1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

[SOLVED] Adobe Acrobat Crashes after....

Discussion in 'All Other Software' started by jediliz, Nov 25, 2001.

Thread Status:
Not open for further replies.
Advertisement
  1. jediliz

    jediliz Thread Starter

    Joined:
    Jun 4, 2001
    Messages:
    160
    trying to open the online posted Best Buy Ad.
    I think I have 5.0.

    This is a consistent error.


    Here is what I get:

    ACRORD32 caused an invalid page fault in
    module unknown at 0000:00000009.
    Registers:
    EAX=00010000 CS=017f EIP=00000009 EFLGS=00010286
    EBX=00000000 SS=0187 ESP=009ef050 EBP=009ef128
    ECX=027f6030 DS=0187 ESI=01bc7920 FS=19ef
    EDX=00000008 ES=0187 EDI=00000000 GS=0000
    Bytes at CS:EIP:
    00 b6 05 65 04 70 00 65 04 70 00 54 ff 00 f0 8f
    Stack dump:
    01bc0187 37034af0 027f6030 00000000 00000000 00000000 00000003 00000080 00000000 00000000 01bc7920 0000000b 00640072 00540020 cf329001 e55a7b96


    Any help or suggestions?
     
  2. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    35,168
    Hiya

    you know for the module: Did it come up with Unknown or something else but with <>'s surrounding it? If so, can you edit it so that these are removed. They won't post otherwise.

    As soon as we get that, we can delve deeper. For the moment, whilst we wait, as it may be unknown, go here and download AddAware www.lavasoftusa.com
    Install and run it, ensuring that Deep Registry Scan is enabled. Remove all except any references to Web3000 or new.net. If you're unsure, copy/paste the list.

    regards

    eddie
     
  3. jediliz

    jediliz Thread Starter

    Joined:
    Jun 4, 2001
    Messages:
    160
    I already have AdAware installed and this is the list I get:


    Okay, I am having trouble with running AdAware right now. I'll edit this post when I get it to work.

    Okay here are the results:


    Scan initialized on 11/25/01 6:40:19 PM.
    (AAW release 5.62, referencefile 087-24.06.2001)
    =================================================


    Started extended registry scan
    ===============================
    Aureate key:HKEY_USERS\.default\software\aureate\
    Timesink key:HKEY_USERS\.default\software\timesink, inc.\
    Gator key:HKEY_CLASSES_ROOT\clsid\{21ffb6c0-0da1-11d5-a9d5-00500413153c}\
    New.Net key:HKEY_CLASSES_ROOT\clsid\{dd521a1d-1f98-11d4-9676-00e018981b9e}\
    New.Net key:HKEY_CLASSES_ROOT\interface\{dd521a1c-1f98-11d4-9676-00e018981b9e}\
    Aureate key:HKEY_CLASSES_ROOT\software\aureate\
    Aureate key:HKEY_CURRENT_USER\software\aureate\
    Aureate key:HKEY_LOCAL_MACHINE\software\aureate\
    DSSAgent key:HKEY_LOCAL_MACHINE\software\broderbund software\dss\
    Gator key:HKEY_LOCAL_MACHINE\software\gator.com\
    New.Net key:HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{dd521a1d-1f98-11d4-9676-00e018981b9e}\
    Gator key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/iegator.dll\
    New.Net key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net\
    Aureate key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\radiate advertising\
    New.Net key:HKEY_LOCAL_MACHINE\software\new.net\
    New.Net key:HKEY_LOCAL_MACHINE\software\new.net\
    Timesink key:HKEY_CURRENT_USER\software\timesink, inc.\
    Timesink key:HKEY_LOCAL_MACHINE\software\timesink, inc.\
    New.Net key:HKEY_CLASSES_ROOT\tldctl2.tldctl2c\
    New.Net key:HKEY_CLASSES_ROOT\tldctl2.tldctl2c.1\
    New.Net key:HKEY_CLASSES_ROOT\typelib\{dd521a10-1f98-11d4-9676-00e018981b9e}\
    New.Net key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\new.net startup
    New.Net key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\new.net startup
    Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\stashedgef
    Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\stashedgmg
    Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\msipcsv.exe
    Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\htmdeng.exe
    Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\ipcclient.dll
    Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\adimage.dll
    Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\tfde.dll
    New.Net key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\tldctl2.ocx
    Gator key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\IEGator.dll
    New.Net value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\newdotnet3_23.dll
    New.Net value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\newdotnet3_23.dll
    New.Net value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\newdotnet3_23.dll
    New.Net value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\newdotnet3_23.dll
    New.Net key:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\moduleusage\C:/WINDOWS/Downloaded Program Files/tldctl2.ocx
    Gator key:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\moduleusage\C:/WINDOWS/Downloaded Program Files/IEGator.dll
    New.Net key:CLSID\{DD521A1D-1F98-11D4-9676-00E018981B9E}


    Registry scan result:
    Suspicious keys found :39


    Started folder scan
    ====================
    Now processing drive (C), 0 remaining.
    Gator file:C:\WINDOWS\GatorPlugin.log
    FileSize : 1 kb
    FileCreation time : 11/16/01 9:38:03 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    New.Net file:C:\WINDOWS\newdotnet3_23.dll
    FileSize : 116 kb
    FileCreation time : 3/23/58 12:16:43 PM
    Last accessed : 2/10/65 5:30:33 PM
    Build : 3.0.0.23
    OS : No executable
    Comments:
    Description:New.net Application
    Version:3, 0, 0, 23
    ProductName:New.net Application

    Timesink file:C:\WINDOWS\TSAd.dll
    FileSize : 206 kb
    FileCreation time : 8/16/01 6:15:43 PM
    Last accessed : 11/25/01
    Build : 4.1.0.1
    OS : No executable
    Description:tsad
    Version:4, 1, 0, 1
    ProductName:Conducent AdGateway

    Timesink file:C:\WINDOWS\VcpDLL.dll
    FileSize : 224 kb
    FileCreation time : 8/16/01 6:15:43 PM
    Last accessed : 11/25/01
    Build : 4.1.0.1
    OS : No executable
    Description:VcpDLL
    Version:4, 1, 0, 1
    ProductName:Conducent Technologies, Inc. VcpDLL

    Aureate folder:C:\WINDOWS\Start Menu\Programs\Radiate
    Aureate folder:C:\WINDOWS\amcdl\adcache
    Aureate folder:C:\WINDOWS\amcdl
    OnFlow folder:C:\Program Files\Internet Explorer\PLUGINS\Onflow
    Aureate folder:C:\Program Files\Qualcomm\Eudora\EudPriv\Ads\AdCache
    Timesink folder:C:\Program Files\TimeSink\AdGateway
    Timesink folder:C:\Program Files\TimeSink
    OnFlow folder:C:\Program Files\onflow
    Finished processing Drive(C), 5582 folders total.

    Folder scan result:
    Folders processed:5582
    Suspicious folders found:8


    Started file scan
    ==================
    Aureate file:C:\WINDOWS\SYSTEM\adimage.dll
    FileSize : 108 kb
    FileCreation time : 3/23/58 12:16:43 PM
    Last accessed : 2/10/65 5:30:33 PM
    Build : 1.0.1.2
    OS : No executable
    Comments:,
    Description:Ad Image Display Engine
    Version:1.0.1.2
    ProductName:Aureate Network

    Aureate file:C:\WINDOWS\SYSTEM\htmdeng.exe
    FileSize : 52 kb
    FileCreation time : 8/28/01 4:43:42 PM
    Last accessed : 11/25/01
    Build : 1.0.1.0
    OS : No executable
    Comments:
    Description:Demographic Module
    Version:1,0,1,0
    ProductName:Demographic Module

    Aureate file:C:\WINDOWS\SYSTEM\ipcclient.dll
    FileSize : 36 kb
    FileCreation time : 3/23/58 12:16:43 PM
    Last accessed : 2/10/65 5:30:33 PM
    Build : 1.0.1.0
    OS : No executable
    Comments:
    Description:IPC Client
    Version:1, 0, 1, 0
    ProductName:IPC Client

