Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

VxD Errors


  • Please log in to reply

#1
ashish

ashish

    Member

  • Member
  • PipPip
  • 39 posts
I recently downloaded and installed Pc-Cillin Antivirus but after installing it the following error has started showing up frequently. Mainly this error shows up when i m starting or working with Pc-cillin.

ERROR :
An exception OE has occured at0028:C001A1AA in VxD NDIS (01) + 00002636. This was called from 0028:C001C3D4 in VxD NDIS (01) + 00004860.

It may be possible to continue normally.
Press any key to continue...........


Now i have uninstalled Pc-cillin but could u tell me what was the problem and how it could be solved.

Also can u sugest me a small and powerful Antivirus software that would be low on usage of system resources.

And one thing more after i uninstalled Pc-cillin i installed a new antivirus program called solo Antivirus from download.com where it was among largest downloaded antivirus software. I updated it and scanned when it revealed a virus named "Shredder???" and deleted it . It was located in system folder of windows. I couldn't get the exact name of virus coz the Antivirus program doesn't has the function of viewing virus database nor it keeps record of any scan.

Logfile of HijackThis v1.97.7
Scan saved at 12:21:37 AM, on 7/21/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\SAVE\SAVE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\SRN MICRO\SOLOSENT.EXE
C:\PROGRAM FILES\SRN MICRO\SOLOCFG.EXE
C:\PROGRAM FILES\ELITECORE\CYBEROAM CLIENT FOR 24ONLINE\CYBEROAMCLIENT.EXE
C:\PROGRAM FILES\OPERA7\OPERA.EXE
D:\VIMP SOFTWARES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [SoloSentry] C:\PROGRA~1\SRNMIC~1\SOLOSENT.EXE
O4 - HKLM\..\Run: [SoloSchedule] C:\PROGRA~1\SRNMIC~1\SOLOCFG.EXE
O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRAM FILES\NOVOSOFT\HANDY BACKUP\hbagent.exe -logon
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRAM FILES\FLASHGET\jc_link.htm

Edited by ashish, 20 July 2004 - 12:55 PM.

  • 0

Advertisements


#2
admin

admin

    Founder Geek

  • Administrator
  • 24,501 posts
Reboot in safe mode (by tapping F8 at startup and select safe mode from the menu).
Be sure you're able to view hidden files, and remove the following files in bold (if found):
C:\PROGRAM FILES\SAVE <- this folder
C:\WINDOWS\SYSTEM\DDHELP.EXE

Reboot your PC.

If you would please, rescan with HijackThis and post a fresh log, and let us know how your system's working. <_<

P.S. We recommend the free version of AVG anti-virus software:
http://www.grisoft.c...s_dwnl_free.php
  • 0

#3
ashish

ashish

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
I rebooted in Safe mode and with all hidden files viewable but did not find the SAVE folder in program files. And i found ddhelp.exe but couldn't delete it coz windows returned the error that it is been used by windows.
And the error as i have mentioned also appeared in safe mode. I think that whenever any drive or folder is open the error occurs, i mean mostly the error occurs when any folder is open.
i have uninstalled Pc-cillin.

Logfile of HijackThis v1.97.7
Scan saved at 12:05:23 AM, on 7/22/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ELITECORE\CYBEROAM CLIENT FOR 24ONLINE\CYBEROAMCLIENT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\OPERA7\OPERA.EXE
D:\VIMP SOFTWARES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRAM FILES\NOVOSOFT\HANDY BACKUP\hbagent.exe -logon
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRAM FILES\FLASHGET\jc_link.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
  • 0

#4
Smokey

Smokey

    Member 1K

  • Retired Staff
  • 1,423 posts
Please go offline, close all browsers and any open Windows, making sure that only HijackThis is open. Scan and when it finishes, put an X in the boxes, only next to these following items, then click fix checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Reboot your PC.

If you would please, rescan with HijackThis and post a fresh log, and let us know how your system's working. <_<
  • 0

#5
ashish

ashish

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
OK i have fixed the items u said and i m posting new hijack log.

But i want to tell u that the problem i mentioned u was a blue screen problem which was solved after i uninstalled pccillin. But now the problem i m discussing is about illegal operation in mostly some dll files like kernel32.dll/context.dll/etc.

When i fixed the problems with hijackthis and rebooted i tried to copy a file from d to c drive when again the following error showed up.

EXPLORER executed an invalid instruction in
module CONTEXT.DLL at 017f:02acf9d8.
Registers:
EAX=024d0fe2 CS=017f EIP=02acf9d8 EFLGS=00010283
EBX=0136ed06 SS=0187 ESP=0136eb34 EBP=0136eb48
ECX=024d0fe7 DS=0187 ESI=0136ec84 FS=226f
EDX=0136eb94 ES=0187 EDI=00000000 GS=0000
Bytes at CS:EIP:
ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
Stack dump:
bfb742fa 00000330 0000001c 00000000 fffe512d 0136eb64 bfb742de 024d0fe2 00000330 0000001c 00000000 fffe512d 0136ebc0 bfb741ff 00000330 0000001c

So this is my problem.
the above error shows frequently and randomly with random modules.

Sometime following error shows without any reason.

EXPLORER caused an invalid page fault in
module <unknown> at 0000:01adf9d8.
Registers:
EAX=01670fe2 CS=017f EIP=01adf9d8 EFLGS=00010283
EBX=0059f70c SS=0187 ESP=0059f538 EBP=0059f54c
ECX=01670fe7 DS=0187 ESI=0059f688 FS=2fff
EDX=0059f598 ES=0187 EDI=00000000 GS=0000
Bytes at CS:EIP:

Stack dump:
bfb742fa 00000ed4 0000001c 00000001 00000000 0059f568 bfb742de 01670fe2 00000ed4 0000001c 00000001 00000000 0059f5c4 bfb741ff 00000ed4 0000001c

And most frequently following error shows up.

EXPLORER caused an invalid page fault in
module KERNEL32.DLL at 017f:bff9db61.
Registers:
EAX=c00309c4 CS=017f EIP=bff9db61 EFLGS=00010212
EBX=010eff88 SS=0187 ESP=010aff7c EBP=010b0218
ECX=00000000 DS=0187 ESI=010b0368 FS=20f7
EDX=bff76855 ES=0187 EDI=010eff74 GS=0000
Bytes at CS:EIP:
53 8b 15 e4 9c fc bf 56 89 4d e4 57 89 4d dc 89
Stack dump:


I hope i m not confusing u.

Pls help i m fed up of these errors.



Logfile of HijackThis v1.97.7
Scan saved at 12:05:57 AM, on 7/23/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\OPERA7\OPERA.EXE
C:\PROGRAM FILES\ELITECORE\CYBEROAM CLIENT FOR 24ONLINE\CYBEROAMCLIENT.EXE
D:\VIMP SOFTWARES\HIJACKTHIS\HIJACKTHIS.EXE

O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRAM FILES\NOVOSOFT\HANDY BACKUP\hbagent.exe -logon
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRAM FILES\FLASHGET\jc_link.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

Edited by ashish, 22 July 2004 - 12:45 PM.

  • 0

#6
admin

admin

    Founder Geek

  • Administrator
  • 24,501 posts
Try using the System File Checker to repair the explorer errors:
http://support.micro...kb;EN-US;185836
  • 0

#7
ashish

ashish

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
I scanned with system file checker and no file was corrupted or lost.

So what now?

Logfile of HijackThis v1.97.7
Scan saved at 11:17:34 PM, on 7/25/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ELITECORE\CYBEROAM CLIENT FOR 24ONLINE\CYBEROAMCLIENT.EXE
C:\PROGRAM FILES\OPERA7\OPERA.EXE
D:\VIMP SOFTWARES\HIJACKTHIS\HIJACKTHIS.EXE

O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRAM FILES\NOVOSOFT\HANDY BACKUP\hbagent.exe -logon
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRAM FILES\FLASHGET\jc_link.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP