Not sure if XP Home has System Restore, but roll back to before these problems occured if you can.
Run a spyware cleaner or two (adaware/spybot, etc) and a full system scan AV (avast is a good free one).
Main Topics
Browse All TopicsEvery time I boot my computer I get an error as per the attached screen shot. Is this a virus. I ran a Microsoft scanner which report presence of a trojan as per the attached screen shot. Please help.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Boot your computer into Windows click start>run>msconfig, click the startup tab and disable everything on startup this should prevent anything program from starting up on bootup.
Download MalwareBytes from this location and Upddate the definitions and run a scan on your computer. http://download.cnet.com/M
If problem persists, also run Combofix and show us the logfile. If it doesn't run at first go, redownload and rename the file before saving it to your desktop.
Please download ComboFix by sUBs:
http://download.bleep
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I
f needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepin
Dear All,
To give you more details I attach Drwatson32 log file to enable you to study the problem in more detail:
QUOTE
Application exception occurred:
App: C:\Program Files\Internet Explorer\IEXPLORE.EXE (pid=2812)
When: 07-08-2009 @ 11:24:32.336
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: BIMALJAIN
User Name: Ion Exchange
Terminal Session Id: 0
Number of Processors: 1
Processor Type: x86 Family 6 Model 22 Stepping 1
Windows Version: 5.1
Current Build: 2600
Service Pack: 3
Current Type: Uniprocessor Free
Registered Organization: Ion Exchange Infrastructure Ltd.
Registered Owner: Ion Exchange Infrastructure Ltd.
*----> Task List <----*
0 System Process
4 System
680 smss.exe
740 csrss.exe
764 winlogon.exe
808 services.exe
820 lsass.exe
968 svchost.exe
1032 svchost.exe
1096 svchost.exe
1172 svchost.exe
1220 svchost.exe
1500 spoolsv.exe
148 svchost.exe
212 mDNSResponder.exe
280 InCDsrv.exe
388 jqs.exe
504 MDM.EXE
576 mnmsrvc.exe
700 Explorer.EXE
724 MSCamS32.exe
932 rundll32.exe
1076 opssvc.exe
1296 HPZipm12.exe
1372 EMLPROXY.EXE
1560 quhlpsvc.exe
1364 qhfw.exe
1600 RichVideo.exe
1892 scanwscs.exe
1948 svchost.exe
1972 tallylicserver.exe
2596 alg.exe
2620 wmiprvse.exe
2812 IEXPLORE.EXE
3472 EMLPROUI.EXE
3524 UPSCHD.EXE
3980 SCANMSG.EXE
3988 OnlineNT.EXE
3996 LVCOMSX.EXE
4016 igfxtray.exe
4032 igfxpers.exe
4044 hkcmd.exe
1548 Apoint.exe
524 AGRSMMSG.exe
1568 RocketDock.exe
1576 ctfmon.exe
1828 Apntex.exe
2496 wuauclt.exe
3000 drwtsn32.exe
*----> Module List <----*
(0000000000400000 - 000000000049c000: C:\Program Files\Internet Explorer\IEXPLORE.EXE
(0000000000a90000 - 0000000000a99000: C:\WINDOWS\system32\Normal
(0000000001370000 - 00000000013c5000: C:\WINDOWS\system32\NETAPI
(0000000016080000 - 00000000160a5000: C:\Program Files\Bonjour\mdnsNSP.dll
(000000003d930000 - 000000003da00000: C:\WINDOWS\system32\WININE
(000000003dfd0000 - 000000003e015000: C:\WINDOWS\system32\iertut
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\UXTHEM
(000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\comctl
(0000000066000000 - 0000000066086000: C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblin
(0000000066500000 - 000000006650a000: C:\WINDOWS\system32\wbsys.
