office12\Groove
ShellExten
sions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.6.0_06\bin
\ssv.dll
O3 - Toolbar: LinkedIn Toolbar - {BB670D0B-5C46-40C7-B38B-4
0DD2698772
3} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\Linkedi
nIEToolbar
.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
rs.exe
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.ex
e
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DWPersistentQueuedReporti
ng] C:\PROGRA~1\COMMON~1\MICRO
S~1\DW\DWT
RIG20.EXE -a
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office2003\Office12\Groove
Monitor.ex
e"
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin
\jusched.e
xe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatro
l.exe -expressboot
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dump
rep 0 -u
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office2003\OFFICE11\ONENOT
EM.EXE
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office2003\Office12\ONENOT
EM.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1
\Office12\
EXCEL.EXE/
3000
O8 - Extra context menu item: Linked&In Search - res://C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\Linkedi
nIEToolbar
.dll/Conte
xtMenu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_06\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_06\bin
\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~1\Offic
e12\ONBttn
IE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~1\Offic
e12\ONBttn
IE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~1\Offic
e12\REFIEB
AR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4EFA317A-8569-4788-B175-5
BAF9731A54
9} (Microsoft Virtual Server VMRC Advanced Control) -
https://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1192078234609O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192105086812O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
060082AA75
C} (GpcContainer Class) -
https://ultimus.webex.com/client/T23L/event/ieatgpc.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{E
7050A54-6B
C0-4736-AE
4E-62E9EB2
F20E7}: NameServer = 192.168.0.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3
CB6248B04C
D} - C:\Program Files\Microsoft Office2003\Office12\Groove
SystemServ
ices.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
0C04F8EC29
4} - c:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-0
0B0D022E94
5} - C:\PROGRA~1\COMMON~1\MICRO
S~1\OFFICE
12\MSOXMLM
F.DLL
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsnt
fy.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: MSSQL$PCTOOLS - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$PCTOOLS\Binn\
sqlservr.e
xe" -sPCTOOLS (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexing
Service.ex
e
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: SQLAgent$PCTOOLS - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$PCTOOLS\Binn\
sqlagent.E
XE" -i PCTOOLS (file missing)
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService
.exe