Hi
I started to have a problem for which I can not find any explanation, the
following group of pop-ups start coming up every time I start computor or
close those pop-ups(cannot reproduce a picture sorry)

Header: 16 bit MS-DOS Subsystem
Text: C:\DOCUME~1\ADMINI~1\23r6d.exe
The NTVDM CPU has encountered an illegal instruction.
CS:0544 IP:01fb OP:63 6f 6c 6f 72 Choose 'Close' to terminate
the application

I followed the address and have found a lot of .exe files (as the one in the
address above), all of which are 4 KB in size, and I think there are 2 more
files which are belong to this group - ntuser.dat.LOG and ntuser.dat.
I don't have a clue what is happened here? May be OS (XP PRO, no service
packs - this PC is more than 4 years old and can not handle SP2) problem, may
spyware or virus - Scanned with AD-WARE, Spybot, and Microsoft Antispyware
Beta - nothing helps.
Please help.
Deeply appreciate for any inside info/suggestions.
Garry

P.S. Those pop-ups looks like appearing in certain standard intervals...

Re: Annoying pop-ups by Roger

Roger
Sat Feb 11 00:53:08 CST 2006

ntuser.dat.LOG and ntuser.dat are system files that are part of
your account profile (reg data).
You should leave those alone.
I cannot imagine a 2 year old system being insufficient for
loading service packs, and I am loath to imagine the state
of a machine that has been internet active without any
XP service packs. You may be best off by rebuilding the
system from a fresh format on up, including installing SP2
and turning on the firewall before the machine is first connected
to the network.

"Garry" <Garry@discussions.microsoft.com> wrote in message
news:84A0F1C7-7E9F-4332-ABA7-35E488C84FC5@microsoft.com...
> Hi
> I started to have a problem for which I can not find any explanation, the
> following group of pop-ups start coming up every time I start computor or
> close those pop-ups(cannot reproduce a picture sorry)
>
> Header: 16 bit MS-DOS Subsystem
> Text: C:\DOCUME~1\ADMINI~1\23r6d.exe
> The NTVDM CPU has encountered an illegal instruction.
> CS:0544 IP:01fb OP:63 6f 6c 6f 72 Choose 'Close' to terminate
> the application
>
> I followed the address and have found a lot of .exe files (as the one in
> the
> address above), all of which are 4 KB in size, and I think there are 2
> more
> files which are belong to this group - ntuser.dat.LOG and ntuser.dat.
> I don't have a clue what is happened here? May be OS (XP PRO, no service
> packs - this PC is more than 4 years old and can not handle SP2) problem,
> may
> spyware or virus - Scanned with AD-WARE, Spybot, and Microsoft Antispyware
> Beta - nothing helps.
> Please help.
> Deeply appreciate for any inside info/suggestions.
> Garry
>
> P.S. Those pop-ups looks like appearing in certain standard intervals...



Re: Annoying pop-ups by Garry

Garry
Sat Feb 11 03:13:26 CST 2006

Hi.
Appreciate the quick response. However, I hoped for at least a hint of what
might have happened instead of an advice to rebuild my machine. Yes, this
machine is not that powerful - it's only Celeron 600 Mhz 320 MB SDRAM,
manufactured December 1999, with WinME originally installed. I've installed
WinXP PRO on that machine more than a year ago, and didn't have any
significant problems. And, yes, it did work just fine without the SP2 (i
tried to install that, but that slowed down my system a lot, which was
unacceptable), so, you, probably, should refrain from loathing my poor old
machine that much.
I gather, Roger, that you don't have any idea what is happening to my
machine, and, frankly, i'm totally flabbergasted why you just don't admit it
or refer me to someone more knowledgeable/experienced.
I strongly hope that Microsoft does have competent engineers to provide some
insight into my problem.
If moderators of this discussion group think that my topic should be moved
to a different subcategory/discussion group - please, by all means, do so.
Your help is greatly appreciated.
Garry

"Roger Abell [MVP]" wrote:

> ntuser.dat.LOG and ntuser.dat are system files that are part of
> your account profile (reg data).
> You should leave those alone.
> I cannot imagine a 2 year old system being insufficient for
> loading service packs, and I am loath to imagine the state
> of a machine that has been internet active without any
> XP service packs. You may be best off by rebuilding the
> system from a fresh format on up, including installing SP2
> and turning on the firewall before the machine is first connected
> to the network.
>
> "Garry" <Garry@discussions.microsoft.com> wrote in message
> news:84A0F1C7-7E9F-4332-ABA7-35E488C84FC5@microsoft.com...
> > Hi
> > I started to have a problem for which I can not find any explanation, the
> > following group of pop-ups start coming up every time I start computor or
> > close those pop-ups(cannot reproduce a picture sorry)
> >
> > Header: 16 bit MS-DOS Subsystem
> > Text: C:\DOCUME~1\ADMINI~1\23r6d.exe
> > The NTVDM CPU has encountered an illegal instruction.
> > CS:0544 IP:01fb OP:63 6f 6c 6f 72 Choose 'Close' to terminate
> > the application
> >
> > I followed the address and have found a lot of .exe files (as the one in
> > the
> > address above), all of which are 4 KB in size, and I think there are 2
> > more
> > files which are belong to this group - ntuser.dat.LOG and ntuser.dat.
> > I don't have a clue what is happened here? May be OS (XP PRO, no service
> > packs - this PC is more than 4 years old and can not handle SP2) problem,
> > may
> > spyware or virus - Scanned with AD-WARE, Spybot, and Microsoft Antispyware
> > Beta - nothing helps.
> > Please help.
> > Deeply appreciate for any inside info/suggestions.
> > Garry
> >
> > P.S. Those pop-ups looks like appearing in certain standard intervals...
>
>
>

Re: Annoying pop-ups by Roger

Roger
Sat Feb 11 04:12:41 CST 2006

Garry,

First, I am mostly a server person, with desktop systems being only
something I have to get into. There are others with ability to provide
more detailed advise on how to, or whether it is possible to, clean up
the machine.

Notice that these forums are entire volunteer and unmoderated.

Anyway, it just seemed to me that if XP could be installed at all on
a machine then it could accept SP2 unless it had an very small amount
of free disk space on the boot drive. From the specs you mention I
would think SP2 would run as well as XP Gold, but a small boost in
RAM could likely yield a sizable preceived increase in performance
and responsiveness. While 600 Mhz seems small by today's speeds,
in point of fact the large percentage of processor power just goes
unused on most people's machines that are used for email, surfing,
and an occassional Word file edit.

You should check back in this newsgroup to a thread started 1/30
by Byron Hynes with subject Spyware/Virus Cleaning Favor
However, if you review the info referenced in the replies you may
come to see that in today's world there is no real "cleaning" of a
system if it has been compromised. I am not saying that the exe
files that are 16 bit apps and live in your profile, that cause the pop-ups
nasty when they fail are nasty. However, you may just have accomplished
a miracle if you have existed with XP Gold connected to the internet at
least occassionally and yet kept a clean machine.

Roger
"Garry" <Garry@discussions.microsoft.com> wrote in message
news:52580DCD-7C1F-45CA-8BF1-AFE20AA2571A@microsoft.com...
> Hi.
> Appreciate the quick response. However, I hoped for at least a hint of
> what
> might have happened instead of an advice to rebuild my machine. Yes, this
> machine is not that powerful - it's only Celeron 600 Mhz 320 MB SDRAM,
> manufactured December 1999, with WinME originally installed. I've
> installed
> WinXP PRO on that machine more than a year ago, and didn't have any
> significant problems. And, yes, it did work just fine without the SP2 (i
> tried to install that, but that slowed down my system a lot, which was
> unacceptable), so, you, probably, should refrain from loathing my poor old
> machine that much.
> I gather, Roger, that you don't have any idea what is happening to my
> machine, and, frankly, i'm totally flabbergasted why you just don't admit
> it
> or refer me to someone more knowledgeable/experienced.
> I strongly hope that Microsoft does have competent engineers to provide
> some
> insight into my problem.
> If moderators of this discussion group think that my topic should be moved
> to a different subcategory/discussion group - please, by all means, do so.
> Your help is greatly appreciated.
> Garry
>
> "Roger Abell [MVP]" wrote:
>
>> ntuser.dat.LOG and ntuser.dat are system files that are part of
>> your account profile (reg data).
>> You should leave those alone.
>> I cannot imagine a 2 year old system being insufficient for
>> loading service packs, and I am loath to imagine the state
>> of a machine that has been internet active without any
>> XP service packs. You may be best off by rebuilding the
>> system from a fresh format on up, including installing SP2
>> and turning on the firewall before the machine is first connected
>> to the network.
>>
>> "Garry" <Garry@discussions.microsoft.com> wrote in message
>> news:84A0F1C7-7E9F-4332-ABA7-35E488C84FC5@microsoft.com...
>> > Hi
>> > I started to have a problem for which I can not find any explanation,
>> > the
>> > following group of pop-ups start coming up every time I start computor
>> > or
>> > close those pop-ups(cannot reproduce a picture sorry)
>> >
>> > Header: 16 bit MS-DOS Subsystem
>> > Text: C:\DOCUME~1\ADMINI~1\23r6d.exe
>> > The NTVDM CPU has encountered an illegal instruction.
>> > CS:0544 IP:01fb OP:63 6f 6c 6f 72 Choose 'Close' to
>> > terminate
>> > the application
>> >
>> > I followed the address and have found a lot of .exe files (as the one
>> > in
>> > the
>> > address above), all of which are 4 KB in size, and I think there are 2
>> > more
>> > files which are belong to this group - ntuser.dat.LOG and ntuser.dat.
>> > I don't have a clue what is happened here? May be OS (XP PRO, no
>> > service
>> > packs - this PC is more than 4 years old and can not handle SP2)
>> > problem,
>> > may
>> > spyware or virus - Scanned with AD-WARE, Spybot, and Microsoft
>> > Antispyware
>> > Beta - nothing helps.
>> > Please help.
>> > Deeply appreciate for any inside info/suggestions.
>> > Garry
>> >
>> > P.S. Those pop-ups looks like appearing in certain standard
>> > intervals...
>>
>>
>>



Re: Annoying pop-ups by Malke

Malke
Sat Feb 11 06:59:57 CST 2006

Garry wrote:

> Hi.
> Appreciate the quick response. However, I hoped for at least a hint
> of what might have happened instead of an advice to rebuild my
> machine. Yes, this machine is not that powerful - it's only Celeron
> 600 Mhz 320 MB SDRAM, manufactured December 1999, with WinME
> originally installed. I've installed WinXP PRO on that machine more
> than a year ago, and didn't have any significant problems. And, yes,
> it did work just fine without the SP2 (i tried to install that, but
> that slowed down my system a lot, which was unacceptable), so, you,
> probably, should refrain from loathing my poor old machine that much.
> I gather, Roger, that you don't have any idea what is happening to my
> machine, and, frankly, i'm totally flabbergasted why you just don't
> admit it or refer me to someone more knowledgeable/experienced.
> I strongly hope that Microsoft does have competent engineers to
> provide some insight into my problem.
> If moderators of this discussion group think that my topic should be
> moved to a different subcategory/discussion group - please, by all
> means, do so. Your help is greatly appreciated.

First of all, you posted in the security newsgroup. Roger is a security
professional. You are a home user with viruses/malware on your
computer. This is a public newsgroup hosted on Microsoft servers; while
some MS employees occasionally post, the majority of regular helpers
(like me and Roger) are volunteers who do not work for the company.
This is Usenet and is not a moderated newsgroup. You were extremely
rude to Roger, who was amazingly polite back.

You have not practiced "Safe Hex". You haven't protected your operating
system by patching it - and that includes SP2. If your machine was slow
after installing SP2, it was probably already infested. Now you have
malware on your computer. Follow the steps to remove malware at the
link below, and I would suggest you start with the virus scanning using
either Sysclean or David Lipman's Multi-AV. Do the preparatory work
first.

http://www.elephantboycomputers.com/page2.html#Removing_Malware

If the work looks daunting, either back up your stuff and format your
drive so you can clean-install Windows or take the machine to a
professional computer repair shop (not your local equivalent of
BigStoreUSA).