    Aureate file:C:\WINDOWS\SYSTEM\msipcsv.exe
    FileSize : 296 kb
    FileCreation time : 8/28/01 4:43:41 PM
    Last accessed : 11/25/01
    Build : 1.0.1.7
    OS : No executable
    Comments:
    Description:IPC Server
    Version:1.0.1.7
    ProductName:IPC Server

    Aureate file:C:\WINDOWS\SYSTEM\tfde.dll
    FileSize : 56 kb
    FileCreation time : 3/23/58 12:16:43 PM
    Last accessed : 2/10/65 5:30:33 PM
    Build : 1.0.1.6
    OS : No executable
    Comments:
    Description:tfde
    Version:1, 0, 1, 6
    ProductName:Aureate Media tfde

    Aureate file:C:\WINDOWS\Start Menu\Programs\Radiate\Radiate Web Site.url
    FileSize : 0 kb
    FileCreation time : 8/28/01 4:43:46 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    Gator file:C:\WINDOWS\Downloaded Program Files\IEGator.dll
    FileSize : 212 kb
    FileCreation time : 10/23/01 5:45:38 PM
    Last accessed : 11/25/01
    Build : 3.0.2.7
    OS : No executable
    Description:Gator installer plugin for Internet Explorer
    Version: 3.0.2.7
    ProductName:GAIN

    Gator file:C:\WINDOWS\Downloaded Program Files\IEGator.inf
    FileSize : 0 kb
    FileCreation time : 10/23/01 5:45:56 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    New.Net file:C:\WINDOWS\Downloaded Program Files\tldctl2.inf
    FileSize : 0 kb
    FileCreation time : 9/27/01 11:14:24 AM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    New.Net file:C:\WINDOWS\Downloaded Program Files\tldctl2.ocx
    FileSize : 116 kb
    FileCreation time : 9/27/01 11:12:12 AM
    Last accessed : 11/25/01
    Build : 3.0.0.23
    OS : No executable
    Comments:
    Description:New.net Application
    Version:3, 0, 0, 23
    ProductName:New.net Application

    Other file:C:\WINDOWS\Cookies\elizabeth [email protected][1].txt
    FileSize : 0 kb
    FileCreation time : 10/5/01 8:09:36 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    Doubleclick file:C:\WINDOWS\Cookies\elizabeth [email protected][1].txt
    FileSize : 0 kb
    FileCreation time : 11/25/01 6:43:08 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    Flyswat file:C:\WINDOWS\Cookies\elizabeth [email protected][1].txt
    FileSize : 0 kb
    FileCreation time : 10/1/01 4:35:55 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    Other file:C:\WINDOWS\Cookies\elizabeth [email protected][2].txt
    FileSize : 0 kb
    FileCreation time : 11/25/01 6:41:43 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    Other file:C:\WINDOWS\Cookies\elizabeth [email protected][1].txt
    FileSize : 0 kb
    FileCreation time : 10/2/01 7:17:53 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    Gator file:C:\WINDOWS\GatorPlugin.log
    FileSize : 1 kb
    FileCreation time : 11/16/01 9:38:03 PM
    Last accessed : 11/25/01
    Build :
    OS : No executable

    New.Net file:C:\WINDOWS\newdotnet3_23.dll
    FileSize : 116 kb
    FileCreation time : 3/23/58 12:16:43 PM
    Last accessed : 2/10/65 5:30:33 PM
    Build : 3.0.0.23
    OS : No executable
    Comments:
    Description:New.net Application
    Version:3, 0, 0, 23
    ProductName:New.net Application

    Timesink file:C:\WINDOWS\TSAd.dll
    FileSize : 206 kb
    FileCreation time : 8/16/01 6:15:43 PM
    Last accessed : 11/25/01
    Build : 4.1.0.1
    OS : No executable
    Description:tsad
    Version:4, 1, 0, 1
    ProductName:Conducent AdGateway

    Timesink file:C:\WINDOWS\VcpDLL.dll
    FileSize : 224 kb
    FileCreation time : 8/16/01 6:15:43 PM
    Last accessed : 11/25/01
    Build : 4.1.0.1
    OS : No executable
    Description:VcpDLL
    Version:4, 1, 0, 1
    ProductName:Conducent Technologies, Inc. VcpDLL

    Timesink file:C:\Program Files\TimeSink\AdGateway\TSADBOT.EXE
    FileSize : 93 kb
    FileCreation time : 8/16/01 6:15:44 PM
    Last accessed : 11/25/01
    Build : 4.1.0.1
    OS : No executable
    Description:TSAdBot
    Version:4, 1, 0, 1
    ProductName:Conducent AdGateway

    OnFlow file:C:\Program Files\onflow\uninstall onflow.exe
    FileSize : 81 kb
    FileCreation time : 5/30/01 10:58:11 PM
    Last accessed : 11/25/01
    Build : 1.14.187.0
    OS : No executable
    Comments:Onflow (TM)
    Description:Onflow Stub Installer
    Version:01.14.0187
    ProductName:Onflow Player Version 1.14

    OnFlow file:C:\My Documents\Elizabeth15\netscape plugins\nponflow.dll
    FileSize : 25 kb
    FileCreation time : 8/29/01 6:20:12 PM
    Last accessed : 11/25/01
    Build : 1.14.187.0
    OS : No executable
    Comments:Onflow (TM)
    Description:Onflow Plugin Stub for Netscape and IE
    Version:01.14.0187
    ProductName:Onflow Player Version 1.14

    OnFlow file:C:\My Documents\Elizabeth15\netscape plugins\onflowplayer0.dll
    FileSize : 404 kb
    FileCreation time : 8/29/01 6:20:14 PM
    Last accessed : 11/25/01
    Build : 1.14.187.0
    OS : No executable
    Comments:Onflow (TM)
    Description:Onflow OFB and OFS Player
    Version:01.14.0187
    ProductName:Onflow Player Version 1.14

    OnFlow file:C:\TEMP\of_stub_ins_w_2045.exe
    FileSize : 81 kb
    FileCreation time : 5/30/01 10:58:11 PM
    Last accessed : 11/25/01
    Build : 1.14.187.0
    OS : No executable
    Comments:Onflow (TM)
    Description:Onflow Stub Installer
    Version:01.14.0187
    ProductName:Onflow Player Version 1.14


    Remark: Doubleclick-optout cookie found and ignored.


    File scan result:
    Suspicious files found:28



    Scanning finished
    ==================
    Suspicious modules found:0
    Suspicious keys found :39
    Suspicious folders found:8
    Suspicious files found:28
    ==========================
    Spyware components ignored:0
    Total spyware components found:75


    I upgraded to version 5.62 and that seemed to fix the errors I was getting scanning the drive.


    So, what do I delete?
     
  4. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    35,168
    Okay

    You have new.net in there. Read this on how to remove it:

    http://www.cexx.org/newnet.htm

    I see you use Gator, which is for your Passwords. This won't work when you remove the files.

    It also seems that you have Web3000. DON'T do anything until we remove the host software. It replaces your wsock32.dll, which you need to dialup with.

    Have a look here:

    http://www.uninet.net/~blaisdel/web3000.htm#Removing Web3000

    If you can't figure it out, just post the list of all your programs, not Microsofts.

    Once we are fully satisfied, then we can runb AddAware again.

    Regards

    eddie
     
  5. jediliz

    jediliz Thread Starter

    Joined:
    Jun 4, 2001
    Messages:
    160
    1. Actually, I don't dial up, I have a cable modem
    2. I installed Gator A Long Time Ago, but I thought I had removed it awhile back........


    Whatever else you said, really confused me........


    I checked the web3000 and newnet and put them in an ignore file.....was that wrong?
     
