IE 6 Errors and Program Crashes

G

Guest

At certain times when browsing, the error message "IE has encountered a
problem and needs to close. We are sorry for the inconvenience" is
encountered. This is happening with a very regular frequency and I have
tried several things to repair - none have worked yet.

I am running Windows XP SP2

The Crash Report contains the following information:
AppName iexplore.exe
AppVer 6.0.2900.2180
ModName unknown
ModVer 0.0.0.0
Offset <usually reports blank>

I have been able to save /print the appcompat.txt file and it references the
following dll's and plugins:

hmmapi.dll
iedw.exe
iexplore.exe
Connection Wizard\icwconn.dll
Connection Wizard\icwconn1.exe
Connection Wizard\icwconn2.exe
Connection Wizard\icwdl.dll
Connection Wizard\icwhelp.dll
Connection Wizard\icwres.dll
Connection Wizard\icwrmind.exe
Connection Wizard\icwtutor.exe
Connection Wizard\icwutil.dll
Connection Wizard\inetwiz.exe
Connection Wizard\isignup.exe
Connection Wizard\trialoc.dll
mui\0409\mscorier.dll
mui\041e\browselc.dll
mui\041e\inetres.dll
mui\041e\mshtmler.dll
mui\041e\msoeres.dll
mui\041e\shdoclc.dll
mui\041e\was32res.dll
PLUGINS\RichFX\Player\nprfxins.dll
PLUGINS\RichFX\Player\npvpg004.dll
kernel32.dll

I need HELP in solviong this crash problem.

Thanks,

Peter
 
F

Frank Saunders, MS-MVP IE/OE

PeterK said:
At certain times when browsing, the error message "IE has encountered
a problem and needs to close. We are sorry for the inconvenience" is
encountered. This is happening with a very regular frequency and I
have tried several things to repair - none have worked yet.

I am running Windows XP SP2

The Crash Report contains the following information:
AppName iexplore.exe
AppVer 6.0.2900.2180
ModName unknown
ModVer 0.0.0.0
Offset <usually reports blank>

I have been able to save /print the appcompat.txt file and it
references the following dll's and plugins:

hmmapi.dll
iedw.exe
iexplore.exe
Connection Wizard\icwconn.dll
Connection Wizard\icwconn1.exe
Connection Wizard\icwconn2.exe
Connection Wizard\icwdl.dll
Connection Wizard\icwhelp.dll
Connection Wizard\icwres.dll
Connection Wizard\icwrmind.exe
Connection Wizard\icwtutor.exe
Connection Wizard\icwutil.dll
Connection Wizard\inetwiz.exe
Connection Wizard\isignup.exe
Connection Wizard\trialoc.dll
mui\0409\mscorier.dll
mui\041e\browselc.dll
mui\041e\inetres.dll
mui\041e\mshtmler.dll
mui\041e\msoeres.dll
mui\041e\shdoclc.dll
mui\041e\was32res.dll
PLUGINS\RichFX\Player\nprfxins.dll
PLUGINS\RichFX\Player\npvpg004.dll
kernel32.dll

I need HELP in solviong this crash problem.

Thanks,

Peter

First eliminate any spyware.
What You Should Know About Spyware
http://www.microsoft.com/athome/security/spyware/devioussoftware.mspx

CAUTION!!!!! Removing some spyware can damage the Winsock stact. Before
you try to remove spyware using any of these programs , download a copy of
LSP-Fix - a free program to repair damaged Winsock 2 stacks (all Windows
versions)
http://www.cexx.org/lspfix.htm
Winsockfix for W95, W98, ME, NT, 2000, XP
http://www.tacktech.com/pub/winsockfix/WinsockFix.zip
Directions here: http://www.tacktech.com/display.cfm?ttid=257
WinXP:
Get WinSockxpFix
http://www.spychecker.com/program/winsockxpfix.html
How to Reset Internet Protocol (TCP/IP) in Windows XP
http://support.microsoft.com/kb/299357
In WinXP SP2: You can fix Winsock by going to Start | Run and typing
CMD
In the command window type
netsh winsock reset

See
Dealing with Unwanted Malware, Parasites, Toolbars and Search Engines
http://mvps.org/winhelp2002/unwanted.htm

Note that AdAware and SpyBot S & D will each catch some things the other
won't. Also, each needs to be updated with the program's update function
before every use, even when just downloaded. There's also a lot more to do
than just those two programs. CWShredder is also available here:
http://www.intermute.com/products/cwshredder
**Post your HijackThis log to
http://www.spywareinfo.com/forums/
http://forums.tomcoyote.org/
http://castlecops.com/forum67.html
http://www.wilderssecurity.com/ or the Spyware forum at
http://forum.aumha.org/viewforum.php?f=30 for expert analysis, not here.**
Alternative download pages for Ad-Aware, Spybot, HijackThis and CWShredder
may be found on this page:
http://aumha.org/a/parasite.htm.

