IE crashing

A

Alfredo

My Internet Explorer keeps shutting down & I don't know what else to do.
I run I.E. v6.0.2800 on Windows 98 second edition.
My Internet explorer is fully updated & I have run a virus check, spybot &
ad aware but it still doesn't resolve it.

This is what the details button comes up with;

EXPLORER caused an invalid page fault in
module MSVCRT.DLL at 0167:780154a7.
Registers:
EAX=7803a152 CS=0167 EIP=780154a7 EFLGS=00010246
EBX=00000010 SS=016f ESP=023c69a4 EBP=023c69b4
ECX=0000a6f0 DS=016f ESI=70a9a6f0 FS=3527
EDX=0fffffff ES=016f EDI=023c69ee GS=0000
Bytes at CS:EIP:
66 8b 04 48 a8 04 74 5b 83 c1 d0 3b cb 73 7b 83
Stack dump:
023c6a58 70a9f33b 00000000 00000000 023c6a10 7801540c 023c69ec 00000000
0000000f 00000000 63706b61 023c69ec 00000000 00000010 00000002 636b4660

Hope you can help.
 
P

PA Bear

Check your system for "hijackware":

Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/Darnit.htm

CoolWebSearch Chronicles
http://www.spywareinfo.com/~merijn/cwschronicles.html

Run these tools in the following order with nothing else running in
background:

1. CWShredder (fix all found)

2. Ad-Aware (fix all found)

3. Spybot (RTFM but generally fix everything in red)

Important: You *must* seek updates for Ad-Aware, Spybot, etc., before each
and every use, even "right out of the box". But even they can't catch
everything, 24/7. When all else fails, HijackThis
(http://www.spywareinfo.com/~merijn/files/HijackThis.exe) is the preferred
tool to use. It will help you to both identify and remove any
hijackware/spyware. **Post your files to http://forums.spywareinfo.com/ or
http://forum.aumha.org/viewforum.php?f=30 for expert analysis, not here.**

[Alternate download pages for many of the above tools may be found at
http://aumha.org/a/parasite.htm.]

Also:

1. Download and run Stinger (http://vil.nai.com/vil/stinger/); then...

2. Update your virus definitions, enable Show Hidden Files
(http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2002092715262339)
and then run a full system scan in Safe Mode
(http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406)
with nothing else running in background.

So How Did I Get Infected Anyway?
http://boards.cexx.org/viewtopic.php?t=957

--
HTH - Please Reply to This Thread

~Robear Dyer (PA Bear)
MS MVP-Windows (IE/OE), AH-VSOP

AumHa Forums
http://forum.aumha.org

What You Should Know About Spyware
http://www.microsoft.com/mscorp/twc/privacy/spyware.mspx
 
A

Alfredo

Hijack results. Please help.

Logfile of HijackThis v1.97.7
Scan saved at 11:39:25, on 09/06/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS.000\SYSTEM\KERNEL32.DLL
C:\WINDOWS.000\SYSTEM\MSGSRV32.EXE
C:\WINDOWS.000\SYSTEM\SPOOL32.EXE
C:\WINDOWS.000\SYSTEM\MPREXE.EXE
C:\WINDOWS.000\SYSTEM\mmtask.tsk
C:\WINDOWS.000\EXPLORER.EXE
C:\WINDOWS.000\TASKMON.EXE
C:\WINDOWS.000\SYSTEM\SYSTRAY.EXE
C:\WINDOWS.000\SYSTEM\PSTORES.EXE
C:\WINDOWS.000\SYSTEM\WMIEXE.EXE
C:\UNZIPPED\HIJACKTHIS[1]\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.google.co.uk/
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
E:\ADOBE\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} -
D:\SOLIDCONVERTERPDF\EXPLOREEXTPDF.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS.000\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {0AAF602E-72A1-45FE-BAB1-06971E07EAA2} - (no file)
O3 - Toolbar: SolidConverter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} -
D:\SOLIDCONVERTERPDF\EXPLOREEXTPDF.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS.000\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS.000\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [Ati2cwxx] Ati2cwxx.exe
O4 - HKLM\..\Run: [PCCIOMON.EXE] "d:\Trend PC-cillin 2000\PCCIOMON.EXE"
O4 - HKLM\..\Run: [pop3trap.exe] "d:\Trend PC-cillin 2000\pop3trap.exe"
O4 - HKLM\..\Run: [WebTrap.exe] "d:\Trend PC-cillin 2000\WebTrap.exe"
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [Shell32] Shell32.exe
O4 - HKLM\..\Run: [Winsock32driver] win32server.scr
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\Program Files\CD-Writer
Plus\DirectCD\DIRECTCD.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [PCCIOMON.EXE] "d:\Trend PC-cillin
2000\PCCIOMON.EXE"
O4 - HKCU\..\Run: [LTM2] C:\WINDOWS.000\litmus\MSGSRV32.exe
O4 - Startup: Outlook Express.lnk = C:\Program Files\Outlook
Express\MSIMN.EXE
O8 - Extra context menu item: Download with GetRight -
E:\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser -
E:\GetRight\GRbrowse.htm
O9 - Extra button: PDFtypewriter (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {A51FD294-EDEE-11D3-9B2F-00A0CC501586} (XSolRace Control) -
http://www.horseracing4cast.com/XSolRace.ocx
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX
Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: Yahoo! Spades -
http://download.games.yahoo.com/games/clients/y/st0_x.cab
O16 - DPF: Yahoo! Backgammon -
http://download.games.yahoo.com/games/clients/y/at0_x.cab
O16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/games/clients/y/ct0_x.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37943.242037037
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) -
https://flash.ladbrokescasino.com/ladbrokes/FlashAX.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl
Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update
Installation Engine) -
http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: Yahoo! Go Fish -
http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
http://download.abacast.com/download/files/abasetup144.cab
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top