Re: Ok, so I'm a lazy moron - Explorer crashes at startup

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: PA Bear (PABear_at_mvps.org)
Date: 05/27/04


Date: Thu, 27 May 2004 13:09:58 -0400


<eg> Then you certainly would have your eyes opened if you visited
http://forum.aumha.org/viewforum.php?f=30.

e.g., http://forum.aumha.org/viewtopic.php?p=30842 (one of the more
successful exchanges; OP was also posting almost simulataneously in IE6
Browser, another forum which would open your eyes even wider, my Cajun
canoodle.)

-- 
~PAB
Kelly wrote:
> Sheesh, am tired just from reading this PaBear.  :o(
>
>
> "PA Bear" <PABear@mvps.org> wrote in message
> news:OJSI0F4QEHA.4020@TK2MSFTNGP11.phx.gbl...
>> First, move HijackThis to its own dedicated folder so your HT backups
>> have a
>> place to "live".
>>
>> Update your anti-virus definitions; Download & seek updates for
>> CWShredder,
>> Ad-aware and Spybot; Disable System Restore temporarily, enable Show
>> Hidden
>> Files, and reboot into Safe mode; run a full system scan in this
>> environment.
>>
>> Still in this environment, run, in order:
>>
>>    CWShredder (fix all)
>>
>>    Ad-aware (fix all)
>>
>>    Spybot v1.3 (generally, fix all in red)
>>
>> Reboot into Windows.  If problem persists, reboot back into Safe Mode,
>> run HijackThis (no other windows open) and save the log.
>>
>> Reboot into Windows & re-enable System Restore.  After registering, post
>> to
>> one of the following forums: http://forums.spywareinfo.com/ or
>> http://forum.aumha.org/viewforum.php?f=30 for expert analysis, **not
>> here**;
>> include a description of your problem, your OS, the steps you've taken so
>> far, and your latest HT log.
>> --
>> HTH - Please Reply to This Thread
>>
>> ~Robear Dyer (PA Bear)
>> MS MVP-Windows (IE/OE), AH-VSOP
>>
>> AumHa Forums
>> http://forum.aumha.org
>>
>> What You Should Know About Spyware
>> http://www.microsoft.com/mscorp/twc/privacy/spyware.mspx
>>
>> Steve Nielsen wrote:
>>>> Run the rest of them, just in case:
>>>>
>>>> CWShredder (Line 313)
>>>> http://www.kellys-korner-xp.com/xp_tweaks.htm
>>>
>>> Nothing found.
>>>
>>>>
>>>> Hijack This
>>>> http://www.spychecker.com/program/hijackthis.html
>>>
>>> Nothing obvious. I include the log at the end of this message.
>>>
>>>>
>>>> Free Online Virus Scan
>>>> http://housecall.trendmicro.com/housecall/start_corp.asp
>>>
>>> No infections found.
>>>
>>>>
>>>> More info:
>>>>
>>>> Windowx XP Patch: Explorer May Generate an Application Error When You
>>>> Close a Folder:  http://tinyurl.com/68pt
>>>
>>> Tried to look at more details on this patch but the page was moved or
>>> unavailable. Besides the general description doesn't quite match; it
>>> happens at startup (and even in Safe Mode) and randomly when I run just
>>> about anything, not when closing folders though.
>>>
>>>>
>>>> Error Message: Explorer.exe Has Generated Errors and Will Be Closed by
>>>> Windows - Norton Cleansweep
>>>> http://support.microsoft.com/?scid=kb;EN-US;Q314867
>>>
>>> No Norton products installed.
>>>
>>>>
>>>> Right Click Crash
>>>> http://www.theinquirer.net/?article=9403
>>>> http://support.microsoft.com/default.aspx?scid=kb;en-us;819101
>>>
>>> Not applicable.
>>>
>>>>
>>>> Common behavior if Hotbar is installed.  If this is the case, run the
>>>> edit listed below:
>>>>
>>>> Hotbar - Windows Explorer/New/Folder Freezes (Line 206)
>>>> http://www.kellys-korner-xp.com/xp_tweaks.htm
>>>
>>> No Hotbar installed.
>>>
>>>>
>>>> If this is not the case try these suggestions:
>>>>
>>>> Right click a blank area on the Desktop/Properties/Appearance/Effects.
>>>> In
>>>> the Effects dialog box, click to clear the: "Use the following
>>>> Transition
>>>> effect for menus and tooltips check box, and ok your way out.
>>>
>>> Made no difference.
>>>
>>>>  And/or:
>>>> Click the folder or file that you want (select it) before you
>>>> right-click it to display the shortcut menu.
>>>
>>> Not applicable as stated above.
>>>
>>>>
>>>> Lastly run the two edits on line 157 from here:
>>>> http://www.kellys-korner-xp.com/xp_tweaks.htm
>>>>
>>>
>>> Tried merging but it would not, error was there may be a disk error (a
>>> disk check was done, no errors). Manually added the edits, still made no
>>> difference.
>>>
>>> Thanks,
>>> Steve
>>>
>>> Hijackthis log follows:
>>>
>>> Logfile of HijackThis v1.97.7
>>> Scan saved at 11:34:14 AM, on 5/26/2004
>>> Platform: Windows XP SP1 (WinNT 5.01.2600)
>>> MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>>>
>>> Running processes:
>>> C:\WINDOWS\System32\smss.exe
>>> C:\WINDOWS\system32\winlogon.exe
>>> C:\WINDOWS\system32\services.exe
>>> C:\WINDOWS\system32\lsass.exe
>>> C:\WINDOWS\system32\svchost.exe
>>> C:\WINDOWS\System32\svchost.exe
>>> C:\WINDOWS\system32\spoolsv.exe
>>> C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
>>> C:\WINDOWS\System32\cusrvc.exe
>>> C:\Program Files\Common Files\Command Software\dvpapi.exe
>>> C:\WINDOWS\System32\gearsec.exe
>>> C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
>>> C:\WINDOWS\System32\NALNTSRV.EXE
>>> C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
>>> C:\WINDOWS\System32\wm.exe
>>> C:\NOVELL\ZENRC\wuser32.exe
>>> C:\NOVELL\ZENRC\WUOLService.exe
>>> C:\WINDOWS\SYSTEM32\WISPTIS.EXE
>>> C:\WINDOWS\System32\tabbtnu.exe
>>> C:\WINDOWS\System32\ctfmon.exe
>>> C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
>>> C:\Program Files\Common Files\microsoft shared\ink\TPA.exe
>>> C:\WINDOWS\System32\igfxtray.exe
>>> C:\WINDOWS\System32\hkcmd.exe
>>> C:\Program Files\Acer\Notebook Manager\almxptray.exe
>>> C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
>>> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
>>> C:\Progra~1\Launch Manager\LaunchAp.exe
>>> C:\Progra~1\Launch Manager\PowerKey.exe
>>> C:\Progra~1\Launch Manager\HotkeyApp.exe
>>> C:\Progra~1\Launch Manager\CtrlVol.exe
>>> C:\Progra~1\Launch Manager\Wbutton.exe
>>> C:\WINDOWS\System32\NWTRAY.EXE
>>> C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
>>> C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
>>> C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
>>> C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
>>> C:\Program Files\Palm\AlarmApp.exe
>>> C:\WINDOWS\Explorer.exe
>>> C:\WINDOWS\System32\wuauclt.exe
>>> C:\temp\HijackThis\HijackThis.exe
>>>
>>> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
>>> http://global.acer.com
>>> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
>>> http://global.acer.com
>>> R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext =
>>> http://global.acer.com/
>>> O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
>>> C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
>>> O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} -
>>> C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
>>> O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
>>> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
>>> O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
>>> c:\program files\google\googletoolbar1.dll
>>> O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} -
>>> C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
>>> O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
>>> C:\WINDOWS\System32\msdxm.ocx
>>> O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -
>>> C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
>>> O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} -
>>> C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
>>> O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
>>> c:\program files\google\googletoolbar1.dll
>>> O4 - HKLM\..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft
>>> shared\ink\tabtip.exe" /resume
>>> O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
>>> O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
>>> O4 - HKLM\..\Run: [AcerNotebookManager] C:\Program Files\Acer\Notebook
>>> Manager\almxptray.exe
>>> O4 - HKLM\..\Run: [SynTPLpr] C:\Program
>>> Files\Synaptics\SynTP\SynTPLpr.exe
>>> O4 - HKLM\..\Run: [SynTPEnh] C:\Program
>>> Files\Synaptics\SynTP\SynTPEnh.exe
>>> O4 - HKLM\..\Run: [LaunchAp] C:\Progra~1\Launch Manager\LaunchAp.exe
>>> O4 - HKLM\..\Run: [PowerKey] "C:\Progra~1\Launch Manager\PowerKey.exe"
>>> O4 - HKLM\..\Run: [HotkeyApp] C:\Progra~1\Launch Manager\HotkeyApp.exe
>>> O4 - HKLM\..\Run: [CtrlVol] C:\Progra~1\Launch Manager\CtrlVol.exe
>>> O4 - HKLM\..\Run: [Wbutton] "C:\Progra~1\Launch Manager\Wbutton.exe"
>>> O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
>>> O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft
>>> Hardware\Keyboard\type32.exe"
>>> O4 - HKLM\..\Run: [ZENRC Tray Icon] zentray.exe
>>> O4 - HKLM\..\Run: [untray] C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
>>> O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
>>> O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
>>> O4 - HKLM\..\Run: [CSAV_CheckViruses]
>>> C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe O4 - HKCU\..\Run: [ctfmon.exe]
>>> C:\WINDOWS\System32\ctfmon.exe
>>> O4 - HKCU\..\Run: [Zinio DLM] C:\Program Files\Zinio\ZDLM.exe /hide
>>> O4 - Global Startup: SketchBook Snapshot.lnk = C:\Program
>>> Files\AliasWavefront\Alias SketchBook Pro 1.0\SketchBookSnap.exe
>>> O4 - Global Startup: Alarm Manager.LNK = C:\Program
>>> Files\Palm\AlarmApp.exe O9 - Extra button: FlingIt (HKLM)
>>> O9 - Extra button: Research (HKLM)
>>> O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX
>>> Control) -
>>> http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
>>> O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) -
>>> http://webmail.lincoln.k12.or.us/iNotes.cab
>>> O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) -
>>> http://webmail.lincoln.k12.or.us/iNotes6.cab
>>> O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
>>>
>>
http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe
>>> O16 - DPF: {6F74F92E-8DD8-4DDE-8FB8-CBB882A68048} (Microsoft Office XP
>>> Professional Step by Step Interactive) - file://C:\Program
>>> Files\Microsoft Interactive Training\O10C\mitm0026.cab
>>> O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
>>>
>>
http://a840.g.akamai.net/7/840/537/7d90ae05585062/housecall.antivirus.com/housecall/xscan53.cab
>>> O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
>>> Object) -
>>> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Quantcast