See this link for information about malware:
http://arstechnica.com/articles/paedia/malware.ars

If nothing there helps, please post back to this thread.

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup only. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com./athome/security/protect/default.aspx
http://defendingyourmachine.blogspot.com/
 
G

Guest

I tried what you suggested and my IE still crashes. In fact, during my reply
it failed and I have attached the crash report - in case it helps to
determine the problem. I scanned for adware using Ad Adware SE version 1.3
and came up clean after about 6 passes. Then I used Spybot version 1.3,
whihch required about 4 passes before almost everything was gone. There are
still 5 occurrences of "DSO Exploit" and they all deal with internet
settings. I tried to remove them with Spybot and it says they have been
corrected, yet they remain on each scan. Hopefully this information will
help....

the appcompat.txt file follows:

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="iexplore.exe" FILTER="GRABMI_FILTER_PRIVACY">
<MATCHING_FILE NAME="hmmapi.dll" SIZE="38912" CHECKSUM="0xD85D870C"
BIN_FILE_VERSION="6.0.2900.2180" BIN_PRODUCT_VERSION="6.0.2900.2180"
PRODUCT_VERSION="6.00.2900.2180" FILE_DESCRIPTION="Microsoft HTTP Mail Simple
MAPI" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="HMMAPI.DLL" INTERNAL_NAME="HMMAPI" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x1667F" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:15"
UPTO_LINK_DATE="08/04/2004 07:56:15" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="iedw.exe" SIZE="18432" CHECKSUM="0x88F1640"
BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180"
PRODUCT_VERSION="5.1.2600.2180" FILE_DESCRIPTION="IE Crash Detection"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="iedw.exe" INTERNAL_NAME="iedw.exe" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x67D2" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="5.1.2600.2180"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/04/2004 06:02:35"
UPTO_LINK_DATE="08/04/2004 06:02:35" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="iexplore.exe" SIZE="93184" CHECKSUM="0xE187626E"
BIN_FILE_VERSION="6.0.2900.2180" BIN_PRODUCT_VERSION="6.0.2900.2180"
PRODUCT_VERSION="6.00.2900.2180" FILE_DESCRIPTION="Internet Explorer"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="IEXPLORE.EXE" INTERNAL_NAME="iexplore" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x23C72" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 06:00:33"
UPTO_LINK_DATE="08/04/2004 06:00:33" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwconn.dll" SIZE="61440"
CHECKSUM="0xDD04DAB" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Internet Connection Wizard" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="icwconn.dll" INTERNAL_NAME="icwconn" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x11BD7" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:14"
UPTO_LINK_DATE="08/04/2004 07:56:14" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwconn1.exe" SIZE="214528"
CHECKSUM="0xC9B5555" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Internet Connection Wizard" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="icwconn1.exe" INTERNAL_NAME="icwconn1" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x3C746" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 05:59:19"
UPTO_LINK_DATE="08/04/2004 05:59:19" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwconn2.exe" SIZE="86016"
CHECKSUM="0x7DE2AFFE" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Internet Connection Wizard" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="ICWCONN2.EXE" INTERNAL_NAME="ICWCONN2" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x1DDE9" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 05:59:22"
UPTO_LINK_DATE="08/04/2004 05:59:22" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwdl.dll" SIZE="32768"
CHECKSUM="0xF4CC9266" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Internet Service MIME Mutlipart Download"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="ICWDL.DLL" INTERNAL_NAME="ICWDL" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x174A9" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:16"
UPTO_LINK_DATE="08/04/2004 07:56:16" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwhelp.dll" SIZE="172032"
CHECKSUM="0xCBAB0AC0" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Internet Connection Wizard Helper functions"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="icwhelp.dll" INTERNAL_NAME="icwhelp" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x33E62" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:17"
UPTO_LINK_DATE="08/04/2004 07:56:17" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwres.dll" SIZE="61440"
CHECKSUM="0xA488AA92" BIN_FILE_VERSION="6.0.2600.0"
BIN_PRODUCT_VERSION="6.0.2600.0" PRODUCT_VERSION="6.00.2600.0000"
FILE_DESCRIPTION="Internet Connection Wizard" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2600.0000 (xpclient.010817-1148)"
ORIGINAL_FILENAME="icwres.dll" INTERNAL_NAME="icwres" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x1AA60" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2600.0" UPTO_BIN_PRODUCT_VERSION="6.0.2600.0"
LINK_DATE="08/18/2001 05:35:05" UPTO_LINK_DATE="08/18/2001 05:35:05"
VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwrmind.exe" SIZE="24576"
CHECKSUM="0x70643FDC" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Internet Connection Wizard Reminder"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="ICWRMIND.EXE" INTERNAL_NAME="ICWRMIND" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x13447" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 05:59:09"
UPTO_LINK_DATE="08/04/2004 05:59:09" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwtutor.exe" SIZE="73728"
CHECKSUM="0xF945F7EB" BIN_FILE_VERSION="6.0.2600.0"
BIN_PRODUCT_VERSION="6.0.2600.0" PRODUCT_VERSION="6.00.2600.0000"
FILE_DESCRIPTION="Internet Connection Wizard" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2600.0000 (xpclient.010817-1148)"
ORIGINAL_FILENAME="icwtutor.exe" INTERNAL_NAME="icwtutor" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x16B27" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2600.0" UPTO_BIN_PRODUCT_VERSION="6.0.2600.0"
LINK_DATE="08/17/2001 20:49:08" UPTO_LINK_DATE="08/17/2001 20:49:08"
VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="Connection Wizard\icwutil.dll" SIZE="49152"
CHECKSUM="0xB9156DF5" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Internet Connection Wizard" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="icwutil.dll" INTERNAL_NAME="icwutil" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0xF816" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:19"
UPTO_LINK_DATE="08/04/2004 07:56:19" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\inetwiz.exe" SIZE="20480"
CHECKSUM="0x3D8A325B" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Internet Connection Wizard" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="INETWIZ.EXE" INTERNAL_NAME="INETWIZ" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0xE297" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 05:59:25"
UPTO_LINK_DATE="08/04/2004 05:59:25" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="Connection Wizard\isignup.exe" SIZE="16384"
CHECKSUM="0xF8AB8D6E" BIN_FILE_VERSION="6.0.2600.0"
BIN_PRODUCT_VERSION="6.0.2600.0" PRODUCT_VERSION="6.00.2600.0000"
FILE_DESCRIPTION="Internet Signup" COMPANY_NAME="Microsoft Corporation"
PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2600.0000 (xpclient.010817-1148)"
ORIGINAL_FILENAME="ISIGNUP.EXE" INTERNAL_NAME="ISIGNUP" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x443C" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2600.0" UPTO_BIN_PRODUCT_VERSION="6.0.2600.0"
LINK_DATE="08/17/2001 20:48:46" UPTO_LINK_DATE="08/17/2001 20:48:46"
VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="Connection Wizard\trialoc.dll" SIZE="40960"
CHECKSUM="0x68F70073" BIN_FILE_VERSION="6.0.2600.0"
BIN_PRODUCT_VERSION="6.0.2600.0" PRODUCT_VERSION="6.00.2600.0000"
FILE_DESCRIPTION="Internet Connection Wizard Trial Reminder Helper"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2600.0000 (xpclient.010817-1148)"
ORIGINAL_FILENAME="trialoc.dll" INTERNAL_NAME="trialoc" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x198FE" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2600.0" UPTO_BIN_PRODUCT_VERSION="6.0.2600.0"
LINK_DATE="08/18/2001 05:36:03" UPTO_LINK_DATE="08/18/2001 05:36:03"
VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="mui\0409\mscorier.dll" SIZE="16896"
CHECKSUM="0x4AABD360" BIN_FILE_VERSION="1.1.4322.2032"
BIN_PRODUCT_VERSION="1.1.4322.2032" PRODUCT_VERSION="1.1.4322.2032"
FILE_DESCRIPTION="Microsoft .NET Runtime IE resources"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft .NET Framework"
FILE_VERSION="1.1.4322.2032" ORIGINAL_FILENAME="mscorier.dll"
INTERNAL_NAME="MSCORIER.DLL" LEGAL_COPYRIGHT="Copyright © Microsoft
Corporation 1998-2002. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x131F3" LINKER_VERSION="0x50000"
UPTO_BIN_FILE_VERSION="1.1.4322.2032"
UPTO_BIN_PRODUCT_VERSION="1.1.4322.2032" LINK_DATE="07/15/2004 06:34:05"
UPTO_LINK_DATE="07/15/2004 06:34:05" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="mui\041e\browselc.dll" SIZE="63488"
CHECKSUM="0xDAE5427E" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Shell Browser UI Library" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="BROWSEUI.DLL" INTERNAL_NAME="BROWSEUI.DLL"
LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved."
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x11598" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:07"
UPTO_LINK_DATE="08/04/2004 07:56:07" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="mui\041e\inetres.dll" SIZE="48128"
CHECKSUM="0xFA1EE2CF" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Microsoft Internet Messaging API Resources"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="INETRES.DLL" INTERNAL_NAME="INETRES" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0xF045" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:38"
UPTO_LINK_DATE="08/04/2004 07:56:38" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="mui\041e\mshtmler.dll" SIZE="56832"
CHECKSUM="0xDEF939F" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Microsoft (R) HTML Editing Component's Resource DLL"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="MSHTMLER.DLL" INTERNAL_NAME="MSHTMLER" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x10B5A" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:58:11"
UPTO_LINK_DATE="08/04/2004 07:58:11" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="mui\041e\msoeres.dll" SIZE="2479616"
CHECKSUM="0x752385C1" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Outlook Express" COMPANY_NAME="Microsoft Corporation"
PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="MSOERES.DLL" INTERNAL_NAME="MSOERES" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x25FEA8" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:58:51"
UPTO_LINK_DATE="08/04/2004 07:58:51" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="mui\041e\shdoclc.dll" SIZE="549376"
CHECKSUM="0x9A0B86D4" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Shell Doc Object and Control Library"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="SHDOCVW.DLL" INTERNAL_NAME="SHDOCVW.DLL"
LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved."
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x92C46" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:37"
UPTO_LINK_DATE="08/04/2004 07:56:37" VER_LANGUAGE="English (United States)
[0x409]" />
<MATCHING_FILE NAME="mui\041e\wab32res.dll" SIZE="249856"
CHECKSUM="0x7611ED53" BIN_FILE_VERSION="6.0.2900.2180"
BIN_PRODUCT_VERSION="6.0.2900.2180" PRODUCT_VERSION="6.00.2900.2180"
FILE_DESCRIPTION="Microsoft (R) Address Book DLL" COMPANY_NAME="Microsoft
Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System"
FILE_VERSION="6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="WAB32res.DLL" INTERNAL_NAME="WAB32res.DLL"
LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved."
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x42D6F" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="6.0.2900.2180"
UPTO_BIN_PRODUCT_VERSION="6.0.2900.2180" LINK_DATE="08/04/2004 07:56:38"
UPTO_LINK_DATE="08/04/2004 07:56:38" VER_LANGUAGE="English (United States)
[0x409]" />
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="kernel32.dll" SIZE="983552" CHECKSUM="0x4CE79457"
BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180"
PRODUCT_VERSION="5.1.2600.2180" FILE_DESCRIPTION="Windows NT BASE API Client
DLL" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows®
Operating System" FILE_VERSION="5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)"
ORIGINAL_FILENAME="kernel32" INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="©
Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0xFF848" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="5.1.2600.2180"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/04/2004 07:56:36"
UPTO_LINK_DATE="08/04/2004 07:56:36" VER_LANGUAGE="English (United States)
[0x409]" />
</EXE>
</DATABASE>


