Results 1 to 4 of 4

Thread: Need Help

  1. #1
    Member
    Join Date
    Aug 2011
    Posts
    1
    Points
    0

    Default Need Help

    I downloaded world of warcraft not too long ago and every time i click play on the launcher it shuts down and gives me an error saying something with the memory cannot be written.

    This application has encountered a critical error:

    ERROR #132 (0x85100084) Fatal exception!

    Program: C:\Program Files\World of Warcraft\WoW.exe
    ProcessID: 3616
    Exception: 0xC0000005 (ACCESS_VIOLATION) at 001B:10037066

    The instruction at "0x10037066" referenced memory at "0xE2067200".
    The memory could not be "written".


    WoWBuild: 14480
    Version: 4.2.0
    Type: WoW
    Platform: X86
    Settings:
    SET readTOS "-1"
    SET readEULA "-1"
    SET readScanning "-1"
    SET readContest "-1"
    SET checkAddonVersion "1"
    SET locale "enUS"
    SET playIntroMovie "0"
    SET showToolsUI "1"
    SET accounttype "CL"
    SET readTerminationWithoutNotice "-1"
    SET installType "Retail"
    SET hwDetect "0"

    ----------------------------------------
    GxInfo
    ----------------------------------------
    GxApi: D3D9
    Shader Model: 1_1
    Vertex: vs_1_1
    Pixel: ps_1_1
    Adapter Count: 1

    Adapter 0 (primary):
    Driver: nv4_disp.dll
    Version: 6.14.0010.5673
    Description: NVIDIA GeForce4 Ti 4400 (Microsoft Corporation)
    DeviceName: \\.\DISPLAY1

    ------------------------------------------------------------------------------

    ----------------------------------------
    x86 Registers
    ----------------------------------------

    EAX=E2067200 EBX=00000000 ECX=00000000 EDX=00000000 ESI=0012F504
    EDI=00000080 EBP=0012F5B0 ESP=0012F4DC EIP=10037066 FLG=00010246
    CS =001B DS =0023 ES =0023 SS =0023 FS =003B GS =0000


    ----------------------------------------
    Stack Trace (Manual)
    ----------------------------------------

    Address Frame Logical addr Module

    Showing 9/9 threads...

    --- Thread ID: 3812 [Current Thread] ---
    10037066 0012F5B0 0001:00036066 C:\WINDOWS\system32\nvapi.dll
    00858BA8 0012F5D0 0001:00457BA8 C:\Program Files\World of Warcraft\WoW.exe
    0084D014 0012FAB0 0001:0044C014 C:\Program Files\World of Warcraft\WoW.exe
    0084E2B9 0012FB2C 0001:0044D2B9 C:\Program Files\World of Warcraft\WoW.exe
    0082B0F7 0012FB38 0001:0042A0F7 C:\Program Files\World of Warcraft\WoW.exe
    0084E541 0012FB58 0001:0044D541 C:\Program Files\World of Warcraft\WoW.exe
    00829A0F 0012FB68 0001:00428A0F C:\Program Files\World of Warcraft\WoW.exe
    0062A866 0012FBE8 0001:00229866 C:\Program Files\World of Warcraft\WoW.exe
    0062B45E 0012FCC4 0001:0022A45E C:\Program Files\World of Warcraft\WoW.exe
    00407BCA 0012FF1C 0001:00006BCA C:\Program Files\World of Warcraft\WoW.exe
    00407D76 0012FF2C 0001:00006D76 C:\Program Files\World of Warcraft\WoW.exe
    00407DC7 0012FFC0 0001:00006DC7 C:\Program Files\World of Warcraft\WoW.exe
    7C817077 0012FFF0 0001:00016077 C:\WINDOWS\system32\kernel32.dll

    --- Thread ID: 1288 ---
    77DF8631 0975FFB4 0001:00027631 C:\WINDOWS\system32\ADVAPI32.dll
    7C80B729 0975FFEC 0001:0000A729 C:\WINDOWS\system32\kernel32.dll

