WOOPS!!!!

Discussion in 'Trojan Defence Suite' started by FireDancer, Jul 28, 2003.

Thread Status:
Not open for further replies.
  1. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Hey All,

    Can any one tell me why I am getting this annoying pop up everytime I close TDS and WormGuard. At present I have no spyware/adware viruses and or trojans on my puter it's squeaky clean but TDS and Worm are trial versions.. Wanted to try them out after reading all the raves!!!!! :p The programs seem to be doing thier jobs and running smooth!!! :cool: If ya can help I would greatly appreciate it ;)

    Regards,
    FireDancer
     

    Attached Files:

  2. Mr.Blaze

    Mr.Blaze The Newbie Welcome Wagon

    Joined:
    Feb 3, 2003
    Posts:
    2,842
    Location:
    on the sofa
    ARE YOU ON WINDOWS XP?
     
  3. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi Firedancer,

    Could you hit the "Details" button the next time you get that message, and let us know what it says.
    Normally they would reveal the program that's doing the crashing and the module that is "causing" it to do so.

    Regards,

    Pieter
     
  4. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    you are so right I amvery tired LOL ill open it again and look for ya

    Firedancer
     
  5. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Pieter,

    This is what I found hope ya can help

    TDS-3 caused an invalid page fault in
    module KERNEL32.DLL at 0167:bff9db61.
    Registers:
    EAX=c00309c4 CS=0167 EIP=bff9db61 EFLGS=00010212
    EBX=0089fe20 SS=016f ESP=0079ff2c EBP=007a01c8
    ECX=00000000 DS=016f ESI=00000000 FS=3a87
    EDX=bff76855 ES=016f EDI=66019870 GS=0000
    Bytes at CS:EIP:
    53 8b 15 e4 9c fc bf 56 89 4d e4 57 89 4d dc 89
    Stack dump:

    regards
    FireDancer
     
  6. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi FireDancer,

    Could you check if you have the required system files:

    http://www.wilderssecurity.com/showthread.php?t=2906

    Regards,

    Pieter
     
  7. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Hi Pieter,

    Well the new day is off to a not so good start..
    I followed your link from last post and checked
    to see if I had proper files.

    OS Win98 SE

    I followed al the instructions givin. I first ran the RUNTIME
    UPDATE (sercive pack 5) and I still had the same problem.

    I then downloaded all the givin file updates in zip form adn extracted them to C:\Windows\System all overwrote fine except for 2 the MSVBVM60 and the MSVCRT files would not overwrite. I get this same message for both files.. regardless original problem still exsists.

    Best Regards,
    FireDancer
     
  8. Dan Perez

    Dan Perez Retired Moderator

    Joined:
    May 18, 2003
    Posts:
    1,495
    Location:
    Sunny San Diego
    Hi FireDancer,

    To get around this last issue, you should boot up in SafeMode (preferably command-prompt only if you are comfortable with DOS commands).

    Please let us know how this works out.

    Thanks,

    Dan
     
  9. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Which version of the MSVBVM60 do you have now?
    I have version 6.00.9237.
    Is the error still the kernel*.dll ?
    I had it long ago with some other program and i just repaired/updated my IE6.0 which seems to have helped too in placing the most actual files.
    You might like to first do such a repair in the Control panel > software > click once on the ms internet explorer after which on the popup you choose for repair, reboot and see if that helps.
    Can you give that a try?
    If still not i would like you to get Faber Toys at www.faberbox.com , a free tool, just install and fire it up and in the upper window of it get the TDS and in the bottom window you'll see all files and dependecies for that; this last window you can easily save and paste in a message here. Please make it TXT format for readability. It gives in one overview the files versions so easy to see if there is anything.
     
  10. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Jooske,

    I have version 6.00 8964 running at this time.
    In answer to your second question yes it is the kernel problem still. I will follow your instructions and be back to you in just a bit.

    Thanks So Much,
    FireDancer
     
  11. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    That MSVBVM60 version should be very ok! So don't worry for that one. As you said you got the vbruntimes first.
    Fingers crossed.
     
  12. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Hi Jooske,

    Ok went to the link you posted and d loaded Faber
    this is what I was able to come up with.. hope you can help :D

    Regards
    FireDancerFile generated by Faber Toys (Version 2.4 - Build 216)
    Date: Monday, July 28, 2003 - 11:17:08 AM
    Program created by Faber
    --------------------------------------------------------------------------------

    Dependencies of TDS-3.EXE - 6 Threads - Priority: Normal
    TDS-3 Professional
    Version 3.20
    (C:\PROGRAM FILES\TDS3\TDS-3.EXE)
    --------------------------------------------------------------------------------

    49 Modules loaded by TDS-3.EXE
    -----------------------------------------------------------------------------------------------------------------------------------------------------------
    Name Date Size ActiveX Version Description
    -----------------------------------------------------------------------------------------------------------------------------------------------------------
    C:\WINDOWS\SYSTEM\ADVAPI32.DLL 4/23/99 64 KB No 4.80.1675 Win32 ADVAPI32 core component
    C:\PROGRAM FILES\TDS3\ADVSCAN.DLL 6/9/03 33 KB No
    C:\WINDOWS\MSAGENT\AGENTCTL.DLL 9/15/98 160.1 KB Yes 2.00.0.2115 Microsoft Agent Control
    C:\WINDOWS\MSAGENT\AGENTMPX.DLL 9/15/98 60.1 KB Yes 2.00.0.2115 Microsoft Agent Custom Marshaling Proxy DLL
    C:\WINDOWS\SYSTEM\ASYCFILT.DLL 9/23/99 144.3 KB No 2.40.4277 Microsoft OLE 2.40 for Windows NT(TM) and Windows 95(TM) Operating Systems
    C:\WINDOWS\SYSTEM\COMCTL32.DLL 8/29/02 535.8 KB No 5.81 Common Controls Library
    C:\WINDOWS\SYSTEM\COMDLG32.DLL 4/23/99 172 KB No 4.72.3510.2300 Common Dialogs DLL
    C:\WINDOWS\SYSTEM\CRYPT32.DLL 9/12/02 363.8 KB No 5.131.1878.12 Crypto API32
    C:\PROGRAM FILES\TDS3\DCSFPS.DLL 3/27/02 18 KB No
    C:\PROGRAM FILES\TDS3\DCSMEM9X.DLL 9/27/00 9 KB No
    C:\WINDOWS\SYSTEM\GDI32.DLL 4/23/99 152 KB No 4.10.1998 Win32 GDI core component
    C:\WINDOWS\SYSTEM\IMON.DLL 7/27/03 172 KB No
    C:\WINDOWS\SYSTEM\KERNEL32.DLL 4/23/99 460 KB No 4.10.2222 Win32 Kernel core component
    C:\WINDOWS\SYSTEM\MFC42.DLL 4/23/99 972.1 KB Yes 6.00.8447.0 MFCDLL Shared Library - Retail Version
    C:\WINDOWS\SYSTEM\MSAFD.DLL 4/23/99 44 KB No 4.10.1998 Microsoft Windows Sockets 2.0 Service Provider
    C:\WINDOWS\SYSTEM\MSCOMCTL.OCX 5/22/00 1.0 MB Yes 6.00.8862 Windows Common Controls ActiveX Control DLL
    C:\WINDOWS\SYSTEM\MSI.DLL 1/26/02 1.8 MB Yes 2.0.2600.2 Windows Installer
    C:\WINDOWS\SYSTEM\MSOSS.DLL 4/23/99 148 KB No 5.131.1877.3 Microsoft Trust ASN APIs
    C:\WINDOWS\SYSTEM\MSSCRIPT.OCX 7/22/02 104.0 KB Yes 1.0.0.7615 Microsoft (r) Script Control
    C:\WINDOWS\SYSTEM\MSVBVM60.DLL 8/21/00 1.3 MB Yes 6.00.8964 Visual Basic Virtual Machine
    C:\WINDOWS\SYSTEM\MSVCRT.DLL 10/9/02 284.1 KB No 6.10.8924.0 Microsoft (R) C Runtime Library
    C:\WINDOWS\SYSTEM\MSVCRT20.DLL 4/23/99 268 KB No 2.11.000 Microsoft® C Runtime Library
    C:\WINDOWS\SYSTEM\MSWINSCK.OCX 6/24/98 105.8 KB Yes 6.00.8169 Microsoft Winsock Control DLL
    C:\WINDOWS\SYSTEM\MSWSOCK.DLL 4/23/99 84 KB No 4.10.2222 Microsoft WinSock Extension APIs
    C:\WINDOWS\SYSTEM\MSWSOSP.DLL 4/23/99 44 KB No 4.10.2222 Microsoft Windows Sockets 2.0 Service Provider
    C:\WINDOWS\SYSTEM\NTSVC.OCX 5/21/97 33.5 KB Yes 1, 0, 0, 1 NT Service Control Module
    C:\WINDOWS\SYSTEM\OLE32.DLL 4/23/99 772 KB Yes 4.71.2900 Microsoft OLE for Windows and Windows NT
    C:\WINDOWS\SYSTEM\OLEAUT32.DLL 7/6/03 908 KB Yes 2.40.4518
    C:\WINDOWS\SYSTEM\OLEDLG.DLL 4/23/99 152 KB No 1.0 Microsoft Windows(TM) OLE 2.0 User Interface Support
    C:\WINDOWS\SYSTEM\OLEPRO32.DLL 7/6/03 224 KB Yes 5.0.4518
    C:\WINDOWS\SYSTEM\RAPILIB.DLL 4/23/99 28 KB No 5.00.1755.1 RSVP Libary 1.0 DLL
    C:\WINDOWS\SYSTEM\RICHED32.DLL 5/7/98 170.3 KB No 4.00.993.4 Windows 95 Rich Text Edit Control
    C:\WINDOWS\SYSTEM\RICHTX32.OCX 5/22/00 199.2 KB Yes 6.00.8804 RichTx32.OCX
    C:\WINDOWS\SYSTEM\RPCRT4.DLL 4/23/99 332 KB Yes 4.71.2900 Remote Procedure Call DLL
    C:\WINDOWS\SYSTEM\RSVPSP.DLL 4/23/99 40 KB No 5.00.1755.1 Microsoft Windows Rsvp 1.0 Service Provider
    C:\WINDOWS\SYSTEM\SHELL32.DLL 12/6/01 1.3 MB No 4.72.3812.600 Windows Shell Common Dll
    C:\WINDOWS\SYSTEM\SHLWAPI.DLL 8/29/02 386 KB No 6.00.2800.1106 Shell Light-weight Utility Library
    C:\WINDOWS\SYSTEM\TABCTL32.OCX 5/22/00 204.7 KB Yes 6.00.8804 TABCTL32 OLE Control DLL
    C:\PROGRAM FILES\TDS3\TDS3EXT.DLL 7/2/01 27 KB No
    C:\PROGRAM FILES\TDS3\UNZIP.DLL 12/2/98 82.5 KB No 5.4 Info-ZIP's UnZip DLL for Win32
    C:\WINDOWS\SYSTEM\USER32.DLL 4/21/00 54 KB No 4.10.2227 Win32 USER32 core component
    C:\WINDOWS\SYSTEM\VBSCRIPT.DLL 7/6/03 452.1 KB Yes 5.6.0.7426 Microsoft (r) VBScript
    C:\WINDOWS\SYSTEM\VERSION.DLL 4/23/99 24 KB No 4.10.1998 Win32 VERSION core component
    C:\WORMGUARD\WGUARD.DLL 8/24/01 136 KB Yes 3.00 DiamondCS WormGuard Core Module
    C:\WINDOWS\SYSTEM\WININET.DLL 8/29/02 572 KB No 6.00.2800.1106 Internet Extensions for Win32
    C:\WINDOWS\SYSTEM\WS2_32.DLL 4/23/99 72 KB No 4.10.2222 Windows Socket 2.0 32-Bit DLL
    C:\WINDOWS\SYSTEM\WS2HELP.DLL 4/23/99 24 KB No 4.10.1998 Windows Socket 2.0 Helper for Windows 98
    C:\WINDOWS\SYSTEM\WSOCK32.DLL 7/6/03 40 KB No 4.10.1998 BSD Socket API for Windows
    C:\WINDOWS\SYSTEM\XVOICE.DLL 1/12/99 191 KB Yes 4.0.4.2512 DirectSpeechSynthesis Module


    MODULES NOT LISTED ABOVE
    --------------------------------------------------------------------------------
    C:\PROGRAM FILES\TDS3\TDS-3.EXE
     
  13. Dan Perez

    Dan Perez Retired Moderator

    Joined:
    May 18, 2003
    Posts:
    1,495
    Location:
    Sunny San Diego
    Hi FireDancer,

    Were you able to replace those last files within safe mode or command-prompt-only-mode? Even though some of the file versions may match it may be that the file is corrupt so it might be good to try replacing them in any case.
     
  14. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Hi Dan,

    No sir I didnt try as I am still a real green horn as far as puters go... I am comfortable with some Dos commands but not most. I wouldnt know how to start replaceing file within the Dos Promt :( I am ashamed to say! Anyways
    if you have other suggestions or a link I can read up on
    per your instructions I am always ready to learn... LOL
    Determination can at times be one of my DownFualts as I
    wil probably kill the puter just trying to learn!!! I worked so hard to attain through months of saving and the worst thing is the minute I picked it up from the shop and walked out with it
    it was out of date ! :p ughh anyways I feel I still have a good system and will learn all this new stuff one way or another thanks so much for your responces... Wilders has been a real help from the get go and most of the replys have been paitent!!!!! :blink:

    Best Regards
    FireDancer
     
  15. Dan Perez

    Dan Perez Retired Moderator

    Joined:
    May 18, 2003
    Posts:
    1,495
    Location:
    Sunny San Diego
    Hey :)

    Well, you should be able to replace those files while in safe mode. If you don't know how to get into safe mode, you need to restart your system from the Start menu and when it is coming back up while the black screen and test is still on the screen and before you see any GUI of windows you press F8 repeatedly until it comes to the boot menu, one of the options there will be Safe Mode.

    {I hope I remembered that right, its been a while since I used Win9x :) }
     
  16. DolfTraanberg

    DolfTraanberg Registered Member

    Joined:
    Nov 20, 2002
    Posts:
    676
    Location:
    Amsterdam
    SHFT F5 ? ?? ?
     
  17. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
  18. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Hi All,

    I mis spoke I know how to get to safe mode I gues I should of asked in more detail ... While in safe mode
    do go ahead and unzip the files to C:\Windows\System
    the same way I would while in Normal? And would it be advisable to shutdown all running apps like fire wall, AV and such while doing so?
    Or can I run the update packet first in safe mode to see if that works?

    FireDancer :)
     
  19. DolfTraanberg

    DolfTraanberg Registered Member

    Joined:
    Nov 20, 2002
    Posts:
    676
    Location:
    Amsterdam
    I suppose NOTHING is running in save mode, you might not even have an Internet connection...
    yes (system32 ??)

    Dolf
     
  20. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Dolf,

    Hope i read this right...

    Unzip the required files and place them in your Windows\System directory for Windows 98 or WINNT\System32 if you have Windows NT - Windows XP may be installed to Windows, so put the files in Windows\System32. Always backup your originals. Please check your file version information first, and do not replace a file when the version you have is newer than the version here. These are the recommended minimum versions required. The recommended OS to use each file on is included.

    Windows\System for win98 users and Winnt\System32 for WinNT.

    Well anyways I ran in safe mode and ran the update packet but to no avail still same kernel crash so i will go back re run safe and unzip each file to C:\Windows\System individually and see if that fixxes it.
    Got any ideas? :)

    Best Regards,
    FireDancer ;)
     
  21. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Running win98se myself --
    to get into safe mode F8
    sometimes it jumps through, for which i use an upstart diskette, if you have boot from diskette enabled.
    But as you said all files were replaced except the msv...60.dll and the one you do have at the moment should be the right version..... but ok, go ahead replace it by unzipping/running it and maybe you like now first to unzip the required files zip and after the vbruntimes just in case a file could get overwritten. In fact you could first check the versions from the zip with what is on your system.
    In such cases i rightclick such a zip and if i get a choice to "extract to" i click that one and after cancel so i get the overview what's in it and can check each file version with what is there.
    I would really love if windows always would ask if i want to keep a newer file but it doesn't always.
    Anyway, you can be sure the files from the site are ok and not corrupt nor infected, so you can replace as was adviced.
    The files go automatically to their right places, although they should and for Win98 most will go to windows\system.

    Did you try the IE repair in the meantime and reboot? For me it cured lots of times lot of problems, two minutes work and a reboot.
    If that didn't work indeed replace those required files.
    If still no luck you could run System File Check, but first do those steps you're intending to do.
    If i'm not sure with that result, i occasionally go to the windows update site and from there do an IE repair install for which it downloads possible missing files. Saw it happening various times, although maybe those files were thrown out by later ms security patches and updates :) never know with that windows :)

    We crossed posting.
    SFC
    In normal mode, start > run > type SFC
    you will get an option to check all files, missing, corrupt, replaced......
    If i'm not sure i ignore the finds, if i know i just replaced it like you did now with several files you can update those few.
    If it speaks of missing or corrupt files it's another matter. Corrupt should be replaced from the windows cd-rom for instance, but missing can be caused by crashes or by uninstalls, hard to say.

    Did you try if it also happens if you close something else like AVG or another thing? (temporary, just for trying)
    Which firewall was there? No other errors like missing user.exe or gdi.... (dll or exe) ?
    And you had uninstalled and reinstalled WG and TDS, did you?
     
  22. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    You run NOD and AVG? Not together at the same time i suppose?
    Did you have these same problems from the first start?
    NOD32 v2 or 1?
    Still looking at your system files versions comparing with mine; i see no dramas yet, but some ?? so i come back on that later.
     
  23. FireDancer

    FireDancer Registered Member

    Joined:
    Jul 24, 2003
    Posts:
    316
    Hi Jooske,

    I am trialing Nod32 version 2. I was running AVG and had no problems. I uninstalled AVG first and rebooted. Did not have any problems with TDS3 till I tryed to close it right after configuration.. to hold save configuration I then restarted TDS3 and got the Kernel error. I am also
    trialing WG.

    All 3 programs are trials at this time. I have not changed or alterd any files or programs befor installs I am currentlt running Kerio PFW and all seems to be running smooth with it.

    I followed your instuctions "ALL of them" to a tee and to no avail I still get same kernel problem. I did run file checker and found one corrupt file in C:\Windows\System
    setupx.dll and repaired it. I re ran file checker and came up clean.

    And now I am seeing a problem with WG when closeing with the MSVBVM60 file. I un installed TDS3 and reinstalled. I ran configuration and then closed it and again got the kernel error. All other programs open run and close fine. He He He... Im not sure what to do anymore :) hopeing you can give more insight with the file I sent you. here is a screen shot of the error I recieved when closeing WG.

    Awaiting a reply,
    Regards,
    FireDancer ;)
     

    Attached Files:

  24. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Still wrestling through the differences of our system files, as i see a lot i have newer and some you have and i not and others i have and you not, so it's lot of work to compare them.

    I guess you did not take the most recent security updates and patches, the new virtual machine, directX and all those, which include various of the files which now seem to differ so much between our systems.

    Don't know where the setupx.dll comes from? Now since that file is added you have the problem with the vbrun and WG first time? Sounds very suspicious!
    Maybe you should just run that vbrun60sp5 exe again and see if WG still makes trouble.

    But i see WG is running with TDS and that is very strange.
    Did you install it in the same directory in stead of an own directory? Did not have the impression with the pathnames, so this is strange! Normally it runs completely invisible and should not even show up in this dependencies file unless you has it open for some reason!
     
  25. Gavin - DiamondCS

    Gavin - DiamondCS Former DCS Moderator

    Joined:
    Feb 10, 2002
    Posts:
    2,080
    Location:
    Perth, Western Australia
    Yes Jooske has the answer to MSVBVM60 troubles, just install the VBRun50 SP6 distribution, this will copy the file for you, no hassles :)

    http://download.microsoft.com/download/vb60pro/Redist/sp5/WIN98Me/EN-US/vbrun60sp5.exe
     
Thread Status:
Not open for further replies.