Over 1 million tech questions and answers.

kernel32 infection

Q: kernel32 infection

Deckard's System Scanner v20070711.54
Run by Philip Denton on 2007-07-23 at 15:47:21
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point
-- Last 5 Restore Point(s) --
80: 2007-07-23 07:47:45 UTC - RP1287 - Deckard's System Scanner Restore Point
79: 2007-07-23 03:08:10 UTC - RP1286 - System Checkpoint
78: 2007-07-22 01:58:48 UTC - RP1285 - System Checkpoint
77: 2007-07-21 01:40:21 UTC - RP1284 - System Checkpoint
76: 2007-07-20 01:17:30 UTC - RP1283 - Software Distribution Service 3.0


-- First Restore Point --
1: 2007-05-27 06:20:10 UTC - RP1208 - Windows Defender Checkpoint


Backed up registry hives.

Performed disk cleanup.


-- HijackThis (run as Philip Denton.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:52:41 PM, on 23/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Westnet\iConnect\launcher.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\iCBB_04_05 R11-23 WESTNET B01 Monitor Temporary Items\monSvr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Philip Denton\Local Settings\Temporary Internet Files\Content.IE5\Y2DUMS3I\dss[1].exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Philip Denton.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mywestnet.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mywestnet.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cmonitor] C:\Program Files\SystemDoctor 2006 Free\pasmon.exe
O4 - HKLM\..\Run: [T-Remover] C:\Documents and Settings\Philip Denton\trojanremover.exe +ls
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Service Centre.lnk = C:\Program Files\Westnet\iConnect\launcher.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...rch.jhtml?p=ZN
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://cdn.downloadcontrol.com/files...reeInstall.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1150100175406
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole...rcadeRdxIE.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents...r/imloader.cab
O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com
O18 - Protocol: bw+0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {37FB8D78-3815-4869-A609-1435FF2B66BC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

--
End of file - 22906 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>

S0 szkg - c:\windows\system32\drivers\szkg.sys (file missing)
S3 AX88172 (USB2.0 to Fast Ethernet Adapter) - c:\windows\system32\drivers\uc210t.sys <Not Verified; ASIX Electronics Corp.; Windows (R) 2000 DDK driver>
S3 PCASp50 (PCASp50 NDIS Protocol Driver) - c:\windows\system32\drivers\pcasp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 LicCtrlService (LicCtrl Service) - c:\windows\runservice.exe


-- Scheduled Tasks -------------------------------------------------------------

2007-07-23 12:05:08 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2007-07-21 19:26:00 316 --a------ C:\WINDOWS\Tasks\Ad-Aware SE Personal.job
2003-05-23 14:15:51 428 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job


-- Files created between 2007-06-23 and 2007-07-23 -----------------------------

2007-07-23 15:50:39 0 d-------- C:\Program Files\Trend Micro
2007-07-23 15:13:40 0 d-------- C:\ie-spyad
2007-07-23 13:19:23 0 d-------- C:\Program Files\SpywareBlaster
2007-07-15 13:26:22 0 d-------- C:\Documents and Settings\Philip Denton\Application Data\Uniblue
2007-07-13 20:13:16 0 d-------- C:\Documents and Settings\Philip Denton\Application Data\Yahoo!
2007-07-13 20:13:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-07-13 09:46:42 0 d-------- C:\Program Files\Westnet
2007-07-13 09:46:26 0 d-------- C:\Documents and Settings\All Users\Application Data\OPEN Networks
2007-07-04 16:08:10 18816 -----n--- C:\WINDOWS\system32\drivers\PCAMp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
2007-07-04 16:08:09 17664 -----n--- C:\WINDOWS\system32\drivers\PCASp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
2007-06-29 13:49:41 0 d-------- C:\Program Files\Common Files\Ankiro
2007-06-29 13:29:38 0 d-------- C:\Program Files\Common Files\Application
2007-06-29 13:25:42 0 d-------- C:\Program Files\SPAMfighter


-- Find3M Report ---------------------------------------------------------------

2007-07-23 12:01:57 857 --ahs---- C:\WINDOWS\system32\mmf.sys
2007-07-23 08:19:38 0 d-------- C:\Documents and Settings\Philip Denton\Application Data\AVG7
2007-07-22 21:52:44 1744 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-07-15 21:32:06 0 d-------- C:\Documents and Settings\Philip Denton\Application Data\LimeWire
2007-07-15 21:24:24 1632 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-07-15 18:25:54 0 d-------- C:\Documents and Settings\Philip Denton\Application Data\Canon
2007-06-29 14:48:14 0 d-------- C:\Program Files\Common Files\DriveCleaner
2007-06-23 17:32:29 0 d-------- C:\Program Files\MSN Messenger
2007-06-22 13:45:08 0 d-------- C:\Program Files\Windows Live Toolbar
2007-06-22 13:42:28 0 d-------- C:\Program Files\Java
2007-06-21 15:49:13 0 d-------- C:\Program Files\Google
2007-06-15 15:03:37 0 d-------- C:\Program Files\Trojan-Remover
2007-05-27 18:48:10 0 d-------- C:\Documents and Settings\Philip Denton\Application Data\DriveCleaner
2007-05-27 17:01:34 0 d-------- C:\Documents and Settings\Philip Denton\Application Data\SPAMfighter


-- Registry Dump ---------------------------------------------------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4efb-9B51-7695ECA05670} C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} C:\Program Files\Yahoo!\Common\yiesrvc.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar3.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"cmonitor"="C:\\Program Files\\SystemDoctor 2006 Free\\pasmon.exe"
"T-Remover"="C:\\Documents and Settings\\Philip Denton\\trojanremover.exe +ls"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"My Web Search Bar Search Scope Monitor"="\"C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\m3SrchMn.exe\" /m=0"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe"
"SPAMfighter Agent"="\"C:\\Program Files\\SPAMfighter\\SFAgent.exe\" update delay 60"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\nbj.exe\""
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"LDM"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\BackWeb-8876480.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
"Uniblue RegistryBooster 2"="C:\\Program Files\\Uniblue\\RegistryBooster 2\\RegistryBooster.exe /S"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MWSBAR"
"hkey"="HKLM"
"command"="rundll32 C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\MWSBAR.DLL,S"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NEWDOT~2"
"hkey"="HKLM"
"command"="rundll32 C:\\PROGRA~1\\NEWDOT~1\\NEWDOT~2.DLL,NewDotNetStartup -s"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



-- Hosts -----------------------------------------------------------------------

127.0.0.1 localhost #***Inserted By STOPzilla***
127.0.0.1 2005-search.com # ***Inserted By STOPzilla***
127.0.0.1 600pics.com # ***Inserted By STOPzilla***
127.0.0.1 a1.interclick.com # ***Inserted By STOPzilla***
127.0.0.1 absolutepics.net # ***Inserted By STOPzilla***
127.0.0.1 ad.yieldmanager.com # ***Inserted By STOPzilla***
127.0.0.1 all-tgp.org # ***Inserted By STOPzilla***
127.0.0.1 all-websearch.com # ***Inserted By STOPzilla***
127.0.0.1 apps.deskwizz.com # ***Inserted By STOPzilla***
127.0.0.1 awmdabest.com # ***Inserted By STOPzilla***

95 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2007-07-23 at 15:54:18 ---------

RELEVANCY SCORE 200
Preferred Solution: kernel32 infection

I recommend downloading and running DAP. It can help sort out any driver and firmware related issues on your system

It's worked out well for many of us in the past.

You can download it direct from this link http://downloaddap.org. (This link will open the download page of DAP so you can save a copy to your computer.)

A: kernel32 infection

Hello and welcome to TSF. I apologize for the delay in responding to your log.

I recommend you Subscribe to this thread so you are notified of any replies via email. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

I don't see anything particularly malicious in your log. Can you elaborate on the problem and the reason you titled your thread "kernel32 infection"?

Online Scan
Perform an online scan with Internet Explorer with Panda ActiveScan Click on located at the bottom of the page.
A "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
Enter your e-mail address, country, and state & click "Free Online Scan" *The download of the 8 MB Panda's ActiveX control will take place*
Begin the scan by selecting If it finds any malware, it will offer you a report.
Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
Click on then click
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
In your next post please include:[list][*]Panda Activescan Log

Read other 4 answers
RELEVANCY SCORE 55.2

Hello BC,I have found the internet explorer titling "Hacked by 8bits" worm infected on 3 of my computers, likely because of flash drive infection. This post will be focused on the pc in the most dire situationI was moving a .dll plugin into an audio editing program on my xp pro pc, and that was immediately followed by a system crash, with the message:STOP: C0000221 unknown hard error\systemroot\system32\ntdll.dlland When attempting to reboot, the screen shows "NTLDR is missing. Press any key to restart" I am wondering if this crash was my mistake of messing with program files, or if it was because of the kernel32.dll.vbs infections, because I found on the symantec site that this infection attempts to delete these files: * %SystemDrive%\boot.ini * %SystemDrive%\IO.SYS * %SystemDrive%\MSDOS.SYS * %SystemDrive%\NTDETECT.COM * %SystemDrive%\ntldrand recursively delete all files, folders and subfolders on all available drives excluding the following: * %Windir% * %ProgramFiles% * %SystemDrive%\Documents and Settings(quoted from this site)http://www.symantec.com/security_response/...-99&tabid=3I basically only have windows recovery console capability on this computer. Is there any hope left for her?I hope it is okay that I am removing the worm on the other computers with the advice given by quietman7 on topic 121323http://www.bleepingcomputer.com/forums/t/121323/hacked-by-8bit-on-internet-explorer-title-bar/ (I am the one who accidently passed this viru... Read more

A:Possible Infection And Crash From Kernel32.dll.vbs

If you get "NTLDR is missing, press any key to restart" what's most likely going on is the BIOS either didn't look for the right drive, didn't find the right partition, didn't find the MBR, the MBR didn't list NTLDR in the right place, a misconfiguration with the boot.ini file or the location of NTLDR changed. NTLDR should be in the root of C: (Boot) drive.NTLDR is Missing: Fix Solutions NTLDR Missing - fix using fdisk, Recovery ConsoleHow to fix: NTLDR is missing...Access/Enter Motherboard BIOSHow to enter the BIOSAccess to BIOS Setup -- instructions for most models

Read other 9 answers
RELEVANCY SCORE 36.4

Hi,

I have just done 2 full sys scans using AVG & its stating the above.
Can somebody please help in this matter.