    --- Thread ID: 3904 ---
    71A55FA7 09DDFC04 0001:00004FA7 C:\WINDOWS\system32\mswsock.dll
    71AB314F 09DDFC54 0001:0000214F C:\WINDOWS\system32\WS2_32.dll
    3D95B7F5 09DDFFAC 0001:0002A7F5 C:\WINDOWS\system32\WININET.dll
    3D957F44 09DDFFB4 0001:00026F44 C:\WINDOWS\system32\WININET.dll
    7C80B729 09DDFFEC 0001:0000A729 C:\WINDOWS\system32\kernel32.dll

    --- Thread ID: 3908 ---
    7C80B729 09EDFFEC 0001:0000A729 C:\WINDOWS\system32\kernel32.dll

    --- Thread ID: 3912 ---
    7C80B729 09FDFFEC 0001:0000A729 C:\WINDOWS\system32\kernel32.dll

    --- Thread ID: 1640 ---
    7C80B729 0A15FFEC 0001:0000A729 C:\WINDOWS\system32\kernel32.dll

    --- Thread ID: 3208 ---
    7C802542 0A25FF24 0001:00001542 C:\WINDOWS\system32\kernel32.dll
    007C8170 0A25FF5C 0001:003C7170 C:\Program Files\World of Warcraft\WoW.exe
    007CC26A 0A25FF70 0001:003CB26A C:\Program Files\World of Warcraft\WoW.exe
    009EE6BE 0A25FFA8 0001:005ED6BE C:\Program Files\World of Warcraft\WoW.exe
    009EE766 0A25FFB4 0001:005ED766 C:\Program Files\World of Warcraft\WoW.exe
    7C80B729 0A25FFEC 0001:0000A729 C:\WINDOWS\system32\kernel32.dll

    --- Thread ID: 988 ---
    7C802542 0A35FF24 0001:00001542 C:\WINDOWS\system32\kernel32.dll
    007C7C4F 0A35FF5C 0001:003C6C4F C:\Program Files\World of Warcraft\WoW.exe
    007CC26A 0A35FF70 0001:003CB26A C:\Program Files\World of Warcraft\WoW.exe
    009EE6BE 0A35FFA8 0001:005ED6BE C:\Program Files\World of Warcraft\WoW.exe
    009EE766 0A35FFB4 0001:005ED766 C:\Program Files\World of Warcraft\WoW.exe
    7C80B729 0A35FFEC 0001:0000A729 C:\WINDOWS\system32\kernel32.dll

    --- Thread ID: 1528 ---
    7C802542 0A45FF28 0001:00001542 C:\WINDOWS\system32\kernel32.dll
    007C8049 0A45FF5C 0001:003C7049 C:\Program Files\World of Warcraft\WoW.exe
    007CC26A 0A45FF70 0001:003CB26A C:\Program Files\World of Warcraft\WoW.exe
    009EE6BE 0A45FFA8 0001:005ED6BE C:\Program Files\World of Warcraft\WoW.exe
    009EE766 0A45FFB4 0001:005ED766 C:\Program Files\World of Warcraft\WoW.exe
    7C80B729 0A45FFEC 0001:0000A729 C:\WINDOWS\system32\kernel32.dll

    ----------------------------------------
    Stack Trace (Using DBGHELP.DLL)
    ----------------------------------------

    Showing 9/9 threads...

    --- Thread ID: 3812 [Current Thread] ---
    10037066 nvapi.dll DllUnregisterServer+215296 (00000001,0A97F008,0012FAC8,00000400)
    00858BA8 WoW.exe GetBattlenetAllocator+2109976 (00000001,0A9817DC,0A97F008,5F34766E)
    0084D014 WoW.exe GetBattlenetAllocator+2061956 (0012FAC8,01010054,0012FB90,0A97F008)
    0084E2B9 WoW.exe GetBattlenetAllocator+2066729 (0012FB90,0012FB58,0084E541,0085DE40)
    0082B0F7 WoW.exe GetBattlenetAllocator+1922919 (0085DE40,0012FB90,00000001,00000001)
    0084E541 WoW.exe GetBattlenetAllocator+2067377 (0085DE40,0012FB90,0012FBE8,0062A866)
    00829A0F WoW.exe GetBattlenetAllocator+1917055 (00000001,0085DE40,0012FB90,0012FB90)
    0062A866 WoW.exe AssertAndCrash+55414 (0012FBFC,000000FC,000000F2,00000000)
    0062B45E WoW.exe AssertAndCrash+58478 (0012FCEC,00000001,00000001,00000000)
    00407BCA WoW.exe <unknown symbol>+0 (00000001,00000001,0012FFC0,00407DC7)
    00407D76 WoW.exe <unknown symbol>+0 (0040D975,00400000,00000000,0016233C)
    00407DC7 WoW.exe <unknown symbol>+0 (00000114,72676F72,7FFDA000,C0000005)
    7C817077 kernel32.dll RegisterWaitForInputIdle+73 (004011B0,00000000,78746341,00000020)

    --- Thread ID: 1288 ---
    77DF8631 ADVAPI32.dll WmiFreeBuffer+590 (00000000,00000000,77DF8AE4,00000000)
    7C80B729 kernel32.dll GetModuleFileNameA+442 (77DF848A,00000000,00000000,78746341)

    --- Thread ID: 3904 ---
    71A55FA7 mswsock.dll <unknown symbol>+0 (00000001,09DDFE84,09DDFC7C,09DDFD80)
    71AB314F WS2_32.dll select+167 (00000001,09DDFE84,09DDFC7C,09DDFD80)
    3D95B7F5 WININET.dll Ordinal101+10221 (09DDFFEC,7C80B729,0017CE88,00125C94)
    3D957F44 WININET.dll InternetSetStatusCallback+473 (0017CE88,00125C94,00160000,0017CE88)
    7C80B729 kernel32.dll GetModuleFileNameA+442 (3D957F37,0017CE88,00000000,00000000)

    --- Thread ID: 3908 ---
    7C80B729 kernel32.dll GetModuleFileNameA+442 (7C927D83,00000000,00000000,00000000)

    --- Thread ID: 3912 ---
    7C80B729 kernel32.dll GetModuleFileNameA+442 (7C910250,00000000,00000000,00000001)

    --- Thread ID: 1640 ---
    7C80B729 kernel32.dll GetModuleFileNameA+442 (71A5D2C6,0019A318,00000000,00000000)

    --- Thread ID: 3208 ---
    7C802542 kernel32.dll WaitForSingleObject+18 (00002300,FFFFFFFF,097990E8,00000042)
    007C8170 WoW.exe GetBattlenetAllocator+1517536 (09A71FC0,00000042,097990E8,0A25FFA8)
    007CC26A WoW.exe GetBattlenetAllocator+1534170 (09799080,8BAB89C7,00000042,097990E8)
    009EE6BE WoW.exe GetBattlenetAllocator+3771694 (09FDFB60,0A25FFEC,7C80B729,097990E8)
    009EE766 WoW.exe GetBattlenetAllocator+3771862 (097990E8,00000042,09FDFB60,097990E8)
    7C80B729 kernel32.dll GetModuleFileNameA+442 (009EE6E4,097990E8,00000000,00000000)

    --- Thread ID: 988 ---
    7C802542 kernel32.dll WaitForSingleObject+18 (0000210C,FFFFFFFF,7C9101DB,09AAD660)
    007C7C4F WoW.exe GetBattlenetAllocator+1516223 (00000000,7C9101DB,09A7E1B0,0A35FFA8)
    007CC26A WoW.exe GetBattlenetAllocator+1534170 (09AAD660,8BBB89C7,7C9101DB,09A7E1B0)
    009EE6BE WoW.exe GetBattlenetAllocator+3771694 (0012F7E8,0A35FFEC,7C80B729,09A7E1B0)
    009EE766 WoW.exe GetBattlenetAllocator+3771862 (09A7E1B0,7C9101DB,0012F7E8,09A7E1B0)
    7C80B729 kernel32.dll GetModuleFileNameA+442 (009EE6E4,09A7E1B0,00000000,00000000)

    --- Thread ID: 1528 ---
    7C802542 kernel32.dll WaitForSingleObject+18 (0000217C,FFFFFFFF,00000000,0979BDB8)
    007C8049 WoW.exe GetBattlenetAllocator+1517241 (09A7E568,00000000,09A7E598,0A45FFA8)
    007CC26A WoW.exe GetBattlenetAllocator+1534170 (0979BDB8,8BCB89C7,00000000,09A7E598)
    009EE6BE WoW.exe GetBattlenetAllocator+3771694 (0012FAB8,0A45FFEC,7C80B729,09A7E598)
    009EE766 WoW.exe GetBattlenetAllocator+3771862 (09A7E598,00000000,0012FAB8,09A7E598)
    7C80B729 kernel32.dll GetModuleFileNameA+442 (009EE6E4,09A7E598,00000000,FFFFFFFF)



    ----------------------------------------
    Loaded Modules
    ----------------------------------------

    DBG-MODULE<00360000 00009000 "Normaliz.dll" "normaliz.pdb" 0 {d0658e32-2b2d-4ddc-a57fb9c9715c6cad} 1 1151593542>
    DBG-MODULE<00400000 00C98000 "WoW.exe" "Wow.pdb" 0 {69998df6-47b1-49a4-a94fe352d257e808} 1 1312424395>
    DBG-MODULE<0B580000 00115000 "dbghelp.dll" "dbghelp.pdb" 0 {a95a9676-9559-4b16-959820e93cb1abec} 1 1152389492>
    DBG-MODULE<10000000 000A5000 "nvapi.dll" "nvapi.pdb" 0 {3873b400-0846-4fe3-b8cb5005ec325b13} 1 1238178497>
    DBG-MODULE<3D930000 000D3000 "WININET.dll" "wininet.pdb" 0 {ca7c7990-d99b-46d1-9152d1336a3c8189} 2 1308681839>
    DBG-MODULE<3DFD0000 00045000 "iertutil.dll" "iertutil.pdb" 0 {8a922a9a-6ee3-4e6c-ade890f5bebf02c1} 2 1308681846>
    DBG-MODULE<4FDD0000 001A6000 "d3d9.dll" "d3d9.pdb" 0 {d7b3488c-9e0d-42be-aa48a6c25eb42520} 1 1208131753>
    DBG-MODULE<5AD70000 00038000 "uxtheme.dll" "uxtheme.pdb" 0 {e99e1630-8f09-4767-b1f07fb5c3e5e246} 2 1208131870>
    DBG-MODULE<5B860000 00055000 "NETAPI32.dll" "netapi32.pdb" 0 {49d4d68e-25ca-4118-a09aa9a66e7390e3} 2 1224088464>
    DBG-MODULE<5D090000 0009A000 "comctl32.dll" "comctl32.pdb" 0 {77ef193b-0498-456f-92411b02620462fb} 2 1282579924>
    DBG-MODULE<5ED00000 000CC000 "OPENGL32.dll" "opengl32.pdb" 0 {06786566-d8b1-4b11-a8222a2b9755c03b} 1 1208131866>
    DBG-MODULE<64D00000 00034000 "snxhk.dll" "snxhk.pdb" 0 {4bb7b967-d64d-4061-9671943278d25ca9} 1 1309779367>
    DBG-MODULE<662B0000 00058000 "hnetcfg.dll" "HNetCfg.pdb" 0 {87332c2b-ff6e-42fc-b89784a1d24ec271} 1 1208131786>
    DBG-MODULE<688F0000 00009000 "HID.DLL" "hid.pdb" 0 {f78c0103-108e-416d-82704e923299d5a0} 2 1208131781>
    DBG-MODULE<68B20000 00020000 "GLU32.dll" "glu32.pdb" 0 {9e94e4a4-bddc-445e-b27d7035846df02f} 1 1208131774>
    DBG-MODULE<6CE10000 00038000 "DINPUT8.dll" "dinput8.pdb" 0 {1944680c-2597-4803-b1ba9715a8aa1aa0} 1 1208131788>
    DBG-MODULE<6D990000 00006000 "d3d8thk.dll" "d3d8thk.pdb" 0 {39aab8d2-6f8c-4220-b1699d3007e8712f} 1 1208131752>
    DBG-MODULE<71A50000 0003F000 "mswsock.dll" "mswsock.pdb" 0 {cc64d911-8d4e-4582-92af634d2c79ef66} 2 1213977767>
    DBG-MODULE<71A90000 00008000 "wshtcpip.dll" "wshtcpip.pdb" 0 {de2e5260-3ffb-406d-9052c8d884a1ad72} 2 1208131950>
    DBG-MODULE<71AA0000 00008000 "WS2HELP.dll" "ws2help.pdb" 0 {6049cf58-77c5-4e2a-b512abc1b4b2e799} 2 1208131940>
    DBG-MODULE<71AB0000 00017000 "WS2_32.dll" "ws2_32.pdb" 0 {a7605f86-95a3-4329-b38ddb8421a004ca} 2 1208131939>
    DBG-MODULE<71BF0000 00013000 "SAMLIB.dll" "samlib.pdb" 0 {4bb85de7-9b10-4f15-95f96df1adac91c8} 2 1208131846>
    DBG-MODULE<722B0000 00005000 "sensapi.dll" "sensapi.pdb" 0 {0d689741-fe69-4c81-ade2e0092de57092} 2 1208131847>
    DBG-MODULE<73760000 0004B000 "DDRAW.dll" "ddraw.pdb" 0 {df483a83-3685-447f-9f96d93012393c34} 2 1208131768>
    DBG-MODULE<73BC0000 00006000 "DCIMAN32.dll" "dciman32.pdb" 0 {5b52df1b-8235-4a7b-9079b1417497d5a4} 2 1208131767>
    DBG-MODULE<74720000 0004C000 "MSCTF.dll" "msctf.pdb" 0 {c52f0b4c-00e9-4556-ae999f228b001966} 2 1208131884>
    DBG-MODULE<755C0000 0002E000 "msctfime.ime" "msctfime.pdb" 0 {60228888-3af4-4453-979369233e091e64} 1 1208131885>
    DBG-MODULE<76390000 0001D000 "IMM32.dll" "imm32.pdb" 0 {f7a5b5db-1332-4153-b57aaf340c77ea51} 2 1208131815>
    DBG-MODULE<76790000 0000C000 "cryptdll.dll" "cryptdll.pdb" 0 {b6f842b0-da88-4502-8bc9317dd362e385} 2 1208131801>
    DBG-MODULE<769C0000 000B4000 "USERENV.dll" "userenv.pdb" 0 {9fee774e-5473-4779-9689d6baf9dab410} 2 1208131868>
    DBG-MODULE<76B20000 00011000 "ATL.DLL" "atl.pdb" 0 {dd005635-25a4-40c8-96aa028cfa184ae6} 1 1247857266>
    DBG-MODULE<76B40000 0002D000 "WINMM.dll" "winmm.pdb" 0 {90fc96d5-ad84-40a2-b14855895bd92ed6} 2 1208131900>
    DBG-MODULE<76D40000 00018000 "MPRAPI.dll" "mprapi.pdb" 0 {ebeffbe1-aa30-4514-b6fb6b3bdf505441} 2 1208131846>
    DBG-MODULE<76D60000 00019000 "iphlpapi.dll" "iphlpapi.pdb" 0 {9b09f073-003f-4ca4-8f9980b3c091448f} 2 1208131792>
    DBG-MODULE<76E10000 00025000 "adsldpc.dll" "adsldpc.pdb" 0 {c06d6868-db30-42eb-bc2d5821f9bea28f} 2 1208131752>
    DBG-MODULE<76E80000 0000E000 "rtutils.dll" "rtutils.pdb" 0 {78f85ebe-5de9-4562-98b4cb8c58247bd1} 2 1208131855>
    DBG-MODULE<76E90000 00012000 "rasman.dll" "rasman.pdb" 0 {1b54792b-1023-4898-83622d756f50b6bc} 2 1208131843>
    DBG-MODULE<76EB0000 0002F000 "TAPI32.dll" "tapi32.pdb" 0 {d13c5720-554b-441e-91e5f858f9af1d6a} 2 1208131861>
    DBG-MODULE<76EE0000 0003C000 "RASAPI32.dll" "rasapi32.pdb" 0 {feddfb06-cebb-43e3-98ad39a694fb4d3d} 2 1208131839>
    DBG-MODULE<76F20000 00027000 "DNSAPI.dll" "dnsapi.pdb" 0 {f01111d1-a397-4a80-837b62abd17fbf11} 2 1299135319>
    DBG-MODULE<76F60000 0002C000 "WLDAP32.dll" "wldap32.pdb" 0 {ac04bcf6-ff29-4fce-ac8b8d937cba3a17} 2 1208131886>
    DBG-MODULE<76FB0000 00008000 "winrnr.dll" "winrnr.pdb" 0 {9fe1a466-9b69-400f-ac821a4367aa9cc5} 2 1208131874>
    DBG-MODULE<76FC0000 00006000 "rasadhlp.dll" "rasadhlp.pdb" 0 {cca669b1-5828-47d0-b330d7abdb446a47} 2 1208131838>
    DBG-MODULE<77120000 0008B000 "OLEAUT32.dll" "oleaut32.pdb" 0 {e04ecb48-caed-47b2-958c3d2c1094e23f} 2 1292866335>
    DBG-MODULE<773D0000 00103000 "comctl32.dll" "MicrosoftWindowsCommon-Controls-6.0.2600.6028-comctl32.pdb" 0 {e882c2c8-9072-4d59-8449e20a4fe6f07c} 1 1282579921>
    DBG-MODULE<774E0000 0013E000 "ole32.dll" "ole32.pdb" 0 {0e732075-36d6-4e9c-9fb83c682ed9e585} 2 1279281955>
    DBG-MODULE<77920000 000F3000 "SETUPAPI.dll" "setupapi.pdb" 0 {9d521824-15aa-4179-960b37f4c694f90d} 2 1208131851>
    DBG-MODULE<77BE0000 00015000 "MSACM32.dll" "msacm32.pdb" 0 {8256bd89-de02-4f3c-970b66b9b5e5d899} 2 1208131863>
    DBG-MODULE<77C00000 00008000 "VERSION.dll" "version.pdb" 0 {ea3d1bd3-fe65-475c-8449c8d8b0072296} 2 1208131869>
    DBG-MODULE<77C10000 00058000 "msvcrt.dll" "msvcrt.pdb" 0 {7bcf30d8-c91b-4f1b-85fa4e5589625011} 1 1208131976>
    DBG-MODULE<77C70000 00025000 "msv1_0.dll" "msv1_0.pdb" 0 {41b28088-7268-4154-a0c235b55acf3b5a} 2 1252678719>
    DBG-MODULE<77CC0000 00032000 "ACTIVEDS.dll" "activeds.pdb" 0 {074e41e0-84c5-43f6-8034bdcdb96a3fbe} 2 1208131741>
    DBG-MODULE<77DD0000 0009B000 "ADVAPI32.dll" "advapi32.pdb" 0 {f759d3f1-c661-4313-b07c84bc33f02e4d} 2 1234181448>
    DBG-MODULE<77E70000 00093000 "RPCRT4.dll" "rpcrt4.pdb" 0 {1a465c67-8282-42f2-8a8c70e3b9d5c477} 2 1281948300>
    DBG-MODULE<77F10000 00049000 "GDI32.dll" "gdi32.pdb" 0 {372c0f0e-08fb-456e-ab7b4cb2b53e2795} 2 1224765374>
    DBG-MODULE<77F60000 00076000 "SHLWAPI.dll" "shlwapi.pdb" 0 {483e8894-476b-412d-abc2fba7f470e39a} 2 1260264208>
    DBG-MODULE<77FE0000 00011000 "Secur32.dll" "secur32.pdb" 0 {7867b3f2-8b5c-41ce-847895e3fc013dc5} 2 1245918326>
    DBG-MODULE<78130000 00129000 "urlmon.dll" "urlmon.pdb" 0 {a3e55eb1-c885-4ca3-9f4bbe4f1be12751} 2 1308681839>
    DBG-MODULE<7C800000 000F6000 "kernel32.dll" "kernel32.pdb" 0 {072ff0eb-54d2-4dfa-ae9d13885486ee09} 2 1237644418>
    DBG-MODULE<7C900000 000B2000 "ntdll.dll" "ntdll.pdb" 0 {cefc0863-b1f8-4130-a11e0f54180cd21a} 2 1291907709>
    DBG-MODULE<7C9C0000 00817000 "SHELL32.dll" "shell32.pdb" 0 {df59c75c-a10b-4bf8-9b447bb924c4292c} 2 1295621077>
    DBG-MODULE<7E410000 00091000 "USER32.dll" "user32.pdb" 0 {d18a41b7-4e7f-458c-aaac1847e2d8bf02} 2 1208131867>

