Forum Home
Press F1
 
Thread ID: 103753 2009-10-05 06:15:00 Runtime Error ollieogg (6593) Press F1
Post ID Timestamp Content User
817099 2009-10-05 06:15:00 Hi there,

I have this aggravating message show up when I start my computer. All I can do is drag it down to the bottom of the screen. Here is the message that I get.

Microsoft Visual C++ Runtime Library

program: C:\Windows\Explorer.exe

This Application has requested the Runtime to terminate it in an
unusual way.
Please contact the application's support team for more information.


I have downloaded and run Hijack this, but it may as well be a foreign language. I don't understand the half of it.

Please someone help?

Regards Katy :confused:

P.S.

I don't like Internet Explorer, I use Google Chrome as my browser. Its quicker than even Firefox :)

Here is the log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:50:33 p.m., on 5/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\BOINC\boinc.exe
C:\ProgramData\BOINC\projects\www.worldcommunitygr id.org\wcg_faah_autodock_6.07_windows_intelx86
C:\ProgramData\BOINC\projects\www.worldcommunitygr id.org\wcg_hfcc_autodock_6.10_windows_intelx86
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Black Beauty\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\s wg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ avast! ] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [boincmgr] "C:\Program Files\BOINC\boincmgr.exe" /a /s
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Users\Black Beauty\AppData\Roaming\Mozilla\Firefox\Profiles\su rxs33u.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Users\Black Beauty\AppData\Roaming\Mozilla\Firefox\Profiles\su rxs33u.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - platformdl.adobe.com
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: Acer TV Share Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer TV Share\Kernel\DMSTV\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Update Service (gupdate1c9e3d5fa5e394c) (gupdate1c9e3d5fa5e394c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\Windows\system32\wwSecure.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9271 bytes
ollieogg (6593)
817100 2009-10-05 06:31:00 You can tick these then tick fix checked

Close browsers

Disable windows defender

Uninstall this, it looks like it can crash IE

O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

Do you need this ?

O4 - HKLM\..\Run: [boincmgr] "C:\Program Files\BOINC\boincmgr.exe" /a /s

Has this been uninstalled?

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

I would uninstall adaware and a-squared. Use malwarebytes instead
Speedy Gonzales (78)
817101 2009-10-05 08:40:00 Thank you soo much! I am heading off to do just as you suggested.

Regards Katy:punk
ollieogg (6593)
817102 2009-10-05 09:40:00 No probs :) Umm, since Avast is installed, right mouse on the a in the taskbar / program settings. Click on troubleshooting, tick the 2nd option. Then OK. Sometimes, programs that boot on startup, conflict with Avast, when it starts. This option will tell Avast to delay its services, till everything else loads. Did it show the name of the program thats crashing on startup? Speedy Gonzales (78)
817103 2009-10-05 10:17:00 I did everything as you suggested and still the message appears. No programme name appears with the message. Avast is now doing a scan on boot and by the looks of it its going to take a while. I might just let it run and turn the screen off for tonight. Luckily I have a laptop I can work on in the meantime. Any other ideas? (using a hammer is tempting)

Cheers Katy:badpc:
ollieogg (6593)
817104 2009-10-05 10:32:00 mm, one other thing you can try is see what it says in event viewer. Click on the orb / run type eventvwr. Look under windows logs on the left (click on the arrow. Look under application for any errors (about the time the error comes up). Tell us what it says Speedy Gonzales (78)
817105 2009-10-05 11:40:00 Ok here goes .....
Information 6/10/2009 12:25:45 a.m. gusvc 0 None
Information 6/10/2009 12:24:46 a.m. SecurityCenter 1 None
Information 6/10/2009 12:24:45 a.m. gusvc 0 None
Information 6/10/2009 12:23:21 a.m. CertificateServicesClient 1 None
Information 6/10/2009 12:23:22 a.m. Search 1003 Search service
Information 6/10/2009 12:23:13 a.m. CertificateServicesClient 1 None
Information 6/10/2009 12:23:12 a.m. NVRAIDSERVICE 1024 None
Information 6/10/2009 12:23:04 a.m. gupdate1c9e3d5fa5e394c 0 None
Information 6/10/2009 12:22:44 a.m. WMI 5617 None
Information 6/10/2009 12:22:39 a.m. Service1 0 None
Information 6/10/2009 12:22:37 a.m. ESENT 102 General
Information 6/10/2009 12:22:33 a.m. WMI 5615 None
Information 6/10/2009 12:22:33 a.m. RichVideo 0 None
Information 6/10/2009 12:22:32 a.m. LightScribeService 4 None
Information 6/10/2009 12:22:31 a.m. gupdate1c9e3d5fa5e394c 0 None
Information 6/10/2009 12:22:29 a.m. AcerMemUsageCheckService 0 None
Information 6/10/2009 12:22:21 a.m. Security-Licensing-SLC 902 None
Information 6/10/2009 12:22:21 a.m. Security-Licensing-SLC 1005 None
Information 6/10/2009 12:22:21 a.m. Security-Licensing-SLC 1003 None
Information 6/10/2009 12:22:21 a.m. Security-Licensing-SLC 1033 None
Information 6/10/2009 12:21:58 a.m. Winlogon 6000 None
Information 6/10/2009 12:21:58 a.m. Winlogon 4101 None
Information 6/10/2009 12:21:55 a.m. EventSystem 4625 None
Information 6/10/2009 12:21:55 a.m. Security-Licensing-SLC 900 None
Information 6/10/2009 12:21:54 a.m. User Profile Service 1531 None

Hope this means something.

Regards Katy
ollieogg (6593)
817106 2009-10-05 11:50:00 Umm which one/s had a warning / or error beside it? Reboot then go back to event viewer. Go through application / system. Look for the time now (if that message comes up again) Speedy Gonzales (78)
817107 2009-10-06 00:33:00 These were the only errors I could find . All the rest were just "information"

Regards Katy


Error 6/10/2009 8:35:29 a . m . ACPI 4 None
AMLI: ACPI BIOS is attempting to read from an illegal IO port address (0x71), which lies in the 0x70 - 0x71 protected address range . This could lead to system instability . Please contact your system vendor for technical assistance




Error 6/10/2009 8:35:29 a . m . ACPI 4 None
AMLI: ACPI BIOS is attempting to write to an illegal IO port address (0x70), which lies in the 0x70 - 0x71 protected address range . This could lead to system instability . Please contact your system vendor for technical assistance .

Error 6/10/2009 8:37:28 a . m . Service Control Manager Eventlog Provider 7023 None
The Offline Files service terminated with the following error:
The system cannot find the path specified .

AMLI: ACPI BIOS is attempting to write to an illegal IO port address (0x70), which lies in the 0x70 - 0x71 protected address range . This could lead to system instability . Please contact your system vendor for technical assistance .
ollieogg (6593)
817108 2009-10-06 01:17:00 Dont think thats the cause of the error. But it looks like you need to update the BIOS. Only other way, I could see where or what it is, is if I login to your system remotely, with teamviewer. You'll see what I'm doing Speedy Gonzales (78)
1 2 3