1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

IE Keeps closing

Discussion in 'Virus & Other Malware Removal' started by $lim, Feb 1, 2005.

Thread Status:
Not open for further replies.
Advertisement
  1. $lim

    $lim Thread Starter

    Joined:
    Oct 26, 2004
    Messages:
    183
    I am running windows 2000 on a machine and everytime i open IE i get an error message that says IE has encountered and error and needs to close. The strange thing is that its not the normal error message, where you have the option to send an error report. It has a check box that says "Restart Micorsoft Internet Explorer" and another strange thing is if you just move the error message out of the way and you can continue to use IE normally. I disabled script debugging and i still get the same message. I also ran Spybot, Ad-Aware, and Microsoft antispyware bete 1. Each found alot of spyware and it was removed and browser was restored. But i am still getting the same error message when openingn IE. I am downloading a patch for office 2000 that will supposely correct the problem according to microsoft. I do not think it will work though. Does anyone have any idea on how to fix this. One more thing, a trojan was detected when i ran antivirus, i think it was called dqsduck.exe or something like that. Also, when i do keep IE with the error message, and try to download something the whole pc crashes and restarts automatically.
     
  2. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Create a directory on your hardrive to save HijackThis.exe. A directory like c:\hijackthis. If you do not do this, you will not be able to use the backup/restore features.

    Download HijackThis from:

    http://www.spywareinfo.com/~merijn/files/hijackthis.zip

    Save this file into the directory you made previously and then run the program named hijackthis.exe. When the program opens click on the Config button, then click on the Misc Tools button, and click on the Check for update online button. When it completes checking/applying updates press the back button.

    Now click on the Scan button and when it is finished click on the Save Log button. A Notepad window will open with the contents of this log. Click on Edit then click on Select all. Then click on Edit and then Click on Copy.

    Create a reply to this post here and right click in message area and select paste to paste the log into the post.
     
  3. $lim

    $lim Thread Starter

    Joined:
    Oct 26, 2004
    Messages:
    183
    When spyware software scanned newdotnet the pc crashed and restarted on it own, jus tto let you know.

    Logfile of HijackThis v1.99.0
    Scan saved at 2:45:55 PM, on 2/1/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\OfficeScan NT\ntrtscan.exe
    C:\WINNT\system32\regsvc.exe
    C:\OfficeScan NT\tmlisten.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\OfficeScan NT\ofcdog.exe
    C:\OfficeScan NT\PCCNTMON.EXE
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\WINNT\system32\mdm.exe
    V:\Vmfg\Vm.exe
    V:\Vmfg\VMPLNWIN.EXE
    C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
    C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
    V:\Vmfg\VMSHPENT.EXE
    V:\Vmfg\VMORDENT.EXE
    V:\Vmfg\VMCUSINQ.EXE
    C:\Documents and Settings\cross\Desktop\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R3 - Default URLSearchHook is missing
    O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 6\SnagItBHO.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = emclocal.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = emclocal.com
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = emclocal.com
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: OfficeScanNT RealTime Scan - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
    O23 - Service: OfficeScanNT Listener - Unknown - C:\OfficeScan NT\tmlisten.exe
     
  4. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    First please download http://www.spyware911.net/downloads/LSPFix.exe
    Open it and click "I know what i'm doing.
    Then move all instances of newdotnet6_38.dll to the remove section then click finish

    Now rescan once again with hijack, insert a check next to each of the following then close all other open windows and click "fix checked"


    R3 - Default URLSearchHook is missing


    Then reboot, rescan and post a fresh log.
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/325637

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice