Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
Status
Not open for further replies.

IE Keeps closing

2K views 3 replies 2 participants last post by  mobo 
#1 ·
I am running windows 2000 on a machine and everytime i open IE i get an error message that says IE has encountered and error and needs to close. The strange thing is that its not the normal error message, where you have the option to send an error report. It has a check box that says "Restart Micorsoft Internet Explorer" and another strange thing is if you just move the error message out of the way and you can continue to use IE normally. I disabled script debugging and i still get the same message. I also ran Spybot, Ad-Aware, and Microsoft antispyware bete 1. Each found alot of spyware and it was removed and browser was restored. But i am still getting the same error message when openingn IE. I am downloading a patch for office 2000 that will supposely correct the problem according to microsoft. I do not think it will work though. Does anyone have any idea on how to fix this. One more thing, a trojan was detected when i ran antivirus, i think it was called dqsduck.exe or something like that. Also, when i do keep IE with the error message, and try to download something the whole pc crashes and restarts automatically.
 
#2 ·
Create a directory on your hardrive to save HijackThis.exe. A directory like c:\hijackthis. If you do not do this, you will not be able to use the backup/restore features.

Download HijackThis from:

http://www.spywareinfo.com/~merijn/files/hijackthis.zip

Save this file into the directory you made previously and then run the program named hijackthis.exe. When the program opens click on the Config button, then click on the Misc Tools button, and click on the Check for update online button. When it completes checking/applying updates press the back button.

Now click on the Scan button and when it is finished click on the Save Log button. A Notepad window will open with the contents of this log. Click on Edit then click on Select all. Then click on Edit and then Click on Copy.

Create a reply to this post here and right click in message area and select paste to paste the log into the post.
 
#3 ·
When spyware software scanned newdotnet the pc crashed and restarted on it own, jus tto let you know.

Logfile of HijackThis v1.99.0
Scan saved at 2:45:55 PM, on 2/1/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\regsvc.exe
C:\OfficeScan NT\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\OfficeScan NT\ofcdog.exe
C:\OfficeScan NT\PCCNTMON.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\system32\mdm.exe
V:\Vmfg\Vm.exe
V:\Vmfg\VMPLNWIN.EXE
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
V:\Vmfg\VMSHPENT.EXE
V:\Vmfg\VMORDENT.EXE
V:\Vmfg\VMCUSINQ.EXE
C:\Documents and Settings\cross\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 6\SnagItBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = emclocal.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = emclocal.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = emclocal.com
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: OfficeScanNT RealTime Scan - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: OfficeScanNT Listener - Unknown - C:\OfficeScan NT\tmlisten.exe
 
#4 ·
First please download http://www.spyware911.net/downloads/LSPFix.exe
Open it and click "I know what i'm doing.
Then move all instances of newdotnet6_38.dll to the remove section then click finish

Now rescan once again with hijack, insert a check next to each of the following then close all other open windows and click "fix checked"

R3 - Default URLSearchHook is missing

Then reboot, rescan and post a fresh log.
 
Status
Not open for further replies.
You have insufficient privileges to reply here.
Top