Toolbar settings lost

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

OK, this is really frustrating. Every time I configure IE (Ver 6.0 SP1) on my Windows XP machine (i.e. - toolbar positions and window size), after logging out or rebooting IE reverts back to a default state. I've tried everything recommended here (locking the toolbars, shift-X, etc.) but nothing works

What's really odd is that I have an almost identical machine (HP Pavilion with WinXP Pro) at the office and it does not exhibit this behavior - IE preferences stick reliably

Can anybody help? I'm at my wit's end having to reconfigure IE every time I boot up!
 
Reset the toolbar positions using this fix:
http://www.dougknox.com/xp/utils/xp_toolbarfix.htm

Customize it and lock the toolbar again. If this does not help, run
"Hijackthis" and post the log here.

--
Ramesh - Microsoft MVP
http://www.mvps.org/sramesh2k

Microsoft Most Valuable Professional Program
http://mvp.support.microsoft.com

~ Please reply to newsgroup ~


OK, this is really frustrating. Every time I configure IE (Ver 6.0 SP1) on
my Windows XP machine (i.e. - toolbar positions and window size), after
logging out or rebooting IE reverts back to a default state. I've tried
everything recommended here (locking the toolbars, shift-X, etc.) but
nothing works.

What's really odd is that I have an almost identical machine (HP Pavilion
with WinXP Pro) at the office and it does not exhibit this behavior - IE
preferences stick reliably.

Can anybody help? I'm at my wit's end having to reconfigure IE every time I
boot up!
 
Ramesh

Tried the Doug Knox toolbarfix - no effect (actually, IE hung the system when I first tried to move a toolbar, required a forced reboot)

Here's the logfile from Hijackthis. Hope you can help

Logfile of HijackThis v1.97.
Scan saved at 10:38:13 PM, on 11/19/200
Platform: Windows XP SP1 (WinNT 5.01.2600
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106

Running processes
C:\WINDOWS\System32\smss.ex
C:\WINDOWS\system32\winlogon.ex
C:\WINDOWS\system32\services.ex
C:\WINDOWS\system32\lsass.ex
C:\WINDOWS\System32\Ati2evxx.ex
C:\WINDOWS\system32\svchost.ex
C:\WINDOWS\System32\svchost.ex
C:\WINDOWS\system32\spoolsv.ex
C:\WINDOWS\Explorer.EX
C:\windows\system\hpsysdrv.ex
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.ex
C:\Program Files\HP\HP Software Update\HPWuSchd.ex
C:\WINDOWS\System32\hphmon05.ex
C:\HP\KBD\KBD.EX
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.ex
C:\Program Files\Multimedia Card Reader\shwicon2k.ex
C:\WINDOWS\ALCXMNTR.EX
C:\Program Files\AdobeCS\Adobe Version Cue\ControlPanel\VersionCueTray.ex
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EX
C:\Program Files\Logitech\MouseWare\system\em_exec.ex
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.ex
C:\Program Files\Dialog Box Assistant\OSDEx.ex
C:\Program Files\Microsoft Office\Office\1033\msoffice.ex
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.ex
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.ex
C:\Program Files\Internet Explorer\iexplore.ex
C:\Documents and Settings\Mark\My Documents\My Received Files\HijackThis.ex

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = javascript:resizeTo(1280,1024);moveTo(0,0);document.location.href='http://www.terrierclub.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhos
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dl
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dl
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dl
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dl
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.oc
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dl
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dl
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dl
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.ex
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.ex
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.ex
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.ex
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.ex
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EX
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EX
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartu
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetec
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.ex
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.ex
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.ex
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EX
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\AdobeCS\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo 2200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus Photo 2200" /O6 "USB001" /M "Stylus Photo 2200"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Startup: Dialog Box Assistant.lnk = C:\Program Files\Dialog Box Assistant\OSDEx.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PhotoCAL Startup.lnk = C:\Program Files\PANTONE COLORVISION\PhotoCAL\PhotoCAL.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI31CC~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O10 - Broken Internet access because of LSP provider 'spsublsp.dll' missing
 
Tried toolbarfix, no effect

Here's the log from Hijackthis
(Sorry if this reply appears twice - first post didn't seem to take...

Logfile of HijackThis v1.97.
Scan saved at 10:38:13 PM, on 11/19/200
Platform: Windows XP SP1 (WinNT 5.01.2600
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106

Running processes
C:\WINDOWS\System32\smss.ex
C:\WINDOWS\system32\winlogon.ex
C:\WINDOWS\system32\services.ex
C:\WINDOWS\system32\lsass.ex
C:\WINDOWS\System32\Ati2evxx.ex
C:\WINDOWS\system32\svchost.ex
C:\WINDOWS\System32\svchost.ex
C:\WINDOWS\system32\spoolsv.ex
C:\WINDOWS\Explorer.EX
C:\windows\system\hpsysdrv.ex
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.ex
C:\Program Files\HP\HP Software Update\HPWuSchd.ex
C:\WINDOWS\System32\hphmon05.ex
C:\HP\KBD\KBD.EX
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.ex
C:\Program Files\Multimedia Card Reader\shwicon2k.ex
C:\WINDOWS\ALCXMNTR.EX
C:\Program Files\AdobeCS\Adobe Version Cue\ControlPanel\VersionCueTray.ex
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EX
C:\Program Files\Logitech\MouseWare\system\em_exec.ex
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.ex
C:\Program Files\Dialog Box Assistant\OSDEx.ex
C:\Program Files\Microsoft Office\Office\1033\msoffice.ex
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.ex
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.ex
C:\Program Files\Internet Explorer\iexplore.ex
C:\Documents and Settings\Mark\My Documents\My Received Files\HijackThis.ex

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhos
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dl
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dl
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dl
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dl
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.oc
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dl
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dl
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dl
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.ex
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.ex
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.ex
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.ex
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.ex
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EX
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EX
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartu
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetec
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.ex
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.ex
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.ex
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EX
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.ex
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Ex
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\AdobeCS\Adobe Version Cue\ControlPanel\VersionCueTray.ex
O4 - HKLM\..\Run: [EPSON Stylus Photo 2200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus Photo 2200" /O6 "USB001" /M "Stylus Photo 2200
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Startup: Dialog Box Assistant.lnk = C:\Program Files\Dialog Box Assistant\OSDEx.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PhotoCAL Startup.lnk = C:\Program Files\PANTONE COLORVISION\PhotoCAL\PhotoCAL.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI31CC~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O10 - Broken Internet access because of LSP provider 'spsublsp.dll' missing
 
Mark, The log seems to be OK. No spyware present. You may disable the
third-party browser extensions to check if it helps:

If not, set yourself read only permission for this key: (after customizing
the toolbars)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser

--
Ramesh - Microsoft MVP
http://www.mvps.org/sramesh2k

Microsoft Most Valuable Professional Program
http://mvp.support.microsoft.com

~ Please reply to newsgroup ~


Tried toolbarfix, no effect.

Here's the log from Hijackthis:
(Sorry if this reply appears twice - first post didn't seem to take...)

Logfile of HijackThis v1.97.7
Scan saved at 10:38:13 PM, on 11/19/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\AdobeCS\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dialog Box Assistant\OSDEx.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mark\My Documents\My Received Files\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://srch-us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program
Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program
files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program
Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar1.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program
Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital
Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software
Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program
Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card
Reader\shwicon2k.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\AdobeCS\Adobe Version
Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo 2200]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus
Photo 2200" /O6 "USB001" /M "Stylus Photo 2200"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital
Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Startup: Dialog Box Assistant.lnk = C:\Program Files\Dialog Box
Assistant\OSDEx.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PhotoCAL Startup.lnk = C:\Program Files\PANTONE
COLORVISION\PhotoCAL\PhotoCAL.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel
present
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1
\MI31CC~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O10 - Broken Internet access because of LSP provider 'spsublsp.dll' missing
 
Mark said:
OK, this is really frustrating. Every time I configure IE (Ver 6.0
SP1) on my Windows XP machine (i.e. - toolbar positions and window
size), after logging out or rebooting IE reverts back to a default
state. I've tried everything recommended here (locking the toolbars,
shift-X, etc.) but nothing works.

What's really odd is that I have an almost identical machine (HP
Pavilion with WinXP Pro) at the office and it does not exhibit this
behavior - IE preferences stick reliably.

Can anybody help? I'm at my wit's end having to reconfigure IE every
time I boot up!

Right click the toolbar and make sure Lock Toolbars is not checked.
 
Mark,
Odd Toolbar Behavior
http://www.mvps.org/winhelp2002/ietips.htm#Odd
Download: ResetBrowserToolbar.reg
--
As for your HijackThis log, I see a few problems there:
(including the bottom half of your log is missing)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost

Did you select the above?
--
O10 - Broken Internet access because of LSP provider 'spsublsp.dll' missing
http://www.spywareinfo.com/~merijn/htlogtutorial.html#o10
present
Did you enable these Restrictions?
http://www.spywareinfo.com/~merijn/htlogtutorial.html#o6
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 11-19-03]
Please post replies to this Newsgroup, email address is invalid
--

Mark said:
Tried toolbarfix, no effect.

Here's the log from Hijackthis:
<snip>
 
Thanks for the tips, Ramesh

Third party browser extensions is already disabled
Also, I tried the Read only permission for that key and it didn't seem to help either (though I'm not sure I did it right...do I leave Full Control permissions for System and Administrators? What about the "Inherit from parent..." checkbox?

FWIW, I tried changing the toolbar layout in Windows Explorer and it also gets reset on startup so this problem afflicts both IE and Explorer.

Mark
 
Thanks Mike

I'll try the ResetBrowserToolbar.reg download you recommended

As for the following points you mentioned

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Interne
Settings,ProxyOverride = localhos

- Not sure where this came from. Should I delete it from within HijackThis

O10 - Broken Internet access because of LSP provider 'spsublsp.dll
missin

- Also don't know where this came from, but I have no problems with Internet access. However, this line also appears in the log on my office machine which does not exhibit the toolbar issue
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restriction presen
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Pane
presen

- Shall I also delete these from within HijackThis? Note that I've already run Spybot Search and Destroy and removed any suspect spyware/adware.
 
You may try this:
http://www.winguides.com/registry/display.php/152/
[IE checks for NoSaveSettings value everytime. So, the above might help]

If not, try a repair of IE:
How to Reinstall or Repair Internet Explorer and Outlook Express in Windows
XP:
http://support.microsoft.com/?kbid=318378

[Set the registry key "IsInstalled" to 0]

304872 - Unable to Install Internet Explorer 6 on Windows XP:
http://support.microsoft.com/?kbid=304872


--
Ramesh - Microsoft MVP
http://www.mvps.org/sramesh2k

Microsoft Most Valuable Professional Program
http://mvp.support.microsoft.com

~ Please reply to newsgroup ~


Thanks for the tips, Ramesh.

Third party browser extensions is already disabled.
Also, I tried the Read only permission for that key and it didn't seem to
help either (though I'm not sure I did it right...do I leave Full Control
permissions for System and Administrators? What about the "Inherit from
parent..." checkbox?)

FWIW, I tried changing the toolbar layout in Windows Explorer and it also
gets reset on startup so this problem afflicts both IE and Explorer.

Mark
 
I had a similar problem, not with IE but with XP folders. Every time I
logged back on the system the folder toolbar settings went back to
default instead of what I had them set to in the previous session. The
fix was to stop the program Autotkit.exe from running at startup. I
did it thru msconfig.
I see you have it running from your Hijack log.......
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE


Mark said:
Ramesh,

Tried the Doug Knox toolbarfix - no effect (actually, IE hung the system when I first tried to move a toolbar, required a forced reboot).

Here's the logfile from Hijackthis. Hope you can help!

Logfile of HijackThis v1.97.7
Scan saved at 10:38:13 PM, on 11/19/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\AdobeCS\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dialog Box Assistant\OSDEx.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mark\My Documents\My Received Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = javascript:resizeTo(1280,1024);moveTo(0,0);document.location.href='http://www.terrierclub.com'
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\AdobeCS\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo 2200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus Photo 2200" /O6 "USB001" /M "Stylus Photo 2200"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Startup: Dialog Box Assistant.lnk = C:\Program Files\Dialog Box Assistant\OSDEx.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PhotoCAL Startup.lnk = C:\Program Files\PANTONE COLORVISION\PhotoCAL\PhotoCAL.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI31CC~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O10 - Broken Internet access because of LSP provider 'spsublsp.dll' missing
 
Chuck,
"The fix was to stop the program Autotkit.exe from running at startup"
Thanks for the feedback! ..... I'll have to remember that.
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 11-19-03]
Please post replies to this Newsgroup, email address is invalid
--

Chuck said:
I had a similar problem, not with IE but with XP folders. Every time I
logged back on the system the folder toolbar settings went back to
default instead of what I had them set to in the previous session. The
fix was to stop the program Autotkit.exe from running at startup. I
did it thru msconfig.
I see you have it running from your Hijack log.......
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
<snip>
 
Giant sigh of relief
Chuck's suggestion to disable Autotkit.exe fixed my toolbar issue. I had nearly given up after trying every conceivable fix and registry edit. And yes, I even disabled many of the startup processes but left Autotkit since I couldn't find any info on the web regarding this program and thought it might be critical

HP should really yank this thing from their PCs or at least issue a warning. What exactly is its purpose anyway

Thanks again, guys
Mark
 
Back
Top