Registry Corrupt [every morning]

P

Pink Sparkle Girl

For the last few days everytime I have booted up my PC in the morning I find
the registry has become corrupt and I need to use the Recovery Console to
get it up and running again.
Today I have restored the system to three weeks ago where as the last few
times I used a dated from a few days before the first time it happened (22nd
Oct).
I have run all kinds of spyware along with Norton but found nothing
different from the usual tracking cookies. When I reboot or turn off then on
again later during the day the PC is fine, it is just after it has been
turned of for 12 hours or so. I didn't download anything on Friday 21st that
would cause a change like this as far as I can recall.
Bar re-installing XP I don't know what else to do if it repeats itself
tomorrow morning!

Any ideas what is wrong and how to fix it?

Thanks, Sarah.

P.S.
Here is my HijackThis log (just in case):

Logfile of HijackThis v1.99.1
Scan saved at 15:11:57, on 27/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\System32\mqsvc.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\system32\inetsrv\DavCData.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program
Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class -
{AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet
Security\IAMAPP.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st
800-840\dslmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF -
res://C:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program
Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program
Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .MID: C:\Program Files\Internet
Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .tif: C:\Program Files\Internet
Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/act...l_v1-0-3-24.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by103fd.bay103.hotmail.msn.c...es/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
http://software-dl.real.com/070048d...ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.c...b?1111008140780
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
Class) - http://security.symantec.com/sscv6/...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microso...b?1128358082365
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/controls/msnchat45.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{7F41286F-AEEF-4BAD-8336-1C7A8EA0856F}:
NameServer = 80.225.250.178 80.225.250.186
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common
Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program
Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Iomega App Services - Iomega Corporation -
C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec
Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec
Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec
Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) -
Symantec Corporation - C:\Program Files\Norton Internet
Security\SymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega
Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
 
C

Carey Frisch [MVP]

Apparently, your system is hopelessly corrupt.
I would suggest backing up your files and proceed
with a clean install of Windows XP.

Clean Install Windows XP
http://www.michaelstevenstech.com/cleanxpinstall.html

--
Carey Frisch
Microsoft MVP
Windows - Shell/User
Microsoft Community Newsgroups
news://msnews.microsoft.com/

-------------------------------------------------------------------------------------------

:

| For the last few days everytime I have booted up my PC in the morning I find
| the registry has become corrupt and I need to use the Recovery Console to
| get it up and running again.
| Today I have restored the system to three weeks ago where as the last few
| times I used a dated from a few days before the first time it happened (22nd
| Oct).
| I have run all kinds of spyware along with Norton but found nothing
| different from the usual tracking cookies. When I reboot or turn off then on
| again later during the day the PC is fine, it is just after it has been
| turned of for 12 hours or so. I didn't download anything on Friday 21st that
| would cause a change like this as far as I can recall.
| Bar re-installing XP I don't know what else to do if it repeats itself
| tomorrow morning!
|
| Any ideas what is wrong and how to fix it?
|
| Thanks, Sarah.
|
| P.S.
| Here is my HijackThis log (just in case):
|
| Logfile of HijackThis v1.99.1
| Scan saved at 15:11:57, on 27/10/2005
| Platform: Windows XP SP2 (WinNT 5.01.2600)
| MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
|
| Running processes:
| C:\WINDOWS\System32\smss.exe
| C:\WINDOWS\system32\winlogon.exe
| C:\WINDOWS\system32\services.exe
| C:\WINDOWS\system32\lsass.exe
| C:\WINDOWS\system32\svchost.exe
| C:\WINDOWS\System32\svchost.exe
| C:\Program Files\Ahead\InCD\InCDsrv.exe
| C:\WINDOWS\system32\spoolsv.exe
| C:\WINDOWS\System32\inetsrv\inetinfo.exe
| C:\PROGRA~1\Iomega\System32\AppServices.exe
| C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
| C:\Program Files\Norton AntiVirus\navapsvc.exe
| C:\Program Files\Norton Internet Security\NISUM.EXE
| C:\WINDOWS\System32\tcpsvcs.exe
| C:\WINDOWS\System32\snmp.exe
| C:\Program Files\Norton Internet Security\SymProxySvc.exe
| C:\Program Files\Iomega\AutoDisk\ADService.exe
| C:\WINDOWS\System32\mqsvc.exe
| C:\Program Files\Norton Internet Security\NISSERV.EXE
| C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
| C:\WINDOWS\System32\mqtgsvc.exe
| C:\WINDOWS\Explorer.EXE
| C:\WINDOWS\system32\ctfmon.exe
| C:\PROGRA~1\NORTON~1\navapw32.exe
| C:\Program Files\Norton Internet Security\IAMAPP.EXE
| C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
| C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
| C:\Program Files\Common Files\Real\Update_OB\realsched.exe
| C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
| C:\WINDOWS\System32\dllhost.exe
| C:\WINDOWS\system32\inetsrv\DavCData.exe
| C:\Program Files\Internet Explorer\iexplore.exe
| C:\Program Files\Outlook Express\msimn.exe
| C:\Program Files\Messenger\msmsgs.exe
| C:\Program Files\HijackThis\HijackThis.exe
|
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
| http://www.google.co.uk/
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
| http://www.google.co.uk
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
| http://www.google.co.uk/
| O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
| C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
| O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program
| Files\Spybot - Search & Destroy\SDHelper.dll
| O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
| c:\program files\google\googletoolbar1.dll
| O2 - BHO: AcroIEToolbarHelper Class -
| {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat
| 7.0\Acrobat\AcroIEFavClient.dll
| O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
| Files\Norton AntiVirus\NavShExt.dll
| O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
| C:\Program Files\Norton AntiVirus\NavShExt.dll
| O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -
| C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
| O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
| files\google\googletoolbar1.dll
| O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
| O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
| O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
| O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
| O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet
| Security\IAMAPP.EXE
| O4 - HKLM\..\Run: [Symantec NetDriver Monitor]
| C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
| O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
| AntiSpyware\gcasServ.exe"
| O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
| O4 - HKLM\..\Run: [adiras] adiras.exe
| O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
| Files\Real\Update_OB\realsched.exe" -osboot
| O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
| O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st
| 800-840\dslmon.exe
| O8 - Extra context menu item: &Google Search - res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmsearch.html
| O8 - Extra context menu item: Backward Links - res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmbacklinks.html
| O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmcache.html
| O8 - Extra context menu item: Convert link target to Adobe PDF -
| res://C:\Program Files\Adobe\Acrobat
| 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
| O8 - Extra context menu item: Convert link target to existing PDF -
| res://C:\Program Files\Adobe\Acrobat
| 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
| O8 - Extra context menu item: Convert selected links to Adobe PDF -
| res://C:\Program Files\Adobe\Acrobat
| 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
| O8 - Extra context menu item: Convert selected links to existing PDF -
| res://C:\Program Files\Adobe\Acrobat
| 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
| O8 - Extra context menu item: Convert selection to Adobe PDF -
| res://C:\Program Files\Adobe\Acrobat
| 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
| O8 - Extra context menu item: Convert selection to existing PDF -
| res://C:\Program Files\Adobe\Acrobat
| 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
| O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program
| Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
| O8 - Extra context menu item: Convert to existing PDF - res://C:\Program
| Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
| O8 - Extra context menu item: E&xport to Microsoft Excel -
| res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
| O8 - Extra context menu item: Similar Pages - res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmsimilar.html
| O8 - Extra context menu item: Translate into English - res://C:\Program
| Files\Google\GoogleToolbar1.dll/cmtrans.html
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
| C:\Program Files\Messenger\msmsgs.exe
| O9 - Extra 'Tools' menuitem: Windows Messenger -
| {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
| Files\Messenger\msmsgs.exe
| O12 - Plugin for .MID: C:\Program Files\Internet
| Explorer\PLUGINS\npqtplugin2.dll
| O12 - Plugin for .tif: C:\Program Files\Internet
| Explorer\PLUGINS\npqtplugin5.dll
| O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
| http://tools.ebayimg.com/eps/wl/act...l_v1-0-3-24.cab
| O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
| http://by103fd.bay103.hotmail.msn.c...es/MsnPUpld.cab
| O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
| http://software-dl.real.com/070048d...ip/RdxIE601.cab
| O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
| http://v5.windowsupdate.microsoft.c...b?1111008140780
| O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
| Class) - http://security.symantec.com/sscv6/...n/bin/cabsa.cab
| O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
| http://update.microsoft.com/microso...b?1128358082365
| O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
| http://chat.msn.com/controls/msnchat45.cab
| O17 -
| HKLM\System\CCS\Services\Tcpip\..\{7F41286F-AEEF-4BAD-8336-1C7A8EA0856F}:
| NameServer = 80.225.250.178 80.225.250.186
| O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common
| Files\Adobe Systems Shared\Service\Adobelmsvc.exe
| O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program
| Files\Ahead\InCD\InCDsrv.exe
| O23 - Service: Iomega App Services - Iomega Corporation -
| C:\PROGRA~1\Iomega\System32\AppServices.exe
| O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec
| Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
| O23 - Service: Norton Internet Security Service (NISSERV) - Symantec
| Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
| O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec
| Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
| O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
| C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
| O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
| Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
| O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) -
| Symantec Corporation - C:\Program Files\Norton Internet
| Security\SymProxySvc.exe
| O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program
| Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
| O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega
| Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
 