    ----------------------------------------
    Memory Dump
    ----------------------------------------

    Code: 16 bytes starting at (EIP = 10037066)

    10037066: 89 10 89 50 04 89 50 08 89 50 0C 89 50 10 5F 89 ...P..P..P..P._.


    Stack: 1024 bytes starting at (ESP = 0012F4DC)

    * = addr ** *
    0012F4D0: 00 00 00 00 00 00 00 00 00 00 00 00 08 F5 12 00 ................
    0012F4E0: 04 F5 12 00 F6 7B 03 10 B0 F5 12 00 C8 19 98 0A .....{..........
    0012F4F0: 08 F0 97 0A E5 99 03 10 08 F0 97 0A 00 00 00 00 ................
    0012F500: A0 58 1B 00 A0 58 1B 00 80 1F 1D 00 80 00 00 00 .X...X..........
    0012F510: 00 72 06 E2 00 72 06 E2 80 00 00 00 00 00 00 00 .r...r..........
    0012F520: 00 00 00 FF 00 00 00 00 A4 58 1B 00 00 00 00 00 .........X......
    0012F530: 1C F5 12 00 B0 FF 12 00 F8 0F F5 4F 01 00 00 00 ...........O....
    0012F540: 7C F5 12 00 90 9A 85 00 A4 58 1B 00 00 00 00 00 |........X......
    0012F550: 1C F5 12 00 B0 FF 12 00 08 13 F5 4F FF FF FF FF ...........O....
    0012F560: 90 F5 12 00 81 6C 85 00 A0 58 1B 00 00 00 00 00 .....l...X......
    0012F570: 00 00 00 00 02 00 00 00 00 00 00 FF 00 00 80 3F ...............?
    0012F580: 00 00 00 00 00 00 00 00 B0 FF 12 00 3B C6 07 10 ............;...
    0012F590: 00 00 00 00 0A 89 85 00 A0 58 1B 00 C8 19 98 0A .........X......
    0012F5A0: 00 00 00 00 08 F0 97 0A 78 1E 98 0A 00 00 00 FF ........x.......
    0012F5B0: D0 F5 12 00 A8 8B 85 00 01 00 00 00 08 F0 97 0A ................
    0012F5C0: C8 FA 12 00 00 04 00 00 00 00 00 00 0A D0 7F 02 ................
    0012F5D0: B0 FA 12 00 14 D0 84 00 01 00 00 00 DC 17 98 0A ................
    0012F5E0: 08 F0 97 0A 6E 76 34 5F 64 69 73 70 2E 64 6C 6C ....nv4_disp.dll
    0012F5F0: 00 00 70 00 00 00 00 00 00 00 00 00 00 00 00 00 ..p.............
    0012F600: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F610: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F620: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F630: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F640: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F650: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F660: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F670: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F680: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F690: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F6A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F6B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F6C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F6D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F6E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F6F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F700: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F710: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F720: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F730: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F740: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F750: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F760: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F770: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F780: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F790: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F7A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F7B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F7C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F7D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F7E0: 00 00 00 00 4E 56 49 44 49 41 20 47 65 46 6F 72 ....NVIDIA GeFor
    0012F7F0: 63 65 34 20 54 69 20 34 34 30 30 20 28 4D 69 63 ce4 Ti 4400 (Mic
    0012F800: 72 6F 73 6F 66 74 20 43 6F 72 70 6F 72 61 74 69 rosoft Corporati
    0012F810: 6F 6E 29 00 00 00 00 00 00 00 00 00 00 00 00 00 on).............
    0012F820: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F830: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F840: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F850: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F860: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F870: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F880: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F890: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F8A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F8B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F8C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
    0012F8D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................