(0000000066600000 - 0000000066617000: C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhel
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\System32\mswsoc
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HEL
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32
(0000000071bf0000 - 0000000071c03000: C:\WINDOWS\System32\SAMLIB
(0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanm
(0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP
(0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1
(0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfi
(0000000075a70000 - 0000000075a91000: C:\WINDOWS\system32\MSVFW3
(0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov
(0000000075f70000 - 0000000075f7a000: C:\WINDOWS\System32\davcln
(0000000076380000 - 0000000076385000: C:\WINDOWS\system32\msimg3
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.
(0000000076600000 - 000000007661d000: C:\WINDOWS\system32\cscdll
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\Iphlpa
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP3
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadh
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Micr
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphel
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSIO
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI
(0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4
(0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAP
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur3
(0000000078130000 - 0000000078257000: C:\WINDOWS\system32\urlmon
(000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel
(000000007c900000 - 000000007c9b2000: C:\WINDOWS\system32\ntdll.
(000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL3
(000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32
*----> State Dump for Thread Id 0xb00 <----*
eax=004031b9 ebx=7ffdf000 ecx=01c2f31c edx=01000000 esi=00000000 edi=000002bc
eip=7c810705 esp=0012fffc ebp=01c2f3d8 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000200
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel
function: kernel32!CreateThread
7c8106f2 fd std
7c8106f3 ffff ???
7c8106f5 5d pop ebp
7c8106f6 c21800 ret 0x18
7c8106f9 33ed xor ebp,ebp
7c8106fb 53 push ebx
7c8106fc 50 push eax
7c8106fd 6a00 push 0x0
7c8106ff e9eeafffff jmp kernel32!GetModuleFileName
7c810704 90 nop
7c810705 33ed xor ebp,ebp
7c810707 50 push eax
7c810708 6a00 push 0x0
7c81070a e945690000 jmp kernel32!RegisterWaitForIn
7c81070f 90 nop
7c810710 8bff mov edi,edi
kernel32!SwitchToFiber:
7c810712 648b1518000000 mov edx,fs:[00000018]
7c810719 8b4210 mov eax,[edx+0x10]
7c81071c 8bcc mov ecx,esp
7c81071e 8998b8000000 mov [eax+0xb8],ebx
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01c2f3d8 00000000 00000000 00000000 00000000 kernel32!CreateThread+0x2e
*----> Raw Stack Dump <----*
000000000012fffc 00 00 00 00 41 63 74 78 - 20 00 00 00 01 00 00 00 ....Actx .......
000000000013000c 98 24 00 00 c4 00 00 00 - 00 00 00 00 20 00 00 00 .$.......... ...
000000000013001c 00 00 00 00 14 00 00 00 - 01 00 00 00 06 00 00 00 ................
000000000013002c 34 00 00 00 14 01 00 00 - 01 00 00 00 00 00 00 00 4...............
000000000013003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000013004c 02 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000013005c 14 02 00 00 9c 01 00 00 - 00 00 00 00 5b 49 59 2d ............[IY-
000000000013006c b0 03 00 00 32 00 00 00 - e4 03 00 00 d2 02 00 00 ....2...........
000000000013007c 00 00 00 00 e4 02 02 83 - b8 06 00 00 46 00 00 00 ............F...
000000000013008c 00 07 00 00 ea 02 00 00 - 00 00 00 00 d2 d5 8c d1 ................
000000000013009c ec 09 00 00 46 00 00 00 - 34 0a 00 00 ea 02 00 00 ....F...4.......
00000000001300ac 00 00 00 00 2e ad 6a d8 - 20 0d 00 00 46 00 00 00 ......j. ...F...
00000000001300bc 68 0d 00 00 04 03 00 00 - 10 00 00 00 04 00 00 00 h...............
00000000001300cc d4 00 00 00 02 00 00 00 - 01 00 00 00 14 01 00 00 ................
00000000001300dc 8c 0f 00 00 01 00 00 00 - 02 00 00 00 a0 10 00 00 ................
00000000001300ec 2c 03 00 00 01 00 00 00 - 04 00 00 00 cc 13 00 00 ,...............
00000000001300fc 50 10 00 00 02 00 00 00 - 06 00 00 00 1c 24 00 00 P............$..
000000000013010c 7c 00 00 00 02 00 00 00 - 53 73 48 64 2c 00 00 00 |.......SsHd,...
000000000013011c 01 00 00 00 01 00 00 00 - 01 00 00 00 05 00 00 00 ................
000000000013012c 88 00 00 00 01 00 00 00 - 58 0f 00 00 2c 00 00 00 ........X...,...
*----> State Dump for Thread Id 0xb84 <----*
eax=77df848a ebx=00c9fed0 ecx=00000006 edx=00000000 esi=00000000 edi=7ffdf000
eip=7c90e514 esp=00c9fea8 ebp=00c9ff44 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.
function: ntdll!KiFastSystemCallRet
7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528)
7c90e4ff 8b0424 mov eax,[esp]
7c90e502 8be5 mov esp,ebp
7c90e504 5d pop ebp
7c90e505 c3 ret
7c90e506 8da42400000000 lea esp,[esp]
7c90e50d 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e510 8bd4 mov edx,esp
7c90e512 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e514 c3 ret
7c90e515 8da42400000000 lea esp,[esp]
7c90e51c 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e520 8d542408 lea edx,[esp+0x8]
7c90e524 cd2e int 2e
7c90e526 c3 ret
7c90e527 90 nop
ntdll!RtlRaiseException:
7c90e528 55 push ebp
7c90e529 8bec mov ebp,esp
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ADVAPI
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00c9ff44 77df8631 00000002 00c9ff6c 00000000 ntdll!KiFastSystemCallRet
00c9ffb4 7c80b729 00000000 7c9142af 00000000 ADVAPI32!WmiFreeBuffer+0x2
00c9ffec 00000000 77df848a 00000000 00000000 kernel32!GetModuleFileName
*----> Raw Stack Dump <----*
0000000000c9fea8 4a df 90 7c 90 95 80 7c - 02 00 00 00 d0 fe c9 00 J..|...|........
0000000000c9feb8 01 00 00 00 01 00 00 00 - 04 ff c9 00 e0 2e aa 00 ................
0000000000c9fec8 60 66 e4 77 00 10 00 00 - 60 00 00 00 6c 00 00 00 `f.w....`...l...
0000000000c9fed8 c0 fe c9 00 ff ff ff ff - dc ff c9 00 d8 9a 83 7c ...............|
0000000000c9fee8 50 0b 81 7c 00 10 00 00 - 14 00 00 00 01 00 00 00 P..|............
0000000000c9fef8 00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d ............../M
0000000000c9ff08 ff ff ff ff 00 10 00 00 - 00 f0 fd 7f 00 c0 fd 7f ................
0000000000c9ff18 dc ff c9 00 04 ff c9 00 - d0 fe c9 00 06 00 00 00 ................
0000000000c9ff28 02 00 00 00 c4 fe c9 00 - 06 00 00 00 dc ff c9 00 ................
0000000000c9ff38 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 b4 ff c9 00 ...|...|........
0000000000c9ff48 31 86 df 77 02 00 00 00 - 6c ff c9 00 00 00 00 00 1..w....l.......
0000000000c9ff58 e0 93 04 00 01 00 00 00 - af 42 91 7c 00 00 00 00 .........B.|....
0000000000c9ff68 00 00 00 00 60 00 00 00 - 6c 00 00 00 00 10 00 00 ....`...l.......
0000000000c9ff78 e0 2e aa 00 00 00 00 00 - 00 10 00 00 e8 3e aa 00 .............>..
0000000000c9ff88 00 67 e4 77 28 00 00 00 - e0 66 e4 77 00 10 00 00 .g.w(....f.w....
0000000000c9ff98 00 00 00 00 00 67 e4 77 - e0 2e aa 00 e0 66 e4 77 .....g.w.....f.w
0000000000c9ffa8 e5 03 00 00 00 10 00 00 - e8 3e aa 00 ec ff c9 00 .........>......
0000000000c9ffb8 29 b7 80 7c 00 00 00 00 - af 42 91 7c 00 00 00 00 )..|.....B.|....
