1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Second Request on "Creating New Folder"

Discussion in 'Earlier Versions of Windows' started by ktrexler, Sep 20, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. ktrexler

    ktrexler Thread Starter

    Joined:
    Jul 13, 2002
    Messages:
    122
    When I right-click desktop to create a NEW folder, I get the error message:

    This program has performed an illegal operation and will shut down. If the problem persist, contact program vendor.

    EXPLORER caused an invalid page fault in
    module SHDOC401.DLL at 0167:5001f4f8.
    Registers:
    EAX=0043cbe4 CS=0167 EIP=5001f4f8 EFLGS=00010206
    EBX=00000000 SS=016f ESP=0059ea20 EBP=00590065
    ECX=816c8974 DS=016f ESI=bff772fc FS=5fcf
    EDX=00430000 ES=016f EDI=80000000 GS=2a46
    Bytes at CS:EIP:
    89 45 f8 74 67 6a 43 8b f8 59 8d 85 b8 fc ff ff
    Stack dump:
    00439830 000005d4 00007800 00000000 00000000 00025ce8 8ac81600 8aac0059 8a4e0000 0000448f 00470000 05180518 ffff0000 5ce85f30 8a700002 00040654

    It seems the other features on the right click menu work (i.e.; "Rearrange icons" and "Properties" are working. Has anyone else had this problem and do you know how to fix this? Could it be something in my registry was changed somehow..........????

    Thanks,
    Elaine
    (This is my second requestÂ…..thanks....ps, can't find anything on googe relating to this but I could be I'm not asking the question properly.)
     
  2. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
  3. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
  4. steamwiz

    steamwiz

    Joined:
    Oct 4, 2002
    Messages:
    2,773
    Do you have "hotbar" installed by any chance
     
  5. ktrexler

    ktrexler Thread Starter

    Joined:
    Jul 13, 2002
    Messages:
    122
    I did re-install ie AFTER the problems started, AcaCandy. I will try the two links you sent me.

    Steamwiz.....as far as I know, I don't have a hot bar installed. How would I check this.

    And, like Arnold........"I'll be back"......(after I try the links).

    Thanks,
    Elaine
     
  6. steamwiz

    steamwiz

    Joined:
    Oct 4, 2002
    Messages:
    2,773
    You would know if you had "hotbar" - it sometimes places a key in the registry which causes the exact problem you are having

    So that we can have a better idea of what could be causing this

    Please Download hijackthis

    http://tomcoyote.org/hjt

    Unzip, doubleclick HijackThis.exe, and hit "Scan".

    After the scan has finished the "scan" button will turn into a "save log" button

    save the log file and paste it here
     
  7. ktrexler

    ktrexler Thread Starter

    Joined:
    Jul 13, 2002
    Messages:
    122
    OK Steamwiz.......here 'tis. Thanks, Elaine

    Logfile of HijackThis v1.97.2
    Scan saved at 9:36:43 PM, on 9/22/03
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\SXGDSENU.EXE
    C:\MOUSE\SYSTEM\EM_EXEC.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\HP PSC 900 SERIES\BIN\HPOBRT07.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\SHARED\BIN\HPOEVM07.EXE
    C:\WINDOWS\SYSTEM\HPOIPM07.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\SHARED\BIN\HPOSTS07.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\SHARED\BIN\HPOFXM07.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\REGPROT\REGPROT.EXE
    C:\UNZIPPED\HIJACKTHIS[1]\HIJACKTHIS.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchv.com/1/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/1/search.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.passthison.com/r4/?vu083...02228333933989000222833393398900022283339.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/1/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/1/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/1/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchv.com/1/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/1/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/1/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/1/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/1/search.php?qq=%s
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [SXGDSENU] SXGDSENU.exe
    O4 - HKLM\..\Run: [EM_EXEC] c:\MOUSE\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
    O4 - HKLM\..\Run: [RegProt] c:\regprot\regprot.exe /start
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: @Home (HKCU)
    O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\NPSWF32.dll
    O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
    O12 - Plugin for .avi: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npavi32.dll
    O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.charter.com/sdccommon/download/tgctlcm.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4285/mcfscan.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir8d196a.cab
    O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37865.5865393519
     
  8. steamwiz

    steamwiz

    Joined:
    Oct 4, 2002
    Messages:
    2,773
  9. ktrexler

    ktrexler Thread Starter

    Joined:
    Jul 13, 2002
    Messages:
    122
    Here is CWS log: (Thanks, Elaine)

    CWShredder v1.15.1 scan only report

    Windows 98 (4.10.1998 )
    Windows dir: C:\WINDOWS
    Windows system dir: C:\WINDOWS\system

    Infected Registry value:
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar
    Infected data: http://www.searchv.com/1/search.html
    Infected Registry value:
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page
    Infected data: http://www.searchv.com/1/search.html
    Infected Registry value:
    HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant
    Infected data: http://www.searchv.com/1/search.html
    Infected Registry value:
    HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch
    Infected data: http://www.searchv.com/1/search.html
    Infected Registry value:
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page,about:blank
    Infected data: http://www.searchv.com/1/
    Infected Registry value:
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar
    Infected data: http://www.searchv.com/1/search.html
    Infected Registry value:
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page
    Infected data: http://www.searchv.com/1/search.html
    Infected Registry value:
    HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch,http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    Infected data: http://www.searchv.com/1/search.html
    Infected Registry value:
    HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant,http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    Infected data: http://www.searchv.com/1/search.html
    Found Hosts file: C:\WINDOWS\hosts (124 bytes, A)
    Found Win.ini file: C:\WINDOWS\win.ini (14885 bytes, A)

    - END OF REPORT -
     
  10. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
    Hi Elaine, I think what the guys want to see is a new hijack log......
     
  11. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/166224

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice