runtime error abnormal termination

C

Cheezio

ok, ive spent the last few weeks looking over loads of posts relating
to my problem, ive tried all the obvious solutions (except a complete
reinstal)
heres the problem:
i get a browser crash a random times at a variety of sites, heres a
list of sites that it can happen at:
www.paypal.com www.ebay.com www.nationwide.co.uk
i also tried a site someone else said they had crashes on
www.jsiinc.com
i had an immediate crash there, but i never crash at this site
www.vinylrhythm.com
its really annoying as sometimes i can work with no problems then out
of the blue it will happen continually for a while

ok heres the error message:
runtime error
program c:\program files\internet explorer\iexplore:exe
abnormal program termination

i also get another message sometimes saying:
internet explorer has encountered a problem
debug or close

if i choose debug it just closes anyway

im running xp pro and have all the service\critical packs installed
regards to solutions these i have done:
tools - ticked disable script debugging
tools - ive unticked ms java, installed sun java both to no avail and
ive reverted back to the original java option (when i tried several
options with the java i went to the sites ive engaged problems , i
still had problems)
ive run spyware, adaware,nortons

if you need more info then pls ask as ive probaly forgot some things
ive done to try and fix it
please help
please please please

adam
 
C

Cheezio

thanks for getting back quick, unfortunatly your help didnt solve the
error.
i tried the various solution you gave me below to no avail.
the first didnt coinside with the problem and i dont have the parasite
u mentioned in the 2nd tip.
but i got some more info, when the problem started i was also getting
this message when i started up my pc
wjviewer error could not execute the main (this has recently stopped
b4 i posted the original thread)
i looked it up and found that i have some adware from
'WebSavingsfromEbates'
ihave deleted the suggested folders
but i still get the problem, is this 'WebSavingsfromEbates' likely to
be the root cause?? (can i sue them!!!!)
is there anymore help avaliable??

1 - Runtime error. Abnormal program termination.
http://support.microsoft.com/?kbid=307817 ( XP )

Or this parasite is the cause.

2 - Runtime Library Microsoft Visual C++. Runtime Error Program
C:\Windows\Explorer.exe or Iexplore.exe, abnormal program termination.
http://www.doxdesk.com/parasite/CommonName.html

Dealing with Unwanted Spyware, Parasites, Toolbars and Search Engines
http://mvps.org/winhelp2002/unwanted.htm
 
M

Mike Burgess

Cheezio,
Dealing with Unwanted Malware, Parasites, Toolbars and Search Engines
http://mvps.org/winhelp2002/unwanted.htm
Note: be *sure* to follow-up with HijackThis
Post back with the URL where you posted if you want help with your log.
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 04-02-04]
Please post replies to this Newsgroup, email address is invalid
 
C

Cheezio

mike
ive run shredder and got this message which asked to be checked with
someone who knows, is this a problem? c:\windows\ctdrvins.exe
should i delete this?

also here is my log from hijackthis, can u help me with it (i noticed
the websavingsfromebates!!)
any suggestions???
thanks
adam


Logfile of HijackThis v1.97.7
Scan saved at 11:30:30, on 06/04/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\srvany.exe
C:\WINDOWS\system32\resetservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\TrayIcon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\IMsecure\IMsecure.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Winamp\winamp.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Adam\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -
C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -on
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft
Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [DisplayTrayIcon] C:\WINDOWS\System32\TrayIcon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client]
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check]
C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinPatrol]
"C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN
Messenger\msnmsgr.exe" /background
O4 - Startup: IMsecure.lnk = C:\Program Files\IMsecure\IMsecure.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Web Savings - file://C:\Program
Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Broken Internet access because of LSP provider 'imslsp.dll'
missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {1096842F-FEE8-11D2-965E-0010E3622565} (IFS_Lib00) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_RYD.cab
O16 - DPF: {1E89A357-CF86-11D1-8CAE-00805F93E2D7} (IFS_Wizard1
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz01.cab
O16 - DPF: {219CF65A-B13C-11D2-8D4A-0004ACF74B57} (IFS_Lib04) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb04.cab
O16 - DPF: {29166FB6-2AD6-11D2-8DB7-0001FAF8D270} (IFS_Wizard6
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz06.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX
Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {498439C0-0921-11D3-9484-0001FAF8503C} (IFS_Lib10) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb10.cab
O16 - DPF: {4DE7E614-E69B-11D2-947C-0001FAF8503C} (IFS_Lib07) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb07.cab
O16 - DPF: {5915C16A-F555-11D1-8E31-08005AAA630C} (IFS_Wizard5
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz05.cab
O16 - DPF: {5B2FD039-D08C-11D2-9FFD-0004ACF74B57} (IFS_Lib08) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb08.cab
O16 - DPF: {5DD1BBF5-E4B2-11D1-9211-0004ACF75CFC} (IFS_Wizard2
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz02.cab
O16 - DPF: {6A863F66-CA4A-11D2-9FF9-0004ACF74B57} (IFS_Lib05) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb05.cab
O16 - DPF: {6CAE02B8-EB30-11D1-8CE5-0004ACF74B57} (IFS_List Control) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_List.cab
O16 - DPF: {74545298-2152-11D2-8D16-0004ACF74B57} (IFS_Wizard3
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz03.cab
O16 - DPF: {8F78C964-B20B-11D2-8D4A-0004ACF74B57} (IFS_Lib01) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb01.cab
O16 - DPF: {9D24756B-CBFC-11D2-9FFB-0004ACF74B57} (IFS_Lib13) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb13.cab
O16 - DPF: {9E2D89BB-D888-11D2-A002-0004ACF74B57} (IFS_Lib12) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb12.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37823.6618865741
O16 - DPF: {B37DB118-5623-11D3-8769-0010E36241AE} (IFS_Wizard9
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz09.cab
O16 - DPF: {BBAE9E7E-3F7D-11D3-94B7-0001FAF8503C} (IFS_Lib16) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb16.cab
O16 - DPF: {C0E10B5C-DA42-11D3-9FED-0004ACF74B57} (IFS_Lib02) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb02.cab
O16 - DPF: {C1BA9623-F27F-11D2-947D-0001FAF8503C} (IFS_Lib11) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb11.cab
O16 - DPF: {C6726AD0-E1E0-11D2-929E-0004ACF75CFC} (IFS_Lib03) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb03.cab
O16 - DPF: {C6C07D4E-3911-11D2-8708-0001FAF8D5C4} (IFS_Wizard7
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz07.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player
Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71A2028-D578-11D2-9FFF-0004ACF74B57} (IFS_Lib14) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb14.cab
O16 - DPF: {DF3AA904-233E-11D3-9495-0001FAF8503C} (IFS_Lib17) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb17.cab
O16 - DPF: {F0FB4064-2940-11D3-92B1-0004ACF75CFC} (IFS_Lib06) -
http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb06.cab
O16 - DPF: {F3DAE1EA-01DA-11D2-8E33-08005AAA630C} (IFS_Wizard4
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz04.cab
O16 - DPF: {F49159DA-E0C6-11D1-8E28-08005AAA630C} (IFS_Service
Control) - http://roylinedirect.rbs.co.uk/dbpc2/controls/2.6.11.0/IFS_Serv.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX/kdx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5EF84EB3-D67A-4CFA-A1F4-90A83EC7E583}:
NameServer = 212.159.6.9 212.159.13.49
 
C

Cheezio

ok chaps.....this is really do my head in!!!!!!!!!!!!!!!!
thanks to H Leboeuf & Mike Burgess but im afraid your tips havnt
worked for me, although ive run hijackthis and posted the results if
anyone can see anything that shouldnt be there then pls tell me...

i got a new error report today that i havnt seen b4(it closed ie as
usual):

iexplore.exe application error
the instruction 0x1000a9b9 referenced memory at 0 x 0000000 the memory
could not be written

please someone help if you can because im going mad
i have a lot of work in and out of www.paypal.com and this is the site
that i crash 8/10 atempts, which is not very helpful at all.

does this mean a complete reinstal of xp pro??
i cant install ie6 only can i???
 
C

Cheezio

i seem to have fxed this error
recently i download an addition to ZONEALARM called IM SECURE(makes
MSN conversations secure), when i chqd one of my 'debug' notices i had
an error with a .dll file which was associated with IM SECURE, so i
uninstalled it and for the past 24 hrs ive had no
problems.....hopefully thats it
thanks for all your tips
cheezio...:)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top