> The computer generates an error message window each time one tries to launch Windows Explorer or the internet Explorer
Would you please tell us which error message it generates?
Main Topics
Browse All TopicsI believe my nephew's computers a Dell 8200 P4 has a virus. The computer generates an error message window each time one tries to launch Windows Explorer or the internet Explorer. I can get everything to work by booting the machine in safe mode. The operating system is XP Home. It has Norton Anti-virus 2003 on it. Norton virus scan with the latest update failed to find any viruses.
I had given up on fixing the problem and was in the process of copying my nephew's data files to my main computer. In the course of transferring the files to my computer my McAfee antivirus software identified a virus in the transfered files. The identification was vbs\psyme. We removed the contaminated files from my nephew's computer but this has not fixed the problem. This included the step of turning off auto-recovery of files in XP configuration. I have rerun Norton Antivirus; it found no problems. But, the computer still does nothing but send an error message when any program relies on explorer components is called.
Any help would be appreciated.
Regards,
Jerald
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
The error message is as follows:
A nice rectangle with a blue top margin appears with a title "Internet Explorer". Below this is a white band with the statement that "Internet Explorer has encountered a problem and needs to close. We are sorry......"
Clicking on error details tab yields:
Error Signature
AppName iexplore.exe Appver 6.0.2800.1106 Modname tps 108.dll
Modver 0.3.1.9 Offset 000104d6
If I were to open Windows Explorer, I get the same error box but with AppName explore.exe
Is this any help?
Thanks for your attention.
An update---After attempting to close all the open windows from generating the previous error messages for this board, the following message window popped up:
http://watson.microsoft.co
DOWS'. Make sure you typed the name correctly & then try again. To search for a file click the Start button & then click search.
Thank you all for responding. I have run the hijackThis program and have pasted in the file.
Here it is:
Logfile of HijackThis v1.97.7
Scan saved at 5:49:43 PM, on 1/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\devldr
C:\PROGRA~1\WinZip\winzip3
C:\DOCUME~1\ADMINI~1\LOCAL
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
O2 - BHO: (no name) - {0000026A-8230-4DD4-BE4F-6
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {22941A26-7033-432C-94C7-6
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: (no name) - {D5C778F1-CF13-4E70-ADF0-4
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Prog
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\b
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearSharePro\BearSha
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPO
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Verizon Online\VisualIPInsight\IPC
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Verizon Online\VisualIPInsight\IPM
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EX
O4 - HKLM\..\Run: [MoviePlace] "C:\Program Files\MoviePlace\MoviePlac
O4 - HKLM\..\Run: [Sentry] C:\WINDOWS\Sentry.exe
O4 - HKLM\..\Run: [SearchEnhancement] "C:\Program Files\scbar\v1\scbar.exe" /U
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navap
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATC
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJ
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IME
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PI
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TI
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TI
O4 - HKLM\..\Run: [mcappins.exe] "D:\Vsc\Enu\mcappins.exe" vsocfg.ini
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTR
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickD
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digi
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT4
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\m
O9 - Extra button: Control Pad (HKLM)
O9 - Extra 'Tools' menuitem: Control Pad (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O16 - DPF: ConferenceRoom Java Client - http://painaid.painfoundat
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/u
O16 - DPF: {02C20140-76F8-4763-83D5-B
O16 - DPF: {1000026A-8230-4DD4-BE4F-6
O16 - DPF: {2B323CD9-50E3-11D3-9466-0
O16 - DPF: {30528230-99F7-4BB4-88D8-F
O16 - DPF: {343DF0E4-8DF2-4280-953A-B
O16 - DPF: {3C98538E-6A9A-11D3-A8FB-F
O16 - DPF: {3E68E405-C6DE-49FF-83AE-4
O16 - DPF: {41F17733-B041-4099-A042-B
O16 - DPF: {597C45C2-2D39-11D5-8D53-0
O16 - DPF: {5EF06782-55B2-4DF3-A57A-3
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O16 - DPF: {A17E30C4-A9BA-11D4-8673-6
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
O16 - DPF: {C606BA60-AB76-48B6-96A7-2
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-0
O16 - DPF: {EB6AFDAB-E16D-430B-A5EE-0
O16 - DPF: {ED71FA11-AA35-11D2-BE5C-3
O16 - DPF: {EE8CEFA4-1F91-11D4-B31E-0
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
only this looks bad
R1 - HKLM\Software\Microsoft\In
Also did you run virus scanners and Cwshredder ?
I stupidly ran the HijackThis in Safe Mode when everything functions okay.
I have rerun the program when it is malfunctioning. The log in that case is as follows.
