1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

explorer has performed an illegal operation

Discussion in 'Earlier Versions of Windows' started by newdumbo, Sep 24, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. newdumbo

    newdumbo Thread Starter

    Joined:
    Oct 18, 2001
    Messages:
    85
    Whenever I am connected to the internet via Internet Explorer and I need to access a document I always get the message:-
    Explorer:
    This program has performed an illegal operation and will be shut down.When I look at the details the following appears:-
    isEngine.dll page fault.
    If I disconnect from the Internet I do not have any problems and can access any documents.I am using Windows 98SE.
    Thanks JT
     
  2. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    What version of internet explorer ?
    have you done any spyware checks ?
    Have you done and virus scans ?
    have you tried repairing Internet explorer from add/remove programs ?
     
  3. newdumbo

    newdumbo Thread Starter

    Joined:
    Oct 18, 2001
    Messages:
    85
    The version of Explorer that I am using is 6.0.2800.1106.
     
  4. newdumbo

    newdumbo Thread Starter

    Joined:
    Oct 18, 2001
    Messages:
    85
    The version of Internet Explorer that I have is 6.0.2800.1106.I have done the checks that you suggested.
    Thank you for your help
     
  5. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Go to add/remove programs and selct Internet explorer from the list and select remove. Then select the option to repair..
     
  6. newdumbo

    newdumbo Thread Starter

    Joined:
    Oct 18, 2001
    Messages:
    85
    Thank you for replying.I removed explorer as you suggested and the message came up to restart computer.I did this and then attempted to repair under the add/remove programs dialogue but could not find a repair option,so I repaired by running msinfo32.exe and choosing the repair option there.Also in the add/remove programs list there is now no longer an entry for explorer.Having done all this however the problem still persists.If I browse using the Opera browser I do not have any problems.
     
  7. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Try redownloading IE again..
     
  8. newdumbo

    newdumbo Thread Starter

    Joined:
    Oct 18, 2001
    Messages:
    85
    Downloaded the service pack 6.1 but unfortuneatly the problem still persists.
     
  9. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Lets have a look at a Hijackthis log..Unzip the download, do a scan then save the log and paste that log here...
     
  10. newdumbo

    newdumbo Thread Starter

    Joined:
    Oct 18, 2001
    Messages:
    85
    Logfile of HijackThis v1.97.2
    Scan saved at 15:24:40, on 25/09/03
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\TREND PC-CILLIN 2000\PCCIOMON.EXE
    C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\TREND PC-CILLIN 2000\POP3TRAP.EXE
    C:\PROGRAM FILES\TREND PC-CILLIN 2000\WEBTRAP.EXE
    C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
    C:\PROGRAM FILES\LSOFT TECHNOLOGIES\ACTIVE ZDELETE\POPUPKILL.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\INCREDIMAIL\BIN\IMAPP.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\INCREDIMAIL\BIN\IMNOTFY.EXE
    C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;<local>
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\system32\blank.htm
    F1 - win.ini: run=hpfsched
    O1 - Hosts: 64.14.40.138 www.searchscout.com
    O1 - Hosts: 64.14.40.138 www.letssearch.com
    O1 - Hosts: 64.14.40.138 www.searchex.com
    O1 - Hosts: 64.14.40.138 srch.lop.com
    O1 - Hosts: 64.14.40.138 www.searchresult.net
    O1 - Hosts: 64.14.40.138 www.xupiter.com
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_1_6_0.DLL
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {BA25708B-154D-4D40-8607-67AA5190C395} - C:\PROGRA~1\INTELL~1\ISENGINE.DLL
    O2 - BHO: (no name) - {A09790E7-DD00-4A83-B632-5B563423CFBB} - C:\PROGRAM FILES\SMARTPOPUPKILLER\POPUPKILLERIEDLL.DLL
    O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\PROGRAM FILES\LYCOS\SIDESEARCH\SIDESEARCH.DLL
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_1_6_0.DLL
    O3 - Toolbar: (no name) - {21C32A07-0176-4FFE-BCDA-65D4A24F4303} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [PCCIOMON.EXE] "C:\Program Files\Trend PC-cillin 2000\PCCIOMON.EXE"
    O4 - HKLM\..\Run: [pop3trap.exe] "C:\Program Files\Trend PC-cillin 2000\pop3trap.exe"
    O4 - HKLM\..\Run: [WebTrap.exe] "C:\Program Files\Trend PC-cillin 2000\WebTrap.exe"
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
    O4 - HKLM\..\Run: [P2P NETWORKING] C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE /AUTOSTART
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [PCCIOMON.EXE] "C:\Program Files\Trend PC-cillin 2000\PCCIOMON.EXE"
    O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
    O4 - HKCU\..\Run: [[email protected] PopUp Killer] C:\PROGRA~1\LSOFTT~1\ACTIVE~1\PopUpKill.exe
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O4 - Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
    O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Sidesearch (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Searchalot (HKCU)
    O9 - Extra button: Downloads (HKCU)
    O9 - Extra button: ZDelete Auto-Cleaner (HKCU)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37882.1827662037
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
    O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} - http://raven.veloz.com/pub/download/oodlz_8bl.cab
    O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} (InstallShield Setup Player 2K2) - http://www.cyberpatrol.com/cponline/setup.exe
    O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
    O16 - DPF: {94118C19-B178-4E43-BBE8-0EFDBB391BDB} (SysWebTelecom Class) - http://www.megadownloads.info/SysWebTelecom.cab
     
  11. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    thanks , but lets download Spybot search and destroy now . First update it , then do a scan and when complete have it fix what it finds. This should take care of most of the spycrud then rescan and post a fresh hijack log.
     
  12. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Put a check in these in hijack and haveit fix them


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;<local>
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\system32\blank.htm
    F1 - win.ini: run=hpfsched
    O1 - Hosts: 64.14.40.138 www.searchscout.com
    O1 - Hosts: 64.14.40.138 www.letssearch.com
    O1 - Hosts: 64.14.40.138 www.searchex.com
    O1 - Hosts: 64.14.40.138 srch.lop.com
    O1 - Hosts: 64.14.40.138 www.searchresult.net
    O1 - Hosts: 64.14.40.138 www.xupiter.com
    O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\PROGRAM FILES\LYCOS\SIDESEARCH\SIDESEARCH.DLL
    O3 - Toolbar: (no name) - {21C32A07-0176-4FFE-BCDA-65D4A24F4303} - (no file)O4 - HKLM\..\Run: [P2P NETWORKING] C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE /AUTOSTART
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O9 - Extra button: Sidesearch (HKLM)O14 - IERESET.INF: START_PAGE_URL=
     
  13. newdumbo

    newdumbo Thread Starter

    Joined:
    Oct 18, 2001
    Messages:
    85
    Sorry about the delay.I have done as you suggested but unfortuneatly the problem persists
     
  14. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    From the start / run box type sfc and have it run a check for missing or corrupted files.
     
  15. BlueSpruce

    BlueSpruce

    Joined:
    Jul 24, 2003
    Messages:
    420
    newdumbo ,

    Have Hijack This fix these as well ,

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com

    O2 - BHO: (no name) - {BA25708B-154D-4D40-8607-67AA5190C395} - C:\PROGRA~1\INTELL~1\ISENGINE.DLL

    O3 - Toolbar: (no name) - {21C32A07-0176-4FFE-BCDA-65D4A24F4303} - (no file)

    O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} - http://raven.veloz.com/pub/download/oodlz_8bl.cab

    The following link can assist you in enabling the ''Show all Files and Folders'' option in Windows
    http://service1.symantec.com/SUPPOR...92715262339?Open&src=&docid=2000040412261548&

    Shutdown & Reboot your computer in Safe Mode
    http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

    Navigate to and Delete the following

    C:\PROGRAM FILES\LYCOS\SIDESEARCH > Folder
    C:\WINDOWS\SYSTEM\P2P NETWORKING > Folder

    Shutdown & Normal Reboot

    Download , configure , and run Ad-aware 6.0 Personal , Build 6.181 according to the following Reference Guide http://forums.techguy.org/t164245/s0bd00da6e0f7008495f1c26aa8c2e08c.html

    Next , consider installing SpywareBlaster v2.6.1 and SpywareGuard v2.2 for the prevention of both Spyware Active X installation and running , and Browser Hijacking protection in real-time http://www.wilderssecurity.net/index.html

    The following link can assist you in optimizing your start-up applications www.pacs-portal.co.uk/startup_pages/startup_full.htm

    Good luck
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/167174

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice