windows exe application error
 
  Tweaks.com
 Home    Members    Calendar    Who's On        Main Site
 



««12345»»»

windows exe application errorExpand / Collapse
Author
Message
Posted 7/15/2003 1:11 PM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 9/14/2003 8:55 AM
Posts: 20, Visits: 1

Hi, When I try to open certain web pages I gat a 'explorer exe application error'. The error message reads


The instruction at "0x00ff2008" referenced memory at "0x00ff2008". The memory could not be 'read'.


Has anyone any idea what is causing this. 

Post #76
Posted 7/15/2003 1:11 PM


Senior Forum Advisor

Senior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum Advisor

Group: Senior Advisor
Last Login: 12/4/2005 12:31 AM
Posts: 4,743, Visits: 5

Hi Tempest,


Just for clarification (for me anyway) is this an explorer or iexplorer error ?  Are there any clues in your event viewer ?



Cheers

Post #23090
Posted 7/15/2003 1:11 PM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 9/14/2003 8:55 AM
Posts: 20, Visits: 1
HI Bulldog, It is a iexplorer exe application error and when i try to open the application report on the event viewer I get a 'corrupt' error, saying 'The event log file is corrupt'.
Post #23091
Posted 7/15/2003 1:11 PM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 9/14/2003 8:55 AM
Posts: 20, Visits: 1
It is iexplore exe and I am using xp. How do I clear the event log?
Post #23093
Posted 7/15/2003 1:11 PM


Senior Forum Advisor

Senior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum Advisor

Group: Senior Advisor
Last Login: 12/4/2005 12:31 AM
Posts: 4,743, Visits: 5

Hi tempest,


LstN'Space is correct, this is often caused by spy/adware, notably "bad"  browser plugins. Please do this: If you haven't already, please get Spybot S&D to clear out most of the spyware.
Short tutorial and download link here:
http://tomcoyote.org/SPYBOT/
After installing, first press Online, and search for, put a check mark at, and install all updates.
Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot fix everything it labels in red.



When you've done all that, go to
http://www.tomcoyote.org/hjt/
and download 'Hijack This!'.
Unzip, double-click HijackThis.exe, and hit "Scan".


When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log somewhere, load it in Notepad, and copy its contents here.


Most of what it lists will be harmless or even required, so do NOT fix anything yet.
Someone here will be happy to help you analyze the results.



Cheers

Post #23095
Posted 7/15/2003 1:11 PM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 9/14/2003 8:55 AM
Posts: 20, Visits: 1

Logfile of HijackThis v1.95.0


Scan saved at 16:46:51, on 16/07/2003


Platform: Windows XP SP1 (WinNT 5.01.2600)


MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\System32\svchost.exe


C:\WINDOWS\Explorer.exe


C:\WINDOWS\system32\LEXBCES.EXE


C:\WINDOWS\system32\spoolsv.exe


C:\WINDOWS\system32\LEXPPS.EXE


C:\WINDOWS\System32\nvsvc32.exe


C:\WINDOWS\System32\svchost.exe


C:\WINDOWS\System32\Wt32exe.exe


C:\WINDOWS\system32\fxssvc.exe


C:\WINDOWS\System32\cmd32.exe


C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe


C:\PROGRA~1\ALWILS~1\AVAST32\AvMaiSrv.exe


C:\WINDOWS\System32\LXSUPMON.EXE


C:\PROGRA~1\ALWILS~1\AVAST32\avServer.exe


C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe


C:\Program Files\Common Files\Real\Update_OB\realsched.exe


C:\WINDOWS\System32\tblmouse.exe


C:\WINDOWS\System32\wininetd.exe


C:\WINDOWS\System32\ctfmon.exe


C:\Program Files\Messenger\msmsgs.exe


C:\WINDOWS\System32\devldr32.exe


C:\Program Files\Smart Explorer\SmartExplorer.exe


C:\Program Files\Microsoft Money\System\urlmap.exe


C:\WINZIP\winzip32.exe


C:\unzipped\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.freeserve.com/


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL=about:blank


R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=about:blank


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.freeserve.com/


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title=Microsoft Internet Explorer provided by Freeserve


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm


F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\System32\cmd32.exe


O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL


O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx


O2 - BHO: (no name) - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.2\NHelper.dll


O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll


O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx


O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL


O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe


O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers


O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"


O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize


O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe


O4 - HKLM\..\Run: [AvMaiSrv] C:\PROGRA~1\ALWILS~1\AVAST32\AvMaiSrv.exe


O4 - HKLM\..\Run: [Avast32] C:\PROGRA~1\ALWILS~1\AVAST32\ASTART32.EXE /keepserver


O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe


O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN


O4 - HKLM\..\Run: [IEKILL] C:\Program Files\IE_Kill\iekill.exe


O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon


O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot


O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program Files\Stop-the-Pop-Up\stopthepop.exe" -minimized


O4 - HKLM\..\Run: [tblfunc] tblmouse.exe


O4 - HKLM\..\RunServices: [CMD] cmd32.exe


O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe


O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background


O4 - HKCU\..\Run: [Ultimate Popup Killer] C:\Program Files\Ultimate Popup Killer\Popupkiller.exe


O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


O8 - Extra context menu item: Allow popups - file://C:\Program Files\Ultimate Popup Killer\Popupkiller.html


O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000


O8 - Extra context menu item: IE Booster Copy Meister - res://C:\Program Files\IE Booster 2\ieb.dll/copy-wiz.ieb


O8 - Extra context menu item: IE Booster Interactive HTML Detective - res://C:\Program Files\IE Booster 2\ieb.dll/contextmenu.ieb


O8 - Extra context menu item: IE Booster Open Frame In New Window - res://C:\Program Files\IE Booster 2\ieb.dll/open-frame-in-new-window.ieb


O8 - Extra context menu item: IE Booster Open Frame In This Window - res://C:\Program Files\IE Booster 2\ieb.dll/open-frame-in-new-window.ieb


O8 - Extra context menu item: IE Booster Web Page Analyzer - res://C:\Program Files\IE Booster 2\ieb.dll/element.ieb


O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)


O9 - Extra button: Researcher (HKLM)


O9 - Extra button: Related (HKLM)


O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)


O9 - Extra button: Money Viewer (HKLM)


O9 - Extra button: Messenger (HKLM)


O9 - Extra 'Tools' menuitem: Messenger (HKLM)


O9 - Extra button: Page Analysis (HKCU)


O9 - Extra 'Tools' menuitem: IE Booster Web Page Analyzer (HKCU)


O9 - Extra button: HTML Detective (HKCU)


O9 - Extra 'Tools' menuitem: IE Booster Interactive HTML Detective (HKCU)


O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll


O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/


O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=www.viewpoint.com


O16 - DPF: {0D6451B3-FDDA-11D3-BFEC-00D0B725EB0B} (Yahoo! Vision) - http://download.yahoo.com/dl/fv/yv.cab


O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab


O16 - DPF: {3717DF55-0396-463D-98B7-647C7DC6898A} - http://tb-static.adpowerzone.com/mtb/toolbar.cab


O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20011217/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe


O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab


O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/2499c3c1f66653abbe20/netzip/RdxIE6.cab


O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab


O16 - DPF: {6ABC861A-31E7-4D91-B43B-D3C98F22A5C0} - http://secure.goodthinxx.com/(mk1stee2m5yrmn45ffc4u3e2)/secureweb/securewebgt.cab


O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB


O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37582.4705092593


O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/download/bin/actxcab.cab


O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab


O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


O16 - DPF: {F2A84794-EE6D-447B-8C21-3BA1DC77C5B4} (SDKInstall Class) - http://activex.microsoft.com/activex/controls/sdkupdate/sdkinst.cab


When iI carried out the spybot check I tried to open a wab page I had earlier encountered problems with and on this occassion it did not crash BUT the web page dissapeared and I was left with the desktop!!!!!!! never mind hopefully someone can anylise the above and fix the problem, thanks for all your help.

Post #23096
Posted 7/15/2003 1:11 PM


Senior Forum Advisor

Senior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum Advisor

Group: Senior Advisor
Last Login: 12/4/2005 12:31 AM
Posts: 4,743, Visits: 5

Hi tempest,


Right off the hop, this is a virus.


cmd32.exe


Please do a scan with an up-to- date signature and then repost a new log.



Cheers

Post #23097
Posted 7/15/2003 1:11 PM


Senior Forum Advisor

Senior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum Advisor