Logfile of HijackThis v1.97.7
Scan saved at 6:20:51 PM, on 1/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcC
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\nvsvc3
C:\PROGRA~1\COMMON~1\SYMAN
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\devldr
C:\Program Files\MUSICMATCH\MUSICMATC
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell\Support\Alert\b
C:\PROGRA~1\VERIZO~1\SUPPO
C:\Program Files\Verizon Online\VisualIPInsight\IPC
C:\Program Files\Verizon Online\VisualIPInsight\IPM
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Sentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\MUSICMATCH\MUSICMATC
C:\WINDOWS\System32\ctfmon
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickD
C:\Program Files\Hewlett-Packard\Digi
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digi
C:\Program Files\Microsoft Office\Office\1033\OLFSNT4
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Verizon Online\SupportCenter\bin\m
C:\Program Files\Hewlett-Packard\Digi
C:\Documents and Settings\Big Daddy\Desktop\HijackThis.e
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
O2 - BHO: (no name) - {0000026A-8230-4DD4-BE4F-6
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {22941A26-7033-432C-94C7-6
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: (no name) - {D5C778F1-CF13-4E70-ADF0-4
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Prog
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\b
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearSharePro\BearSha
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPO
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Verizon Online\VisualIPInsight\IPC
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Verizon Online\VisualIPInsight\IPM
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EX
O4 - HKLM\..\Run: [MoviePlace] "C:\Program Files\MoviePlace\MoviePlac
O4 - HKLM\..\Run: [Sentry] C:\WINDOWS\Sentry.exe
O4 - HKLM\..\Run: [SearchEnhancement] "C:\Program Files\scbar\v1\scbar.exe" /U
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navap
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATC
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJ
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IME
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PI
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TI
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TI
O4 - HKLM\..\Run: [mcappins.exe] "D:\Vsc\Enu\mcappins.exe" vsocfg.ini
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickD
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digi
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT4
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\m
O9 - Extra button: Control Pad (HKLM)
O9 - Extra 'Tools' menuitem: Control Pad (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O16 - DPF: ConferenceRoom Java Client - http://painaid.painfoundat
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/u
O16 - DPF: {02C20140-76F8-4763-83D5-B
O16 - DPF: {1000026A-8230-4DD4-BE4F-6
O16 - DPF: {2B323CD9-50E3-11D3-9466-0
O16 - DPF: {30528230-99F7-4BB4-88D8-F
O16 - DPF: {343DF0E4-8DF2-4280-953A-B
O16 - DPF: {3C98538E-6A9A-11D3-A8FB-F
O16 - DPF: {3E68E405-C6DE-49FF-83AE-4
O16 - DPF: {41F17733-B041-4099-A042-B
O16 - DPF: {597C45C2-2D39-11D5-8D53-0
O16 - DPF: {5EF06782-55B2-4DF3-A57A-3
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O16 - DPF: {A17E30C4-A9BA-11D4-8673-6
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
O16 - DPF: {C606BA60-AB76-48B6-96A7-2
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-0
O16 - DPF: {EB6AFDAB-E16D-430B-A5EE-0
O16 - DPF: {ED71FA11-AA35-11D2-BE5C-3
O16 - DPF: {EE8CEFA4-1F91-11D4-B31E-0
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
O2 - BHO: (no name) - {22941A26-7033-432C-94C7-6
O4 - HKLM\..\Run: [SearchEnhancement] "C:\Program Files\scbar\v1\scbar.exe" /U
R1 - HKLM\Software\Microsoft\In
I would download spybot and run it.
http://www.webattack.com/d
along with CWS.
Business Accounts
Answer for Membership
by: sunray_2003Posted on 2004-01-19 at 12:18:01ID: 10149652
Spyware/Adware removal tools:
--------------------------
What is spyware : http://www.spychecker.com/
SpyBot-S&D : http://www.webattack.com/d
Ad-aware : http://www.webattack.com/d
Trojan Remover :http://www.simplysup.com/
HijackThis : http://www.webattack.com/d
KL-Detector :http://www.webattack.com/
X-Cleaner Free :http://www.webattack.com/
SpywareBlaster :http://www.webattack.com/
SpywareGuard :http://www.webattack.com/
SpySites :http://www.webattack.com/
Keylogger Hunter :http://www.webattack.com/
Spycop: http://www.spycop.com/
BHODemon : http://www.spywareinfo.com
Browser Hijack Blaster : http://www.wilderssecurity
Goodbye Spy http://www.topshareware.co
CWShredder: http://www.spywareinfo.com
Other spyware removal instructions: http://www.pchell.com/supp
online virus scanner:
---------------------
http://housecall.trendmicr
http://security.symantec.c
http://www.pandasoftware.c
http://www.pcpitstop.com/a