IE freezes, and won't quit at shutdown

P

Paul Pedersen

Internet Explorer frequently freezes up. And at shutdown I frequently get
error messages saying that iexplore.exe cannot quit. Even though IE appears
not to be running at all, there are often two or three instances that have
to be killed manually when shutting down.

I'm using IE 6 with all updates. Windows XP Pro SP1 with all updates. I have
third party extensions turned off. All drivers, including video drivers, are
up to date. Scans with up-to-date versions of Ad-Aware, CWShredder, and
Norton SystemWorks find nothing out of the ordinary.

Anyone have suggestions?
 
S

siljaline

Paul Pedersen said:
Internet Explorer frequently freezes up. And at shutdown I frequently get
error messages saying that iexplore.exe cannot quit. Even though IE appears
not to be running at all, there are often two or three instances that have
to be killed manually when shutting down.

I'm using IE 6 with all updates. Windows XP Pro SP1 with all updates. I have
third party extensions turned off. All drivers, including video drivers, are
up to date. Scans with up-to-date versions of Ad-Aware, CWShredder, and
Norton SystemWorks find nothing out of the ordinary.

Anyone have suggestions?

Ensure that you have Ad-aware configured for a Full Scan >
http://www.lavahelp.com/howto/fullscan/
Once configured, attempt another and post back your findings.

~Silj

--
siljaline

MS - MVP Windows (IE/OE) AH-VSOP
________________________________
Anti-Parasite Definition Updates
http://forum.aumha.org/viewforum.php?f=31

(Reply to group, as return address
is invalid - that we may all benefit)
 
P

Paul Pedersen

siljaline said:
Ensure that you have Ad-aware configured for a Full Scan >
http://www.lavahelp.com/howto/fullscan/
Once configured, attempt another and post back your findings.

~Silj


Thanks for your response. I did as you suggested. (Full scan takes a while!)
It didn't find anything other than Alexa, some tracking cookies, and a
couple of suspect URLs in my favorites (which I had put there myself).
Nothing else.

Any other ideas?
 
S

siljaline

Paul Pedersen said:
Thanks for your response. I did as you suggested. (Full scan takes a while!)
It didn't find anything other than Alexa, some tracking cookies, and a
couple of suspect URLs in my favorites (which I had put there myself).
Nothing else.

Any other ideas?

Yes Paul,
Run CWShredder: http://www.spywareinfo.com/~merijn/files/cwshredder.zip
Close all running applications and Browser Windows - unzip >
click on the executable and follow the prompts.

If no joy, run "HijackThis" > FAQ and download >
http://mvps.org/winhelp2002/unwanted.htm

HTH
~Silj

--
siljaline

MS - MVP Windows (IE/OE) AH-VSOP
________________________________
Anti-Parasite Definition Updates
http://forum.aumha.org/viewforum.php?f=31

(Reply to group, as return address
is invalid - that we may all benefit)
 
P

Paul Pedersen

siljaline said:
Yes Paul,
Run CWShredder: http://www.spywareinfo.com/~merijn/files/cwshredder.zip
Close all running applications and Browser Windows - unzip >
click on the executable and follow the prompts.

If no joy, run "HijackThis" > FAQ and download >
http://mvps.org/winhelp2002/unwanted.htm

HTH
~Silj

Like I said in my first post, I already ran CWShredder, and it found
nothing. I updated my version of HijackThis and ran it. The log is below.

There is a no-name BHO in there - could that be the problem? I looked up its
CSLID in the registry. There's an entry, but that's all. No data, no
associated file. I suspect it's just something left over from an incomplete
deinstallation. Or?

I don't recognize every item in the log, so if you see something "bad",
please let me know. Thanks for your help.

=================
Logfile of HijackThis v1.97.7

Scan saved at 10:57:42 AM, on 6/27/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\NetScreen\NetScreen-Remote\IreIKE.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\WINDOWS\system32\cisvc.exe

C:\WINDOWS\System32\inetsrv\inetinfo.exe

C:\Program Files\NetScreen\NetScreen-Remote\IPSecMon.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe

C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe

C:\WINDOWS\system32\slserv.exe

C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE

C:\WINDOWS\System32\shpc32.exe

C:\Program Files\PopUp Killer\PopUpKiller.EXE

C:\Program Files\Microsoft Hardware\Mouse\point32.exe

C:\Program Files\Microsoft Hardware\Keyboard\type32.exe

C:\Program Files\IBDrive for IBackup\IBDrive.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe

C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Microsoft Money\System\mnyexpr.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\NetScreen\NetScreen-Remote\SafeCfg.exe

C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

C:\Program Files\Handspring\HOTSYNC.EXE

C:\Program Files\Dantz\Retrospect\retrorun.exe

C:\WINDOWS\system32\cidaemon.exe

C:\WINDOWS\system32\cidaemon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\All Users\Documents\anti-spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://news.google.com/

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program
Files\Microsoft Money\System\mnyside.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [GW Port Controller] C:\Program
Files\Samsung\SmarThru\PORTCTRL.EXE

O4 - HKLM\..\Run: [xkstartup] RunDll32 InstZ82.dll,SetUsbPrinterPort

O4 - HKLM\..\Run: [SHPC32] shpc32.exe

O4 - HKLM\..\Run: [PopUpKiller] C:\Program Files\PopUp
Killer\PopUpKiller.EXE

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil
/RemAdvDef /Migration32

O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft
Hardware\Mouse\point32.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft
Hardware\Keyboard\type32.exe"

O4 - HKLM\..\Run: [IBDrive.exe] "C:\Program Files\IBDrive for
IBackup\IBDrive.exe" Min

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"

O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password
Manager\AcctMgr.exe /startup

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\j2re1.4.2_04\bin\jusched.exe

O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM\..\Run: [LexStart] lexstart.exe

O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft
Money\System\mnyexpr.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE

O4 - Global Startup: NetScreen-Remote.lnk = C:\Program
Files\NetScreen\NetScreen-Remote\SafeCfg.exe

O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL
Server\80\Tools\Binn\sqlmangr.exe

O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Save Flash By FlashFavorite -
res://C:\PROGRA~1\FLASHF~1\FFCom.dll/IeMenu.htm

O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)

O9 - Extra button: FlashFavorite (HKLM)

O9 - Extra 'Tools' menuitem: Flash Favorite (HKLM)

O9 - Extra button: Related (HKLM)

O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

O9 - Extra button: MoneySide (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-9.cab

O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) -
http://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB

O16 - DPF: {9CF28A69-7659-4C51-BFD5-9ADE19E19EC3} (RegConfig Class) -
http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
 
S

siljaline

< SNIP>
While I appreciate your enthususiam and want to get to
the bottom of your issue -

***_Please refrain from posting huge logs in a text-only
***_environment -
Post your log here: > ( not here )
One of these Forums, for _Expert Analysis_

http://forum.aumha.org/viewforum.php?f=30

http://forums.spywareinfo.com/index.php?showforum=18

http://computercops.biz/forum67.html

~Silj

--
siljaline

MS - MVP Windows (IE/OE) AH-VSOP
________________________________
Anti-Parasite Definition Updates
http://forum.aumha.org/viewforum.php?f=31

(Reply to group, as return address
is invalid - that we may all benefit)
 
P

Paul Pedersen

OK, tried that too. After several days, there've been no responses, which
leads me to think that there's nothing unusual in the HijackThis report,
either.

Given the facts that none of the usual diagnosis methods find any malware,
and that I have no symptoms clearly attributable to malware, I have no
reason to believe malware is involved.

So if that's the case, what else could be causing the problem? Any ideas?

Thanks.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top