  6. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    35,168
    If you do a search for wsock32.dll, it will be on your system. Without it, you cannot connect to the web.

    Uninstalling Gator does not remove the spyware components.

    Also, you say you put new.net and Web3000 in an ignore file. Whats that? They still need to be removed off your system manually.

    Just follow the link for new.net and we'll go through it first.


    Just twigged. Don't use AddAware until its removed.

    eddie
     
  7. jediliz

    jediliz Thread Starter

    Joined:
    Jun 4, 2001
    Messages:
    160
    I removed the gator components. The ignore file was something in the adaware program. I followed the new.net removal instructions, but it didn't work to remove it using the instructions.

    Okay, what next?
     
  8. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    35,168
    Hiya

    I assume that you tried this:

    http://www.new.net/help_faq.tp#p4

    and you're still having problems. Well, there is a number to ring or email:

    [email protected] (626) 229-7800

    There are some other methods of removal, but I don't know if people here have used them.

    eddie
     
  9. jediliz

    jediliz Thread Starter

    Joined:
    Jun 4, 2001
    Messages:
    160
    Okay, I got new.net removed. I'm not restarting my computer again, yet.


    It worked this time. I guess my computer was screwed up yesterday. :( :p

    I'm going to do adaware again and check what to get rid of next. What if I have a download program, will it still work? I have download accelerator.....I don't want to delete it yet.
     
  10. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    35,168
    Thats half done. Have you removed the Web3000 using the link that I provided?

    download accelerator is not spyware from what I can remember. You can keep this.

    Just confirm about the Web3000 first before using AddAware.

    eddie
     
  11. jediliz

    jediliz Thread Starter

    Joined:
    Jun 4, 2001
    Messages:
    160
    I ran adaware again and deletd the aureauate components.....and I noticed web3000 was not listed....probably because it was being ignored......it might still be the log.....I'll check.....


    Okay, is there a list of things that are included with web3000 or what it contains?

    I don't see it listed in my Add/Remove Programs


    I did a search for wsock and its still there. I am hoping I will be able to view my adobe acrobat stuff soon.
     
  12. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    35,168
    Okay

    To find out which it is may take a while. Can you post a list of all programs? We don't need Microsoft's stuff. If you have a lot, then you can post go via MSINFO32 as earlier, but this time in Software Enviroment, go to Program Groups.

    Regards

    eddie
     
  13. jediliz

    jediliz Thread Starter

    Joined:
    Jun 4, 2001
    Messages:
    160
    Sorry it took me a week, but I finally got what the web300 is.....though I have no idea how I will remove it.


    The things listed for web3000 were:

    stashedgef

    AND

    stash edgmg



    Not sure where to find these? :confused: :confused: :confused: :confused:
     
  14. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    35,168
    Hiya

    I have just twigged what the Ignore bit was. You don't want to ignore Web3000.

    When you open AddAware, go to the third button down, called Configuration. In there, click Ignore List. As I don't have anything in there, I am assuming you have a few files in there. Just check them then click Remove Checked Items.

    This will hopefully allow you to remove the parts that you couldn't before. The files that you have listed isn't exactly what I was looking for. There's not much comming up on those.

    This is roughly what I'm after. Go to the MSINFO32 bit that I posted earlier but this time in Software Enviroment, go to Program Groups.

    Here is mine. I have edited it just to show the programs. There is accessories in there, but that's not what we're after:

    Zone Labs
    AntiViral Toolkit Pro
    WinZip
    Team17
    Team17\Worms World Party
    The Cleaner
    Ad-aware 5.6
    Lavasoft RefUpdate

    I know, not much, but its newish :p

    So, from the list, if I had, say Gozilla in there, then that is a major scource. I can check all programs for spyware.

    Regards

    eddie
     
  15. jediliz

    jediliz Thread Starter

    Joined:
    Jun 4, 2001
    Messages:
    160
    I had the cleaner and uninstalled the program just now. I hope that helps me.


    What else should I do? I am still very confused.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/59598

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice