0

Windows 2000 Pro
explorer.exe - Application Error

The instruction at "0x7ce82a8c" referenced memory at "0x0363b9d0". The memory could not be "read".

Click on OK to terminate the program
Click on Cancel to debug the program

I click cancel, because if I click OK I usually have to restart Windows altogether. Cancel it does the following.

The second cancel mentioned below is something to do with a log file. There is no other button except cancel on that one.

Haven't noted if it is the same reference numbers each time, but after this comes up I click on two different "cancel" buttons and then wait about 10 seconds during which Windows is locked up then goes to a Blank Blue screen then comes back up with my desktop as though it had restarted Windows. I say this because one of the tasktray icons by the clock comes back up as well that I usually close when I first boot up the computer which I close again. Anyway, this happens usually when I close an open folder window or sometimes when I close a browser window. It just happens basically at random really. It was happening before any of my new hardware changes, but I didn't note when it first started happening as far as software changes. Some google searches kept saying registry fixing programs would resolve it, but they have not.

Explorer.exe basically is Windows isn't it?

Anyway, are there any fixes for this that don't involve reinstalling Windows? If I do need to reinstall Windows is there such a thing as a Cabs file restore like you could do with Windows 98SE that doesn't kill any of your programs, but basically restores just your Windows files and settings without wiping the hard drive?

Also, could this be caused by software conflicts running in the background. I have noticed that sometimes, but not every time it will bring up my Anti-Virus & Firewall programs when it reloads explorer.exe.

Sorry for such a long post, but I use to do tech support myself and I remember that the more details I could get usually helped me diagnose the issue.

Thanks in advance for any advice!

3
Contributors
20
Replies
21
Views
9 Years
Discussion Span
Last Post by gerbil
0

Explorer.exe basically is Windows isn't it? Yep, it's the pretty UI that you usually use to start pgms from and navigate about your files.
The blank blue screen is what you see when explorer stops running - no desktop icons, task bar, backgound etc. It does look like some bad software is killing explorer.... and bad software is most often malware.
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
==download hijackthis: http://www.majorgeeks.com/download5554.html
-copy it to a new FOLDER placed either alongside your program files or on your desktop and then... rename hijackthis.exe to imabunny.exe
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here.
We'll go from there. And you can rarely give too much info....

0

Hi gerbil thanks for the advice.

I downloaded and ran both programs per your instructions. I looked over the log files myself. Mostly I noted that at the end of the combofix.txt file it showed pre-run and post-run free bytes. Apparently it had freed up or IE deleted over 350MB's of whatever. It should be noted that I ran Several different spyware/malware removal programs as well as anti-virus and then Regcure a registry checker before running either of these. Of course updated all these programs before running them. They found nothing as far as a virus or any major spyware/malware, two low risk items of spyware(tracking cookies) were removed. Then I ran both of the applications you gave me links and instructions for. I also went into my Firewall rules after running your programs and had it clean up rules for applications that didn't exist. It cleaned out 1 rule for something that I had blocked.

Anyway, I will attach both files to this thread reply.

Thanks again for your help!

Attachments
ComboFix 08-05-01.1 - Administrator 01/05/2008 22:56:39.1 - NTFSx86
Running from: C:\Documents and Settings\Administrator\My Documents\downloads\ComboFix.exe

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\Web\default.htt

.
(((((((((((((((((((((((((   Files Created from 2008-04-02 to 2008-05-02  )))))))))))))))))))))))))))))))
.

2008-05-01 22:21 . 01/05/08 10:21p	54,156	--ah-----	C:\WINNT\QTFont.qfn
2008-05-01 22:21 . 01/05/08 10:21p	1,409	--a------	C:\WINNT\QTFont.for
2008-05-01 00:39 . 01/05/08 12:39a	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\aignes
2008-04-30 23:04 . 30/04/08 11:04p	<DIR>	d--------	C:\Program Files\AM-DeadLink
2008-04-30 22:38 . 06/12/00 01:00a	109,248	--a------	C:\WINNT\system32\MSWINSCK.OCX
2008-04-30 22:38 . 26/01/03 01:41p	40,960	--a------	C:\WINNT\system32\SSubTmr6.dll
2008-04-30 22:30 . 01/05/08 12:54a	<DIR>	d--------	C:\Program Files\Opera
2008-04-30 13:07 . 30/04/08 01:07p	16,384	--a----t-	C:\WINNT\system32\Perflib_Perfdata_410.dat
2008-04-30 01:05 . 30/04/08 01:26a	<DIR>	d--------	C:\Program Files\RegCure
2008-04-29 23:38 . 01/05/08 01:56p	<DIR>	d--------	C:\Program Files\XoftSpySE
2008-04-29 21:43 . 29/04/08 09:43p	1,160	--a------	C:\WINNT\mozver.dat
2008-04-29 20:03 . 29/04/08 08:04p	<DIR>	d--------	C:\Program Files\JAP
2008-04-29 01:40 . 29/04/08 01:40a	<DIR>	d--------	C:\Program Files\STOIK Imaging
2008-04-29 01:40 . 29/04/08 01:40a	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\STOIK
2008-04-29 00:53 . 27/08/05 02:38a	1,435,272	--a------	C:\WINNT\system32\Flash8.ocx
2008-04-29 00:53 . 04/03/02 12:27p	1,140,472	--a------	C:\WINNT\system32\IGUltraGrid20.ocx
2008-04-29 00:53 . 19/11/03 01:59p	512,688	--a------	C:\WINNT\system32\XceedCry.dll
2008-04-29 00:53 . 08/03/04 11:00p	131,856	--a------	C:\WINNT\system32\MSADODC.ocx
2008-04-29 00:53 . 26/01/99 07:36p	11,012	--a------	C:\WINNT\system32\threadapi.tlb
2008-04-29 00:48 . 29/04/08 12:48a	<DIR>	d--------	C:\Converted Videos
2008-04-29 00:47 . 27/08/05 03:38a	1,435,272	--a------	C:\WINNT\system32\Flash.ocx
2008-04-28 23:32 . 28/04/08 11:32p	<DIR>	d--------	C:\Program Files\Any Video Converter
2008-04-28 23:32 . 29/04/08 04:22a	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\Any Video Converter
2008-04-26 02:13 . 26/04/08 02:13a	<DIR>	d--------	C:\Program Files\VideoSoft.org
2008-04-25 06:16 . 30/04/08 07:11a	30	--a------	C:\WINNT\TruxShare.INI
2008-04-25 05:58 . 25/04/08 06:05a	<DIR>	d--------	C:\Program Files\TruxShare
2008-04-25 05:49 . 25/04/08 05:49a	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\Shareaza
2008-04-25 05:48 . 25/04/08 05:57a	<DIR>	d--------	C:\Program Files\Trilix
2008-04-25 04:31 . 25/04/08 04:31a	<DIR>	d--------	C:\Program Files\TV
2008-04-24 04:28 . 01/05/08 02:20p	<DIR>	d--------	C:\Program Files\SpywareGuard
2008-04-24 04:25 . 01/05/08 02:19p	<DIR>	d--------	C:\Program Files\SpywareBlaster
2008-04-24 04:25 . 25/08/05 06:19p	115,920	--a------	C:\WINNT\system32\MSINET.OCX
2008-04-24 04:23 . 24/04/08 04:23a	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-24 04:22 . 24/04/08 04:22a	0	--a------	C:\WINNT\nsreg.dat
2008-04-24 04:00 . 24/04/08 04:00a	<DIR>	d--------	C:\Program Files\BibleOcean.com
2008-04-24 03:49 . 24/04/08 03:50a	<DIR>	d--------	C:\WINNT\system32\URTTemp
2008-04-24 03:33 . 20/02/03 05:39p	512,000	--a--c---	C:\WINNT\system32\dllcache\msado15.dll
2008-04-24 03:32 . 24/04/08 03:32a	126,976	--a------	C:\WINNT\system32\odbcconf.dll
2008-04-24 03:32 . 24/04/08 03:32a	126,976	--a--c---	C:\WINNT\system32\dllcache\odbcconf.dll
2008-04-24 03:32 . 24/04/08 03:32a	69,632	--a------	C:\WINNT\system32\odbcconf.exe
2008-04-24 03:32 . 24/04/08 03:32a	69,632	--a--c---	C:\WINNT\system32\dllcache\odbcconf.exe
2008-04-24 03:32 . 24/04/08 03:32a	181	--a------	C:\WINNT\system32\sqlclnt.rsp
2008-04-24 03:32 . 24/04/08 03:32a	28	--a------	C:\WINNT\system32\redist.rsp
2008-04-24 03:31 . 24/04/08 03:31a	253	--a------	C:\WINNT\system32\mdaccore.rsp
2008-04-22 09:16 . 22/04/08 09:16a	16,384	--a----t-	C:\WINNT\system32\Perflib_Perfdata_240.dat
2008-04-22 09:04 . 22/04/08 09:04a	<DIR>	d--------	C:\Program Files\Lavasoft
2008-04-17 22:58 . 17/04/08 10:58p	4,096	--a------	C:\WINNT\d3dx.dat
2008-04-17 22:23 . 24/04/08 02:52a	<DIR>	d--------	C:\Program Files\PC Wizard 2008
2008-04-17 22:23 . 15/09/07 03:11p	27,136	--a------	C:\WINNT\system32\PCWizard.cpl
2008-04-15 03:02 . 19/06/03 12:05p	40,752	--a------	C:\WINNT\system32\drivers\1394bus.sys
2008-04-15 03:02 . 19/06/03 12:05p	37,680	--a------	C:\WINNT\system32\drivers\ohci1394.sys
2008-04-14 02:43 . 14/04/08 02:43a	16,384	--a----t-	C:\WINNT\system32\Perflib_Perfdata_314.dat
2008-04-12 11:04 . 12/04/08 11:12a	<DIR>	d--------	C:\Program Files\ATMA V
2008-04-11 12:04 . 11/04/08 12:04p	1,097,570	---h-----	C:\WINNT\ShellIco
2008-04-11 03:38 . 11/04/08 03:38a	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\WebCompiler3
2008-04-11 03:23 . 11/04/08 03:23a	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-11 03:22 . 11/04/08 03:22a	<DIR>	d--------	C:\Program Files\Yahoo!
2008-04-11 03:22 . 11/04/08 03:22a	<DIR>	d--------	C:\Program Files\CCleaner
2008-04-11 02:27 . 11/04/08 02:27a	<DIR>	d--------	C:\Program Files\Crawler
2008-04-11 02:26 . 01/05/08 02:54p	<DIR>	d-a------	C:\Program Files\Spyware Terminator
2008-04-11 02:26 . 01/05/08 02:54p	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-04-11 02:26 . 01/05/08 02:37p	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\Spyware Terminator
2008-04-11 02:26 . 11/04/08 02:26a	141,312	--a------	C:\WINNT\system32\drivers\sp_rsdrv2.sys
2008-04-09 21:27 . 09/04/08 09:27p	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\ScamBlocker
2008-04-07 19:07 . 07/04/08 07:07p	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-04-04 08:12 . 07/04/08 07:07p	<DIR>	d--------	C:\Program Files\Ascentive
2008-04-04 08:12 . 10/08/07 01:56p	303,104	--a------	C:\WINNT\system32\ciplListBar.ocx
2008-04-04 08:12 . 12/03/08 03:13p	208,896	--a------	C:\WINNT\system32\ConTest.dll
2008-04-04 08:12 . 10/08/07 01:56p	155,648	--a------	C:\WINNT\system32\ciplImageList.ocx
2008-04-04 06:34 . 04/04/08 06:56a	<DIR>	d--------	C:\Program Files\Max Registry Cleaner
2008-04-04 06:34 . 24/05/07 05:57p	143,360	--a------	C:\WINNT\system32\GetHardDiskNo.dll
2008-04-04 06:34 . 04/04/08 06:34a	63	--a------	C:\WINNT\system\SYSRegC.dll
2008-04-04 06:10 . 04/04/08 06:10a	<DIR>	d--------	C:\Program Files\Eusing Free Registry Cleaner
2008-04-03 19:58 . 03/04/08 07:58p	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\Apple
2008-04-03 00:23 . 03/04/08 12:23a	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-02 19:34 . 02/04/08 07:34p	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\ErrorSmart

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-02 04:21	20	---h--w	C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2008-05-02 04:21	20	---h--w	C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2008-05-01 21:00	---------	d-----w	C:\Documents and Settings\Administrator\Application Data\AVG7
2008-05-01 20:19	---------	d---a-w	C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-29 12:43	---------	d-----w	C:\Program Files\Common Files\Wise Installation Wizard
2008-04-29 07:40	---------	d--h--w	C:\Program Files\InstallShield Installation Information
2008-04-25 19:49	---------	d-----w	C:\Program Files\Diablo II
2008-04-22 11:59	---------	d-----w	C:\Program Files\LimeWire
2008-04-17 09:21	---------	d-----w	C:\Program Files\DivX
2008-04-11 21:55	43,520	----a-w	C:\WINNT\system32\CmdLineExt03.dll
2008-04-11 09:17	---------	d-----w	C:\Program Files\PeoplePC
2008-04-05 20:38	---------	d-----w	C:\Program Files\Diablo II normal
2008-04-04 13:32	---------	d-----w	C:\Program Files\Maxthon
2008-04-04 13:27	---------	d---a-w	C:\Program Files\McAfee.com
2008-04-04 12:44	---------	d-----w	C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-04-04 01:58	---------	d-----w	C:\Program Files\Apple Software Update
2008-04-03 06:19	---------	d-----w	C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-04-01 04:49	---------	d-----w	C:\Program Files\Spyware Doctor
2008-03-31 21:25	831,488	----a-w	C:\WINNT\system32\divx_xx0a.dll
2008-03-31 21:25	823,296	----a-w	C:\WINNT\system32\divx_xx0c.dll
2008-03-31 21:25	823,296	----a-w	C:\WINNT\system32\divx_xx07.dll
2008-03-31 21:25	802,816	----a-w	C:\WINNT\system32\divx_xx11.dll
2008-03-31 21:25	682,496	----a-w	C:\WINNT\system32\DivX.dll
2008-03-31 21:25	161,096	----a-w	C:\WINNT\system32\DivXCodecVersionChecker.exe
2008-03-31 02:28	---------	d-----w	C:\Program Files\VideoLAN
2008-03-31 01:46	---------	d-----w	C:\Program Files\AVIcodec
2008-03-28 19:26	---------	d-----w	C:\Documents and Settings\Administrator\Application Data\Orbit
2008-03-26 17:22	---------	d-----w	C:\Program Files\FLV Player
2008-03-26 07:06	---------	d-----w	C:\Program Files\Common Files\SWF Studio
2008-03-21 20:30	524,288	----a-w	C:\WINNT\system32\DivXsm.exe
2008-03-21 20:30	3,596,288	----a-w	C:\WINNT\system32\qt-dx331.dll
2008-03-21 20:30	200,704	----a-w	C:\WINNT\system32\ssldivx.dll
2008-03-21 20:30	1,044,480	----a-w	C:\WINNT\system32\libdivx.dll
2008-03-21 20:28	81,920	----a-w	C:\WINNT\system32\dpl100.dll
2008-03-21 20:28	593,920	----a-w	C:\WINNT\system32\dpuGUI11.dll
2008-03-21 20:28	57,344	----a-w	C:\WINNT\system32\dpv11.dll
2008-03-21 20:28	53,248	----a-w	C:\WINNT\system32\dpuGUI10.dll
2008-03-21 20:28	344,064	----a-w	C:\WINNT\system32\dpus11.dll
2008-03-21 20:28	294,912	----
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:09 PM, on 01/05/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\GWMDMMSG.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Documents and Settings\Administrator\Desktop\imabunny.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [3c1807pd] C:\WINNT\SYSTEM32\3cmlink.exe RunServices \Device\3cpipe-3c1807pd
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Ashampoo FireWall] "C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Trilix\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SysProExe.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1206366193906
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Events Log (Event) - Elaborate Bytes AG - (no file)
O23 - Service: Fix-It Task Manager - Ontrack Data International - C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 8042 bytes
0

Hi gerbil, I posted my reply after doing what you said a few days ago and haven't seen any further reply from you. The problem hasn't gone away. Any further suggestions? Thanks

0

No problem. By the way it seems to mostly happen when I'm closing anything to do with Windows its self. Such as having My Documents open and then closing it and it will happen sometimes. Or having My computer open and then closing it and it will happen sometimes. It's intermittent. I also noticed that when it gives the explorer.exe - application error it does reference the same instruction at "0x7ce82a8c" but does not reference the same ref mem address each time. If that's of any help?

0

I guess I missed your post because for a while Opera was not working with this site, and so I did not look in much. Anyway.... you will notice that I have turned on your windows updates in one of the registry lines - if you do not want that just delete these two lines from the block before you run it with Combofix...
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= -

Heh.... I still like playing Diablo II also... okay, let's get down to it.
Start hijackthis, select Scan Only, place checkmarks against all the entries listed below that still exist, and then press Fix Checked.

O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)

==Please copy the text in the box to a notepad [format/wordwrap unchecked] and save as CFScript.txt to where you saved Combofix -that is, to a folder or your desktop.

Killall::

File::
C:\WINNT\eraseme_18043.exe
C:\WINNT\eraseme_18536.exe
C:\WINNT\eraseme_24270.exe
C:\WINNT\eraseme_25226.exe
C:\WINNT\eraseme_27280.exe
C:\WINNT\eraseme_27710.exe
C:\WINNT\eraseme_28350.exe
C:\WINNT\eraseme_28884.exe
C:\WINNT\eraseme_41588.exe
C:\WINNT\eraseme_51842.exe
C:\WINNT\eraseme_55717.exe
C:\WINNT\eraseme_61051.exe
C:\WINNT\eraseme_68082.exe
C:\WINNT\eraseme_70626.exe
C:\WINNT\eraseme_74404.exe
C:\WINNT\eraseme_84170.exe

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msci"=-

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= -

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.FCKK"= -

Good. Now drag CFScript.txt onto Combofix [drag the icon if on your desktop, or the filename if in a folder]. Combofix will start, let it run, if your firewall prompts then allow all; post the log.

352 Megs gone? That will be your most precious photos smoked... :)

0

By the way, if you look into your Combofix log you will note that you have had that erasme_*****.exe /winbin worm for over a year - that has given it ample time to make many copies of itself, and also to trot out into networked computers. It infects Explorer.exe as well....
To make sure it is gone...
==Run a BitDefender online scan: http://www.bitdefender.com/scan8/ie.html - and post the results, please.

=Check your hosts file, it may have been modified to block some security sites.
If you wish to clear your hosts file manually [C:\Windows\system32\drivers\etc\hosts] you may not be able to save the changed/corrected file. This is because some security applications, possibly also various malware, will lock your Hosts file [make it read-only] as a protection.
Go Start, run, type cmd -press Enter. Paste this line into the window at the prompt, press Enter, close the window and try to save the file again.
attrib -r -h -s %SystemRoot%\system32\drivers\etc\HOSTS

Drag HOSTS into a notepad and make any changes, then save it.
Or just use this tool:
==download HostsXpert from http://www.funkytoad.com/content/view/13/31/
-click the top button Make Writable if it is available
-click Restore MS Hosts File button.

0

Thanks for the new info. Also, make that diffenent about what I said earlier. If it is just a windows compatible application no errors when closing or using. If it is a folder of part of windows its self such as My computer, My Documents, Windows Help etc... when you are using them it is fine. When you close them that's when I get the original error.

Anyway, just finished doing everything you said. However, I ran the online virus scan first on both this computer and my wireless notebook with win98se. It found 2 viruses on the win98se and 5 on this win2000Pro plus 1 that it guessed was a virus and it deleted them all. Saved the log file, but it would only save as HTML file so hope I can attach that or whatever.

Did the Hijack thing and that seemed to run ok.

Did the combofix.exe script file you gave me, but it said it wasn't a real reg edit script file or something like that, but I clicked ok to that error message and then it ran the script anyway, because I watched it delete the items you had listed.

Downloaded the tool on the Hosts file part. However it did not have the Make writeable button instead it was a Make readonly button, which I did not choose, but I did choose the "Restore MS Hosts File button" and then closed the window.

Will have to reboot and see if the original problem still exists, but if nothing else we have killed yet some more viruses/malware etc... Amazing considering I have always been one to keep my virus database updated, or spyware or whatever and use more than one and it seems it does not matter how many of all these you use a new different one always seems to find something else the others missed. Sometimes I miss the days of CP/M and DOS sure they were simple, but we didn't know that back then and I never got a virus on my computer for the first 25 years I used them. Now it's going on 31 years and it seems I spend 80% of my time doing system maintenance to kill security issues and keep Windows from crashing. Oh well, I guess I must be a glutton for punishment or I wouldn't still be using these things. :-)

Will attach all the various log files below, but not sure if the HTML one will be allowed. I had to zip the html file, but it's attached.

Thanks again for all your expert advice!

Attachments
ComboFix 08-05-01.1 - Administrator 07/05/2008 13:22:04.2 - NTFSx86
Microsoft Windows 2000 Professional  5.0.2195.4.1252.1.1033.18.302 [GMT -6:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]

FILE ::
C:\WINNT\eraseme_18043.exe
C:\WINNT\eraseme_18536.exe
C:\WINNT\eraseme_24270.exe
C:\WINNT\eraseme_25226.exe
C:\WINNT\eraseme_27280.exe
C:\WINNT\eraseme_27710.exe
C:\WINNT\eraseme_28350.exe
C:\WINNT\eraseme_28884.exe
C:\WINNT\eraseme_41588.exe
C:\WINNT\eraseme_51842.exe
C:\WINNT\eraseme_55717.exe
C:\WINNT\eraseme_61051.exe
C:\WINNT\eraseme_68082.exe
C:\WINNT\eraseme_70626.exe
C:\WINNT\eraseme_74404.exe
C:\WINNT\eraseme_84170.exe
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\eraseme_18043.exe
C:\WINNT\eraseme_18536.exe
C:\WINNT\eraseme_24270.exe
C:\WINNT\eraseme_25226.exe
C:\WINNT\eraseme_27280.exe
C:\WINNT\eraseme_27710.exe
C:\WINNT\eraseme_28350.exe
C:\WINNT\eraseme_28884.exe
C:\WINNT\eraseme_41588.exe
C:\WINNT\eraseme_51842.exe
C:\WINNT\eraseme_55717.exe
C:\WINNT\eraseme_61051.exe
C:\WINNT\eraseme_68082.exe
C:\WINNT\eraseme_70626.exe
C:\WINNT\eraseme_74404.exe
C:\WINNT\eraseme_84170.exe

.
(((((((((((((((((((((((((   Files Created from 2008-04-07 to 2008-05-07  )))))))))))))))))))))))))))))))
.

2008-05-07 07:47 . 08-05-07 11:28 	<DIR>	d--------	C:\WINNT\BDOSCAN8
2008-05-06 02:15 . 08-05-06 02:15 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\IObit
2008-05-06 01:10 . 08-05-06 02:39 	<DIR>	d--------	C:\Program Files\IObit
2008-05-06 00:59 . 08-05-06 01:02 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\NoteTab Light
2008-05-06 00:58 . 08-05-06 00:58 	<DIR>	d--------	C:\Program Files\NoteTab Light
2008-05-05 21:59 . 08-05-07 12:00 	<DIR>	d-a------	C:\Program Files\Spyware Terminator
2008-05-05 21:59 . 08-05-05 22:18 	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-05-05 21:59 . 08-05-07 11:58 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\Spyware Terminator
2008-05-05 21:59 . 08-05-05 21:59 	141,312	--a------	C:\WINNT\system32\drivers\sp_rsdrv2.sys
2008-05-04 11:01 . 08-05-04 11:02 	<DIR>	d--------	C:\Program Files\iTunes
2008-05-04 11:01 . 08-05-04 11:01 	<DIR>	d--------	C:\Program Files\iPod
2008-05-01 00:39 . 08-05-01 00:39 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\aignes
2008-04-30 23:04 . 08-04-30 23:04 	<DIR>	d--------	C:\Program Files\AM-DeadLink
2008-04-30 22:38 . 00-12-06 01:00 	109,248	---------	C:\WINNT\system32\MSWINSCK.OCX
2008-04-30 22:38 . 03-01-26 13:41 	40,960	---------	C:\WINNT\system32\SSubTmr6.dll
2008-04-30 22:30 . 08-05-01 00:54 	<DIR>	d--------	C:\Program Files\Opera
2008-04-30 01:05 . 08-04-30 01:26 	<DIR>	d--------	C:\Program Files\RegCure
2008-04-29 23:38 . 08-05-07 11:41 	<DIR>	d--------	C:\Program Files\XoftSpySE
2008-04-29 21:43 . 08-04-29 21:43 	1,160	---------	C:\WINNT\mozver.dat
2008-04-29 20:03 . 08-04-29 20:04 	<DIR>	d--------	C:\Program Files\JAP
2008-04-29 01:40 . 08-04-29 01:40 	<DIR>	d--------	C:\Program Files\STOIK Imaging
2008-04-29 01:40 . 08-04-29 01:40 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\STOIK
2008-04-29 00:53 . 05-08-27 02:38 	1,435,272	---------	C:\WINNT\system32\Flash8.ocx
2008-04-29 00:53 . 02-03-04 12:27 	1,140,472	---------	C:\WINNT\system32\IGUltraGrid20.ocx
2008-04-29 00:53 . 03-11-19 13:59 	512,688	---------	C:\WINNT\system32\XceedCry.dll
2008-04-29 00:53 . 04-03-08 23:00 	131,856	---------	C:\WINNT\system32\MSADODC.ocx
2008-04-29 00:53 . 99-01-26 19:36 	11,012	---------	C:\WINNT\system32\threadapi.tlb
2008-04-29 00:48 . 08-04-29 00:48 	<DIR>	d--------	C:\Converted Videos
2008-04-29 00:47 . 05-08-27 03:38 	1,435,272	---------	C:\WINNT\system32\Flash.ocx
2008-04-28 23:32 . 08-04-28 23:32 	<DIR>	d--------	C:\Program Files\Any Video Converter
2008-04-28 23:32 . 08-04-29 04:22 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\Any Video Converter
2008-04-26 02:13 . 08-04-26 02:13 	<DIR>	d--------	C:\Program Files\VideoSoft.org
2008-04-25 06:16 . 08-04-30 07:11 	30	---------	C:\WINNT\TruxShare.INI
2008-04-25 05:58 . 08-04-25 06:05 	<DIR>	d--------	C:\Program Files\TruxShare
2008-04-25 05:49 . 08-04-25 05:49 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\Shareaza
2008-04-25 05:48 . 08-04-25 05:57 	<DIR>	d--------	C:\Program Files\Trilix
2008-04-25 04:31 . 08-04-25 04:31 	<DIR>	d--------	C:\Program Files\TV
2008-04-24 04:28 . 08-05-07 13:04 	<DIR>	d--------	C:\Program Files\SpywareGuard
2008-04-24 04:25 . 08-05-07 11:44 	<DIR>	d--------	C:\Program Files\SpywareBlaster
2008-04-24 04:25 . 05-08-25 18:19 	115,920	---------	C:\WINNT\system32\MSINET.OCX
2008-04-24 04:23 . 08-04-24 04:23 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-24 04:22 . 08-04-24 04:22 	0	---------	C:\WINNT\nsreg.dat
2008-04-24 04:00 . 08-04-24 04:00 	<DIR>	d--------	C:\Program Files\BibleOcean.com
2008-04-24 03:49 . 08-04-24 03:50 	<DIR>	d--------	C:\WINNT\system32\URTTemp
2008-04-24 03:33 . 03-02-20 17:39 	512,000	-----c---	C:\WINNT\system32\dllcache\msado15.dll
2008-04-24 03:32 . 08-04-24 03:32 	126,976	--a------	C:\WINNT\system32\odbcconf.dll
2008-04-24 03:32 . 08-04-24 03:32 	126,976	-----c---	C:\WINNT\system32\dllcache\odbcconf.dll
2008-04-24 03:32 . 08-04-24 03:32 	69,632	--a------	C:\WINNT\system32\odbcconf.exe
2008-04-24 03:32 . 08-04-24 03:32 	69,632	-----c---	C:\WINNT\system32\dllcache\odbcconf.exe
2008-04-24 03:32 . 08-04-24 03:32 	181	---------	C:\WINNT\system32\sqlclnt.rsp
2008-04-24 03:32 . 08-04-24 03:32 	28	---------	C:\WINNT\system32\redist.rsp
2008-04-24 03:31 . 08-04-24 03:31 	253	---------	C:\WINNT\system32\mdaccore.rsp
2008-04-22 09:04 . 08-04-22 09:04 	<DIR>	d--------	C:\Program Files\Lavasoft
2008-04-17 22:58 . 08-04-17 22:58 	4,096	---------	C:\WINNT\d3dx.dat
2008-04-17 22:23 . 08-04-24 02:52 	<DIR>	d--------	C:\Program Files\PC Wizard 2008
2008-04-17 22:23 . 07-09-15 15:11 	27,136	---------	C:\WINNT\system32\PCWizard.cpl
2008-04-15 03:02 . 03-06-19 12:05 	40,752	--a------	C:\WINNT\system32\drivers\1394bus.sys
2008-04-15 03:02 . 03-06-19 12:05 	37,680	--a------	C:\WINNT\system32\drivers\ohci1394.sys
2008-04-12 11:04 . 08-04-12 11:12 	<DIR>	d--------	C:\Program Files\ATMA V
2008-04-11 12:04 . 08-04-11 12:04 	1,097,570	---h-----	C:\WINNT\ShellIco
2008-04-11 03:38 . 08-04-11 03:38 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\WebCompiler3
2008-04-11 03:23 . 08-04-11 03:23 	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-11 03:22 . 08-04-11 03:22 	<DIR>	d--------	C:\Program Files\Yahoo!
2008-04-11 03:22 . 08-04-11 03:22 	<DIR>	d--------	C:\Program Files\CCleaner
2008-04-11 02:27 . 08-04-11 02:27 	<DIR>	d--------	C:\Program Files\Crawler
2008-04-09 21:27 . 08-04-09 21:27 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\ScamBlocker
2008-04-07 19:07 . 08-04-07 19:07 	<DIR>	d--------	C:\Documents and Settings\Administrator\Application Data\InstallShield

