[SOLVED] Adobe Acrobat Crashes after....

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

jediliz

Thread Starter
Joined
Jun 4, 2001
Messages
160
trying to open the online posted Best Buy Ad.
I think I have 5.0.

This is a consistent error.


Here is what I get:

ACRORD32 caused an invalid page fault in
module unknown at 0000:00000009.
Registers:
EAX=00010000 CS=017f EIP=00000009 EFLGS=00010286
EBX=00000000 SS=0187 ESP=009ef050 EBP=009ef128
ECX=027f6030 DS=0187 ESI=01bc7920 FS=19ef
EDX=00000008 ES=0187 EDI=00000000 GS=0000
Bytes at CS:EIP:
00 b6 05 65 04 70 00 65 04 70 00 54 ff 00 f0 8f
Stack dump:
01bc0187 37034af0 027f6030 00000000 00000000 00000000 00000003 00000080 00000000 00000000 01bc7920 0000000b 00640072 00540020 cf329001 e55a7b96


Any help or suggestions?
 

eddie5659

Moderator
Malware Specialist
Joined
Mar 19, 2001
Messages
37,270
Hiya

you know for the module: Did it come up with Unknown or something else but with <>'s surrounding it? If so, can you edit it so that these are removed. They won't post otherwise.

As soon as we get that, we can delve deeper. For the moment, whilst we wait, as it may be unknown, go here and download AddAware www.lavasoftusa.com
Install and run it, ensuring that Deep Registry Scan is enabled. Remove all except any references to Web3000 or new.net. If you're unsure, copy/paste the list.

regards

eddie
 

jediliz

Thread Starter
Joined
Jun 4, 2001
Messages
160
I already have AdAware installed and this is the list I get:


Okay, I am having trouble with running AdAware right now. I'll edit this post when I get it to work.

Okay here are the results:


Scan initialized on 11/25/01 6:40:19 PM.
(AAW release 5.62, referencefile 087-24.06.2001)
=================================================


Started extended registry scan
===============================
Aureate key:HKEY_USERS\.default\software\aureate\
Timesink key:HKEY_USERS\.default\software\timesink, inc.\
Gator key:HKEY_CLASSES_ROOT\clsid\{21ffb6c0-0da1-11d5-a9d5-00500413153c}\
New.Net key:HKEY_CLASSES_ROOT\clsid\{dd521a1d-1f98-11d4-9676-00e018981b9e}\
New.Net key:HKEY_CLASSES_ROOT\interface\{dd521a1c-1f98-11d4-9676-00e018981b9e}\
Aureate key:HKEY_CLASSES_ROOT\software\aureate\
Aureate key:HKEY_CURRENT_USER\software\aureate\
Aureate key:HKEY_LOCAL_MACHINE\software\aureate\
DSSAgent key:HKEY_LOCAL_MACHINE\software\broderbund software\dss\
Gator key:HKEY_LOCAL_MACHINE\software\gator.com\
New.Net key:HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{dd521a1d-1f98-11d4-9676-00e018981b9e}\
Gator key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/iegator.dll\
New.Net key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net\
Aureate key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\radiate advertising\
New.Net key:HKEY_LOCAL_MACHINE\software\new.net\
New.Net key:HKEY_LOCAL_MACHINE\software\new.net\
Timesink key:HKEY_CURRENT_USER\software\timesink, inc.\
Timesink key:HKEY_LOCAL_MACHINE\software\timesink, inc.\
New.Net key:HKEY_CLASSES_ROOT\tldctl2.tldctl2c\
New.Net key:HKEY_CLASSES_ROOT\tldctl2.tldctl2c.1\
New.Net key:HKEY_CLASSES_ROOT\typelib\{dd521a10-1f98-11d4-9676-00e018981b9e}\
New.Net key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\new.net startup
New.Net key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\new.net startup
Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\stashedgef
Web3000 key:HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\stashedgmg
Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\msipcsv.exe
Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\htmdeng.exe
Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\ipcclient.dll
Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\adimage.dll
Aureate key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\SYSTEM\tfde.dll
New.Net key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\tldctl2.ocx
Gator key:Software\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\IEGator.dll
New.Net value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\newdotnet3_23.dll
New.Net value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\newdotnet3_23.dll
New.Net value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\newdotnet3_23.dll
New.Net value:System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries:packedCatalogItem=c:\windows\newdotnet3_23.dll
New.Net key:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\moduleusage\C:/WINDOWS/Downloaded Program Files/tldctl2.ocx
Gator key:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\moduleusage\C:/WINDOWS/Downloaded Program Files/IEGator.dll
New.Net key:CLSID\{DD521A1D-1F98-11D4-9676-00E018981B9E}


Registry scan result:
Suspicious keys found :39


Started folder scan
====================
Now processing drive (C), 0 remaining.
Gator file:C:\WINDOWS\GatorPlugin.log
FileSize : 1 kb
FileCreation time : 11/16/01 9:38:03 PM
Last accessed : 11/25/01
Build :
OS : No executable

New.Net file:C:\WINDOWS\newdotnet3_23.dll
FileSize : 116 kb
FileCreation time : 3/23/58 12:16:43 PM
Last accessed : 2/10/65 5:30:33 PM
Build : 3.0.0.23
OS : No executable
Comments:
Description:New.net Application
Version:3, 0, 0, 23
ProductName:New.net Application

Timesink file:C:\WINDOWS\TSAd.dll
FileSize : 206 kb
FileCreation time : 8/16/01 6:15:43 PM
Last accessed : 11/25/01
Build : 4.1.0.1
OS : No executable
Description:tsad
Version:4, 1, 0, 1
ProductName:Conducent AdGateway

Timesink file:C:\WINDOWS\VcpDLL.dll
FileSize : 224 kb
FileCreation time : 8/16/01 6:15:43 PM
Last accessed : 11/25/01
Build : 4.1.0.1
OS : No executable
Description:VcpDLL
Version:4, 1, 0, 1
ProductName:Conducent Technologies, Inc. VcpDLL

Aureate folder:C:\WINDOWS\Start Menu\Programs\Radiate
Aureate folder:C:\WINDOWS\amcdl\adcache
Aureate folder:C:\WINDOWS\amcdl
OnFlow folder:C:\Program Files\Internet Explorer\PLUGINS\Onflow
Aureate folder:C:\Program Files\Qualcomm\Eudora\EudPriv\Ads\AdCache
Timesink folder:C:\Program Files\TimeSink\AdGateway
Timesink folder:C:\Program Files\TimeSink
OnFlow folder:C:\Program Files\onflow
Finished processing Drive(C), 5582 folders total.

Folder scan result:
Folders processed:5582
Suspicious folders found:8


Started file scan
==================
Aureate file:C:\WINDOWS\SYSTEM\adimage.dll
FileSize : 108 kb
FileCreation time : 3/23/58 12:16:43 PM
Last accessed : 2/10/65 5:30:33 PM
Build : 1.0.1.2
OS : No executable
Comments:,
Description:Ad Image Display Engine
Version:1.0.1.2
ProductName:Aureate Network

Aureate file:C:\WINDOWS\SYSTEM\htmdeng.exe
FileSize : 52 kb
FileCreation time : 8/28/01 4:43:42 PM
Last accessed : 11/25/01
Build : 1.0.1.0
OS : No executable
Comments:
Description:Demographic Module
Version:1,0,1,0
ProductName:Demographic Module

Aureate file:C:\WINDOWS\SYSTEM\ipcclient.dll
FileSize : 36 kb
FileCreation time : 3/23/58 12:16:43 PM
Last accessed : 2/10/65 5:30:33 PM
Build : 1.0.1.0
OS : No executable
Comments:
Description:IPC Client
Version:1, 0, 1, 0
ProductName:IPC Client

Aureate file:C:\WINDOWS\SYSTEM\msipcsv.exe
FileSize : 296 kb
FileCreation time : 8/28/01 4:43:41 PM
Last accessed : 11/25/01
Build : 1.0.1.7
OS : No executable
Comments:
Description:IPC Server
Version:1.0.1.7
ProductName:IPC Server

Aureate file:C:\WINDOWS\SYSTEM\tfde.dll
FileSize : 56 kb
FileCreation time : 3/23/58 12:16:43 PM
Last accessed : 2/10/65 5:30:33 PM
Build : 1.0.1.6
OS : No executable
Comments:
Description:tfde
Version:1, 0, 1, 6
ProductName:Aureate Media tfde

Aureate file:C:\WINDOWS\Start Menu\Programs\Radiate\Radiate Web Site.url
FileSize : 0 kb
FileCreation time : 8/28/01 4:43:46 PM
Last accessed : 11/25/01
Build :
OS : No executable

Gator file:C:\WINDOWS\Downloaded Program Files\IEGator.dll
FileSize : 212 kb
FileCreation time : 10/23/01 5:45:38 PM
Last accessed : 11/25/01
Build : 3.0.2.7
OS : No executable
Description:Gator installer plugin for Internet Explorer
Version: 3.0.2.7
ProductName:GAIN

Gator file:C:\WINDOWS\Downloaded Program Files\IEGator.inf
FileSize : 0 kb
FileCreation time : 10/23/01 5:45:56 PM
Last accessed : 11/25/01
Build :
OS : No executable

New.Net file:C:\WINDOWS\Downloaded Program Files\tldctl2.inf
FileSize : 0 kb
FileCreation time : 9/27/01 11:14:24 AM
Last accessed : 11/25/01
Build :
OS : No executable

New.Net file:C:\WINDOWS\Downloaded Program Files\tldctl2.ocx
FileSize : 116 kb
FileCreation time : 9/27/01 11:12:12 AM
Last accessed : 11/25/01
Build : 3.0.0.23
OS : No executable
Comments:
Description:New.net Application
Version:3, 0, 0, 23
ProductName:New.net Application

Other file:C:\WINDOWS\Cookies\elizabeth [email protected][1].txt
FileSize : 0 kb
FileCreation time : 10/5/01 8:09:36 PM
Last accessed : 11/25/01
Build :
OS : No executable

Doubleclick file:C:\WINDOWS\Cookies\elizabeth [email protected][1].txt
FileSize : 0 kb
FileCreation time : 11/25/01 6:43:08 PM
Last accessed : 11/25/01
Build :
OS : No executable

Flyswat file:C:\WINDOWS\Cookies\elizabeth [email protected][1].txt
FileSize : 0 kb
FileCreation time : 10/1/01 4:35:55 PM
Last accessed : 11/25/01
Build :
OS : No executable

Other file:C:\WINDOWS\Cookies\elizabeth [email protected][2].txt
FileSize : 0 kb
FileCreation time : 11/25/01 6:41:43 PM
Last accessed : 11/25/01
Build :
OS : No executable

Other file:C:\WINDOWS\Cookies\elizabeth [email protected][1].txt
FileSize : 0 kb
FileCreation time : 10/2/01 7:17:53 PM
Last accessed : 11/25/01
Build :
OS : No executable

Gator file:C:\WINDOWS\GatorPlugin.log
FileSize : 1 kb
FileCreation time : 11/16/01 9:38:03 PM
Last accessed : 11/25/01
Build :
OS : No executable

New.Net file:C:\WINDOWS\newdotnet3_23.dll
FileSize : 116 kb
FileCreation time : 3/23/58 12:16:43 PM
Last accessed : 2/10/65 5:30:33 PM
Build : 3.0.0.23
OS : No executable
Comments:
Description:New.net Application
Version:3, 0, 0, 23
ProductName:New.net Application