Thanks

Peter
 
P

Peter Kowalski

I attached the Hijack This file below...

Logfile of HijackThis v1.99.0
Scan saved at 10:32:06 PM, on 30/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\ttrxxxtt\RAgFf8RN.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\ttrxxxtt\NR8fFgAR.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\NetAssistant\bin\mpbtn.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\My Documents\PC Protect\HijackThis.exe

O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program
Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN
Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: Flash Extender - {95795B67-BBAB-47d0-8A9F-069E8242C0E5} -
c:\Program Files\Fen\fen.dll
O2 - BHO: Norton Internet Security -
{9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common
Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -
C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-ca\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program
Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-ca\msntb.dll
O3 - Toolbar: Norton Internet Security -
{0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common
Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD
Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark
X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common
Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Motive SmartBridge]
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft
Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O4 - Global Startup: NetAssistant.lnk = C:\Program
Files\NetAssistant\bin\matcli.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} -
C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: {0C4A9D28-66B5-4A70-B915-B6AEA5112472} -
http://www.woosan.com/icon/Mag.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio
Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus
scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/1911de2471f707490c21/netzip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload
Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry
Information Class) -
http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) -
https://sympreg.bell.ca/HSEOrder/systemCheck/MotivePreQual.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer
Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{E38B170B-012F-4A50-8293-CC371030F2BE}:
NameServer = 206.47.244.50 206.47.244.79
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Iomega App Services - Iomega Corporation -
C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: ISSvc - Symantec Corporation - C:\Program Files\Norton
Internet Security\ISSVC.exe
O23 - Service: LexBce Server - Lexmark International, Inc. -
C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec
Corporation - C:\Program Files\Norton Internet Security\Norton
AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton
Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Hopefully, you can help.

Peter
 
F

Frank Saunders, MS-MVP IE/OE

Peter Kowalski said:
I attached the Hijack This file below...

Logfile of HijackThis v1.99.0
Scan saved at 10:32:06 PM, on 30/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

As I said in my first post:
**Post your HijackThis log to
http://www.spywareinfo.com/forums/
http://forums.tomcoyote.org/
http://castlecops.com/forum67.html
http://www.wilderssecurity.com/ or the Spyware forum at
http://forum.aumha.org/viewforum.php?f=30 for expert analysis, not here.**

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup only. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com./athome/security/protect/default.aspx
http://defendingyourmachine.blogspot.com/
 
P

Peter Kowalski

Still trying to search out an answer. I've had some help through teh
tomcoyote site, but stiil receiving the "IE has experienced a problem and
must close" message regularily. I an getting this when my daughter tries to
access her university library site (very discouraging) and when I try and
read a newspaper online.

I really would appreciate some direction on this. My HJT log has been
posted to tomcoyote http://forums.tomcoyote.org/index.php?showforum=27
with at date of Feb 3 @ 6:04 pm

Thanks Peter
 
F

Frank Saunders, MS-MVP IE/OE

Peter Kowalski said:
Still trying to search out an answer. I've had some help through teh
tomcoyote site, but stiil receiving the "IE has experienced a problem
and must close" message regularily. I an getting this when my
daughter tries to access her university library site (very
discouraging) and when I try and read a newspaper online.

I really would appreciate some direction on this. My HJT log has been
posted to tomcoyote
http://forums.tomcoyote.org/index.php?showforum=27 with at date of
Feb 3 @ 6:04 pm

Thanks Peter

Do you have any idea what this is?
C:\PROGRA~1\ttrxxxtt\NR8fFgAR.exe
or c:\Program Files\Fen\fen.dll
or C:\WINDOWS\System32\igfxtray.exe
or C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup only. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com./athome/security/protect/default.aspx
http://defendingyourmachine.blogspot.com/
 
P

Peter Kowalski

I 'm not sure what Line 1, 3 or 4 represent. I was told by one newsgroup
solver to delete fen.dll using HJT and to reboot in SAFE mode and delete the
entire Fen directory. I did both ofthese things, but as you can see, they
returned.

Peter
 
P

Peter Kowalski

I followed the instructions and after browsing several of the pages that had
given me trouble in the past, I am happy to say I was able to view them
without a problem. I posted the HJT to
http://forums.tomcoyote.org/index.php?showforum=27 with at date of Feb 5 @
11:20 am. You will note that several of the files I was asked to remove
came back? I will let you know in the next few days if the problem returns.

Thanks for your help!

PeterK
 
F

Frank Saunders, MS-MVP IE/OE

Peter Kowalski said:
I followed the instructions and after browsing several of the pages
that had given me trouble in the past, I am happy to say I was able
to view them without a problem. I posted the HJT to
http://forums.tomcoyote.org/index.php?showforum=27 with at date of
Feb 5 @ 11:20 am. You will note that several of the files I was
asked to remove came back? I will let you know in the next few days
if the problem returns.

Thanks for your help!

PeterK

Try running the spyware removal programs in Safe Mode.

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup only. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com./athome/security/protect/default.aspx
http://defendingyourmachine.blogspot.com/
 
P

Peter Kowalski

I carried out the instructions listed in a previous post on TomCoyote. I was
successful in deleting the ttrxxxtt problems using killbox. However, the
bpt and fen files and directories have been stubborn and seem to re-appear
after each re-boot no matter how many times I use killbox to remove them.

It was recommended that I download and run Panda ActiveScan... I did and it
found/disinfected 1 additional problem.

Over the past few days, I have been able to use IE without any "IE has
encountered a problems..." messages, so I think the main problem has been
fixed. My most recent logfile has been posted to TomCoyote forum at
http://forums.tomcoyote.org/index.php?showforum=27 dated Feb 10/05 at 2:50
pm.

Thanks Again,

PeterK
..............................................................................................................................................
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top