I am getting this on start up:
exception processing message c0000013 parameters 75b6bf9c 4 75b6bf9c 75b6bf9c
and with a few clicks it goes away till next start up
I am getting this on start up:
exception processing message c0000013 parameters 75b6bf9c 4 75b6bf9c 75b6bf9c
and with a few clicks it goes away till next start up
Are you running XP media?
xp home edition version 2002 service pack 2
This is my first posts on Daniweb and I already have Hijack this on my computer but this is my first posts on Daniweb and I cannot find a way to attach it and post it all my attempts have failed
just copynpaste it in the clear from the notepad log, don't hide it in an attachment.
[but just so you know, attaching files is in Go Advanced tab. Don't use it for the log, tho.]
I am getting this on start up:
exception processing message c0000013 parameters 75b6bf9c 4 75b6bf9c 75b6bf9cand with a few clicks it goes away till next start up
In am getting the same error which goes away after clicking cancel 4 times. Any answers.
I am having the same problem. here is my hijack log
Logfile of HijackThis v1.99.1
Scan saved at 10:23:28 PM, on 5/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\Program Files\Windows Defender\MsMpEng.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\system32\brsvc01a.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\system32\brss01a.exe
H:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
H:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
H:\Program Files\Common Files\AOL\1131506533\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe
H:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
H:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe
H:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
H:\WINDOWS\system32\CTsvcCDA.EXE
H:\WINDOWS\System32\svchost.exe
H:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
H:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
H:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
H:\PROGRA~1\mcafee.com\ANTIVI~1\OasClnt.exe
H:\Program Files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlservr.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\VTTimer.exe
H:\WINDOWS\AGRSMMSG.exe
H:\Program Files\Common Files\AOL\1131506533\ee\AOLSoftware.exe
H:\Program Files\mcafee.com\antivirus\mcvsescn.exe
H:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
H:\WINDOWS\ALCXMNTR.EXE
H:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
H:\Program Files\Common Files\AOL\1131506533\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
H:\Program Files\Windows Defender\MSASCui.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\iTunes\iTunesHelper.exe
H:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
H:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
H:\Program Files\Common Files\AOL\1131506533\ee\SSCEvtHdlr.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\iPod\bin\iPodService.exe
H:\Program Files\America Online 9.0\waol.exe
H:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
H:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
H:\Program Files\Common Files\AOL\1131506533\ee\aolsoftware.exe
H:\Program Files\America Online 9.0\shellmon.exe
h:\program files\common files\aol\1131506533\ee\anotify.exe
h:\program files\common files\aol\1131506533\ee\anotify.exe
h:\program files\common files\aol\1131506533\ee\anotify.exe
H:\Program Files\Common Files\Real\Update_OB\realsched.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\Program Files\nanoCom Corporation\iSpQ VideoChat\iSpQVideoChat8.exe
H:\Documents and Settings\COMPAQ\My Documents\Docs\HijackThis_v1.99.1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - H:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - H:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HostManager] H:\Program Files\Common Files\AOL\1131506533\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] H:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "H:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [TkBellExe] "H:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sscRun] H:\Program Files\Common Files\AOL\1131506533\ee\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] H:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] H:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "H:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] H:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] H:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] H:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AOLSPScheduler] H:\Program Files\Common Files\AOL\1131506533\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [Windows Defender] "H:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "H:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [Creative Detector] H:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "H:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = H:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = H:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Service Manager.lnk = H:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &AOL Toolbar search - res://H:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - H:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - H:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - H:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - H:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.1.10/cfweb_activex.camfrogweb.com-advanced-2.0.1.10_instmodule.exe
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://24.240.197.171/activex/AMC.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - H:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - H:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - H:\Program Files\Common Files\AOL\1131506533\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe
O23 - Service: Autodesk Data Management Job Dispatch - Autodesk Inc - H:\Program Files\Autodesk\Data Management Server 5\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
O23 - Service: Autodesk EDM Server - - H:\Program Files\Autodesk\Data Management Server 5\Server\Webserver\Connectivity.EDMWS.Server.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - H:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - H:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - H:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - H:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - H:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: MSSQL$AUTODESKVAULT - Unknown owner - H:\Program Files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlservr.exe" -sAUTODESKVAULT (file missing)
O23 - Service: SQLAgent$AUTODESKVAULT - Unknown owner - H:\Program Files\Microsoft SQL Server\MSSQL$AUTODESKVAULT\Binn\sqlagent.EXE" -i AUTODESKVAULT (file missing)
i am only guessing here, but it would be one of your startup pgms looking to use a drive that it is configured to expect to be there, but which is in fact not. Could be this one:
O4 - HKCU\..\Run: [Creative Detector] H:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
.work your way thru the list of startups [O4 entries] and check which ones use drive media, and are they setup correctly. Some could be removed with no problems to you.
I am having this same problem> i need some help....
that won't work, karen, we need some detail. post your error, some symptoms and an HT log. Help us help you.
Normal peoples C: (drive) is my H: (drive) are you still confident that this will work?
XP [ as you can see!] is not fussy about being on the C: partition, or about being on the first partition, but [like all OS's ?] must be on a primary partition. That's it. So check the pgms which are trying to run at startup.
This is interesting. When you get a blue screen upon startup, it can mean a certain area on the Hard drive that is unreadable. Or it could be a Motherboard stating that there is a problem with a device like RAM.
First I would run the checks on the HDD.
Try this: When the system starts in Windows go to Start, Run and type MSCONFIG
Click on the startup tab
Click on Disable all (Keep in mind if you are running ME or 98 there are certain startup files that need to be enabled for your Operation system to run properly)
Click on apply and restart your system.
This step is to check the System Files of your Operation system:
Next go to Start Run and type SFC /scannow
(note the space between the C and the /)
This step is to check the integrity of the HDD.
Go to Start Run Type chkdsk (This command may not be included with your XP system or on Recovery console.) If you do not have this command available create a startup diskette with Windows 98 or ME and you will have the Check Disk command.
Question for you. Any Beeps when your system starts up?
RueB 2s De.
Hi all
I am having same problem 3 times at startup. i have been trying to fox this for weeks! and help would be really appreciated
Regards Goose
Here is my HT log:
Logfile of HijackThis v1.99.1
Scan saved at 12:55:38, on 21/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Goose1\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: dns cache reader (DNSCacheReader) - Unknown owner - C:\WINDOWS\system32\j9211037.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Goose, this is the only untoward entry in your hijackthis log:
O23 - Service: dns cache reader (DNSCacheReader) - Unknown owner - C:\WINDOWS\system32\j9211037.exe (file missing)
If you go Start, run, type cmd and press OK and then paste these two commands into the window after the prompt and press Enter each time it may do the trick:..
sc stop DNSCacheReader
sc delete DNSCacheReader
Say how it goes on restart... but pretty much that error comes from a glitch in a pgm which was not finished with a removable medium when it was removed or the pgm was abruptly terminated improperly, or was still registering the medium as inserted when the sys was shutdown... I cannot see from your log what that pgm could be though [if it is actually the case]. Sorry.
sorry no luck!
firstly the cmd said that the process was not running and i entered the second command and restarted but no luck...
Any ideas? i have disabled a few programs from startup...
regards and thanks for your lighting response!
Goose
Goose, would you run these two scans please, in this order?
==Please download VundoFix.exe to your desktop from http://www.atribune.org/ccount/click.php?id=4
Double-click VundoFix.exe to start it, click the Scan for Vundo button.
When the scan completes click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files - click YES
Your desktop will then go blank as the process of removing Vundo starts.
When completed it will prompt that it will restart your computer - click OK.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
Scan for Vundo button." when VundoFix appears at reboot.
Post the contents of C:\vundofix.txt plus a new HijackThis log.
Combofix:
==Download this file to your desktop: http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
...or from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
...or this new one: http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.
I am getting this on Startup exception processing message c0000013 parameters 75b6bf9c 4 75b6bf9c 75b6bf9c
however I am new to computers and am afraid if I change things such as disabling programmes at startup that this will effect my computer and I will not be able to get it running again any help I can get would be very much appreciated
Hi
ChompDog, well i had the same problem, i think it was caused by a faulty windows update and possibly something to do with Quicktime and the quittask process. i had to wipe the computer and then did not bother with automatic updates. the best person to ask would be gerbil as he knows more than i do. i suggest that you send a message to gerbil and carry out his advice. click on his profile and click send private message. i will also have a look to see if i can help. i would like to get the solution to this problem,
Regards
Goose
Goose, Chompdog..[?]... it is quite difficult to help on this one... but if you put a CD in your drive and on any restarts do not get that message, then some pgm has a small corruption in it to cause it to be still seeking a disk even when you think it is not running. It pretty much has to be one of your installed pgms conflicting with something new in your PC.. and the finger seems to be pointing at some update M$ has delivered. A corruption? -well, M$ would say it was their fault for not working with their OS..! You would need to check a complete list of your autostarting pgms that use disk input to find the culprit.
Personally, I'd check any HP stuff right off, cos over time I have built up the impression that there is a "conflict" between HP n M$.... not fighting.. just different ideas about how things should be done. I don't mean to uninstall any HP gear, just check and stop any autostarts.
Say how you get on.
I agree Gerbil, it has definately something to do with XP updates. i have them switched off and now i no longer get that error!
Also i think it may be something to do with qqtask-quicktime and also apple updater and most likely any true image software as they constantly look for drives...
I will post thgis to Chompdog and offer him a solution, but he will have to re format his HDD-only way i think and then disable ms updates
that is the only solution i have found so far!
Thanks for all your help, time and effort Gerbil,
Take care!
Goose
I am getting this on Startup exception processing message c0000013 parameters 75b6bf9c 4 75b6bf9c 75b6bf9c
however I am new to computers and am afraid if I change things such as disabling programmes at startup that this will effect my computer and I will not be able to get it running again any help I can get would be very much appreciated
Hi Chompdog, OK the heres the only solution, re format your hard drive, if you are willing to do this i will talk you through the entire process a-z,it will be no problem.
if you want to do this (as i can see there is no other way, im afraid) then please PM me and i will talk you through the steps.
Kind Regards
Goose
Hi all
Firstly thankyou to both Gerbil and Goose134 for all your help and suggestions. I do however seem to have resolved this isse. i went into the MSCONFIG and into the startup tab and disabled all then turned them back on one by one and found that the culprit was qttask. Ihave enabled all but this startup item and I no longer get this error message.
Hi
Chompdog
excellent i am glad that you have resolved the issue!
Regards
Goose
PS good old Quicktime eh! heheh
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.