Timesink file:C:\WINDOWS\TSAd.dll
FileSize : 206 kb
FileCreation time : 8/16/01 6:15:43 PM
Last accessed : 11/25/01
Build : 4.1.0.1
OS : No executable
Description:tsad
Version:4, 1, 0, 1
ProductName:Conducent AdGateway

Timesink file:C:\WINDOWS\VcpDLL.dll
FileSize : 224 kb
FileCreation time : 8/16/01 6:15:43 PM
Last accessed : 11/25/01
Build : 4.1.0.1
OS : No executable
Description:VcpDLL
Version:4, 1, 0, 1
ProductName:Conducent Technologies, Inc. VcpDLL

Timesink file:C:\Program Files\TimeSink\AdGateway\TSADBOT.EXE
FileSize : 93 kb
FileCreation time : 8/16/01 6:15:44 PM
Last accessed : 11/25/01
Build : 4.1.0.1
OS : No executable
Description:TSAdBot
Version:4, 1, 0, 1
ProductName:Conducent AdGateway

OnFlow file:C:\Program Files\onflow\uninstall onflow.exe
FileSize : 81 kb
FileCreation time : 5/30/01 10:58:11 PM
Last accessed : 11/25/01
Build : 1.14.187.0
OS : No executable
Comments:Onflow (TM)
Description:Onflow Stub Installer
Version:01.14.0187
ProductName:Onflow Player Version 1.14

OnFlow file:C:\My Documents\Elizabeth15\netscape plugins\nponflow.dll
FileSize : 25 kb
FileCreation time : 8/29/01 6:20:12 PM
Last accessed : 11/25/01
Build : 1.14.187.0
OS : No executable
Comments:Onflow (TM)
Description:Onflow Plugin Stub for Netscape and IE
Version:01.14.0187
ProductName:Onflow Player Version 1.14

OnFlow file:C:\My Documents\Elizabeth15\netscape plugins\onflowplayer0.dll
FileSize : 404 kb
FileCreation time : 8/29/01 6:20:14 PM
Last accessed : 11/25/01
Build : 1.14.187.0
OS : No executable
Comments:Onflow (TM)
Description:Onflow OFB and OFS Player
Version:01.14.0187
ProductName:Onflow Player Version 1.14

OnFlow file:C:\TEMP\of_stub_ins_w_2045.exe
FileSize : 81 kb
FileCreation time : 5/30/01 10:58:11 PM
Last accessed : 11/25/01
Build : 1.14.187.0
OS : No executable
Comments:Onflow (TM)
Description:Onflow Stub Installer
Version:01.14.0187
ProductName:Onflow Player Version 1.14


Remark: Doubleclick-optout cookie found and ignored.


File scan result:
Suspicious files found:28



Scanning finished
==================
Suspicious modules found:0
Suspicious keys found :39
Suspicious folders found:8
Suspicious files found:28
==========================
Spyware components ignored:0
Total spyware components found:75


I upgraded to version 5.62 and that seemed to fix the errors I was getting scanning the drive.


So, what do I delete?
 

eddie5659

Moderator
Malware Specialist
Joined
Mar 19, 2001
Messages
37,270
Okay

You have new.net in there. Read this on how to remove it:

http://www.cexx.org/newnet.htm

I see you use Gator, which is for your Passwords. This won't work when you remove the files.

It also seems that you have Web3000. DON'T do anything until we remove the host software. It replaces your wsock32.dll, which you need to dialup with.

Have a look here:

http://www.uninet.net/~blaisdel/web3000.htm#Removing Web3000

If you can't figure it out, just post the list of all your programs, not Microsofts.

Once we are fully satisfied, then we can runb AddAware again.

Regards

eddie
 

jediliz

Thread Starter
Joined
Jun 4, 2001
Messages
160
1. Actually, I don't dial up, I have a cable modem
2. I installed Gator A Long Time Ago, but I thought I had removed it awhile back........


