  1. I've encountered this problem since a while ago and it's very persistent. I've ran Adaware and spybot S&D but the problem never cleaned.

    Here's the error message.

    "A potential problem has been detected and Windows has been shutdown buggy application to prevent damage to your computer.

    ****WXYZ.SYS - Address F73120AE base at C00000, DateStamp 36b072A3

    Kernel Debugger Using: COM2 (Port0x28f, Baud rat 192000)"


    During a scan of files at system startup, potential errors in the system registry were found.

    p-07-0100 irql: 1f SYSVER 0xff0024

    NT_Kernel error 1256


    Desktop appeared 2 new icons and it will return back even I've deleted for times.

    Icon1 : "Windows Update" with target location of -> ""

    Icon2 : "Help and Support Center" with target of -> ""

    This problem will open my ie automatically from time to time and it's very irritating.

    I heard that combofix and vundofix can find this spyware but cannot fix the problem too.

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 8:39:44 PM, on 2/15/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16574)

    Boot mode: Safe mode

    Running processes:









    C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC



    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

    O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"

    O4 - HKLM\..\Run: [0c12089e] rundll32.exe "C:\WINDOWS\system32\ytievfvj.dll",b

    O4 - HKLM\..\Run: [LexPPS.exe] C:\WINDOWS\system32\lexpps.exe

    O4 - HKLM\..\RunOnce: [spybotDeletingA9206] command /c del "C:\WINDOWS\system32\windows"

    O4 - HKLM\..\RunOnce: [spybotDeletingC1941] cmd /c del "C:\WINDOWS\system32\windows"

    O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKCU\..\RunOnce: [spybotDeletingB9076] command /c del "C:\WINDOWS\system32\windows"

    O4 - HKCU\..\RunOnce: [spybotDeletingD8114] cmd /c del "C:\WINDOWS\system32\windows"

    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

    O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm

    O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder\Program\geturl.htm

    O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder\Program\getallurl.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll

    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe

    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O15 - ESC Trusted Zone: http://*

    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -

    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe


    End of file - 6370 bytes

    Can anyone please enlighten my problem please? Thanks in advance.

  2. Hi everyone,

    Recently, The svchost.exe error keeps pop out. I have no idea on how this'll happen actually.

    Svchost.exe - Application Error

    The exception unknown software exception (0xc0000409) occurred in the application at location 0x5b86a3c0.

    > Ok > Cancel

    Click Ok, my theme change into Window Classic theme immediately.

    Click Cancel, nothing happen it seems but my theme change into Window Classic theme after some time.

    I was told to do a hijackthis scan for this.

    Logfile of HijackThis v1.99.1

    Scan saved at 10:56:21 AM, on 11/18/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:










    C:\Program Files\Eset\nod32kui.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\CursorXP\CursorXP.exe



    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\Program Files\Eset\nod32krn.exe


    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe


    C:\Program Files\Mozilla Firefox\firefox.exe



    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

    O1 - Hosts:

    O1 - Hosts:

    O1 - Hosts:

    O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll

    O2 - BHO: ThunderBHO - {02478D37-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll

    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FLASHGET\jccatch.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll

    O3 - Toolbar: (no name) - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - (no file)

    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe


    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm

    O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: ʹÓÃѸÀ×ÃÂÔØ - C:\Program Files\Thunder Network\Thunder\Program\GetUrl.htm

    O8 - Extra context menu item: ʹÓÃѸÀ×ÃÂÔØÈ«²¿Ã´½Ó - C:\Program Files\Thunder Network\Thunder\Program\GetAllUrl.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

    O9 - Extra button: ????5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe

    O9 - Extra 'Tools' menuitem: ????5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe

    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll

    O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) -

    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -

    O17 - HKLM\System\CCS\Services\Tcpip\..\{3A9936F2-4426-4129-9AE9-DD13A4F0F093}: NameServer =,

    O17 - HKLM\System\CCS\Services\Tcpip\..\{50FFE6F6-D796-43A9-9841-0D2603C229EA}: NameServer =

    O17 - HKLM\System\CS1\Services\Tcpip\..\{3A9936F2-4426-4129-9AE9-DD13A4F0F093}: NameServer =,

    O17 - HKLM\System\CS2\Services\Tcpip\..\{3A9936F2-4426-4129-9AE9-DD13A4F0F093}: NameServer =,

    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL

    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

    O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\wbsrv.dll

    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)

    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: LexBce Server (LexBceS) - Unknown owner - C:\WINDOWS\system32\LEXBCES.EXE (file missing)

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

    Can someone please enlighten me?

    Thanks in advance.

  3. You could use msconfig to disable all startup programs. If that solves the error with the next reboot, you could then enable one program at a time to see which one is causing the error.

    I tried it. But it doesn't work for me. I disabled all the programs but the the memory reference error still occur. Shall I disable all the service too? What should I do now?

    "What steps should I attempt to possibly avoid reinstalling Microsoft® Windows® XP?" =

    The link above is about system restore to me. May I know what're the steps should I attempt to possibly avoid reinstalling Microsoft® Windows® XP?

  4. You could use msconfig to disable all startup programs. If that solves the error with the next reboot, you could then enable one program at a time to see which one is causing the error.

    I tried it. But it doesn't work for me. I disabled all the programs but the the memory reference error still occur. Shall I disable all the service too? What should I do now?

  5. Okay, I was going to ask if it happened only with a specific program; but you say it occurs every time you start your computer. Is that correct?

    Next time, starting with the computer off, turn it on and after the POST beep start tapping F8 once a second until you get a start options menu and choose "safe mode"

    Login to safe mode with your usual account and see if you get the error.

    Generally this error is caused by a defective device driver or virtual anything driver which is part of something like an antivirus (or a virus) .

    Can you remember anything you installed or updated just before the problem started?

    If it only happened in Internet Explorer I would say it was a problem with spyware affecting the Layered Service Provider (LSP ) files; but you say it occurs on startup.

    Although if you have dialup and you are using an internet accellerator software it could be the cause . (RelevantKnowledge malware is a known cause of this error do you have it installed?So can Alcanshorty trojan)

    If it were a specific program then either an update or patch or uninstall/ reinstall is generally the solution.

    So please clarify if you can . If you suspect malware, post in the malware board.

    It was a rundll32.exe application error. It occurs everytime on startup. I'm sorry but I can't remember anything I've installed or updated just before the problem stated. What do you mean by malware board? Can you please show me the way to do the malware board?


  6. It's probably a bug. Zero is a standard representation of an invalid address; Windows traps attempts to reference it to catch errors. It's possible that there's an underlying hardware problem, but it's at least equally likely that the process simply jumped without looking, so to speak.

    Then what should I do to overcome this problem?

  7. My computer is continually getting Application Error pop up messages. The error reads:

    "The instruction at "0x000000000" referenced memory at "0x00000000". The memory could not be "read". Click OK to terminate program."

    Any solution for this problem?

    I'll greatly appreciate if someone can help me up with this problem.