Hi Wes,
Thanks so much for getting back. This problem has been driving me
nuts.
I know this is a lot of info, but since you asked about what's
running,
following is a) the report from the defrag tool, and b) a hijackthis
log.
I had everything (incl outlook and google desktop) turned off to do
the
defrag, although I notice below that there are some lines that cite
google
desktop. I don't konw how to interpret, though.
Your further thoughts are much appreciated.
--------DEFRAG REPORT-----------------------
Volume (C

Volume size = 18.63 GB
Cluster size = 4 KB
Used space = 15.14 GB
Free space = 3.49 GB
Percent free space = 18 %
Volume fragmentation
Total fragmentation = 28 %
File fragmentation = 52 %
Free space fragmentation = 5 %
File fragmentation
Total files = 58,727
Average file size = 355 KB
Total fragmented files = 252
Total excess fragments = 78,828
Average fragments per file = 2.34
Pagefile fragmentation
Pagefile size = 700 MB
Total fragments = 14
Folder fragmentation
Total folders = 6,247
Fragmented folders = 1
Excess folder fragments = 0
Master File Table (MFT) fragmentation
Total MFT size = 91 MB
MFT record count = 65,598
Percent MFT in use = 70 %
Total MFT fragments = 10
--------------------------------------------------------------------------------
Fragments File Size Files that cannot be defragmented
481 5 MB \Documents and Settings\All
Users\Documents\Steph transfer\My Music\iTunes\iTunes Music\Janet
Jackson\Velvet Rope\18 I Get Lonely.m4a
481 18 MB \Documents and Settings\Drew\Local
Settings\Application Data\Google\Picasa2\db\thumbs.db
339 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP649\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP646\snapshot\_REGISTRY_MACHINE_SOFTWARE
329 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP647\snapshot\_REGISTRY_MACHINE_SOFTWARE
328 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP671\snapshot\_REGISTRY_MACHINE_SOFTWARE
328 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP672\snapshot\_REGISTRY_MACHINE_SOFTWARE
328 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP673\snapshot\_REGISTRY_MACHINE_SOFTWARE
328 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP674\snapshot\_REGISTRY_MACHINE_SOFTWARE
328 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP675\snapshot\_REGISTRY_MACHINE_SOFTWARE
328 20 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP676\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP684\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP687\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP688\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP679\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP689\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP680\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP681\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP682\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP683\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP685\snapshot\_REGISTRY_MACHINE_SOFTWARE
330 21 MB \System Volume
Information\_restore{C3BEA450-728D-434E-A34C-D4588905521C}\RP686\snapshot\_REGISTRY_MACHINE_SOFTWARE
865 60 MB \Documents and Settings\Drew\Local
Settings\Application Data\Google\Google Desktop Search\dbeao
544 80 MB \Documents and Settings\Drew\Local
Settings\Application Data\Google\Google Desktop Search\dbdam
9,667 254 MB \Documents and Settings\All
Users\Documents\Steph transfer\outlook.pst
1,348 260 MB \Documents and Settings\Drew\Local
Settings\Application Data\Google\Google Desktop Search\fii.cf1
1,140 280 MB \Documents and Settings\Drew\Local
Settings\Application Data\Google\Google Desktop Search\dbeam
8,253 720 MB \Documents and Settings\Drew\Local
Settings\Application Data\Google\Google Desktop Search\rpm.cf1
12,417 742 MB \Documents and Settings\Drew\Local
Settings\Application Data\Microsoft\Outlook\outlook.pst
12,478 1.05 GB \Documents and Settings\Drew\Local
Settings\Application Data\Microsoft\Outlook\archive.pst
---END DEFRAG REPORT-----------
START HIJACK THIS LOG--------------
Logfile of HijackThis v1.98.2
Scan saved at 3:58:01 PM, on 9/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\PavProt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\apachefriends\xampp\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\APVXDWIN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes2\iTunesHelper.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\PavFnSvr.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\Pavkre.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\AVENGINE.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\prevsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus
2005\WebProxy.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\system32\DfrgNtfs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Drew\Local Settings\Temp\Temporary Directory
1 for
hijackthis.zip\HijackThis.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\regedit /s
C:\pav.reg,C:\WINDOWS\System32\pavdr.exe,C:\WINDOWS\System32\userinit.exe,
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Desktop Search Capture -
{7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program
Files\Google\Google
Desktop Search\GoogleDesktopIE.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} -
C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} -
C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon
initialize
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda
Titanium
Antivirus 2005\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program
Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program
Files\iTunes2\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program
Files\Google\Google
Desktop Search\GoogleDesktop.exe" /startup
O4 - Startup: WinMySQLadmin.lnk =
C:\apachefriends\xampp\mysql\bin\winmysqladmin.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM
Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program
files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program
files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://c:\program
files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List -
res://C:\Program
Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print -
res://C:\Program
Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program
Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program
Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Onclave Share it! -
http://www.onclave.org/js/shareit-js.htm
O8 - Extra context menu item: Onclave: Magnet Share it -
http://magnet.onclave.com/js/shareit/shareit-invoker-js.htm
O8 - Extra context menu item: Similar Pages - res://c:\program
files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://c:\program
files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: TypePad QuickPost -
https://www.typepad.com/t/app?__mode=reg_qp_js&qp_show=ca&qp_height=625
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\OneNote\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\Program
Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\program files\google\google
desktop
search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: c:\program files\google\google
desktop
search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: c:\program files\google\google
desktop
search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: c:\program files\google\google
desktop
search\googledesktopnetwork1.dll
---------END HIJACKTHIS LOG------------------
Sorry for all the data, but thanks very much for any further insight.
Wesley Vogel said:
Are any Office programs, Outlook, running when you defrag?
Is Google Desktop running when you defrag?
Close them.