1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Explorer error default

Discussion in 'Earlier Versions of Windows' started by cumberland03, Jan 27, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. cumberland03

    cumberland03 Thread Starter

    Joined:
    Jan 27, 2003
    Messages:
    33
    I would like to see if anyone could help me on my problem that I am having with my computer. I am running windows 98 and i keep getting all these pop ups on my computer. I was thinking that could be from the xupiterstartup2003..but i have deleted that and its still doing it. Also everytime i try to open something up from the desktop I recieve a message that says Explorer error kernal32.dll 017F.bff7429f I am really unsure what to do. It locks my computer up everytime. Please help me!:confused:
     
  2. steamwiz

    steamwiz

    Joined:
    Oct 4, 2002
    Messages:
    2,773
    Hi cumberland03

    Before you go deleting anything else we had better have a look at your startup

    Please post your startup list by doing the following :-

    Please go here and download startuplist 1.51 :-

    http://www.lurkhere.com/~nicefiles/

    Download to any folder or your desktop
    Unzip the zipfile
    Double click the exe file
    go to Edit - select all - copy - and paste the results in a new post here


    steam
     
  3. cumberland03

    cumberland03 Thread Starter

    Joined:
    Jan 27, 2003
    Messages:
    33
    StartupList report, 1/27/03, 7:47:30 PM
    StartupList version: 1.51
    Started from : C:\UNZIPPED\STARTUPLIST151\STARTUPLIST.EXE
    Detected: Windows 98 SE (Win9x 4.10.2222A)
    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ATICWD32.EXE
    C:\WINDOWS\SYSTEM\ATITASK.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\LVCOMS.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
    C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
    C:\PROGRAM FILES\AIM95\AIM.EXE
    C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\RNATHCHK.EXE
    C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\UNZIPPED\STARTUPLIST151\STARTUPLIST.EXE

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\WINDOWS\Start Menu\Programs\StartUp]
    America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
    Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    Wal-Mart Connect Tray Icon.lnk = C:\wmconnect\wmtray.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    SystemTray = SysTray.Exe
    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    AtiCwd32 = Aticwd32.exe
    AtiKey = Atitask.exe
    SoundFusion = RunDll32 cwcprops.cpl,CrystalControlWnd
    LoadQM = loadqm.exe
    DXM6Patch_981116 = C:\WINDOWS\p_981116.exe /Q:A
    LVComs = c:\windows\SYSTEM\LVComS.exe
    StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
    Mirabilis ICQ = C:\Program Files\ICQ\NDetect.exe
    TkBellExe = C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
    MMTray = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    SQUpdatesChecker = C:\Program Files\Sqwire\uc.exe
    SQConfigChecker = C:\Program Files\Sqwire\cc.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    SchedulingAgent = mstask.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    AIM = C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
    Yahoo! Pager = C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet
    msnmsgr = "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background

    --------------------------------------------------

    C:\WINDOWS\WININIT.BAK listing:
    (Created 26/1/2003, 19:13:28)

    [Rename]
    NUL=C:\PROGRA~1\YAHOO!\MESSEN~1\YHEXBM~1.DLL

    --------------------------------------------------

    C:\AUTOEXEC.BAT listing:

    c:\windows\cwcdata\cwcdos.exe

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    NAV Helper - c:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
    Yahoo! Companion BHO - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5,0,2,0.DLL - {13F537F0-AF09-11d6-9029-0002B31F9E59}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Tune-up Application Start.job
    Symantec NetDetect.job
    Norton AntiVirus - Scan my computer.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [YInstStarter Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
    CODEBASE = http://download.yahoo.com/dl/installs/yinst.cab

    [Yahoo! Audio Conferencing]
    InProcServer32 = C:\PROGRAM FILES\YAHOO!\MESSENGER\YACSCOM.DLL
    CODEBASE = http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\SWFLASH.OCX
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    [Windows Media Player]
    InProcServer32 = C:\WINDOWS\SYSTEM\MSDXM.OCX
    CODEBASE = http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab

    [RdxIE Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\RDXIE.DLL
    CODEBASE = http://207.188.7.150/17d171f8cfd455cbb020/netzip/RdxIE6.cab

    [Macromedia Authorware Web Player Control]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\AUTHORWA\AWSWAX.OCX
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab

    [Update Class]
    InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
    CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37644.6283333333

    [Loader Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\SQLOADER.DLL
    CODEBASE = http://www.search-feed.com/bigbar/SQLoader.cab

    --------------------------------------------------
    End of report, 5,729 bytes
    Report generated in 1.645 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  4. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    These two startups are Xupiter allright:

    SQUpdatesChecker = C:\Program Files\Sqwire\uc.exe
    SQConfigChecker = C:\Program Files\Sqwire\cc.exe

    And you have the activeX object as well.

    Do this:

    Download Spybot - Search & Destroy

    It looks for spyware, but also targets dialers, keyloggers, and other nasties, and it's freeware.
    It ought to deal with all versions of Xupiter without a prob.

    After installing, press Online, and search for, put a check mark at, and install all updates.

    Next, go to the Settings tab > File Sets, and uncheck 'System Internals' and 'Tracks' .
    These aren't needed for our present purpose, and you can always experiment with them later on.

    Finally, after closing down Internet Explorer, hit 'Check for Problems', and have SpyBot remove all it finds.

    NOTE: SSD will sometimes not be able to remove all active components in the first 'run'.
    In that case you will get a dialog asking you to run SSD at next start.
    Click yes and reboot.
    Subsequently SSD will come up before the system puts these components 'in use', and it will then be able to 'fix' the rest.

    Good luck,
     
  5. cumberland03

    cumberland03 Thread Starter

    Joined:
    Jan 27, 2003
    Messages:
    33
    i have ran the spybot program and that has corrected most of the pop ups that I get. But everytime i click on my computer, or any of the icons on my desktop the same default error occurs with the explorer. I just to exit out of it but it locks my computer up completly. Does anyone have any ideas about this problem.

    Thanks so much for the help so far.

    Cumberland03
     
  6. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    Yes. It's a problem often associated with Xupiter.

    Would you do this please:

    Go to http://www.spywareinfo.com/downloads.php#det , and download 'Hijack This!'.
    Unzip, doubleclick HijackThis.exe, and hit "Scan".

    When the scan is finished, the "Scan" button will change into a "Save Log" button.
    Press that, save the log somewhere, and please show us its contents.
     
  7. steamwiz

    steamwiz

    Joined:
    Oct 4, 2002
    Messages:
    2,773
  8. cumberland03

    cumberland03 Thread Starter

    Joined:
    Jan 27, 2003
    Messages:
    33
    hi.. I went to that site but i didnt see anything about the hijacker thingy..but i downloaded the spyware scanner and it detected 2 things i really hope you can help me out im a college student and i work with this computer a lot.

    THe huntbar was one of the things it brought up and then it brought up netzip.

    cumberland3
     
  9. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
  10. steamwiz

    steamwiz

    Joined:
    Oct 4, 2002
    Messages:
    2,773
  11. cumberland03

    cumberland03 Thread Starter

    Joined:
    Jan 27, 2003
    Messages:
    33
    it will not let me attach the log on here..i have it saved but when i attach it on here it says its an unvalid attachment.

    cumberland03
     
  12. cumberland03

    cumberland03 Thread Starter

    Joined:
    Jan 27, 2003
    Messages:
    33
    nevermind here it is sorry

    Logfile of HijackThis v1.91.2
    Scan saved at 12:29:43 PM, on 1/28/03
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL=http://www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL=http://www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://www.google.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.cumberlandcollege.edu/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL=about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=about:blank
    R3 - URLSearchHook: XTSearchHook Class - {6E6DD93E-1FC3-4F43-8AFB-1B7B90C9D3EB} - C:\PROGRAM FILES\SQWIRE\S.DLL (file missing)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5,0,2,0.DLL
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiKey] Atitask.exe
    O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [Mirabilis ICQ] C:\Program Files\ICQ\NDetect.exe
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [SQUpdatesChecker] C:\Program Files\Sqwire\uc.exe
    O4 - HKLM\..\Run: [SQConfigChecker] C:\Program Files\Sqwire\cc.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet
    O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
    O4 - Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
    O4 - Startup: Spyware Scanner.lnk = C:\Program Files\Aluria Software\Spyware Scanner\asescanner.exe
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: Wal-Mart Connect Tray Icon.lnk = C:\wmconnect\wmtray.exe
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: ICQ (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ (HKLM)
    O12 - Plugin for .swf: C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\PLUGINS\npswf32.dll
    O15 - Trusted Zone: http://free.aol.com
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
    O16 - DPF: ConferenceRoom Java Client - http://chat.webmaster.com/java-new/cr.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/17d171f8cfd455cbb020/netzip/RdxIE6.cab
    O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37644.6283333333
    O16 - DPF: {3C5BA506-6C30-4738-9CED-797ACADEA8DC} (Loader Class) - http://www.search-feed.com/bigbar/SQLoader.cab
     
  13. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    Well, there certainly is some Xupiter stuff there, as well as a few other things that need to be removed.

    Run Hijack This, and check ALL of the items in bold. Doublecheck so as to be sure not to miss a single one.
    Next, shut down all Internet Explorer Windows, and have HT fix all checked.
    Reboot when you're done.

    R3 - URLSearchHook: XTSearchHook Class - {6E6DD93E-1FC3-4F43-8AFB-1B7B90C9D3EB} - C:\PROGRAM FILES\SQWIRE\S.DLL (file missing)

    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [SQUpdatesChecker] C:\Program Files\Sqwire\uc.exe
    O4 - HKLM\..\Run: [SQConfigChecker] C:\Program Files\Sqwire\cc.exe

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/17d171f8cfd455...tzip/RdxIE6.cab
    O16 - DPF: {3C5BA506-6C30-4738-9CED-797ACADEA8DC} (Loader Class) - http://www.search-feed.com/bigbar/SQLoader.cab


    Cheers,
     
  14. cumberland03

    cumberland03 Thread Starter

    Joined:
    Jan 27, 2003
    Messages:
    33
    ok I did all of that and restarted my computer. Now what do i need to do.

    Cumberland03
     
  15. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    That depends. Are you still having this problem??
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - Explorer error default
  1. 3dmama
    Replies:
    14
    Views:
    840
  2. wolftechlinnk
    Replies:
    1
    Views:
    762
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/115615

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice