Hi and Thanks soooo much for getting back to me sooo quickly!! and for the tip for some reason I didn't think of backing up!
I'm not sure how to start explorer from the Task Manager, can you guide me please?
The exact error codes are:
________________________________________________________
"PROGRAM ERROR"
! "explorer.exe has generated errors and will be closed by Windows.
You will need to restart the program.
An error log is being created.
"CANCEL" comes up first and then after about 1 minute "OK" comes up.
Then after I click "OK" the next error appears immediately:
"explorer.exe - Application Error"
The instruction at "0x77fcd79a" referenced memort at "0x00000000". The memory could not be "written".
Click on OK to terminate the program
"OK"
________________________________________________________
Last night I did another scan in safe mode using yet another scanner and rescanning using the same tools and the error still appears and it found something called:
HK../Microsoft/Windows/Current.... "BazookaBar" - listing it as "Dangerous"
But I couldn't seem to find where to go to delete that file as the scanner i used was unregistered...
Does this info help??
________________________________________________________
I copied the following error log for you from the Dr Watson file in the System Information Registry area I hope it helps!
Application exception occurred:
App: (pid=768)
When: 10/19/2005 @ 08:58:36.012
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: HEATHERJAMES
User Name: Heather James
Number of Processors: 1
Processor Type: x86 Family 6 Model 4 Stepping 2
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 1
Current Type: Uniprocessor Free
Registered Organization: Heather James
Registered Owner: Heather James
*----> Task List <----*
0 Idle.exe
8 System.exe
140 smss.exe
164 csrss.exe
160 winlogon.exe
212 services.exe
224 lsass.exe
384 svchost.exe
412 SPOOLSV.exe
444 svchost.exe
480 regsvc.exe
500 mstask.exe
664 explorer.exe
692 msiexec.exe
764 internat.exe
720 ntvdm.exe
768 tvicon.exe
424 drwtsn32.exe
0 _Total.exe
(00400000 - 00421000)
(77F80000 - 77FFA000)
(77E80000 - 77F35000)
(77E10000 - 77E74000)
(77F40000 - 77F7C000)
(77800000 - 7781D000)
(77D40000 - 77DB0000)
(77DB0000 - 77E0A000)
(69800000 - 69A42000)
(77C70000 - 77CBA000)
(77B50000 - 77BD9000)
(77A50000 - 77B45000)
(779B0000 - 77A45000)
(6E420000 - 6E426000)
(75E60000 - 75E7A000)
(691D0000 - 69255000)
(78000000 - 78046000)
State Dump for Thread Id 0x28c
eax=00000001 ebx=00bd0e10 ecx=00000001 edx=00000000 esi=00000000 edi=0012fe98
eip=00401ae4 esp=0012fda8 ebp=0012fef4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202
function: <nosymbols>
00401aba 50 push eax
00401abb ff15ec434100 call dword ptr [004143ec] ds:004143ec=77a546b8
00401ac1 8d85c4feffff lea eax,[ebp+0xfffffec4] ss:0012fdb8=00000094
00401ac7 c785c4feffff94000000 ss:0012fdb8=00000094
mov dword ptr [ebp+0xfffffec4],0x94
00401ad1 50 push eax
00401ad2 ff151c414100 call dword ptr [0041411c] ds:0041411c=77e87c14
00401ad8 83bdd4feffff01 ss:0012fdc8=00000002
cmp dword ptr [ebp+0xfffffed4],0x1
00401adf 7408 jz 0040a5e9
00401ae1 8b36 mov esi,[esi] ds:00000000=????????
00401ae3 56 push esi
FAULT ->00401ae4 8b06 mov eax,[esi] ds:00000000=????????
00401ae6 ff5058 call dword ptr [eax+0x58] ds:00a8d5d7=????????
00401ae9 6a0b push 0xb
00401aeb 8d45d4 lea eax,[ebp+0xd4] ss:00bbd4ca=????????
00401aee 59 pop ecx
00401aef be28924100 mov esi,0x419228
00401af4 50 push eax
00401af5 8d7da4 lea edi,[ebp+0xa4] ss:00bbd4ca=????????
00401af8 8d45a4 lea eax,[ebp+0xa4] ss:00bbd4ca=????????
00401afb f3a5 rep movsd ds:00000000=???????? es:0012fe98=00000058
00401afd 50 push eax
00401afe ff15e8434100 call dword ptr [004143e8] ds:004143e8=77a5a2a8
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0012FEF4 00402DDA 0041AA48 00BD0E10 0012FFB0 0041383D !<nosymbols>
0012FF10 004107FE 00000000 00000000 7FFDF000 0040B086 !<nosymbols>
0012FFC0 77E992A6 00000000 029ADC38 7FFDF000 C0000005 !<nosymbols>
0012FFF0 00000000 00404021 00000000 000000C8 00000100 kernel32!GetCommandLineW
*----> Raw Stack Dump <----*
0012fda8 00 00 00 00 48 aa 41 00 - 48 aa 41 00 ff ff ff ff ....H.A.H.A.....
0012fdb8 94 00 00 00 05 00 00 00 - 00 00 00 00 93 08 00 00 ................
0012fdc8 02 00 00 00 53 65 72 76 - 69 63 65 20 50 61 63 6b ....Service Pack
0012fdd8 20 31 00 00 30 6e bc 00 - 96 fb 06 0e 00 58 69 cd 1..0n.......Xi.
0012fde8 83 02 00 00 9a d7 28 d1 - 00 76 69 63 6f 6e 2e 49 ......(..vicon.I
0012fdf8 48 82 bc 00 38 af d6 24 - 78 01 bc 00 30 6e bc 00 H...8..$x...0n..
0012fe08 38 6e bc 00 18 14 00 00 - 03 00 00 00 00 e0 fd 7f 8n..............
0012fe18 00 e0 fd 7f 9c fe 12 00 - 45 90 fb 77 70 1f f8 77 ........E..wp..w
0012fe28 ff ff ff ff a8 fe 12 00 - 88 42 40 00 00 00 bc 00 .........B@.....
0012fe38 00 00 00 00 10 14 00 00 - 04 14 00 00 e0 c4 41 00 ..............A.
0012fe48 21 42 40 00 47 00 65 00 - 6e 00 65 00 72 00 61 00 !B@.G.e.n.e.r.a.
0012fe58 6c 00 44 00 65 00 76 00 - 69 00 63 00 65 00 43 00 l.D.e.v.i.c.e.C.
0012fe68 74 00 72 00 6c 00 43 00 - 6d 00 70 00 6e 00 74 00 t.r.l.C.m.p.n.t.
0012fe78 2e 00 47 00 65 00 6e 00 - 65 00 72 00 61 00 6c 00 ..G.e.n.e.r.a.l.
0012fe88 44 00 65 00 76 00 43 00 - 74 00 72 00 6c 00 00 00 D.e.v.C.t.r.l...
0012fe98 58 00 00 00 58 00 00 00 - ff ff ff ff ff ff ff fd X...X...........
0012fea8 60 00 00 00 a0 6a 40 00 - 98 cb 41 00 10 ff 12 00 `....j@...A.....
0012feb8 61 42 40 00 09 00 00 00 - 90 1e bc 00 10 0e bd 00 aB@.............
0012fec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fed8 00 00 00 80 00 00 00 80 - 00 00 00 80 00 00 00 80 ................
________________________________________________________
THIS IS WHAT I AM RUNNING ON START UP.
System Information report written at: 31/01/2006 08:55:09 PM
[Startup Programs]
Program Command User Name Location
Spyware Doctor "c:\program files\spyware doctor\swdoctor.exe" /q HEATHERJAMES\Heather James HKU\S-1-5-21-220523388-1935655697-1060284298-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
internat.exe internat.exe .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Spyware Doctor "c:\program files\spyware doctor\swdoctor.exe" /q .DEFAULT HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adobe Gamma Loader c:\progra~1\common~1\adobe\calibr~1\adobeg~1.exe All Users Common Startup
NvCplDaemon rundll32.exe c:\winnt\system32\nvcpl.dll,nvstartup All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
nwiz nwiz.exe /install All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NvMediaCenter rundll32.exe c:\winnt\system32\nvmctray.dll,nvtaskbarinit All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D066UUtility c:\winnt\twain_32\d66u\d066uuty.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
REGSHAVE c:\program files\regshave\regshave.exe /autorun All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager mobsync.exe /logon All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NeroCheck c:\winnt\system32\nerocheck.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
InCD c:\program files\ahead\incd\incd.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
iTunesHelper "c:\program files\itunes\ituneshelper.exe" All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
QuickTime Task "c:\program files\quicktime\qttask.exe" -atboottime All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MPFExe c:\progra~1\mcafee.com\person~1\mpftray.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MCAgentExe c:\progra~1\mcafee.com\agent\mcagent.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MCUpdateExe c:\progra~1\mcafee.com\agent\mcupdate.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
VSOCheckTask "c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" /checktask All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
VirusScan Online c:\program files\mcafee.com\vso\mcvsshld.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
OASClnt c:\program files\mcafee.com\vso\oasclnt.exe All Users HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
I REALLY APPRECIATE YOUR HELP!!!