- The instruction at "0x009a96bc" referenced memory at "0x00000000". The memory could not be "written".
- Posted by Double Agent 1118 on November 14th, 2004
I'm getting this error:
The instruction at "0x009a96bc" referenced memory at "0x00000000". The
memory could not be "written".
I have ran Ad-aware, Spy-bot, NAV, and McAfee and still do not have
the problem solved. If any help, it would be much appreciated. Thanks.
Oh, and here is my HijackThis log. HELP!!!!!!!
Logfile of HijackThis v1.98.2
Scan saved at 4:01:43 PM, on 11/14/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security
Center\SymWSC.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GS662\LOCALS~1\Temp\Rar$EX00.557\Hijac kThis.exe
C:\WINDOWS\system32\HPZinw12.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.toshiba.com/search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://toshibadirect.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://toshibadirect.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet
Settings,ProxyServer = 168.94.74.68:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
- C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -
C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -
C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program
Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program
Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program
Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TouchED] C:\Program
Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program
Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program
Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program
Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
- (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}
- C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
- http://v5.windowsupdate.microsoft.co...?1099553535622
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
(MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/Ms...Downloader.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} -
C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
- Posted by philo on November 14th, 2004
Double Agent 1118 wrote:
run a ram test
you can google for memtest86
- Posted by Toolman Tim on November 14th, 2004
Um, mister double agent, *when* do you get that message? Are you surfing the
net, are you printing from your word processor, are you staring at naked
ladies on the screen? It seems to be just a little hard to tell from
here...turn up the brightness on the monitor (or the user...) please...
"Double Agent 1118" <villegas.rod@gmail.com> wrote in message
news:850b0f91.0411141407.143a9027@posting.google.c om...
| I'm getting this error:
| The instruction at "0x009a96bc" referenced memory at "0x00000000". The
| memory could not be "written".
|
| I have ran Ad-aware, Spy-bot, NAV, and McAfee and still do not have
| the problem solved. If any help, it would be much appreciated. Thanks.
| Oh, and here is my HijackThis log. HELP!!!!!!!
|
|
|
|
| Logfile of HijackThis v1.98.2
| Scan saved at 4:01:43 PM, on 11/14/2004
| Platform: Windows XP SP2 (WinNT 5.01.2600)
| MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
|
| Running processes:
| C:\WINDOWS\System32\smss.exe
| C:\WINDOWS\system32\winlogon.exe
| C:\WINDOWS\system32\services.exe
| C:\WINDOWS\system32\lsass.exe
| C:\WINDOWS\system32\svchost.exe
| C:\WINDOWS\System32\svchost.exe
| C:\WINDOWS\System32\S24EvMon.exe
| C:\WINDOWS\system32\spoolsv.exe
| C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
| C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
| C:\WINDOWS\System32\DVDRAMSV.exe
| C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
| C:\Program Files\Norton AntiVirus\navapsvc.exe
| C:\WINDOWS\System32\nvsvc32.exe
| C:\WINDOWS\System32\RegSrvc.exe
| C:\Program Files\Norton AntiVirus\SAVScan.exe
| c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
| C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
| C:\Program Files\Common Files\Symantec Shared\Security
| Center\SymWSC.exe
| C:\WINDOWS\system32\ZCfgSvc.exe
| C:\WINDOWS\Explorer.EXE
| C:\WINDOWS\System32\1XConfig.exe
| C:\WINDOWS\AGRSMMSG.exe
| C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
| C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
| C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
| C:\WINDOWS\System32\00THotkey.exe
| C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
| C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
| C:\Program Files\Common Files\Symantec Shared\ccApp.exe
| C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
| C:\WINDOWS\system32\TFNF5.exe
| C:\WINDOWS\system32\TPSMain.exe
| C:\WINDOWS\system32\dla\tfswctrl.exe
| C:\toshiba\ivp\ism\pinger.exe
| C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
| C:\WINDOWS\system32\TPSBattM.exe
| C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
| C:\WINDOWS\system32\RAMASST.exe
| C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
| C:\Program Files\Messenger\msmsgs.exe
| C:\Program Files\WinRAR\WinRAR.exe
| C:\DOCUME~1\GS662\LOCALS~1\Temp\Rar$EX00.557\Hijac kThis.exe
| C:\WINDOWS\system32\HPZinw12.exe
|
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
| http://www.toshiba.com/search
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
| http://toshibadirect.com/
| R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
| http://toshibadirect.com/
| R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet
| Settings,ProxyServer = 168.94.74.68:8080
| O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
| - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
| O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
| C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
| O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -
| C:\WINDOWS\system32\dla\tfswshx.dll
| O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -
| C:\Program Files\Norton AntiVirus\NavShExt.dll
| O3 - Toolbar: Norton AntiVirus -
| {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton
| AntiVirus\NavShExt.dll
| O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
| C:\WINDOWS\System32\NvCpl.dll,NvStartup
| O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
| O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
| O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program
| Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
| O4 - HKLM\..\Run: [SynTPLpr] C:\Program
| Files\Synaptics\SynTP\SynTPLpr.exe
| O4 - HKLM\..\Run: [SynTPEnh] C:\Program
| Files\Synaptics\SynTP\SynTPEnh.exe
| O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
| O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
| O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
| O4 - HKLM\..\Run: [TouchED] C:\Program
| Files\TOSHIBA\TouchED\TouchED.Exe
| O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
| Shared\ccApp.exe"
| O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
| O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
| O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
| O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
| O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
| O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program
| Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
| O4 - HKLM\..\Run: [HP Component Manager] "C:\Program
| Files\HP\hpcoretech\hpcmpmgr.exe"
| O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
| Files\HP\Digital Imaging\bin\hpqtra08.exe
| O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program
| Files\HP\Digital Imaging\bin\hpqthb08.exe
| O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
| O8 - Extra context menu item: E&xport to Microsoft Excel -
| res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
| - (no file)
| O9 - Extra 'Tools' menuitem: Sun Java Console -
| {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
| O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
| C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
| O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
| C:\WINDOWS\System32\Shdocvw.dll
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}
| - C:\Program Files\Messenger\msmsgs.exe
| O9 - Extra 'Tools' menuitem: Windows Messenger -
| {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
| Files\Messenger\msmsgs.exe
| O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
| O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
| -
http://v5.windowsupdate.microsoft.co...?1099553535622
| O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
| (MsnMessengerSetupDownloadControl Class) -
| http://messenger.msn.com/download/Ms...Downloader.cab
| O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} -
| C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
- Posted by 127.0.0.1 on November 14th, 2004
"Double Agent 1118" <villegas.rod@gmail.com> wrote in message
news:850b0f91.0411141407.143a9027@posting.google.c om...
i'm too lazy to read your log file...
instead, try this: chkdsk /r | defrag
before doing so, disk cleanup and delete unnecessary files (temp)
if certain temp files are being stubborn, try deleting in safe mode.
and if you still have problems, uninstall NAV and McAfee
and if you ask Microsoft, updating and installing the latest patches will
fix everything.
if i was you, reformat and ghost up the fresh OS/system
-a|ex
- Posted by °Mike° on November 14th, 2004
On 14 Nov 2004 14:07:14 -0800, in
<850b0f91.0411141407.143a9027@posting.google.com >
Double Agent 1118 scrawled:
Try the fix here:
"The instruction at 0x77f41d24 referenced memory at 0x00000000.
The memory could not be written" access violation error message in
Smlogsvc.exe when you use Performance Logs and Alerts on a
Windows XP-based computer
http://support.microsoft.com/?kbid=840114
There are many more possibilities:
http://www.google.com/search?q=%22me... microsoft.com
Check that the above proxy settings are correct.
Have HijackThis fix the above.
Have HijackThis fix the above.
Have HijackThis fix the above.
--
Basic computer maintenance
http://uk.geocities.com/personel44/maintenance.html
- Posted by Ron Martell on November 15th, 2004
villegas.rod@gmail.com (Double Agent 1118) wrote:
That sort of error usually indicates a programming fault, such as when
the program attempts to read information from a a value that has not
been initialized or previously written to. One example would be
where the program contains a look up table of 12 items and somehow the
program attempts to read a 13th item from that table.
You need to determine which program is involved, which may require
identifying which program is assigned the memory address 0x009a96bc.
Good luck
Ron Martell Duncan B.C. Canada
--
Microsoft MVP
On-Line Help Computer Service
http://onlinehelp.bc.ca
"The reason computer chips are so small is computers don't eat much."
- Posted by ~Joanne420~ on November 15th, 2004
Hey Duncan, White Rock says "Hello!" Us Canadians are a friendly people! lol

"Ron Martell" <ron.martell@gmail.com> wrote in message
news:29jgp0dsc22jc4sr1h5tm35bgu130ndcf1@4ax.com...
| villegas.rod@gmail.com (Double Agent 1118) wrote:
|
| >I'm getting this error:
| >The instruction at "0x009a96bc" referenced memory at "0x00000000". The
| >memory could not be "written".
| >
| >I have ran Ad-aware, Spy-bot, NAV, and McAfee and still do not have
| >the problem solved. If any help, it would be much appreciated. Thanks.
| >Oh, and here is my HijackThis log. HELP!!!!!!!
| >
|
| That sort of error usually indicates a programming fault, such as when
| the program attempts to read information from a a value that has not
| been initialized or previously written to. One example would be
| where the program contains a look up table of 12 items and somehow the
| program attempts to read a 13th item from that table.
|
| You need to determine which program is involved, which may require
| identifying which program is assigned the memory address 0x009a96bc.
|
| Good luck
|
|
| Ron Martell Duncan B.C. Canada
| --
| Microsoft MVP
| On-Line Help Computer Service
| http://onlinehelp.bc.ca
|
| "The reason computer chips are so small is computers don't eat much."