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-07 17:44	---------	d---a-w	C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-07 14:00	---------	d-----w	C:\Documents and Settings\Administrator\Application Data\AVG7
2008-05-04 16:59	---------	d-----w	C:\Program Files\QuickTime
2008-05-03 19:16	---------	d-----w	C:\Program Files\Diablo II
2008-05-02 08:02	---------	d-----w	C:\Program Files\Bible Seeker
2008-05-02 04:21	20	---h--w	C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2008-05-02 04:21	20	---h--w	C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2008-04-29 12:43	---------	d-----w	C:\Program Files\Common Files\Wise Installation Wizard
2008-04-29 07:40	---------	d--h--w	C:\Program Files\InstallShield Installation Information
2008-04-22 11:59	---------	d-----w	C:\Program Files\LimeWire
2008-04-17 09:21	---------	d-----w	C:\Program Files\DivX
2008-04-11 21:55	43,520	------w	C:\WINNT\system32\CmdLineExt03.dll
2008-04-11 09:17	---------	d-----w	C:\Program Files\PeoplePC
2008-04-08 01:07	---------	d-----w	C:\Program Files\Ascentive
2008-04-05 20:38	---------	d-----w	C:\Program Files\Diablo II normal
2008-04-04 13:32	---------	d-----w	C:\Program Files\Maxthon
2008-04-04 13:27	---------	d-----w	C:\Program Files\McAfee.com
2008-04-04 12:56	---------	d-----w	C:\Program Files\Max Registry Cleaner
2008-04-04 12:44	---------	d-----w	C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-04-04 12:10	---------	d-----w	C:\Program Files\Eusing Free Registry Cleaner
2008-04-04 01:58	---------	d-----w	C:\Program Files\Apple Software Update
2008-04-04 01:58	---------	d-----w	C:\Documents and Settings\All Users\Application Data\Apple
2008-04-03 06:23	---------	d-----w	C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-03 06:19	---------	d-----w	C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-04-03 01:34	---------	d-----w	C:\Documents and Settings\Administrator\Application Data\ErrorSmart
2008-04-01 04:49	---------	d-----w	C:\Program Files\Spyware Doctor
2008-03-31 21:25	831,488	------w	C:\WINNT\system32\divx_xx0a.dll
2008-03-31 21:25	823,296	------w	C:\WINNT\system32\divx_xx0c.dll
2008-03-31 21:25	823,296	------w	C:\WINNT\system32\divx_xx07.dll
2008-03-31 21:25	802,816	------w	C:\WINNT\system32\divx_xx11.dll
2008-03-31 21:25	682,496	------w	C:\WINNT\system32\DivX.dll
2008-03-31 21:25	161,096	------w	C:\WINNT\system32\DivXCodecVersionChecker.exe
2008-03-31 02:28	---------	d-----w	C:\Program Files\VideoLAN
2008-03-31 01:46	---------	d-----w	C:\Program Files\AVIcodec
2008-03-28 19:26	-------
0

Back in the days of DOS it was a brave new world, the settlers were gazing enthusiastically out into the wilderness and Microsoft was loved as one of the guides who brought them face to face with it.. But then Microsoft rounded them all up and herded them out into it, some against their will, and now the wolves are circling.
Do you see in the BDF log the .dbx file? That is probably the source - an email.
"However it did not have the Make writeable button instead it was a Make readonly button"... yeah, that means it was already writable, so it gave you the option of making it read-only to stop simply written scripts altering it.
Everything happened correctly with combofix.
=Delete this file:
C:\WINNT\d3dx.dat
There seems to be a problem with your C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ folder. I do not know if it is simply to do with the AShampoo file ASFWHide in there.... I suggest you disconnect from the net, shutdown AShampoo, close any browsers, readers, applications and delete the Temp folder itselfthen recreate it. Restart your firewall.
As far as the error goes, well, there could be sys file corruption still. It can get tedious to scan your system, but I would run this last one [cclean first!]:
==Please use IE or Firefox to do an online scan at panda:- http://www.pandasecurity.com/homeusers/solutions/activescan/?
-for the free online virus scan select the link Scan your PC, then Register [otherwise there will be no disinfection, merely detection] with a valid email and follow through.
Post the log it produces here.
and follow up with system file checker. Go start, run, paste in:
sfc /scannow ....insert your cd when requested.

