PDA

View Full Version : Internet Explorer Question


hayc59
September 7th, 2003, 09:29 PM
can anyone give me a clue why this is happening sometimes??
thank you

LowWaterMark
September 7th, 2003, 09:51 PM
Short of trying to Google search the specifics of the stack dump, which might find something if it's a common problem, you really need to see if you can isolate the cause...

In this case what this means is to see if these IE crashes are being caused by either a conflict with some other running program or a browser hijack. You can start with the usual HijackThis thing...

-{ Quote: "Go to http://www.tomcoyote.org/hjt and download "HijackThis!". Unzip it. Run the HijackThis.exe file and press the [Scan] button... When the scan is finished, the [Scan] button will change into a [Save Log] button. Press that, save the log somewhere and paste the contents into a post here for us to look at.

Note that much of what will be listed there is correct and should not be fixed. So, just post the output here and let's see if the people here can help identify the problem." }-

Perhaps some new hijack is tying something into IE that is causing a crash. On the other hand, perhaps this is related to a conflict with other resident applications. An anti-virus, firewall, other active protective program (download and hijack preventers, BHOs, ATs, etc.) So another method to narrow this down would be to retest IE after disabling, one at a time, these other tools to see if the problem goes away with one specific tool or protection disabled. (Of course, caution should be used with what you disable and what action you take with IE.)

Finally, did you install, patch or upgrade anything recently? It may just be as simple as removing whatever it was.

hayc59
September 7th, 2003, 10:10 PM
-{ Quote: "Logfile of HijackThis v1.96.4
Scan saved at 7:08:27 PM, on 9/7/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\ESET\NOD32KRN.EXE
C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ESET\NOD32KUI.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\DESKTOP\JUNK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Good Day
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\PROGRAM FILES\COMMON FILES\JUSTDO\JD2002.DLL
O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRAM FILES\URLBLAZE\UBMON.DLL
O3 - Toolbar: (no name) - BackBitmap - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE /waitservice
O4 - HKLM\..\RunServices: [NOD32kernel] C:\Program Files\Eset\nod32krn.exe
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE /service
O8 - Extra context menu item: &Define - c:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - c:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\PROGRAM FILES\COMMON FILES\JUSTDO\IECatcher.DLL/FlashCatcher.htm
O9 - Extra button: Encarta Encyclopedia (HKLM)
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia (HKLM)
O9 - Extra button: Define (HKLM)
O9 - Extra 'Tools' menuitem: Define (HKLM)
O9 - Extra button: Flash Catcher (HKLM)
O9 - Extra 'Tools' menuitem: Flash Catcher (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Trashcan (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan (HKCU)
O10 - Broken Internet access because of LSP provider 'imon.dll' missing
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell.com/us/en/systemprofiler/SysProfLcd.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0080AD08A326} (LiveUpdate Crescendo) - http://activex.liveupdate.com/controls/cres.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} -
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} (CTAdjust Class) - http://www.microsoft.com/typography/clearadj.cab
O16 - DPF: {B1AC334E-F814-4884-937D-07EBBA652ED2} (AllControls.AllControl) -
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - http://transfers.one.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: ConferenceRoom Java Client - http://chat.privatefeeds.com:8000/java/cr.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37867.7948148148
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/dj/qdiagh.cab?306
O16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (CSonyPicturesGameDownloaderCtl Object) - http://www.shockwave.com/content/angelx/SonyPicturesGameDownloader.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {FC3A74E5-F281-4F10-AE1E-733078684F3C} (Downloader Class) - http://www.2020search.com/toolbar/2020Search.cab" }-

Pieter_Arntz
September 8th, 2003, 02:20 AM
Hi hayc59,

Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRAM FILES\URLBLAZE\UBMON.DLL
O3 - Toolbar: (no name) - BackBitmap - (no file)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0080AD08A326} (LiveUpdate Crescendo) - http://activex.liveupdate.com/controls/cres.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} -
O16 - DPF: {B1AC334E-F814-4884-937D-07EBBA652ED2} (AllControls.AllControl) -
O16 - DPF: {FC3A74E5-F281-4F10-AE1E-733078684F3C} (Downloader Class) - http://www.2020search.com/toolbar/2020Search.cab

Then reboot. Keep us posted if that solved it.

Regards,

Pieter

Rickster
September 8th, 2003, 04:28 AM
Hey Pieter...thought this might present a small learning experience for me while you're helping Hayc59. When I was looking over his Hijack Log, I first wondered if R1, R0 & 014 were like three big dudes trying to get through a small doorway at the same time, getting stuck. Was my stupid guess close to the reason for those fixes? Sorry for asking, but rationale behind some log adjustments would be fascinating to hear too. Please disregard if this is inappropriate here. Best Regards, Rick

Pieter_Arntz
September 8th, 2003, 04:59 AM
Hi Rickster,

No problem.

I advised him to remove the 2020 Search Page because that is shopnav related:
http://www.doxdesk.com/parasite/ShopNav.html
same for the corresponding O16 entry that put it there.
The R0 entry is an orphaned entry (nothing behind = )
The URLBlaze BHO is listed as an X here: http://www.spywareinfoforum.com/bhos/
The O3 toolbar says (no file) so is useless
The O14 resets the StartPage URL to comcast, where the user should be free to determine that himself.

I am well aware that it would be better to explain why certain advise is given, but there are days that I analyze over 50 logs and it would take at least five times as long to get through them, if I had to explain every decision.
But I will try never to refuse to do so, when asked for it. :)

If you are interested in this matter, here is a good place to start: http://www.spywareinfoforum.com/~merijn/htlogtutorial.html

Regards,

Pieter

Rickster
September 8th, 2003, 05:36 AM
Thanks Pieter, I knew it was cumbersome for those very reasons, but gracious of you to oblige. That tutorial will be a great leaning tool. My logic doesn't serve me well in technoland (quite apparent) so tons to learn.

But Hey, nowadays I know the difference between a host file and a hostess, if someone checks their NAT's WAN they really don't have to wash their hands afterward and when I say the word IP outloud, my family quite throwing me a towel and pointing at the bathroom.

Thanx, Rick

Pieter_Arntz
September 8th, 2003, 05:44 AM
ROFL

Hand me that towel. ;D

hayc59
September 8th, 2003, 12:02 PM
Pieter_Arntz, will try your suggestion and
let you now...thank you ;D

Phant0m
September 8th, 2003, 12:48 PM
File Corruption of Internet Explorer executable or something associated with it is also a high possibility… If this doesn’t work I would try Uninstalling IE/OE/WMP… completely, run Scandisk and Defragmenter and afterwards Install IE back…

hayc59
September 8th, 2003, 01:08 PM
so far so good thanks for all the help!
but with all Micro-crap soft ware, time will tell
;D ;D ;)