After your machine is clean, take the time to read the information at
the following links about how to stay clean. *You* are responsible for
your machine and no one else.

http://www.wilderssecurity.com/showthread.php?t=27971 - So How Did I Get
Infected Anyway?
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://www.claymania.com/safe-hex.html
http://www.aumha.org/a/parasite.htm - The Parasite Fight

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Re: Annoying pop-ups by PA

PA
Sat Feb 11 15:55:06 CST 2006

1. Get WinXP SP1 and everything else Windows Updates offers you (save SP2)
installed...NOW!

Protect Your PC
http://www.microsoft.com/athome/security/protect/

2. Run a /thorough/ check for hijackware.

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine.blogspot.com/
http://www.elephantboycomputers.com/page2.html#Removing_Malware

When all else fails, HijackThis v1.99.1
(http://aumha.net/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware. **Post
your log to http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for expert
analysis, not here.**

3. When your HijackThis log has been given a clean bill of health, install
SP2 [1][2]

[1] You may wish to add a considerable amount of memory before doing so. I
wouldn't run WinXP (SP1) without at least 512MB; as for SP2, please see:

The hard disk space requirements for Windows XP Service Pack 2:
http://support.microsoft.com/default.aspx?kbid=837783

[2] In the not-too-distant future, your machine must have SP2 installed to
get /any/ security updates.
--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE/OE, Shell/User, Security), Aumha.org VSOP, DTS-L.org

Garry wrote:
> Hi
> I started to have a problem for which I can not find any explanation, the
> following group of pop-ups start coming up every time I start computor or
> close those pop-ups(cannot reproduce a picture sorry)
>
> Header: 16 bit MS-DOS Subsystem
> Text: C:\DOCUME~1\ADMINI~1\23r6d.exe
> The NTVDM CPU has encountered an illegal instruction.
> CS:0544 IP:01fb OP:63 6f 6c 6f 72 Choose 'Close' to terminate
> the application
>
> I followed the address and have found a lot of .exe files (as the one in
> the address above), all of which are 4 KB in size, and I think there are
> 2 more files which are belong to this group - ntuser.dat.LOG and
> ntuser.dat.
> I don't have a clue what is happened here? May be OS (XP PRO, no service
> packs - this PC is more than 4 years old and can not handle SP2) problem,
> may spyware or virus - Scanned with AD-WARE, Spybot, and Microsoft
> Antispyware Beta - nothing helps.
> Please help.
> Deeply appreciate for any inside info/suggestions.
> Garry
>
> P.S. Those pop-ups looks like appearing in certain standard intervals...


Re: Annoying pop-ups by George

George
Wed Feb 15 15:05:26 CST 2006

Actually you just need to get those exe files out of your temp directory.
That does not mean they will not come back but they might not. If you
cannot get them out because access is denied then boot into safe mode and
try deleting them then. If you cannot then a reinstallation will be
necessary.

--

George Hester
_________________________________
"Garry" <Garry@discussions.microsoft.com> wrote in message
news:84A0F1C7-7E9F-4332-ABA7-35E488C84FC5@microsoft.com...
> Hi
> I started to have a problem for which I can not find any explanation, the
> following group of pop-ups start coming up every time I start computor or
> close those pop-ups(cannot reproduce a picture sorry)
>
> Header: 16 bit MS-DOS Subsystem
> Text: C:\DOCUME~1\ADMINI~1\23r6d.exe
> The NTVDM CPU has encountered an illegal instruction.
> CS:0544 IP:01fb OP:63 6f 6c 6f 72 Choose 'Close' to
terminate
> the application
>
> I followed the address and have found a lot of .exe files (as the one in
the
> address above), all of which are 4 KB in size, and I think there are 2
more
> files which are belong to this group - ntuser.dat.LOG and ntuser.dat.
> I don't have a clue what is happened here? May be OS (XP PRO, no service
> packs - this PC is more than 4 years old and can not handle SP2) problem,
may
> spyware or virus - Scanned with AD-WARE, Spybot, and Microsoft Antispyware
> Beta - nothing helps.
> Please help.
> Deeply appreciate for any inside info/suggestions.
> Garry
>
> P.S. Those pop-ups looks like appearing in certain standard intervals...