Whatever else you said, really confused me........


I checked the web3000 and newnet and put them in an ignore file.....was that wrong?
 

eddie5659

Moderator
Malware Specialist
Joined
Mar 19, 2001
Messages
37,270
If you do a search for wsock32.dll, it will be on your system. Without it, you cannot connect to the web.

Uninstalling Gator does not remove the spyware components.

Also, you say you put new.net and Web3000 in an ignore file. Whats that? They still need to be removed off your system manually.

Just follow the link for new.net and we'll go through it first.


Just twigged. Don't use AddAware until its removed.

eddie
 

jediliz

Thread Starter
Joined
Jun 4, 2001
Messages
160
I removed the gator components. The ignore file was something in the adaware program. I followed the new.net removal instructions, but it didn't work to remove it using the instructions.

Okay, what next?
 

jediliz

Thread Starter
Joined
Jun 4, 2001
Messages
160
Okay, I got new.net removed. I'm not restarting my computer again, yet.


It worked this time. I guess my computer was screwed up yesterday. :( :p

I'm going to do adaware again and check what to get rid of next. What if I have a download program, will it still work? I have download accelerator.....I don't want to delete it yet.
 

eddie5659

Moderator
Malware Specialist
Joined
Mar 19, 2001
Messages
37,270
Thats half done. Have you removed the Web3000 using the link that I provided?

download accelerator is not spyware from what I can remember. You can keep this.

Just confirm about the Web3000 first before using AddAware.

eddie
 

jediliz

Thread Starter
Joined
Jun 4, 2001
Messages
160
I ran adaware again and deletd the aureauate components.....and I noticed web3000 was not listed....probably because it was being ignored......it might still be the log.....I'll check.....


Okay, is there a list of things that are included with web3000 or what it contains?

I don't see it listed in my Add/Remove Programs


I did a search for wsock and its still there. I am hoping I will be able to view my adobe acrobat stuff soon.
 

eddie5659

Moderator
Malware Specialist
Joined
Mar 19, 2001
Messages
37,270
Okay

To find out which it is may take a while. Can you post a list of all programs? We don't need Microsoft's stuff. If you have a lot, then you can post go via MSINFO32 as earlier, but this time in Software Enviroment, go to Program Groups.

Regards

eddie
 

jediliz

Thread Starter
Joined
Jun 4, 2001
Messages
160
Sorry it took me a week, but I finally got what the web300 is.....though I have no idea how I will remove it.


The things listed for web3000 were:

stashedgef

AND

stash edgmg



Not sure where to find these? :confused: :confused: :confused: :confused:
 

eddie5659

Moderator
Malware Specialist
Joined
Mar 19, 2001
Messages
37,270
Hiya

I have just twigged what the Ignore bit was. You don't want to ignore Web3000.

When you open AddAware, go to the third button down, called Configuration. In there, click Ignore List. As I don't have anything in there, I am assuming you have a few files in there. Just check them then click Remove Checked Items.

This will hopefully allow you to remove the parts that you couldn't before. The files that you have listed isn't exactly what I was looking for. There's not much comming up on those.

This is roughly what I'm after. Go to the MSINFO32 bit that I posted earlier but this time in Software Enviroment, go to Program Groups.

Here is mine. I have edited it just to show the programs. There is accessories in there, but that's not what we're after:

Zone Labs
AntiViral Toolkit Pro
WinZip
Team17
Team17\Worms World Party
The Cleaner
Ad-aware 5.6
Lavasoft RefUpdate

I know, not much, but its newish :p

So, from the list, if I had, say Gozilla in there, then that is a major scource. I can check all programs for spyware.

Regards

eddie
 

jediliz

Thread Starter
Joined
Jun 4, 2001
Messages
160
I had the cleaner and uninstalled the program just now. I hope that helps me.


What else should I do? I am still very confused.
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Members online

Top