    ------------------------------------------------------------------------------
    Percent memory used: 56
    Total physical memory: 1073205248
    Free physical memory: 468402176
    Page file: 2584178688
    Total virtual memory: 2147352576
    Free virtual memory: 1783365632

    Ive downloaded MBAM Avast Superantispyware and Hijack, heres my hijack log
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 10:24:52 AM, on 8/27/2011
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.21302)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Sandboxie\SbieSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Sandboxie\SbieCtrl.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\Program Files\Sandboxie\SandboxieRpcSs.exe
    C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Common Files\Java\Java Update\jucheck.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Ask.com Search Engine - Better Web Search
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = Welcome to the 2007 Microsoft Office System - Office.com
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
    O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Thunder\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AntiSpyware Service] C:\WINDOWS\TEMP\ozzr1alxix.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AntiSpyware Service] C:\WINDOWS\TEMP\ozzr1alxix.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
    O4 - Startup: Reboot.exe
    O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
    O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe

    --
    End of file - 7178 bytes

    Any help would be greatly appreciated. I just wanna play wow again

  2. #2
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello and welcome to Help2Go

    We apologize for the delay in responding to your request for help. Here at Help2Go we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

    Please take note:

    1. If you have since resolved the original problem you were having, we would appreciate you letting us know.
    2. If you are unable to create a log because your computer cannot start up successfully please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
      • If you are unsure about any of these characteristics just post what you can and we will guide you.
    3. Please tell us if you have your original Windows CD/DVD available.
    4. If you are unable to perform the steps we have recommended please try one more time and if unsuccessful alert us of such and we will design an alternate means of obtaining the necessary information.
    5. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.
    6. Upon completing the steps below another staff member will review your topic an do their best to resolve your issues.
    7. If you have already posted a DDS log, please do so again, as your situation may have changed.
    8. Use the 'Add Reply' and add the new log to this thread.


    We need to see some information about what is happening in your machine. Please perform the following scan again:

    • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
    • Notepad will open with the results.
    • Follow the instructions that pop up for posting the results.
    • Close the program window, and delete the program from your desktop.
    Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

    Information on A/V control HERE


    We also need a new log from the GMER anti-rootkit Scanner.

    Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step. Then proceed to run aswMbr.exe as noted below.

    Please first disable any CD emulation programs using the steps found in this topic:

    Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:


    Note:
    If you are unable to run a Gmer scan due the fact you are running a 64bit machine please run the following tool and post its log.

    Please download aswMBR ( 511KB ) to your desktop.
    • Double click the aswMBR.exe icon to run it
    • Click the Scan button to start the scan
    • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.




    Thanks and again sorry for the delay.
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  3. #3
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello.

    Are you still there?

    If you are please follow the instructions in my previous post.

    If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

    Please reply back telling us so. If you don't reply within 3-5 days the topic will need to be closed.

    Thanks for understanding

    With Regards,
    fireman4it
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  4. #4
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello.

    There had been no reply from the topic starter in 5 days. Due to inactivity, this topic is now closed.
    If you are the topic starter and need this topic reopened, send me a message.

    Everyone else, please begin a new topic.

    With Regards,
    fireman4it
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-