PDA

View Full Version : explorer error in unknown


jimmyboy831
January 3rd, 2004, 02:26 AM
When I start up my computer I get this error massage

Explorer has caused an error in <unknown>
explorer will now close.

If you continue to experience problems
try restarting your computer.

I click close and the computer shuts down and open again but desk top goes in recovery desk top and a lot of my icon on the lower right task bar are gone. The computer works well after that until I start the computer again. I have downloaded a program called endit all and I use this when I first startup the computer before I get the error massage . Endit all closes the programs running in the background and this stops the error massage but it also closes some programs that I need.Please HELP!!!!!!!!!!!

gors100
January 3rd, 2004, 07:47 PM
When I start up my computer I get this error massage

Explorer has caused an error in <unknown>
explorer will now close.

If you continue to experience problems
try restarting your computer.

I click close and the computer shuts down and open again but desk top goes in recovery desk top and a lot of my icon on the lower right task bar are gone. The computer works well after that until I start the computer again. I have downloaded a program called endit all and I use this when I first startup the computer before I get the error massage . Endit all closes the programs running in the background and this stops the error massage but it also closes some programs that I need.Please HELP!!!!!!!!!!!
Hi, if you want to look and see what startup programmes you can delete yourself take a look here (www.pacs-portal.co.uk/startup_index.htm).
Be aware not all programmes show up using msconfig, it may be worth downloading HijackThis (www.merijn.org/files/hijackthis.zip) and have someone here have a look. When you run HijackThis do not fix anything, paste the log back to this thread and someone will advise

jimmyboy831
January 4th, 2004, 01:04 AM
Logfile of HijackThis v1.97.7
Scan saved at 8:05:31 PM, on 03/01/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\MESSENGER PLUS! 2\MSGPLUS.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\LAUNCHER\CTLAUNCHER.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\PROGRAM\CTAVTRAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\CTNOTIFY.EXE
C:\PROGRAM FILES\VISIONEER ONETOUCH\ONETOUCHMON.EXE
C:\PROGRAM FILES\COMMON FILES\ADAPTEC SHARED\CREATECD\CREATECD50.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.EXE
C:\WINDOWS\ptsnoop.exe
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\SCANSOFT\PAPERPORT\PPWEBCAP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\LAUNCHER\TASKGUIDE\UPDTRAY.E XE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.sympatico.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca/homepage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico
N1 - Netscape 4: user_pref("browser.startup.homepage", "www1.sympatico.ca"); (C:\Program Files\Sympatico\Users\james.koichopolos@sympatico. ca\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Creative Launcher] C:\PROGRAM FILES\CREATIVE\SBLIVE\LAUNCHER\CTLAUNCHER.EXE
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CTAVTray] C:\PROGRAM FILES\CREATIVE\SBLIVE\PROGRAM\CTAvTray.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRAM FILES\SCANSOFT\PAPERPORT\PPWebCap.exe
O4 - HKLM\..\RunOnce: [CTAVTray] C:\Program Files\Creative\SBLive\Program\CTAvStub.EXE EAX.AVI
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: PowerReg SchedulerV2.exe
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sympatico.ca/homepage.html
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37914.8553356482
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB

This is after a reboot and before the error massage is posted does anyone see something that doen't belong?

AnnMarie
January 4th, 2004, 03:54 AM
Hi jimmyboy831 - your log looks fine. It wouldnt hurt to run an online scan for viruses though (not all show in a log). Go here (http://www.ravantivirus.com/scan/) and run the online scanner. RAV will generate a log. If any malware is found, copy the log and post it back in this thread.

If your scan is clean, try a clean boot to see if you can identify the problem. It's a bit tedious but can be very effective. See here (http://support.microsoft.com/default.aspx?kbid=267288) for instructions on how to do this.

renegade600
January 4th, 2004, 04:12 AM
did you install, delete, upgrade, update, uninstall any hardware or software right before the problem.

If no viruses are found, then I suggest you restoring your computer to a previously saved restore point before the problem started.

jimmyboy831
January 4th, 2004, 04:56 AM
Scan started at 03/01/2004 11:43:36 PM

Scanning memory...
c:\WINDOWS\Temporary Internet Files\Content.IE5\7P0KSNVB\exitpop[1].htm->(SCRIPT0001) - JS/Noclose* -> Infected
c:\WINDOWS\Temporary Internet Files\Content.IE5\69WVQLM5\exitpop[1].htm->(SCRIPT0001) - JS/Noclose* -> Infected
c:\WINDOWS\Temporary Internet Files\Content.IE5\O9SPERWD\exitpop[1].htm->(SCRIPT0001) - JS/Noclose* -> Infected

Scanned
============================
Objects: 25520
Directories: 1434
Archives: 737
Size(Kb): 594558
Infected files: 3

Found
============================
Viruses found: 1
Suspicious files: 0
Disinfected files: 0
Mail files: 100
Hi this is the scan I received from rev antivirus it shows 3 infected files and 1 virus found .What should I do?
Thanks for the site Anne Marie.

AnnMarie
January 4th, 2004, 05:10 AM
You are welcome jimmyboy831 :)

OK, close IE and go to Internet Options in Control Panel. Click on the General Tab and delete all Temporary Internet Files (and offline content too). When you have done this, run another scan and post back the new log.

jimmyboy831
January 4th, 2004, 05:42 AM
Scan started at 04/01/2004 12:30:04 AM

Scanning memory...

Scanned
============================
Objects: 17251
Directories: 1429
Archives: 718
Size(Kb): 429501
Infected files: 0

Found
============================
Viruses found: 0
Suspicious files: 0
Disinfected files: 0
Mail files: 89

Thanks again AnnMarie (sorry about the spelling last time ) as you can see you have done it again there are no infected files and no virus. After I post this I am going to log off and reboot my computer to see if my original problem is gone now.

jimmyboy831
January 4th, 2004, 07:20 AM
I am back. After my reboot I was still having error massages so I tried AnnMarie second suggestion. I when to start,run and typed msconfig Under general tab I selected selective start up, then under the start up tab I check the clean box and then selected *StateMgr only and restarted my computer. After a reboot I open start,run typed msconfig and then to the start up tab, when it open I saw that 2 box were checked besides the *StateMgr so now three boxes were checked ( the other 2 were named CountrySelection and PTSnoop ) under command CountrySelection was PCYPTT.EXE and PTSnoop was PTSNOOP.EXE so I ran a search on these two in the search for files and folders and found three file named Pctel,inc.Mdmchipv from C:\windows\inf\other type setup, next was PTVCD.VXD from C:\windows\system type vitual device driver and last was PTDLL16.DELL from C:\windows type app. extension. So I deleted them and reboot my computer, after the reboot open start,run typed msconfig and whent to startup tab and both of the check boxes are gone (two other boxes with the same name are still in the list but they don't get check automaticly on start up) and for now it looks like my original problem is gone :D

I would I like to say THANK-YOU again to AnnMarie her work is invaluable!!!!!!!!!!!

gatekeeper
September 24th, 2004, 07:46 PM
try to delete this file C:\WINDOWS\SYSTEM\MSDXM.OCX


Good Luck :rotflmao:

AnnMarie
September 24th, 2004, 11:28 PM
Why would you delete that file gatekeeper? It's the Windows Media Player ActiveX Control.