0

Any easy way to get ur program running again is to delete your old explorer.exe file which might be infected. If you have a friend with the same operating system, search for his explorer.exe file and copy it. Paste that into your old folder where your previous explorer.exe file was. If this problem occurs....... dont know......contact your computer configure person.
.:Peace:.
- Purvansh

0

OK did what you said on everything. Thanks for the reminder about SFC I forgot about that little utility. However, I don't have A Windows 2000PRO SP4 installation CD. This Refurbished computer that I bought from www.computer-show.com came with it preinstalled with COA, but no CD. I ran the SFC /scannow anyway hoping I could redirect it to CABs files or something. It said it needed to copy DLL's to a cache folder.

Anyway, I will attach the online virus scan results .txt file. It found some things but I don't think it removed any of it even though I did register. The part I don't understand is the "VULNERABILITIES" which are all Windows/IE patches etc. The reason I don't understand that is that just before running all these new instructions I did my Windows critical updates 19Meg's of them. So not sure why I still need more? At any rate how do I fix all of those?

Is there anyway to get SFC to restore from CAB files etc?

Well anyway I appreciate all the help and links. Oh also it said the combofix.exe was one of the problems the virus scanner you sent me to. Maybe it's been infected. I'm guessing I should delete that also?

Thanks again! :)

0

Panda only deletes viruses and worms in this free scan, but points out adware and trojans etc.
This one is adware, delete it...c:\winnt\system32\unppc.exe
This one is part of a telnet service from Sysinternals. If you do not use telnet, did not install that service, then delete it [can be used by hackers]...C:\WINNT\PSEXESVC.EXE
I must admit I have no idea why the scan shows those critical updates as vulnerabilities - they were only released in Dec last year... are they actually installed?
SFC should work with cab files. It sounds as if your dllcache directory is corrupted. You can change this registry key so that sourcepath points to the DIRECTORY the cab files are in [don't point it at the cab files themselves]:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup]
"SourcePath"="C:\whatever directory contains cab files..."
Or you could try to borrow a cd and copy the I386 folder to the C:root, [eg C:\i386] and point sfc at that...
Combofix infected? Nah, Panda dislikes it... but yes, you can delete it if you wish [or just leave it there for a week and it will timeout and when you try to start it it will remove itself.. :), or you can paste into the run window...
C:\Documents and Settings\Administrator\My Documents\downloads\ComboFix.exe /u
Come back if you need help with sfc....

0

unPPC6000 right next to unPPC delete it too?

Deleted Telnet service. Don't think even in my Bulletin Board days before the Internet I didn't use Telnet then either, I don't think.

"I must admit I have no idea why the scan shows those critical updates as vulnerabilities - they were only released in Dec last year... are they actually installed?"

I hate to admit it, but I'm not sure how to check and see if they are installed. I went to Add/Remove programs and looked at the list of "Hotfixes" there's a couple dozen or so of those, but don't know how to find out if "MS07-069" etc is installed or not?

Regedit:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup]
"SourcePath"="C:\CABS\9519160_XP_2K"

Already had a key named "Installation Sources" with paths listed under the Data column of "D:\Drivers\PTPDriver D:\WIN2K_XP C:\CABS\9519160_XP_2K D:\"

Haven't done a manual regedit in a while, but anyway I went to the above mentioned tree in Regedit then right clicked and selected new string value then added Value name: SourcePath= and Value data: C:\CABS\9519160_XP_2K

Exported the Registry first to a file in My Documents.

Made sure the new RegEdit was in place. Rebooted computer and ran SFC /Scannow still same thing wants a W2KPro CD.

So I had already thought to borrowed one, but it was Windows 2000 Pro with Service pack 2 not Service pack 4. So I said whatever and ran SFC /scannow again anyway and inserted this CD when it asked for the CD. It seem to like it and showed the progress bar going across until it finished. When it finished it just closed, didn't give any report or anything, it just closed. So I don't know if it actually did any copying of files or what, but I took out the CD and rebooted the computer and then tested to see if the Original error that I started this Post on still happened. It does :-( I opened my computer browsed my internal and external hard drives just fine then closed the My Computer window and up pops that same error Explorer.exe - Application Error The Instruction at "0x7ce82a8c" etc... :-(

You can use any created folder or any application without the error popping up, but anything associated with being an integral part of Windows and only when you close the applications window does it the error pop up. With the exception of Internet Explorer. It's happened with the search feature, Windows Help, My Computer, the My Documents folder to name a few.

When it does the blank blue screen for a few seconds and comes back up you can go right on doing whatever you were doing it will even have your applications windows still open and working properly, but I have noticed two of the Icons on the system tray by the clock disappear when that happens? I can only get those back by doing a reboot.

Maybe this is a 3rd party software conflict issue?

Here's my icons in the system tray by the clock from left to right:
1) Unplug or Eject Hardware
2) Volume
3) Local area connection 2
4) Norton Ghost 2003
5) itouch (this is for my wireless Logitech keyboard)
6) Mouse (this is for my wireless Logitech Mouse)
7) Spyware Terminator (Real-Time Shield Enabled)
8) SmartRAM
9) Ashampoo FireWall
10) IObit SmartDefrag
11) SpywareGuard
12) AVG Free Edition - Control Center
13) Clock

Now I made the error happen again and it came back up with the icons in the system tray resorted as far as order from left to right and two of them are now gone.

New order from left to right:
1) Ashampoo FireWall
2) SmartRAM
3) AVG Free Edition - Control Center
4) Norton Ghost 2003
5) IObit SmartDefrag
6) iTouch
7) Spyware Terminator (Real-Time Shield Enabled)
8) Unplug or Eject Hardware
9) Volume
10) Local area connection 2
11) Clock

Missing Icons:
Mouse
SpywareGuard

All of the 13 items where in there before this error started occuring EXCEPT:
IObit SmartDefrag
SmartRAM

Not sure if SpywareGuard was there before the error started to occur, possibly not, because it was a fairly new installation.

Also, I made the error occur a 2nd time without rebooting with the 2 missing icons. It blue screened then came back up reshuffled the same 10 icons yet another sort order and this time I had to click on "Restore my active desktop" button to restore my background.


Going to Try to see if I can make this error occur in SafeMode.

Ok, Safemode it's solid as a rock. Opened and closed and did everything I knew had ever forced the error to occur, but no error.

Now going to try msconfig on the Startup tab and unselect things and reboot until I see if I can make the error go away.

Started by unselecting SpywareGuard and rebooted, but error still occured.

Then I left spywareguard off and also unselected spyware terminator, IObit Smart defrag as well as IObit Ramcleaner.

Error still occurs.

Will now disable firewall and antivirus. (Yes I disconnected the DSL before any of this).

Error still occurs.

Will now disable everything with the disable all button in msconfig on the Startup tab.

Error still occurs.

NOTE: However, noticed upon reboot that even though I had disabled all. One item rechecked itself upon reboot which was:

mobsync.exe /long HKLM\SOFTWARE\microsoft\windows\currentversion\run

Don't know what that is or how it rechecked itself in msconfig?

Now going to go to the General tab on msconfig and use "Diagnostic Startup - load basic devices and services only".

Ok, before I test to see if the error still occurs I want to make a note:
Upon reboot msconfig always comes up on the screen which is normal. However, diagnostic mode was not selected on the General tab even though that is what I had selected. Instead it was on Selective Startup with Load startup items selected and again mobsynce.exe /logon had reselected itself. Also under the services tab all services were deselected except "Remote Procedure Call (RPC) Locator" although this one said it was stopped. Also, "Remote Procedure Call (RPC)" this one was running.

Now going to test for the error with the above mentioned settings.

Well that was quick. Error occured as soon as I closed the msconfig window.

Right now I have nothing but a blue screen up with this notepad window that I'm typing all these notes in. Not sure if I will be able to save this file from here? Going to try anyway. Blue screen not going away as it normally does. Just blank blue screen with this notepad window open on it. This is just plain weird.

Well it did save the notepad file, but when I closed the notepad it just stayed on the blank blue screen and even Ctrl+Alt+Delete would not bring anything up so I had to power off the computer and power it back on again.

Not sure what to do at this point. I guess I will reseach online and see what mobsync.exe /logon is for one thing???

I remember when I was doing tech. support at a call center for a computer manufacturer and the w32.blasterworm hit and crashed everyone with Windows XP it seemed like it was using that RPC service or something? Anyway, on to some research and then I will post all this stuff I tried.

It should be noted that I basically used the same sequence to get the error to occur each time with the exception of it occuring just from closing msconfig.

It should also be noted that while I had unplugged the power to my DSL modem which is hooked into my Wireless broadband router and then via the router through a cable from the back of the router's #1 port to my NIC port on this computer. The router was still on and connected the whole time, but just no Internet access. Maybe that had something to do with it not staying in diagnostics mode on msconfig?

Found this about mobsync.exe /logon
http://www.softwaretipsandtricks.com/useless_files/111-mobsyncexe%20/logon.html

Do you think I should follow this sites suggested procedure?

small excerpt from above link about mobsync:
"This is because it is set by default to synchronise your home page at log-on."

What does it mean to synchronize my home page at log-on? Synchronise it with what?

By the way what does this "C:\Documents and Settings\Administrator\My Documents\downloads\ComboFix.exe /u" do cause combofix.exe to update? I didn't remove it since it's not an issue.

Help!!!!!!!!!!!! :)

However, this all turns out I really appreciate all your patient help and teaching me some more ways to get rid of viruses and other malware. Not to mention reminding about the SFC utility and lots of other things I either didn't know or had forgot. At this stage of the game of computers I've forgotten more things than I can remember. I've been through 30 years of it just about every OS except Vista and win2003. Including CP/M (precursor to DOS) all versions of DOS, All versions of Windows, Unix and unix copies, LInux(various versions), Beos, some others I can't remember the name of. Loads of programming languages, more applications than I can remember, CAD/CAM, NC and CNC programming, even messed around with a mac or two. I like Mac's would probably switch to one if I could afford the one I would like. ;-) Anyway, enough about my life's history. I guess I was just pointing out to anyone else that reads this, that no matter how long you've been working on computers or how much you know there is always ALWAYS more things you can learn.

Thanks again!
PS Check out www.slacker.com it's a new kind of online music site. Pretty cool.

0

sfc only takes what it needs to restore corrupted files, and it knows which versions to take in original form from a folder or cd, and which to take from the updates.
The Security bulletins:
MS07-069 [= KB942615] replaced MS07-057 which repl. MS07-045 which repl MS07-033 which repl MS07-027.
Aaaannnd: The latest bulletin, MS08-010 KB944533, replaced MS07-069 !!
MS07-043 and MS05-055 were separate issues.
Now you could google for the KB articles which represent those... but I have a feeling that Panda picked up those old bulletins from the Windows directory. If you expand C:\Windows almost the first entries are blue $NtUninstallKB****** folders - these are the files which have been replaced by updates along with an app and a batch file which run if you wish to reinstall the old files over the top of the newer [via Add/Remove pgms!].
Which you might be tempted to do if the update in question caused problems. Well, they [blue $NtUninstallKB****** folders] build up, and if all is sweeet I tend to delete em. Do that.
unPPC6000? Delete it. It's PeoplePC or CoolWebSearch.
C:\CABS\9519160_XP_2K is just one driver. Were there no .cab files in C:\CABS ? [C:\CABS would be the sourcepath if there were, but .cabs tend to be drivers...]. No matter anyway, sfc completed happily, found what it wanted. It does just close when successful, no bells or whistles.
"When it does the blank blue screen for a few seconds and comes back up you can go right on doing whatever you were doing it will even have your applications windows still open and working properly"... yeah, apps run independently of explorer, which is just your UI. It seems to be only explorer which is closing then restarting.
"Instead it was on Selective Startup with Load startup items selected " .... yep, it does that.
Not much happens without Remote Procedure calls. RPC.
"Also under the services tab all services were deselected except "Remote Procedure Call (RPC) Locator" ...and DCOM.
Notepad.exe runs indept of explorer. Most stuff does.
That combofix command I gave uninstalls it.
mobsync just synchronises the webpages you have set to View Offline... it updates them, in other words.
"no matter how long you've been working on computers or how much you know there is always ALWAYS more things you can learn" Ahh... this is the distillation of the beauty of Windows - it FORCES you to learn more about it. Non-stop.

Try removing your active desktop... man, but they can cause problems. All sorts.

0

Found this possible solution for the error I get on Cnet forums and tried it. Start>Run regsvr32 vbscript.dll <enter> Seemed to help because I could not force the error like I had been able to, but then the error came back just while working. I thought it might apply to me because I was getting a lot of errors about scripting and the discussion had to do with explorer.exe application error being due to Visual Basic issues which I was learning about a year ago until I figured out the Programming language would not do what I was trying to create. Anyway, just thought I would mention that as well.


"Well, they [blue $NtUninstallKB****** folders] build up, and if all is sweeet I tend to delete em. Do that."

Done.

"unPPC6000? Delete it. It's PeoplePC or CoolWebSearch."

Done. It was peoplepc, because that was my old dial-up connection until recent last few months upgrade to DSL.

"Were there no .cab files in C:\CABS ?"

No there was only the subfolder for the driver you are talking about. No .cab files.

"No matter anyway, sfc completed happily, found what it wanted. It does just close when successful, no bells or whistles."

I was accustomed to SFC in Windows 98SE which gives you nothing but reports and things to do all while it is checking the system files. So was not use to the Windows 2000 Pro version of SFC.

"That combofix command I gave uninstalls it."

I didn't use it since you said it wasn't infected.

"mobsync just synchronises the webpages you have set to View Offline... it updates them, in other words."

Interesting, thanks for the info.

"Try removing your active desktop... man, but they can cause problems. All sorts."

Not sure if I removed it, but I just pulled up Active Desktop in Windows Help and did what it said to turn it off and use standard Windows desktop. Made my background picture go away because it only seems to work with .jpg format graphic files if you are using active desktop. So I converted my .jpg background picture to .bmp and stored it in the standard directory for background pictures. Hate .bmp though, because they take up too much space, but oh well.

Anyway, why does active desktop cause so many problems if you care to expand on that?

Error is still occurring. :-( I tried looking up a price on a new copy of Windows 2000 Pro with SP4 and they were so high it was ridiculous. Windows XP Pro was actually cheaper even one deal I found included Office 2007. I'm thinking of changing to Windows XP Pro, but I don't know if it will work on this desktop that currently has Windows 2000 Pro. I know it will work on my old Windows 98SE Notebook, because I've seen my same exact model used for sell with Windows XP Pro installed on it. Just not sure about drivers for the Desktop. It's a Dell Optiplex GX150, but some of the hardware in it is not original stuff, but some upgrades I added. Anyway, I think XP Pro would work, probably can find any driver I don't have on Driverguide.com.

At any rate for the mean time I would like to know exactly what the deal is with this error:

"Explorer.exe - Application Error"
"The Instruction at "ox7ce82a8c" ref mem blah "The memory could not be "read".

Is it just the program file explorer.exe is corrupt itself and needs to be replaced like whoever it was posted in here a few pages back?

Just out of curiosity I did a search of the whole C: drive for explorer.exe it was found twice in C:\WINNT and C:\WINNT\ServicePackFiles\i386.

Both files the same size and creation date, but the one in i386 folder had an few days older last accessed date.

I'm glad though we got rid of all those blasted viruses and crap with all the various online scanners and such you sent me to.

My AVG Free edition virus software is going to expire by the end of May. I always use to run McAfee Internet suite. Do you have a recommend on a commercial one besides Norton? Maybe subscribe to one or more of those Online ones you sent me to besides one installed on my computer?

Well thanks again for your help. Sorry so long on a reply, just needed a couple of days away from computers in general. :-)

0

WinNT\ServicePackFiles\i386 exists if you did an upgrade by download as against an installation with the servicepack included [or slipstreamed]. That folder is your cache for running sfc - put it in sourcepath as "SourcePath" = "C:\WINNT\ServicePackFiles"
sfc would ensure that the correct version was in place, and if you change that sourcepath it will use the file from that i386 folder. You could rerun sfc, this time using the servicepackfiles directory. But I doubt that the error originates from explorer.exe itself.
My point with Combofix deletion was that it times out after a week - it won't run after that time, if you try it will delete itself.
This is a succinct explanation of Active desktop.... http://www.microsoft.com/technet/archive/ie/reskit/ie4/Part3/part3c.mspx?mfr=true -but if you remove it and the error continues, then put it back.
A few words fell out of a line I edited in a previous post:
""Instead it was on Selective Startup with Load startup items selected " .... yep, it does that." ... "if you have items unchecked in the startup list." Those words were meant to be there; that is why msconfig switched from diagnostic to selective mode.
Does the event viewer not show any listing for the error? I just monitored my machine's activity while closing an explorer window - explorer.exe was the only process involved with about 750 dealings with the registry in the 0.10sec it took to complete. Four system dlls were involved, but no third party sware, AV scanners etc.
And because you brought up the matter of scripting, ensure that you have only one version of .net framework and its hotfix installed [add/rmv pgms].
The error not occurring in safe mode points to a driver issue? Or account issue...? [since you've rather ruled out 3rd party sware].
Does it occur in Normal Mode under another account [admin type]?
I have no recommendations to give re comm AV services, there is too much personal preference involved and not enough difference between them. Okay, avoid Norton.

0

That folder is your cache for running sfc - put it in sourcepath as "SourcePath" = "C:\WINNT\ServicePackFiles"

Done Ran SFC /SCANNOW again still asked for the CD which I put in and let it run through again.

Problem still existed.

After that I got involved in buying McAfee 12-in-1 Internet security suite. Before I installed that I uninstalled almost everything that runs down in the systray. AVG 7.5 free edition, Ashampoo firewall, and a whole list of others that are listed above in this thread.

To get down to the point. The issue is no longer happening. The first time I noticed it was no longer happening is when I got really sick of a spyware prevention program down in the systray called "Spyware Terminator" so I uninstalled it before uninstalling anything else or before the install of McAfee. I then noticed it wasn't happening anymore. However, as persistant as it had been I just waited for a while before coming here to post. I now have the McAfee 12-in-1 installed and doing all of what all those other programs where doing and maybe more. I have not had that particular error message in days and it is FANTASTIC!!! I don't know if it was just the spyware terminator needing to be uninstalled, maybe it was corrupt or something, but after that I had like one error when installing McAfee that was somewhat similar except it had nothing to do with Explorer.exe I forgot what the program or dll was, but I think it was print spooler or spooler something. Only had that error once and I have not had anymore errors since.

I've even finally managed to get my Win2000PRO and my Win98SE computers fully talking over my wireless network. ha ha

Just to answer some of the last things you posted. I only have one account as administrator. I don't log onto windows in other words.

I only have one installation of the .net framework.

"Does the event viewer not show any listing for the error?" Not sure what the event viewer is unless that's Task manager?

I kept wondering where this log file was that it was always saying it was creating also.

Anyway the issue is resolved thanks to your very capable assistance!

How do I make sure everyone on this forum knows you know what you are doing or give you a good rating or whatever to try and repay you for all your time at least in some small way? I don't usually get into forums, but this one has been a good experience.

Thanks for all your help!!!

0

Wheeee...!
Takes me back to my first post.... bad software causing explorer.exe to crash. We focussed a bit on malware being the issue, but we did clean out your worm along the way.
So it merely turned out to be a bad installation of something legit... well, it happens. :). A full-time guard, no less.
You've been quite forensic in tracking this down, well done.
Event Viewer you reach via CP, Admin Tools; you'll see also Performance in that menu, it's where logs are created [if logging is enabled].
I'm sure you realise that being in an Administrator ac all the time means that you give those privileges to any malware you pick up whilst on the web...
I'm not chasing kudos... as I told someone else, this is my version of crossword puzzles. I pick the problems where I think I can help, or those which present a good opportunity to extend my knowledge.
It's been fun. Cheers, bear.

0

Thanks for the compliment about being forensic.

Yes believe it or not I did know it isn't the smartest thing to do running in Administrative all the time. I just really really hate dealing with well administration of various accounts, but I suppose it is adding waaay too much complication to my life now not to use some other type of account.
I understand about the not looking for kudos and this is like crossword puzzles to you, but none the less I did found the thing to at least add to gerbils reputation. Not sure I understand CP, Admin tools, but I'll figure it out.
Have fun, gerbil!

This question has already been answered. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.