0000000000c9ffc8 00 00 00 00 00 c0 fd 7f - 00 06 3c 87 c0 ff c9 00 ..........<.....
0000000000c9ffd8 d0 0f bd 86 ff ff ff ff - d8 9a 83 7c 30 b7 80 7c ...........|0..|
*----> State Dump for Thread Id 0xb88 <----*
eax=7ff60121 ebx=00000000 ecx=7c80becd edx=00daff73 esi=7c91650e edi=7ff6028e
eip=00000000 esp=00dafb7c ebp=00dafba8 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
*** ERROR: Module load completed but symbols could not be loaded for C:\Program Files\Internet Explorer\IEXPLORE.EXE
function: <nosymbols>
No prior disassembly possible
:
00000000 ?? ???
00000002 ?? ???
00000004 ?? ???
00000006 ?? ???
00000008 ?? ???
0000000a ?? ???
0000000c ?? ???
0000000e ?? ???
FAULT ->:
00000000 ?? ???
Error 0x00000001
00000002 ?? ???
00000004 ?? ???
00000006 ?? ???
00000008 ?? ???
0000000a ?? ???
0000000c ?? ???
0000000e ?? ???
00000010 ?? ???
00000012 ?? ???
00000014 ?? ???
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00dafb78 100052a3 7ff60121 00000051 1000ac08 0x0
00dafba8 10004ce7 00daff64 00daff84 00000051 0x100052a3
00daffb4 7c80b729 7ff60000 0b80001c 7c91650e 0x10004ce7
00daffec 00000000 100045a4 7ff60000 00000000 kernel32!GetModuleFileName
*----> Raw Stack Dump <----*
0000000000dafb7c a3 52 00 10 21 01 f6 7f - 51 00 00 00 08 ac 00 10 .R..!...Q.......
0000000000dafb8c 8e 02 f6 7f 0e 65 91 7c - 00 00 f6 7f b4 ff da 00 .....e.|........
0000000000dafb9c dc ff da 00 d8 9a 83 7c - d0 be 80 7c b4 ff da 00 .......|...|....
0000000000dafbac e7 4c 00 10 64 ff da 00 - 84 ff da 00 51 00 00 00 .L..d.......Q...
0000000000dafbbc 1c 00 80 0b 0e 65 91 7c - 00 00 f6 7f 00 00 00 00 .....e.|........
0000000000dafbcc 24 fc da 00 00 f0 fd 7f - 59 d1 4f 77 a4 fb da 00 $.......Y.Ow....
0000000000dafbdc 02 00 00 00 79 2d 28 00 - 28 24 ac 71 96 13 ab 71 ....y-(.($.q...q
0000000000dafbec f5 ff ff ff 02 00 00 00 - 79 f5 96 28 00 00 ab 71 ........y..(...q
0000000000dafbfc 02 00 00 00 04 00 00 00 - 00 00 00 00 24 fc da 00 ............$...
0000000000dafc0c 00 f0 fd 7f 00 00 41 7e - 10 01 00 00 43 3a 5c 57 ......A~....C:\W
0000000000dafc1c 49 4e 44 4f 57 53 5c 73 - 79 73 74 65 6d 33 32 5c INDOWS\system32\
0000000000dafc2c 61 76 69 63 61 70 33 32 - 2e 64 6c 6c 00 fc da 00 avicap32.dll....
0000000000dafc3c c4 b0 91 7c 54 fc da 00 - b7 b1 91 7c 00 b0 fd 7f ...|T......|....
0000000000dafc4c 00 f0 fd 7f 00 00 00 00 - 14 00 00 00 01 00 00 00 ................
0000000000dafc5c 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................
0000000000dafc6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000dafc7c 00 00 00 00 00 f0 fd 7f - 73 12 ab 71 a4 1e 28 00 ........s..q..(.
0000000000dafc8c 48 fc da 00 00 00 00 00 - 0c fd da 00 20 e9 90 7c H........... ..|
0000000000dafc9c 00 b1 91 7c ff ff ff ff - a4 b0 91 7c 9a de 90 7c ...|.......|...|
0000000000dafcac 2a b0 91 7c 30 fd da 00 - 0e 65 91 7c 00 00 f6 7f *..|0....e.|....
