This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

SVCHOST.EXE APPLICATION ERROR!

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

kaspersky log:

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\9e2e5cc636efdb3cdc5a3f955e8447c7_0f8834d6-5a29-4a4c-9e16-c97ab370ae3d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\491228ff3e5f8732f097b321e4bcd546_0f8834d6-5a29-4a4c-9e16-c97ab370ae3d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\511a0f3f9e960fa97de3d0b74adfc574_0f8834d6-5a29-4a4c-9e16-c97ab370ae3d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\Noor\Local Settings\Temp\WZZM407A\uninst.zip^/uninst.exe Infected: not-a-virus:AdWare.Win32.WebSpecial.a skipped
C:\Documents and Settings\Noor\Local Settings\Temp\WZZM407A\uninst.zip^ ZIP: infected - 1 skipped
C:\Documents and Settings\Noor\My Documents\anime\(cracked) power iso.zip/YSB_toolBar.exe/stream Infected: Trojan-Downloader.Win32.IstBar.no skipped
C:\Documents and Settings\Noor\My Documents\anime\(cracked) power iso.zip/YSB_toolBar.exe Infected: Trojan-Downloader.Win32.IstBar.no skipped
C:\Documents and Settings\Noor\My Documents\anime\(cracked) power iso.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe/data.rar/start.bat Infected: Trojan.BAT.Zapchast skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe/data.rar/services.exe Infected: Backdoor.Win32.Iroffer.b skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe/data.rar/red.exe Infected: not-a-virus:RemoteAdmin.Win32.NirComLine.12 skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe/data.rar/psshutdown.exe Infected: not-a-virus:RiskTool.Win32.PsShutdown.232 skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe/data.rar/load.bat Infected: Trojan.BAT.Zapchast skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe/data.rar/csrss.exe Infected: Virus.Win32.Parite.b skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe/data.rar Infected: Virus.Win32.Parite.b skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe Infected: Virus.Win32.Parite.b skipped
C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar RAR: infected - 8 skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\artmoney v7.13.zip/artmoney v7.13.exe Infected: not-a-virus:Monitor.Win32.Ardamax.20 skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\artmoney v7.13.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\Random stuff\GHOST(1)(1).exe/hauntpc.exe Infected: not-virus:BadJoke.Win32.Hauntpc skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\Random stuff\GHOST(1)(1).exe ZIP: infected - 1 skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\Random stuff\MSN.CEDP.Stealer.2.zip/Setup.exe/data0002 Infected: Trojan-Dropper.Win32.VB.av skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\Random stuff\MSN.CEDP.Stealer.2.zip/Setup.exe Infected: Trojan-Dropper.Win32.VB.av skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\Random stuff\MSN.CEDP.Stealer.2.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\Random stuff\setup.exe/data0002 Infected: Trojan-Dropper.Win32.VB.av skipped
C:\Documents and Settings\Noor\My Documents\My Received Files\Random stuff\setup.exe NSIS: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\system\svchost.exe Infected: not-a-virus:Monitor.Win32.HandyKeylogger.a skipped
C:\WINDOWS\system32\dllcache\win32\psshutdown.exe Infected: not-a-virus:RiskTool.Win32.PsShutdown.232 skipped
D:\ca_setup.exe/WISE0023.BIN Infected: not-a-virus:PSWTool.Win32.Cain.284 skipped
D:\ca_setup.exe/WISE0025.BIN Infected: not-a-virus:PSWTool.Win32.Cain.284 skipped
D:\ca_setup.exe WiseSFX: infected - 2 skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat Object is locked skipped
D:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\Noor\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\cert8.db Object is locked skipped
D:\Documents and Settings\Noor\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\formhistory.dat Object is locked skipped
D:\Documents and Settings\Noor\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\history.dat Object is locked skipped
D:\Documents and Settings\Noor\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\key3.db Object is locked skipped
D:\Documents and Settings\Noor\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\parent.lock Object is locked skipped
D:\Documents and Settings\Noor\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-7b3d82c6-2d90b94e.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped
D:\Documents and Settings\Noor\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-534e5212-50806ee9.zip/Mein.class Infected: Trojan.Java.Binny.a skipped
D:\Documents and Settings\Noor\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-534e5212-50806ee9.zip/Beyond.class Infected: Trojan.Java.Binny.a skipped
D:\Documents and Settings\Noor\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-534e5212-50806ee9.zip ZIP: infected - 2 skipped
D:\Documents and Settings\Noor\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\Cache\_CACHE_001_ Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\Cache\_CACHE_002_ Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\Cache\_CACHE_003_ Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\Application Data\Mozilla\Firefox\Profiles\qvb018rb.SUSDUFIUSDIFG\Cache\_CACHE_MAP_ Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\History\History.IE5\MSHist012006082520060826\index.dat Object is locked skipped
D:\Documents and Settings\Noor\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\Noor\ntuser.dat Object is locked skipped
D:\Documents and Settings\Noor\ntuser.dat.LOG Object is locked skipped
D:\mirc617.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
D:\mirc617.exe mIRC: infected - 1 skipped
D:\netpumper-1.25.1-setup-NP_0020.exe/data0079 Infected: not-a-virus:AdWare.Win32.Lop.ai skipped
D:\netpumper-1.25.1-setup-NP_0020.exe Inno: infected - 1 skipped
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2006-08-25.11-03-18.log Object is locked skipped


i stopped the scan because i managed to get to 100% and i was about to save the log and then my pc crashed :(
so i did a scan again and stopped it when it found the same ammount of viruses as before, hope thats ok :)

Logfile of HijackThis v1.99.1
Scan saved at 16:36:36, on 03/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
D:\Program Files\Spyware Doctor\sdhelp.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
D:\WINDOWS\System32\alg.exe
D:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Winamp\winampa.exe
D:\FRAPS\FRAPS.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Logitech\SetPoint\SetPoint.exe
D:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
D:\Program Files\HIJACK THIS\HijackThis.exe
D:\Program Files\Xfire\62.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Xfire] C:\Program Files\Xfire2\Xfire.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKCU\..\Run: [Fraps] D:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Xfire.lnk = D:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Google Search - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://D:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with &ZipScan - D:\PROGRA~1\ZIPSCA~1\zs_ie.htm
O8 - Extra context menu item: Si&milar Pages - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://D:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by101fd.bay101.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{BD8F6EAE-D6F0-4829-8A2D-C7F9FFCD8F2B}: NameServer = 80.225.250.178 80.225.250.186
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: MCPClient - D:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WB - D:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - D:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - D:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcSandraSrv.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - D:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - D:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

done, i found quite a few but only these 2 gave me trouble:

Unable to clean trojan file C:\Documents and Settings\Noor\My Documents\anime\(cracked) power iso.zip/YSB_toolBar.exe because it is contained in an archive
Unable to clean trojan file C:\Documents and Settings\Noor\My Documents\anime\Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.rar/Bitlord.Pro.Bittorrent.Client.FULL.WORKING.KEYGEN+CRACK.exe because it is contained in an archive
Trojan cleaning finished.


shall i just delete them or is there a process i need to stop?
thanks :D
I was having the same problem few weeks ago, and my error messsages similar to this:
—————————
svchost.exe - Application Error
—————————
The exception unknown software exception (0xc0000409) occurred in the application at location 0x5b86a3c0.


—————————
OK   Cancel   
—————————

and I always refered to this board for a fix, but few days ago I've found my fix, with 2 updates file from Microsoft, my problem is now solved, here are the 2 files, hope they will fix up your problem too.
Instructions: Apply both patches then reboot your computer.

http://myfriends.up.md/WindowsXP-KB920683-x86-ENU.rar
http://myfriends.up.md/WindowsXP-KB921883-x86-ENU.rar

Good luck!
searched for those files on google and downloaded them from the official microsoft site, better to be safe then sorry :) thanks
You're welcome, did those files get your problem solved? I'll remove the files from my host and just leaving the file names here Edit: I can't edit that post, so the links will be down, you can search google or microsoft for the files
Since you said this

yeah i downloaded them and ive had no trouble so far, thanks alot mate!


I assumed your issues were resolved.

What problems are you having at the moment. Please post a hijackthis log also.
Ah thats understandable, im not having any issues at the moment, but i was presuming from the following post by you:

Can you scan with wareout again and post the log please. Some of the lag will be from the applications you have loaded and we will clear those out when it is clean.


That there was still stuff 2 do

Here's a hijackthis log:

Hijackthis.txt

Logfile of HijackThis v1.99.1
Scan saved at 17:31:45, on 19/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
D:\Program Files\Spyware Doctor\sdhelp.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
D:\WINDOWS\System32\alg.exe
D:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
D:\FRAPS\FRAPS.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Logitech\SetPoint\SetPoint.exe
D:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
D:\Program Files\Mozilla Firefox\firefox.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Xfire\Xfire.exe
D:\Program Files\HIJACK THIS\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - D:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [kis] "D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKCU\..\Run: [Fraps] D:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: Xfire.lnk = D:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Google Search - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Backward &Links - res://D:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with &ZipScan - D:\PROGRA~1\ZIPSCA~1\zs_ie.htm
O8 - Extra context menu item: Si&milar Pages - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://D:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by101fd.bay101.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{BD8F6EAE-D6F0-4829-8A2D-C7F9FFCD8F2B}: NameServer = 80.225.250.178 80.225.250.186
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: wbsys.dll,,D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - D:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: MCPClient - D:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WB - D:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: BlueSoleil Hid Service - Unknown owner - D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - D:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - D:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcSandraSrv.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - D:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - D:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI