Results 1 to 10 of 10
  1. #1
    Member
    Join Date
    Jul 2003
    Posts
    164
    Points
    14

    Default memory could not be written

    Hi Guys

    It's me again with more problems....... This is a secondary problem to the post.. Trojan Horse.. posted earlier.
    I am trying to complete the list of things to do to remove the Trojan Horse (steps 1-5) and i can sometimes get access to IE and other times (like today), as soon as i access the update page it gives me an error:-

    The instructions at "0x775700005" referenced memory at "0x00000000". The memory could not be written.
    Click to terminate or cancel to debug........ both options close the programme and take me back to the desktop.

    As i said in my previous post this is windows 2000 professional, 80% free space.

    I don't even know what the reference is referring to, let alone what i'm supposed to do about it.

    Hope you guys can help me out

    Best regards Cremora

  2. #2
    Administrator Help2Go Administrator Canuck's Avatar
    Join Date
    May 2003
    Location
    Edmonton, Alberta, Canada
    Posts
    9,817
    Points
    2034

    Default

    The only thing I can think of, if I understand you right, is that the file is a Read Only file. Are you able to copy it from the CD and paste onto desktop for example and then open this file and edit?


  3. #3
    Member Help2Go Moderator
    Join Date
    May 2003
    Location
    Boston, MA USA
    Posts
    2,994
    Points
    931

    Default

    Sounds like the program you're using is having a hell of a time writing to that memory address. It seems as though this error is caused by a few things but most commonly the .avi preview and adobe image editing software (elements and/or photoshop). Firstly, try disabling the thumbnail view in folders by doing this >> Start Menu > click "run" > type "regsvr32 /u shmedia.dll" (no quotes) > click "oK" If this seems to fix your problem then try reinstalling your .avi codecs, especially the divx codec if installed.

    If that doesn't help.. Go to start menu > click "run" > type "regsvr32 shmedia.dll" (no quotes, this is to reinstall the thumbnail view) > click "ok".

    Now uninstall any and all adobe image editing software, restart computer and see if that helps.

    Partie™

  4. #4
    Member galena1's Avatar
    Join Date
    Oct 2003
    Location
    Devon -UK
    Posts
    3,109
    Points
    429

    Default

    Hi cremora - Sometimes this can be resolved by changing your Home page in Tools>Internet Options. This can also sometimes be caused by an issue with SP2. Have you recently installed SP2? Regards.
    I know everything about nothing, nothing about everything and precious little about the bit in between.
    P4-3.0G - Seagate Barracuda 160 - Maxtor 120 - Antec Hard Drive Cooler - 1GRam - Radeon9800Pro - Sony Multi DriveDVDRW - Audigy2 6.1 - XPHome

  5. #5
    Member Help2Go Moderator
    Join Date
    May 2003
    Location
    Boston, MA USA
    Posts
    2,994
    Points
    931

    Default

    Galena, not sure if you didnt' see this but he/she is running Windows 2000. Already up to SP4 (Roll-up 1). Maybe thinking they're running XP?

    Partie™

  6. #6
    Member galena1's Avatar
    Join Date
    Oct 2003
    Location
    Devon -UK
    Posts
    3,109
    Points
    429

    Default

    Duhh You're right Partie, missed it completely.
    I know everything about nothing, nothing about everything and precious little about the bit in between.
    P4-3.0G - Seagate Barracuda 160 - Maxtor 120 - Antec Hard Drive Cooler - 1GRam - Radeon9800Pro - Sony Multi DriveDVDRW - Audigy2 6.1 - XPHome

  7. #7
    Member
    Join Date
    Jul 2003
    Posts
    164
    Points
    14

    Default reply

    Hi guys, thanks all of you for your replies and Partie i will try your suggestions as see if that works, but first i think i should be a little more explanatory.

