-
June 14th, 2004, 01:44 PM
#1
Runtime Error 216 at ....
Hi guys.
I'm hoping you can help me out wth a rather annoying problem I seem to have developed. I have two 'issues', possibly related.
The first is as per the title of the post. A message box pops up when closing IE sometimes that says 'Runtime Error 216 #######'. An initial search brought up microsoft.com saying 'Subseven Trojan' = panic.
So, I've scanned the system with AVG Anti-Virus, Kaspersky Anti-Virus, Spybot, Spyware Blaster & a squared2 (http://www.emsisoft.com/en/software/personal/) and have drawn a blank. I also have Outpost Pro istalled and there are no dodgy looking connections on the list either.
Hijackthis produces the following report:
Logfile of HijackThis v1.97.7
Scan saved at 19:41:36, on 14/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe *
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe *
C:\Program Files\Executive Software\Diskeeper\DkService.exe *
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe *
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Executive Software\Undelete\UdServe.exe *
C:\WINDOWS\system32\Ati2evxx.exe *
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\taskswitch.exe *
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe *
C:\WINDOWS\System32\EXSHOW95.EXE
C:\Program Files\GIANT Company Software\Spam Inspector\siService.exe *
C:\WINDOWS\System32\EXSHOW.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe *
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe *
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe *
C:\Program Files\GIANT Company Software\Spam Inspector\siMailProxyServer.exe *
C:\Program Files\GIANT Company Software\Spam Inspector\siSpamFilterEngine.exe *
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Andy\My Documents\My Received Files\Programs\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Andy/My%20Documents/My%20Webs/Homepage/home.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2K0.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Hotmail Spam Filter - {58A83E4F-477A-4A3F-BF9B-B65BC2BD5598} - C:\Program Files\GIANT Company Software\Spam Inspector\siClientUIHotmail.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [EXSHOW95.EXE] EXSHOW95.EXE
O4 - HKLM\..\Run: [Spam Inspector] C:\Program Files\GIANT Company Software\Spam Inspector\siService.exe
O4 - HKLM\..\Run: [Java] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Video Card] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [siService.exe] "C:\Program Files\GIANT Company Software\Spam Inspector\siService.exe"
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe /waitservice
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Trashcan (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...107.4754166667
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
I've put a '*' beside the things I'm confident I can identify but to be honest,the rest of it makes little sense to me and may as well be in Japanese.
I'm running Windows XP Pro, with all the latest updates installed.
It did seem to kick off after installing Macromedia Shockwave 10 but I've since removed this and still suffer the same problem.
Any help you can give would be appreciated as the thought of reinstalling from scratch sends shivers down my spine.
The second problem is this. When shutting down the system, an Ending Program window pops up for something by the name of 'DDE Server'. What the hell is this??
THANK YOU!!!!
-
June 14th, 2004, 02:40 PM
#2
Banned
Welcome to WD Dr.
Could go to this file and check its properties:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Setting...epage/home.htm
A couple other notes: you should really stick with only one AV program running in the background, so pick one and stick with it.
And, that Kensington Mouseware stuff is crap, so get rid of it unless you like it's features.
-
June 15th, 2004, 02:50 PM
#3
Hello!!
Damn AVG. Switched it off after all the bother started just incase it was it's stupid fault for letting a virus/trojan in and installed Kaspersky in it's place but forgot to disable it in services. Now done.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Andy/My%20Documents/My%20Webs/Homepage/home.htm - This is a page of my links (which WD now resides on) that I made which comes up when IE is opened in place of msn, google etc.. so that they don't benefit from hits from me they don't deserve.
& as for Mouseworks, I know it's crap but if I don't have this installed, my roller wheel seems to work upside down no matter what I do in Mouse Properties! odd.
Found another site (http://www.uksecurityonline.com/) which seems quite informative. They have a list of all the services XP runs, what they do and what they recommend so I've slashed those back too but still get the same damn Runtime 216 @ 024D3812, 02353812 & 02363812 (so far) errors and the elusive DDE Server thing too. On the Services list there were 2 DDE services - Network DDE & Network DDE DSDM but they were set to manual and weren't running (disabled now though) but still no joy.
Did you notice anything else dodgy in the list? It's doing my head in.
Thanks!
-
August 27th, 2004, 10:25 PM
#4
I've got exactly the same problems. Happens with annoying regularity.
It happens on my laptop running XP Pro, but not on the desktop.
Is the cause possibly hardware ?.
Maybe we could compare machines to see if there's a common link.
-
August 29th, 2004, 04:07 AM
#5
Driver Terrier
Welcome to Windrivers Russ Gracie
Russ and Dr There is a new version of hijack this - please use it a post logs.
From the quick reading I have done, 216 is the result of a misbehaving plugin... so you both need to compare software and plugins.
Russ are you running XP sp1?
Never, ever approach a computer saying or even thinking "I will just do this quickly."
-
August 29th, 2004, 08:23 PM
#6
Originally Posted by NooNoo
Welcome to Windrivers Russ Gracie
Russ and Dr There is a new version of hijack this - please use it a post logs.
From the quick reading I have done, 216 is the result of a misbehaving plugin... so you both need to compare software and plugins.
Russ are you running XP sp1?
Thanks for the tip NooNoo. Don't know much about plugins, but will do some swatting up. Any more help you can offer will be appreciated.
I'm using XP Ver: 5.1.2600 SP1
Similar Threads
-
By Dshadna in forum Windows XP
Replies: 11
Last Post: June 13th, 2004, 06:47 AM
-
By felix kk in forum Windows XP
Replies: 3
Last Post: January 29th, 2002, 12:03 PM
-
By brooks18 in forum Windows 95/98/98SE/ME
Replies: 0
Last Post: May 20th, 2000, 07:06 AM
-
By Puff in forum Windows 95/98/98SE/ME
Replies: 0
Last Post: November 19th, 1999, 11:13 PM
-
By JMDISHAW in forum Windows 95/98/98SE/ME
Replies: 1
Last Post: November 12th, 1999, 12:07 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|
Bookmarks