*----> State Dump for Thread Id 0xb94 <----*
eax=00faf9c0 ebx=00000000 ecx=7c91005d edx=00310000 esi=00faff8c edi=7e431211
eip=7c90e514 esp=00fafef4 ebp=00faff18 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528)
7c90e4ff 8b0424 mov eax,[esp]
7c90e502 8be5 mov esp,ebp
7c90e504 5d pop ebp
7c90e505 c3 ret
7c90e506 8da42400000000 lea esp,[esp]
7c90e50d 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e510 8bd4 mov edx,esp
7c90e512 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e514 c3 ret
7c90e515 8da42400000000 lea esp,[esp]
7c90e51c 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e520 8d542408 lea edx,[esp+0x8]
7c90e524 cd2e int 2e
7c90e526 c3 ret
7c90e527 90 nop
ntdll!RtlRaiseException:
7c90e528 55 push ebp
7c90e529 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00faff18 10009b15 00faff8c 00000000 00000000 ntdll!KiFastSystemCallRet
00faffb4 7c80b729 00000000 00000000 00dc0000 0x10009b15
00faffec 00000000 100099e7 00000000 00000000 kernel32!GetModuleFileName
*----> Raw Stack Dump <----*
0000000000fafef4 be 91 41 7e 6b 77 42 7e - 8c ff fa 00 00 00 00 00 ..A~kwB~........
0000000000faff04 00 00 00 00 00 00 00 00 - 00 00 00 00 11 12 43 7e ..............C~
0000000000faff14 cc 9b 00 10 b4 ff fa 00 - 15 9b 00 10 8c ff fa 00 ................
0000000000faff24 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000faff34 00 00 dc 00 00 00 00 00 - 30 00 00 00 00 00 00 00 ........0.......
0000000000faff44 3d 99 00 10 00 00 00 00 - 00 00 00 00 00 00 40 00 =.............@.
0000000000faff54 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000faff64 18 1c 00 10 00 00 00 00 - 1e dc 4f 80 e7 22 6d 80 ..........O.."m.
0000000000faff74 a8 1d 89 86 50 ed 46 aa - 00 00 00 00 00 00 00 00 ....P.F.........
0000000000faff84 01 00 00 00 00 00 00 00 - a0 4d a0 86 42 08 50 80 .........M..B.P.
0000000000faff94 00 00 00 00 00 00 00 00 - 00 00 00 00 80 0c 50 80 ..............P.
0000000000faffa4 9c ec 46 aa 98 0b 00 00 - bc 00 00 00 00 00 40 00 ..F...........@.
0000000000faffb4 ec ff fa 00 29 b7 80 7c - 00 00 00 00 00 00 00 00 ....)..|........
0000000000faffc4 00 00 dc 00 00 00 00 00 - 00 d0 fd 7f 00 06 3c 87 ..............<.
0000000000faffd4 c0 ff fa 00 d8 e7 91 86 - ff ff ff ff d8 9a 83 7c ...............|
0000000000faffe4 30 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 0..|............
0000000000fafff4 e7 99 00 10 00 00 00 00 - 00 00 00 00 c8 00 00 00 ................
0000000000fb0004 4e 01 00 00 ff ee ff ee - 02 10 00 00 00 00 00 00 N...............
0000000000fb0014 00 fe 00 00 00 00 10 00 - 00 20 00 00 00 02 00 00 ......... ......
0000000000fb0024 00 20 00 00 2f 02 00 00 - ff ef fd 7f 0a 00 08 06 . ../...........
*----> State Dump for Thread Id 0xb9c <----*
eax=00000000 ebx=00000000 ecx=0122fee8 edx=76b60200 esi=00000001 edi=00faf140
eip=7c90e514 esp=0122ff08 ebp=0122ffb4 iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
function: ntdll!KiFastSystemCallRet
7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528)
7c90e4ff 8b0424 mov eax,[esp]
7c90e502 8be5 mov esp,ebp
7c90e504 5d pop ebp
7c90e505 c3 ret
7c90e506 8da42400000000 lea esp,[esp]
7c90e50d 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e510 8bd4 mov edx,esp
7c90e512 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e514 c3 ret
7c90e515 8da42400000000 lea esp,[esp]
7c90e51c 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e520 8d542408 lea edx,[esp+0x8]
7c90e524 cd2e int 2e
7c90e526 c3 ret
7c90e527 90 nop
ntdll!RtlRaiseException:
7c90e528 55 push ebp
7c90e529 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0122ffb4 7c80b729 00000000 00faf140 76b42f44 ntdll!KiFastSystemCallRet
0122ffec 00000000 76b5aeaf 00000000 00000000 kernel32!GetModuleFileName
*----> Raw Stack Dump <----*
000000000122ff08 4a df 90 7c e9 ae b5 76 - 02 00 00 00 6c ff 22 01 J..|...v....l.".
000000000122ff18 01 00 00 00 01 00 00 00 - 00 00 00 00 44 2f b4 76 ............D/.v
000000000122ff28 a8 ad bb 86 10 00 00 00 - 00 00 00 00 f2 a3 63 80 ..............c.
000000000122ff38 a0 4d a0 86 a8 ad bb 86 - 00 90 fd 7f 84 ec 46 aa .M............F.
000000000122ff48 98 0c 50 80 00 00 00 00 - 05 00 00 00 00 00 00 00 ..P.............
000000000122ff58 00 00 00 00 00 00 00 00 - 62 db 4f 80 00 00 00 00 ........b.O.....
000000000122ff68 00 00 00 00 d4 00 00 00 - e0 00 00 00 a8 ad bb 86 ................
000000000122ff78 50 ed 46 aa f0 be 22 87 - 00 00 00 00 01 ec 46 aa P.F...".......F.
000000000122ff88 00 00 00 00 a0 4d a0 86 - 42 08 50 80 00 00 00 00 .....M..B.P.....
000000000122ff98 00 00 00 00 00 00 00 00 - 80 0c 50 80 9c ec 46 aa ..........P...F.
000000000122ffa8 35 2c 6d 80 00 00 00 00 - 02 00 00 00 ec ff 22 01 5,m...........".
000000000122ffb8 29 b7 80 7c 00 00 00 00 - 40 f1 fa 00 44 2f b4 76 )..|....@...D/.v
000000000122ffc8 00 00 00 00 00 90 fd 7f - 00 06 3c 87 c0 ff 22 01 ..........<...".
000000000122ffd8 58 ad bb 86 ff ff ff ff - d8 9a 83 7c 30 b7 80 7c X..........|0..|
000000000122ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 af ae b5 76 ...............v
000000000122fff8 00 00 00 00 00 00 00 00 - c8 00 00 00 cf 01 00 00 ................
0000000001230008 ff ee ff ee 02 10 00 00 - 00 00 00 00 00 fe 00 00 ................
0000000001230018 00 00 10 00 00 20 00 00 - 00 02 00 00 00 20 00 00 ..... ....... ..
0000000001230028 2f 02 00 00 ff ef fd 7f - 08 00 08 06 00 00 00 00 /...............
0000000001230038 00 00 00 00 00 00 00 00 - 00 00 00 00 98 05 23 01
UNQUOTE
Please help
The iexplore.exe error is not often an indicative that there is something wrong with IE, a lurking nasties in the system also causes that same error.
The other 2 jpeg captures you posted are evidence of a rootkit/downloader present in the system.
So I don't know why someone would tell you that the error is caused by the IE version.
Weren't you able to run Combofix, if you run Combofix plese show us the log.
Business Accounts
Answer for Membership
by: Milan_OjhPosted on 2009-08-06 at 05:29:10ID: 25032439
Have a view of this link:
change.com /Security/ Win_Securi ty/ Q_21976 549.html
http://www.experts-ex