    I can start the pc without any issues at all and i can work on the office side again with out any issue, then i connect to the internet and can in some cases surf for a while and then for some unknown reason this error occurs. I have often defragmented and i seem to be able to access the problem site but only for a little longer, Then i can shutdown and restart and then i can not get any internet site due to the error and then again i can surf all night without a problem.
    For eg. re my previous post Trojan horse: i was following the instructions steps and found i could not get Trend housecall to do a scan because of this error and so i decided to see if i could skip that stage for a while and download the critical updates from Windows update page. I had 20 updates to do but one i left as it was a seperate installation. The 19 updates downloaded and updated successfully, i then went back to the update page again and the error occurred.
    I left it for the night and tried again the next day and i couldn't even get the Windows update to load for this error.
    This can happen anytime and on any page at random. It used to happen frequently with incredimail after i had downloaded a numerous amount of letter pages from various places, so i deleted all of incredimail thinking that was the problem but its still there.
    I hope that has given you more information to advise on.

    Thanks again guys and sorry for the long long letter.

    Regards Cremora

  8. #8
    Member
    Join Date
    Jul 2003
    Posts
    164
    Points
    14

    Default

    Hi guys
    i have followed the steps you suggested as far as i could:
    Panda online scan completed:
    dialers 1 disinfected 0
    spyware 2 disinfected 0

    Trend housecall would not let me do it due to the memory issue

    Hijack this log log submitted

    CWshredder completed no issues found

    Windows critical updated completed

    Spybot completed no issues found

    Ad-aware completed 8 critical objects found
    1 registry key
    7 registry values (all 8 Alexa & removed)

    AVG completed and 2 viruses found

    No.1 Trojan horse downloader.Istbar.AT
    file....ISTactive.dll
    path..c:\documents and settings\default user

    No.2 Trojan horse downloader.Istbar.AT
    file....0006_adult[1].cab
    path..c:\documents and settings\default user

    I hope this helps you to help me

    Best regards Cremora

    P.S. PartieHonteuse, i have not tried your suggestion yet but will should all else fail

    Logfile of HijackThis v1.99.1
    Scan saved at 10:55:33, on 2005/12/21
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\cdplayer.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\WINNT\system32\internat.exe
    C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    C:\Program Files\MediaKey\Versato.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    C:\Program Files\MediaKey\OSD.EXE
    C:\WINNT\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINNT\System32\mdm.exe
    C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.za/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = http://www.mweb.co.za/home/home.asp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 196.15.244.233:8080
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {DD9EA61E-9556-11D4-BC88-00105A29E461} - (no file)
    O4 - HKLM\..\Run: [DeluxeCD] C:\WINNT\System32\cdplayer.exe -tray
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    O4 - Global Startup: MediaKey.lnk = C:\Program Files\MediaKey\Versato.exe
    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1134568033130
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3DADC940-2DE7-4D2B-B8E4-9943209223F9}: NameServer = 192.168.254.2 192.168.254.2
    O17 - HKLM\System\CS2\Services\Tcpip\..\{3DADC940-2DE7-4D2B-B8E4-9943209223F9}: NameServer = 192.168.254.2 192.168.254.2
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

  9. #9
    Member galena1's Avatar
    Join Date
    Oct 2003
    Location
    Devon -UK
    Posts
    3,109
    Points
    429

    Default

    Hi cremora - Ther is a problem in your Log. One of the experts will advise what to do when they are online. Regards.
    I know everything about nothing, nothing about everything and precious little about the bit in between.
    P4-3.0G - Seagate Barracuda 160 - Maxtor 120 - Antec Hard Drive Cooler - 1GRam - Radeon9800Pro - Sony Multi DriveDVDRW - Audigy2 6.1 - XPHome

  10. #10
    Member
    Join Date
    May 2004
    Posts
    26
    Points
    3

    Default

    <div>Looks like you have not been keeping your PC very up to date, with all the updates you had to do.* As you should know all M$ systems have "holes"* in them.* Keeping any of them up to date is critical.

    Also you said the Trend would not run because of memory issues, how much RAM and free HD space do you have ?

    As you can see the problems are located in your:

    c:\documents and settings\default user

    Go there and try to delete them.* I suugest that you do it in the "Safe Mode"* just incase they are running.

    The Help2Go Spyware forum is closed for two weeks.

    MM



    </div>