P

Pink Sparkle Girl

I hope it is not hopelessly corrupt! I am pleased to say that I back my
files up every week (after my hard drive died earlier this year). I don't
want to do a clean install if possible as I have SO many programs to
install.

I have run a memory test as suggested by someone, and it appears to be
working fine.

Any one else have any suggestions as to how to find the cause of the
corruption!?
 
B

Bruce Chambers

Pink said:
For the last few days everytime I have booted up my PC in the morning I find
the registry has become corrupt and I need to use the Recovery Console to
get it up and running again.


What, exactly, do you mean by saying that your registry is corrupt?
How do you know this? What are the specific indications, symptoms, and
error messages?

Is the following the recovery method you're using?

How to Recover from a Corrupted Registry that Prevents Windows XP from
Starting
http://support.microsoft.com/default.aspx?scid=kb;en-us;307545

Any ideas what is wrong and how to fix it?

Without more specific information (the Hijack log is irrelevant in this
context), it's impossible to say. However, you might want to look here,
as well:

How to Troubleshoot Registry Corruption Issues
http://support.microsoft.com/default.aspx?scid=kb;en-us;822705



--

Bruce Chambers

Help us help you:



You can have peace. Or you can have freedom. Don't ever count on having
both at once. - RAH
 
P

Pink Sparkle Girl

On start up I get a message saying something along the lines of

Windows couldn't open because a file is corrupt or missing.
Windows\System32\Config\System

I followed Microsoft's article about how to start up from this at:
http://support.microsoft.com/?kbid=307545 (as you suggested).

Today my PC turned on fine (28th), so maybe I found a restore point without
the corrupt file, or item causing the corruption.
 
B

Bruce Chambers

Pink said:
On start up I get a message saying something along the lines of

Windows couldn't open because a file is corrupt or missing.
Windows\System32\Config\System

Well, that's certainly clear enough.... ;-}

I followed Microsoft's article about how to start up from this at:
http://support.microsoft.com/?kbid=307545 (as you suggested).

Today my PC turned on fine (28th), so maybe I found a restore point without
the corrupt file, or item causing the corruption.


You should also check out the troubleshooting advice in the second link
I provided. It sounds very much like there's some sort of corruption
occurring when the registry is saved back to the hard drive during the
shut-down process. This could be caused by a hardware problem.


--

Bruce Chambers

Help us help you:



You can have peace. Or you can have freedom. Don't ever count on having
both at once. - RAH
 
J

John Wunderlich

On start up I get a message saying something along the lines of

Windows couldn't open because a file is corrupt or missing.
Windows\System32\Config\System

I followed Microsoft's article about how to start up from this at:
http://support.microsoft.com/?kbid=307545 (as you suggested).

Today my PC turned on fine (28th), so maybe I found a restore
point without the corrupt file, or item causing the corruption.

I had this problem once before and ended up having to replace my hard
drive within two months (complete crash). I recommend making sure all
your critical files are backed up then execute a complete disk check by
right-clicking on your disk drive icon, select Properties, Tools, Check
Now then check both boxes and Start. It will probably tell you that it
will do the check on the next boot so go ahead and restart your
computer. It will take a while, so do it when you don't need to use
your computer.

Good Luck,

John
 
P

Pink Sparkle Girl

Windows failed to start again this morning with the same message:
"Windows could not start because the following file is missing or
corrupt:\WINNT\SYSTEM32\CONFIG\SYSTEM"

I followed the sequence provided in:
http://support.microsoft.com/?kbid=307545
I have not restored the system to a previous date this time.

How to I find out if the registry is becoming corrupt during the shutdown
process? My PC only has start up problems when it has been left off over
night, so if I shut it down during the day, then turn it back on later it is
still fine. On shut down I regularly get an error sound, but as the windows
shutdown screen is up I can't see what is wrong.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top