D
d362636
I just recently had something very odd happen to me. Upon reboot, a
Command Prompt opened up and started deleting virtually everything in
my profile. It got through almost everything before I was able to kill
the window. It deleted everything on my desktop, half of what was is my
"My Documents" folder, everything in the "Application Data" folder,
etc. Noticing an odd folder in my Program Files folder, ACW, I took a
quick look. Apparently it was installed by that "Guided Help" thing as
I had used it to re-create the "Show Desktop" link on the Quick Start
menu(oh yeah, it deleted everything there too). What's curious is the
XML file it left behind. Here's how it reads"
<configuration caseSensitive="no">
<name>ACWExt</name>
<description>
</description>
<lastModifiedBy>REDMOND\kima</lastModifiedBy>
<lastModifiedDate>2006-04-05T15:29:00</lastModifiedDate>
-
<section name="resources">
<key name="ids_DR_DD" value="Rename %1 to %2">
</key>
<key name="ids_FC_DD" value="Delete %1">
</key>
<key name="ids_FR_DD" value="Rename %1 to %2">
</key>
<key name="ids_RCV_DD1" value="Delete registry value %1 under %2">
</key>
<key name="ids_RCV_DD2" value="Update the registry value %1 under %2
with data type %3 and data %4">
</key>
<key name="ids_RDK_DD" value="Restore the registry key %1">
</key>
<key name="ids_RDV_DD" value="Restore the registry value %1 under %2">
</key>
<key name="ids_RPC_DD" value="Launch %1">
</key>
<key name="ids_RRK_DD" value="Rename registry key %1 to %2">
</key>
<key name="ids_RRV_DD" value="Rename registry value %1 to %2 in %3
registry key">
</key>
<key name="ids_SS_DD" value="Stop service %1">
</key>
<key name="ids_STP_DD" value="Start service %1">
</key>
<key name="ids_DD_SD" value="Undo directory changes">
</key>
<key name="ids_FD_DD" value="Restore %1">
</key>
<key name="ids_FR_SD" value="Undo file changes">
</key>
<key name="ids_PS_DD" value="Reboot your computer to finish registering
all the programs those were running before guided help began">
</key>
<key name="ids_RCK_DD" value="Delete registry key %1">
</key>
<key name="ids_RCK_SD" value="Undo registry key">
</key>
<key name="ids_RPC_SD" value="Restore from the system restore point">
</key>
<key name="ids_SS_SD" value="Stop service">
</key>
<key name="ids_STP_SD" value="Start service">
</key>
</section>
</configuration>
What's all that "delete" stuff? I don't think this could have been what
opened that Command Prompt thing(I think it had something to do with
"my profile being unable to load" as I had read in the Windows Event
Log), but I'm just sort of curious now.
Thanks,
DM
Command Prompt opened up and started deleting virtually everything in
my profile. It got through almost everything before I was able to kill
the window. It deleted everything on my desktop, half of what was is my
"My Documents" folder, everything in the "Application Data" folder,
etc. Noticing an odd folder in my Program Files folder, ACW, I took a
quick look. Apparently it was installed by that "Guided Help" thing as
I had used it to re-create the "Show Desktop" link on the Quick Start
menu(oh yeah, it deleted everything there too). What's curious is the
XML file it left behind. Here's how it reads"
<configuration caseSensitive="no">
<name>ACWExt</name>
<description>
</description>
<lastModifiedBy>REDMOND\kima</lastModifiedBy>
<lastModifiedDate>2006-04-05T15:29:00</lastModifiedDate>
-
<section name="resources">
<key name="ids_DR_DD" value="Rename %1 to %2">
</key>
<key name="ids_FC_DD" value="Delete %1">
</key>
<key name="ids_FR_DD" value="Rename %1 to %2">
</key>
<key name="ids_RCV_DD1" value="Delete registry value %1 under %2">
</key>
<key name="ids_RCV_DD2" value="Update the registry value %1 under %2
with data type %3 and data %4">
</key>
<key name="ids_RDK_DD" value="Restore the registry key %1">
</key>
<key name="ids_RDV_DD" value="Restore the registry value %1 under %2">
</key>
<key name="ids_RPC_DD" value="Launch %1">
</key>
<key name="ids_RRK_DD" value="Rename registry key %1 to %2">
</key>
<key name="ids_RRV_DD" value="Rename registry value %1 to %2 in %3
registry key">
</key>
<key name="ids_SS_DD" value="Stop service %1">
</key>
<key name="ids_STP_DD" value="Start service %1">
</key>
<key name="ids_DD_SD" value="Undo directory changes">
</key>
<key name="ids_FD_DD" value="Restore %1">
</key>
<key name="ids_FR_SD" value="Undo file changes">
</key>
<key name="ids_PS_DD" value="Reboot your computer to finish registering
all the programs those were running before guided help began">
</key>
<key name="ids_RCK_DD" value="Delete registry key %1">
</key>
<key name="ids_RCK_SD" value="Undo registry key">
</key>
<key name="ids_RPC_SD" value="Restore from the system restore point">
</key>
<key name="ids_SS_SD" value="Stop service">
</key>
<key name="ids_STP_SD" value="Start service">
</key>
</section>
</configuration>
What's all that "delete" stuff? I don't think this could have been what
opened that Command Prompt thing(I think it had something to do with
"my profile being unable to load" as I had read in the Windows Event
Log), but I'm just sort of curious now.
Thanks,
DM