[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Explorer.EXE-Application Error

Posted on 2006-04-22
15
Medium Priority
?
1,099 Views
Last Modified: 2008-01-09
When I start my system it loads up like normal but then pops up

The Application failed to initializew properly (0xc000005) Click Ok to terminate application.

I click ok and then nothing loads. Not my desktop or anything so I have to reboot to safe mode and work that way so far. So far I have tried Ewido and done a full scan fixing all errors.

Here is my Hijack this logfile which I can only run in safe mode so I dont know if it will help at all.

Logfile of HijackThis v1.99.1
Scan saved at 3:03:23 PM, on 4/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\BRYANC~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comicavalanche.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVK Mail Checker] "C:\Program Files\Boomerang Software\Guardian Worm Killer & AntiVirus\AVKPOP.EXE"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4FA3D392-9349-4D85-8FB9-18733534CFE3} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/gdownloader.ocx
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {97BB6657-DC7F-4489-9067-51FAB9D8857E} (CWebLaunchCtl Object) - http://esupport.cf1live.com/esupport/static/weblaunch/weblaunch2.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vturq - C:\WINDOWS\system32\vturq.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
0
Comment
Question by:bracymarlyle
  • 7
  • 4
  • 2
  • +2
15 Comments
 
LVL 37

Expert Comment

by:Harisha M G
ID: 16517666
Hi, remove these Nasty, Possibly Nasty, Unknown and Unnecessary entries:

http://hijackthis.de/logfiles/8d7d37778b8ed01802bbcf476f6521bc.html

---
Harish
0
 

Author Comment

by:bracymarlyle
ID: 16517706
Ok done but still same problem though however.
0
 
LVL 32

Accepted Solution

by:
r-k earned 500 total points
ID: 16517722
Try "sfc /scannow" at a command prompt. You may need your XP install CD handy for this. See http://support.microsoft.com/default.aspx?scid=kb;en-us;310747 for details.

If that fails, do a repair install using the XP CD, see:

 http://www.michaelstevenstech.com/XPrepairinstall.htm
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 

Author Comment

by:bracymarlyle
ID: 16517763
Tried to run sfc commands from prompt and recieved this

Windows file protection could not initiate a scan of protected system files
The specified error code is 0x000006ba [The RPC server is unavailable]

My problem right now is I can't find my Dell box to just reinstall windows. My box had the restore disc sleeve with key!
0
 
LVL 27

Expert Comment

by:Jonvee
ID: 16517843
This MS KB article may help even though written for Win 2000.  It states >
"This behavior can occur if the certificate for VeriSign time stamping has been removed from the computer ..."      
http://support.microsoft.com/?kbid=296241
0
 

Author Comment

by:bracymarlyle
ID: 16517866
Did all that and no difference. Just same error as before when trying scannow
0
 
LVL 70

Expert Comment

by:Merete
ID: 16518012
hijack this does not detect viruses.
Lets see if if we can get you back to windows . I would say you have a virus or trojan.
In safemode disable your system restore r/click my computer properties system restore, this will delete all your restore points where trojans like to hide. then re-enable it.
run a disc cleanup to delete all old files including internet cookies history from start all programs accessories system tools.
empty your recycle bin.
Delete all old emails.
Run your task manager and lok for any sus programs running, hopefully you have a knowledge of what shoul dbe running.

No desktop task bar fix:
A virus called F-Nimda can cause this.
Info here...
ftp://ftp.f-secure.com/anti-virus/tools/shellfix.txt 
Download the fix...
ftp://ftp.f-secure.com/anti-virus/tools/shellfix.reg
or
ftp://ftp.f-secure.com/anti-virus/tools/shellfix.zip 
==================================
Troubleshooting Windows Explorer Errors
http://www.helpwithwindows.com/techfiles/explorer-crashes.html
=========================================
scan your computer in safemode download these:
http://www.softpedia.com/get/Antivirus/McAfee-AVERT-Stinger.shtml
Stinger is a stand-alone utility used to detect and remove specific viruses. It is not a substitute for full anti-virus protection, but rather a tool to assist administrators and users when dealing with an infected system. Stinger utilizes next generation scan engine technology, including process scanning, digitally signed DAT files, and scan performance optimizations.
------------
If you are not a Trend Micro customer please download the following file.
Sysclean Package  3.1MB  http://www.trendmicro.com/ftp/products/tsc/sysclean.com
 MD5 checksum: ff4ce112cae7005f6046f81d372c8cd7 *SysClean.com
 NOTE:
For instructions on how to use this package, consult the "How to Use" section of the readme file, readme_sysclean.txt. http://www.trendmicro.com/ftp/products/tsc/readme.txt
This file also contains the description and the different features of this package.
Note that for the Trend Micro Sysclean Package to be effective, you must download and place the latest pattern file in the same folder as the Trend Micro Sysclean Package.
----------------------------------------------------------------------------------------------
see if this helps As you cannot access windows to get online scanning online would be helpful.
If can get inot your windows use these asap
http://housecall.trendmicro.com/  scan now
http://us.mcafee.com/root/mfs/default.asp?affid=294

Merete
0
 
LVL 32

Expert Comment

by:r-k
ID: 16518084
Also check this Registry entry in safe mode using Regedit:

 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

Look for the value of "Shell" it should be just "explorer.exe" and nothing else. Change it to explorer.exe if it is anything else.
0
 
LVL 27

Expert Comment

by:Jonvee
ID: 16519273
This previous EE thread may also be useful >
"Explorer.exe application error":

http://www.experts-exchange.com/Operating_Systems/Q_21180292.html
0
 

Author Comment

by:bracymarlyle
ID: 16520375
OK I checked regedit and it was right. I did disc cleanup and email and all that good stuff. I did a full system scann also and no change yet. I can still only open up in safe mode.
0
 

Author Comment

by:bracymarlyle
ID: 16520382
Oh I also still get this when I try to run sfc commands from prompt so I havent been able to do this yet

Windows file protection could not initiate a scan of protected system files
The specified error code is 0x000006ba [The RPC server is unavailable]
0
 
LVL 27

Expert Comment

by:Jonvee
ID: 16520436
When investigating, i found this url.  If you scroll to the entry on Mar 29 2006, 02:00 AM by "Keith", the comments *may* just help:

http://www.geekstogo.com/forum/index.php?showtopic=101560
0
 

Author Comment

by:bracymarlyle
ID: 16520459
Computer name has always stayed the same although I have no clue what the "out of box experience" even is :)
0
 
LVL 27

Expert Comment

by:Jonvee
ID: 16520494
  > "out of box experience" <
Probably explained better here than i could  :)

http://support.microsoft.com/?kbid=311781
0
 

Author Comment

by:bracymarlyle
ID: 16521524
I ended up using restore cd to fix problems. All seems fine now other than needing to reset outlook about.
Thanks!
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are 2 things you must have in order to connect to the internet behind a router, The "Gateway IP" of the router, which is usually something like 192.168.xxx.1, I've seen routers with default values of: 192.168.0.1, 192.168.1.1, 192.168.11.1, …
Step by step guide to Clean and Sort your windows registry! Introduction: Always remember: A Clean registry = Better performance = Save your invaluable time In this article we're going to clear our registry manually! Yes, manually! The e…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
Suggested Courses

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question