Thanks

Sue.

PS in the RESULT/INFECTED column it says CHANGE
 

A:kernel32.dll

Hi Sue,

This is a commonly asked question on the AVG forums ......... http://forum.grisoft.cz/freeforum/read.php?2,32539,32553#msg-32553
 

Read other 3 answers
RELEVANCY SCORE 36.4

Evening Partygoers,
 Just did a clean install of XP Pro. After the install I came across the Kernel32.dll error message (when I was trying install AVG and Chrome). Thinking that there may have been a mistake on the install I did another clean install. Still the same thing so I ran the repair and still nothing.
  Using Explorer was almost impossible because I was coming across another .dll error but I updated Java and that has helped tremendously. Cannot update flash player. When I go to the webpage the middle of the screen in blank and that is where I would download flashplayer (the rest of the page is there, just not the most important part).
  Have tried to install SP3, last night when I was able to get to the webpage to download and install the PC just simply rebooted itself. Tonight the webpage would just freeze.
  The main issue, at least I think so, is the Kernel32.  Like I said this is a new, clean install.
  One last quick note, the  mshtml.dll would be the error which would cause the webpage to freeze and stop responding.
  Thank you in advance for your time and advice.

A:Kernel32.dll help PLEASE!

Please download MiniToolBox  , save it to your desktop and run it.
 
Checkmark the following checkboxes:
  List last 10 Event Viewer log
  List Installed Programs
  List Users, Partitions and Memory size.
 
Click Go and paste the content into your next post.
 
Also...please Publish a Snapshot using Speccy - http://www.bleepingcomputer.com/forums/topic323892.html/page__p__1797792#entry1797792 , taking care to post the link.
 
Louis

Read other 1 answers
RELEVANCY SCORE 36.4

kernel32.dll general protection fault in KRNL386.exe
 

Read other answers
RELEVANCY SCORE 36.4

After a hard drive crash and replacement, now trying to get operational again. Quicken 2000 gives me this error message when trying to
download stock prices:

QW caused an invalid page fault in
module KERNEL32.DLL at 016f:bff7a138.
Registers:
EAX=0ffffffc CS=016f EIP=bff7a138 EFLGS=00010206
EBX=04fa8b10 SS=0177 ESP=0100f3f8 EBP=0100f42c
ECX=ffffffff DS=0177 ESI=04fa8a70 FS=324f
EDX=00000001 ES=0177 EDI=1000009c GS=0000
Bytes at CS:EIP:
89 51 08 8b 53 08 8b 43 04 89 42 04 8d 93 0b 10
Stack dump:
0100f42c 04fa8a70 00df0000 00017090 bff7b31d 00df0000
04fa8a70 000000a0 00000200 0000030c 5f49c94c 00017090
04fa8a70 0100f474 bff7b962 00df0000

Already uninstalled and re-installed. Any thoughts?
 

RELEVANCY SCORE 36.4

I'm trying to install .Net Framework 2.0 Service Pack 1 on my computer. I run Windows 2000. I keep getting a message that says "The procedure entry point HeapSetInformation could not be located in the dynamic link library KERNEL32.dll"
Is there anything I can do? I need .Net for a game, and I have no way of updating to any kind of XP.
 

A:Kernel32 Help

Hi and welcome to TSG.
Check.
http://support.microsoft.com/kb/142606
Let us know if that helps.
 

Read other 1 answers
RELEVANCY SCORE 36.4

Can anyone tell me what Kernel32.dll mean and how I can get rid of it? Kernel32.dll keeps popping up and I just don't know how to get rid of it. Help Please.
 

A:what does Kernel32.dll mean

Hi and welcome

This link will explain what the file actually is http://www.webopedia.com/TERM/K/kernel32_dll.html

However, to determine the problem....we would need more info...like what is the exact error message you receive?
Does it pop up randomly? Or when you open a certain program?
 

Read other 2 answers
RELEVANCY SCORE 36.4

I am having problems trying to reinstall a computer played backgammon game board called "Serious Backgammon. I keep getting these messages: Bg has caused an error in KERNEL32.DLL. I've also seen this same message come up when trying to open my IE. What does this mean and can someone help.

My operating system is "ME".
 

Read other answers
RELEVANCY SCORE 36.4

I got Windows98SE and the newly-downloaded Sygate 5.5,which works fine and stealthy according to ShieldsUp,dslBroadband and Sygate own Tests.
Kernel32.dll is the first application to ask permission as soon as i get on line, and it shows in Connection Details in Port 138 (UDP) and 139 (TCP).I have blocked its requests on a day to day basis until now,as i am unsure whether a perennial block could pose problems of sorts.Is there a reason i shouldnt block it altogether?
thanks nanino
 

A:Kernel32.dll

Hi nanino,

This sounds like a virus. There are several that masquerade as kernel32.

Either run an uptodate virus scan with your own AV or go here and run the online scan.

Once done could you please download Hijack This! from here. Unzip, doubleclick HijackThis.exe, and hit "Scan". When the scan is finished, click "Save Log", and copy and paste it in a reply.

This will give us a rundown of whatís going on in your PC. One of us here will be glad to analyse it for you. Donít fix anything yourself yet, as a lot of the stuff on that list will be harmless or required.

Cheers

Liam
 

Read other 3 answers
RELEVANCY SCORE 36.4

whats up whith this file,i am starting to get a lot of illigal operations with this little devil.any fixes for him,i run win 98 first edition[have all the windows updates]on a p2 300 128 ram.
 

A:kernel32.dll

It's the windows memory manager. You will need to post exact error messages to trouble shoot.
 

Read other 3 answers
RELEVANCY SCORE 36.4

A user here has a Sony Vaio F290 with Microsift Windows 2000 Professional.
After the user logs in, at the desktop stage the folowing dialog box comes up.

The window is labelled: GUU2.tmp - entry point not found

the proceedure entry point SetHandleContext could not be located in the dymanic link library KERNEL32.DLL
Anybody knows what this is ?

Many thanks !
 

A:Kernel32.dll

Looks like they have installed a program that isn't Windows 2000 compatible and which is set to start with Windows. Have a look at this
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q300179

Best bet is to boot into safe mode and uninstall whatever it is from there. If that doesn't fix the problem, boot with the W2K CD and run the repair option to replace damaged files.
 

Read other 1 answers
RELEVANCY SCORE 36.4

For some reason anything that I try to download or sometimes even run won't work. It comes up with this error message:

The procedure entry point EncodePointer could not be located in the dynamic link library KERNEL32.dll

Worried I may have built my computer wrong? (Building up my computer from bits and bobs )

Using Windows XP

Any help will be much appreciated. Thanks
 

A:Kernel32.dll

Oops, windows Xp pro (will that change anything?!?!)
 

Read other 3 answers
RELEVANCY SCORE 36.4

When I install some programmes, the message "GLJID.tmp - Entry Point Not Found" appears and tells me that "The Procedure Entry Point SetHandleContext could not be located in the dynamic link library KERNEL32.dll". If I then try to run the application, the CD drive "whirs" and the cursor indicates that it is thinking, but then nothing. Looking on the windows 2000 pro. task manager processes I find that the it is running and using 99% of the CPU.
So that it only appears to be running in the background, nothing appears on the Applications tab.

What does it mean?
Why can't I get the programmes to run?
What can I do about it?
 

A:KERNEL32.dll

It may be a compatibility issue. Have a look here:

ErrMsg: Procedure Entry Point Could Not Be Located
 

Read other 1 answers
RELEVANCY SCORE 36.4

When I install some programmes, the message "GLJID.tmp - Entry Point Not Found" appears and tells me that "The Procedure Entry Point SetHandleContext could not be located in the dynamic link library KERNEL32.dll". If I then try to run the application, the CD drive "whirs" and the cursor indicates that it is thinking, but then nothing. Looking on the windows 2000 pro. task manager processes I find that the it is running and using 99% of the CPU.
So that it only appears to be running in the background, nothing appears on the Applications tab.

What does it mean?
Why can't I get the programmes to run?
What can I do about it?
 

A:KERNEL32.dll

I just answered you here: http://forums2.techguy.org/showthread.php?s=&postid=768936#post768936

Please do not double-post.

Cheers,
 

Read other 1 answers
RELEVANCY SCORE 36.4

I am trying to activate a linksys wireless printer and I keep receiving this error message and have no idea what to do. Any help would be appreciated.

"The procedure entry point SUnMapLS_IP_EBP_40 could not be located in the dynamic link library kernel32.dll"
Help!!!
 

A:Kernel32.dll

are you sure your computer contains the requirements of the wireless printer?

kernel32.dll is probably not the problem... I would uninstall and disconnect whatever you have loaded; recycle your computer on and off to clear.. then reconnect and reinstall software.
 

Read other 1 answers
RELEVANCY SCORE 36.4

When I try to start Norton I get this message
Memory access violation in module Kernel32 @ 6741:71586213

I have no idea what this is about. Can someone enlighten me?

Thank you in advance for your time.
 

A:Kernel32

I found the answer. I caught the Swen virus. Used symantic tool and all is well now.
jmcmullen
 

Read other 1 answers
RELEVANCY SCORE 36.4

I was downloading a program for a friend, she has windows xp. The program appeared to download, but when i went to open the program i got the error message Procedure entry point encode Pointer could not be located in the dynamic LINK LIBRARY KERNEL 32.DLL. Initially i deleted an earlier version of the program to make space for the new one. After the error msg. I tried to reload both programs (one from the disk, the other from the recycle bin). But i still got the error msg. PLEASE HELP, this isnt my computer and im afraid i messed my friends computer up> Thank you
 

A:Kernel32.dll

If you are running Windows XP and get the error message "The procedure entry point decodepointer could not be located in the dynamic link library KERNEL32.dll.", you will need to install Windows XP service pack 2 or 3.
 

Read other 1 answers
RELEVANCY SCORE 36.4

I've been getting a lot of trouble with my computer lately; specifically, the desktop will disappear and show nothing but my background, then reappear, but some things in the taskbar tray will be gone, including Norton. Some programs reappear, but Norton never does until I restart. First off, is this Explorer crashing?
I'll get error reports from time to time that include the file:

C:\Docume~1\ChrisL~\Locals~1\Temp\WER5.tmp.dir00\appcompat.txt

I've done a search of the appcompat.txt to no success, so I tried searching the file and found this inside of it:

EXE NAME="SYSTEM INFO" FILTER="GRABMI_FILTER_SYSTEM">
<MATCHING_FILE NAME="advapi32.dll" SIZE="558080" CHECKSUM="0x7B6E5DDA" BIN_FILE_VERSION="5.1.2600.1106"

I did a search for this line:

EXE NAME="SYSTEM INFO" FILTER="GRABMI_FILTER_SYSTEM">

And discovered that someone else has the EXACT same problem as me (seemingly).

http://www.mcse.ms/archive64-2003-12-230972.html

The file he copied and pasted resembles mine from what I can see exactly. So, I followed the lead given to him to this:

http://aumha.org/win4/a/kernel32.htm

And discovered the problem may be the kernel32.dll or something. The problem is I'm fairly computer illiterate and am not sure how to fix this problem, or even ensure that the kernel32.dll IS the problem. I'm at the end of my rope, so please, any assistance provided would be GREATLY ... Read more

A:Kernel32.dll???

Read other 13 answers
RELEVANCY SCORE 36.4

hi, can somebody please help?i have recently been having problems with my pc starting up very slowly,i done an avg virus scan and it says that there had been a change with kernel32.dll,user32.dll,shell32.dll and ntoskrnl.exe i reformatted my pc and installed avg.when i ran a scan there were no problems before i installed anything else i installed windows updates once they were all installed i ran avg virus once again and it found the same changes i rebooted my pc and it was once again very slow starting up.can anybody please help with any advice.many thanks
 

A:kernel32.dll

The changed files are normal. It happens when you update certain parts of Windows and when the system repairs files.
 

Read other 3 answers
RELEVANCY SCORE 36.4

can someone plese tell me waht KERNEL32.DLL. is, i keep gettin it in an error:

Explorer
Explorer has caused an error in KERNEL32.DLL.
Explorer will now close

if you continue to experience problem,
try restarting your computer
 

A:Kernel32.dll.

What o\s ?

What is the EXACT error message ?

http://www.generation.net/~hleboeuf/errexplo.htm#ERRKERNEL32.DLL

steam
 

Read other 3 answers
RELEVANCY SCORE 36.4

What is kernel32.dll?

A:Kernel32.dll

The definition of Kernel32.dll is Here in our File Database. Kernel32.dll is the 32-bit dynamic link library found in the Windows operating system kernel.It handles memory management and input/output operations.

Read other 2 answers
RELEVANCY SCORE 36.4

Hello,
I have just uninstalled a demo copy of Trend Micro internet security in order to use a different anti-virus program. After the uninstall was complete and the computer rebooted, I tried to access my C: directory with "My Computer" and an error popped up that was from Windows Script Host. It read "Can not find script file C:\kernel32.dll.vbs (screen shot below).
I was able to access the C: directory when uploading a file and none of my programs seem to be affected.
I searched this error but I found nothing specific to this error.
I did a system restore to before the time I uninstalled Trend Micro but that didn't fix it.
If someone could help that would be great. Thanks
 

A:kernel32.dll.vbs

Read other 6 answers
RELEVANCY SCORE 36.4

My sister's computer seems to have some sort of virus. It shows a blue screen with "kernel32" and then gets taken over by pop ups. Could anyone please help us???
 

A:kernel32??pop-ups..HELP!!

* Click here to download HJTsetup.exe.
Save HJTsetup.exe to your desktop.

Double click on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
Put a check by Create a desktop icon then click Next again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click Finish and it will launch Hijack This.
Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
Click Save to save the log file and then the log will open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
 

Read other 1 answers
RELEVANCY SCORE 36.4

My computer keeps throwing a KERNEL32.DLL error on random web pages and knocks me off line.

Does anyone have any ideas on how to fix this?
 

A:kernel32.dll

Try running a scan for spyware, which is one of the most common causes. Ad-aware will both detect and remove them. Read the 'getting started" and FAQ pages before running it and know how to restore from the backup it creates if necessary.

http://www.lavasoftusa.com/

Have you run an updated antivirus scan? If you don't have a scanner you can do an online one here:

http://housecall.antivirus.com/pc_housecall/

If Ad-Aware doesn't resolve the problem for you, click the "details" tab of the error messages and post the modules and addresses here.
 

Read other 2 answers
RELEVANCY SCORE 36.4

Hi I need some help
all of a sudden today my desktop changed into an html file that Says System Stopped in a black box with a horrible bright blue font in the background.
In my Systems folder I have a kernels32.exe that I imagine is the problem.
Also my Task Manager (Ctrl-Alt-Del is not working it says my administrator has blocked it)
Besides this I also keep getting a Spy Ware Cleaner some sort of program that installs itself and I keep uninstalling it and everytime I restart it pops up again. Also my Norton Antivirus detects no virus when I run a full system scan, but when I restart it pops up and finds tons of them automatically , I'm assuming these virus/trojans or whatever pop up after a program initiates them. I've downloaded the Hijack program in hopes someone can help me. I'm very good with computers and have never had a problem before, but after trying with msconfig, regedit, and safe mode I have had no success please if someone can help me would be great.

Logfile of HijackThis v1.99.1
Scan saved at 1:45:17 PM, on 6/19/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:... Read more

A:need some help with kernel32.exe and other

Hello alvarowong and Welcome to TSF it looks as though you have been hijacked. I'm not an expert at this so I will direct you here http://www.techsupportforum.com/showthread.php?t=15968 and follow instructions carefully. Good Luck!!

Read other 1 answers
RELEVANCY SCORE 36

I get this messge when I try to scan w/ my hp scanner. I t says some other application is using all the menory and to wait until it's done!! I have no idea what that means. It has worked great until I started to get Norton Utilites 2002 loaded, a disaster. so I unistalled that and put my NU2000 back in and that works fine.
I tried using "acquire" from my print shop 12 program bec I want to scan some cards and I get that error. this has never happened before. How do I fix this?
 

A:kernel32.dll error

Read other 9 answers
RELEVANCY SCORE 36

Hi

AVG has recently been detecting kernell32 along with a few other files and states that it has changed it. I uninstalled AVG and installed McAfee but then carried out a system restore to before I uninstalled it thinking all would be ok. Now on start up I get the error message that it cannot find the AVG kernel interface and cannot run. I now cannot start avg or uninstall it.
Does anyone have any answers as to what is going on or how to repair kernel32?

Thanks

Vini88
 

Read other answers
RELEVANCY SCORE 36

I tried to access my Word200o program yesterday and my PC said resources dangerously low and locked up. I tried uninstalling some unnecessary software with no help. Today I reinstalled Word and I get the error message: "The wkfud.exe file is linked to missing export kernel32.dll: Get CommndLicneW." The kernel file is still under my windows/system file, but don't know what to do next?
I can access all my other software programs, but not Word. Any ideas?
Mariboo
 

Read other answers
RELEVANCY SCORE 36

Hello i am trying to play wow. i JUST reinstalled windows and put wow on it immediately but when i try to play i get

"The procedure entry point MakeCriticalSectionGlobal could not be located in the dynamic link library KERNEL32.dll"

While researching ive learned this is not specific to the game but hapens while trying to run other things too. everything works fine for me except wow and i would like to kow if anyone can help me.

PS: i checked my windows folder and kernel 32 IS there. i downloaded another copy of kernel32 from a secure site and tried replacinf it but it wont let me

PSS: The old file and the new kernel 32 are different sizes if that matters.

A:OMG im going crazy tried everything. Kernel32

Do not install Kernel.32!! this may kill your PC. Uninstall the game and reinstall it.

Read other 2 answers
RELEVANCY SCORE 36

I bought a refurbished Dell optiplex (terrible idea) that's had some serious problems with the reloaded windows it came with. I performed a virus scan with Avira Antivir PE and it found a figurative ton of viruses. One infected file was kernel32.dll, and not knowing better, I authorized the program to delete it. Now i get a blue screen at startup that says: stop: c0000135 {unable to locate component} which is apparently kernel32.dll. I got this computer refurbished and reloaded with windows, and I don't think I ever got a reboot disk. How do I get a copy of kernel32.dll to replace so I can into windows again?

Any help would be REALLY appreciated.

Thanks alot,

Kevin

A:kernel32.dll replacement

You will need an XP CD. You can then try to perform a Repair. But if it's infected, I'd just format and reinstall from scratch.

Read other 1 answers
RELEVANCY SCORE 36

I spoke too soon didn't I...

Now I'm getting error messages again when I start Photoshop7 which are different to the ones before

"Photoshop has cased an error in KERNEL32.DLL
Photoshop will now close.

If you continue to experience problems try restarting your computer"

"Could not initialize Photoshop because there is not enough memory (RAM)"

I cna't uninstall all the fonts because I need them... ARRRGHHHH!!! PLEASE help this is rediculous!

It has been perfect for the last 2 days...
 

A:KERNEL32.DLL problem

Read other 6 answers
RELEVANCY SCORE 36

Hi.

Last month my brother had downloaded few games but non of them worked because of dll errors. First i thought its because they were downloaded from pirate sites. But now, i am getting 2 dll errors when i launch World of Tanks (game that was downloaded from official site). I have never had before such an issue with that game but regardless those errors i was still able to play it. Now i have downloaded another game (from official site too) and when i try to launch it, error happens. It says "The procedure entry point GetLogicalProcessorInformation could not be located in the dynamic link library KERNEL32.dll."

I tried to re-register the file but it failed. It said the file was loaded but the DllRegisterServer entry point was not found. I would appreciate if someone would help me fix this problem.
 

Read other answers
RELEVANCY SCORE 36

My computer keeps popping up an error message saying: This program has performed an illegal operation and will shut down.

When I click on details it says: SDKAU caused an invalid page fault in module KERNEL32.DLL.

Could you please help me with this problem? Thanks
 

A:Sdkau + Kernel32.dll

Read other 6 answers
RELEVANCY SCORE 36

Whenever I try to start up an up, such as MSN Messenger, Xfire, Worms World Party, I always get this error :

The procedure entry point Makecriticalsectionglobal could not be found in the dynamic link library Kernel32.dll

I've tried :

1) Going to dll-files.com to replace my dll, didn't work
2) Going to dlldump.com to replace my dll, didn't work again.
3) Replace from my own dll cache, and didn't work.

It's really annoying, can someone help me?

A:Kernel32.dll Prob

This error explains a problem with accessing kernel32.dll. It could be a problem with that dll, or it could be a problem with the way that another program tries to access the Makecriticalsectionglobal entry point.The most common cures for this "generic" error (we'd need more info to pin it down) are:1) Scan your system for malware ( free at http://safety.live.com/ )2) Visit Windows Update and obtain all the latest updates3) Update your motherboard/chipset drivers4) Update your video card driver5) Ensure that you Direct X is updated ( http://www.microsoft.com/downloads/details...6a-9b6652cd92a3 )

Read other 13 answers
RELEVANCY SCORE 36

Hi folks, I have AVG anti-virus (http://free.grisoft.com/) and when it does its daily scheduled scan (which is normally when when I turn the PC on for the first time that day) it always says that kernel32.dll has "changed". It doesn't say it's infected or damaged or anything, just that it's changed, and there are no pop-up warnings such as when a file becomes infected. I'm running winxp home, is this an issue?

Thanks in advance for your help, my system specs are:

asus a8n-e
athlon64 3500+ venice
1gb ram
geforce 7800gt oc
windows xp home

A:Avg Keeps Saying Kernel32.dll Has "changed"...

Reported changes in system files such as kernel32.dll, wsock32.dll, user32.dll, shell32.dll and ntosknrl.exe are normal for AVG.There are many valid reasons for those files to show changed, a Windows update, file system check that replaced them if corrupted, and others. As long as AVG doesn't say they are infected it is ok. If it continues to show changed, delete the following file(s) in the C:\ directory and AVG will create a new one(s)...AVG7DB_F.DAT, AVG7QT.DATkernel32.dll, wsock32.dll, user32.dll, shell32.dll and ntosknrl.exe have "changed"It is normal that AVG shows that files, the MBR or Boot record to have changed. These are done during normal maintainance, when you or windows updates files or have had to correct errors on the drive. The only time that you should worry is if they also show as infected.To get AVG to quit showing them as changed, open the AVG Test Center, click the F3 key on your keyboard and tell it to accept the changes. If it still shows something as changed after this.. delete the file named AVG7QT.DAT in the %ALLUSERSPROFILE%\Application Data\avg7\ folder and AVG will rebuild it the next time it is run.The %ALLUSERSPROFILE% is different for each version of Windows. The following are the typical locations for XP and Win9xXP - C:\Documents and Settings\All Users\Application Data\avg7Win9x -C:\Windows\All Users\Application Data\avg7Changed File Alerts

Read other 3 answers
RELEVANCY SCORE 36

Whenever i try to run this program (Maplestory) i get this protection error, looks like this:

Protection Error
Error: Can't load library, KERNEL32.dll

i've tried system recovery, system restore, deleteing the stupid thing and downloading it, i've tried deteling anything that might have ANYTHING to do with the program.
I also tried to download KERNEL32.dll from somewhere to replace the one in my WINDOWS/SYSTEM file but they wont let me.

also tried praying..

nothing seems to work. CAN ANYONE HELP ME?

p.s: i realllllyyy realyrealyrealy dont want to format my computer.
 

A:KERNEL32.dll error

Read other 12 answers
RELEVANCY SCORE 36

I can't believe I have the same exact problem at the same time!!

No other scanners are picking up on this.

My system was infected by other virus/mal-spyware issues that were resolved.

System is running stable.

Anybody know if this is a false positive?

A:detected kernel32.dll,by A Sq.

Thanks for the quick response. Here is my log. Looks like just a couple leftover registry entries to me, like I said I did have other infections that were cleaned but a-squared insists on finding this last one but can't fix it.

Malwarebytes' Anti-Malware 1.34
Database version: 1878
Windows 5.1.2600 Service Pack 2

3/20/2009 6:09:13 PM
mbam-log-2009-03-20 (18-09-13).txt

Scan type: Quick Scan
Objects scanned: 80065
Time elapsed: 17 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterAntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterFirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Read other 3 answers
RELEVANCY SCORE 36

Whenever i try to run this program (Maplestory) i get this protection error, looks like this:

Protection Error
Error: Can't load library, KERNEL32.dll

i've tried system recovery, system restore, deleteing the stupid thing and downloading it, i've tried deteling anything that might have ANYTHING to do with the program.
I also tried to download KERNEL32.dll from somewhere to replace the one in my WINDOWS/SYSTEM file but they wont let me.

also tried praying..

nothing seems to work. CAN ANYONE HELP ME?

p.s: i realllllyyy realyrealyrealy dont want to format my computer.
 

A:KERNEL32.dll error

bump
 

Read other 2 answers
RELEVANCY SCORE 36

Trying to install TweakUI in Win XP and get the following message.

"The procedure entry point GetDirectoryW could not be located in the dynamic link library KERNE32.dll."

Downloaded a new TweakUI.exe file from Windows PowerToys site thinking perhaps the file I had on CD was corrupted, but no joy.

KERNEL32.dll is, in fact, present in the system 32 folder. So I don't know what the problem is. I suspect the existing file may be corrupted. Any thoughts on downloading a new KERNEL32.dll file and replacing the existing one? If so, anyone have a link to do so?

Any other thoughts or ideas would be appreciated.

BTW... I just finished a format and clean install of XP on this system.

Raybro
 

A:TweakUI and Kernel32.dll

Read other 7 answers
RELEVANCY SCORE 36

how can i terminate this error??because of this error i am unable to install TweakUI.
thanks
 

A:KERNEL32.dll Error??!

and also this message is appeare:"The produce entry point GetllDirectoryW could not be located in the dynamic link library KERNEL32.dll."
 

Read other 1 answers
RELEVANCY SCORE 36

I have an game.(pharaoh's expansion cleopatra)
when i want to start it is gives me an error saying that i need "FT_Thunk (KERNEL32.dll)" can you help me?

If you do know please give me an download link thank you

A:FT_Thunk (KERNEL32.dll)

First link in Google
Looks like a few have the same problem. here was one fix

Quote:




Right click on pharaoh.exe. Select property mode and click on compatibilty mode. Set it to win 2000. Mine works!

Read other 9 answers
RELEVANCY SCORE 36

when I try to open win movie maker and video explosion, both editing programs, i get error that windows has encountered a problem and the program will be shut down...in tech details of the error report that is sent to microsoft it says: Modname kernel32.dll
it only happens with these 2 programs...any advice??

Read other answers
RELEVANCY SCORE 36

First and foremost: Sorry if this sounds jumbled.

So, I play a game called Horizons, Empire of Istaria, which just so happens to not be "Vista Compatible." It requires net framework 1, and vista has framework 3. I followed some installation steps through their website:
http://support.istaria.com/support-c...mod_id=2&id=37

And got it to work eventually. Now, as of today, the game has stopped working. It loads its patcher and then I get a "End program" window displaying this message:
Problem Event Name: APPCRASH
Application Name: horizons.exe
Application Version: 0.0.0.0
Application Timestamp: 44a31023
Fault Module Name: kernel32.dll
Fault Module Version: 6.0.6000.16386
Fault Module Timestamp: 4549bd80
Exception Code: c0000005
Exception Offset: 00047369
OS Version: 6.0.6000.2.0.0.768.3
Locale ID: 1033
Additional Information 1: cf58
Additional Information 2: c7028b6e50da49b2b2ad57bc3b02444f
Additional Information 3: b30a
Additional Information 4: e85a8bb0e8f400f3158fc20ee62b094d

I've contacted Toshiba and windows and followed their recovery steps, with no success. I then REFORMATTED my computer and re-downloaded the game, to still get errors. Is there any way to fix this and get rid of the errors?

A:APPCRASH kernel32.dll

Quote:





Originally Posted by MaxMackey


First and foremost: Sorry if this sounds jumbled.

So, I play a game called Horizons, Empire of Istaria, which just so happens to not be "Vista Compatible." It requires net framework 1, and vista has framework 3. I followed some installation steps through their website:
http://support.istaria.com/support-c...mod_id=2&id=37

And got it to work eventually. Now, as of today, the game has stopped working. It loads its patcher and then I get a "End program" window displaying this message:
Problem Event Name: APPCRASH
Application Name: horizons.exe
Application Version: 0.0.0.0
Application Timestamp: 44a31023
Fault Module Name: kernel32.dll
Fault Module Version: 6.0.6000.16386
Fault Module Timestamp: 4549bd80
Exception Code: c0000005
Exception Offset: 00047369
OS Version: 6.0.6000.2.0.0.768.3
Locale ID: 1033
Additional Information 1: cf58
Additional Information 2: c7028b6e50da49b2b2ad57bc3b02444f
Additional Information 3: b30a
Additional Information 4: e85a8bb0e8f400f3158fc20ee62b094d

I've contacted Toshiba and windows and followed their recovery steps, with no success. I then REFORMATTED my computer and re-downloaded the game, to still get errors. Is there any way to fix this and get rid of the errors?







Hello and Welcome to the Tech Support Forum.

I followed the link that you provided in your post.... Read more

Read other 2 answers
RELEVANCY SCORE 36

I keep getting a kernel32.dll error when using AIM. I have uninstalled and reinstalled a few times after clearing all folders and files related to AIM. The program loads fine but when I click on a username to message someone, I get the error report. What can I do?

A:kernel32.dll error

AOL's recommendations are:
http://www.aol.com/support/index.adp...nnect&page=078

Read other 1 answers
RELEVANCY SCORE 36

Received the following error message on a Win98se system.
Any ideas as to what the cause could be?

The application overflowed its temporary memory area.

Module Name: KERNEL32.DLL
Description: Win32 Kernel core component
Version: 4.10.2222
Product: Microsoft(R) Windows(R) Operating System
Manufacturer: Microsoft Corporation

Application Name: Act.exe
Description: ACT! 5.0 Application
Version: 5.0.3.423
Product: ACT! for Windows
Manufacturer: Interact Commerce Corporation

Rich
 

A:Kernel32 error

http://iaweb1.saleslogix.com/ask/As...origin%>&snapshot=<%=snapshot%>&metasearch=no
 

Read other 1 answers