Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 09-06-2004, 03:15 PM   #1
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
Unhappy IE error message

hi all,
I keep getting an error message when on the internet and it closes IE. It's Getting very agrivating Maybe someone can help. The message is:
"This program has performed an Illegal Operation"
BROWSEUI.dll at 0257:711678a9
Does anyone know how to fix this? I have defragged, run spybot,adaware, and virus scans. HELP!
Ray
lovesranch is offline   Reply With Quote
Old 09-06-2004, 08:20 PM   #2
Ride 'em Cowboy
 
EzyStvy's Avatar
 
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,109
Error Message: "Caused an invalid page fault in module Kernel32.dll"
http://support.microsoft.com/support.../Q187/9/65.ASP


Frequently Asked Questions About Illegal Operations and Invalid Page Faults in Internet Explorer
http://support.microsoft.com/support...pics/ieipf.asp


Unrecoverable Errors Such as "Invalid Page Faults" or "General Protection Faults" in Internet Explorer
http://support.microsoft.com/support.../Q276/3/93.ASP
EzyStvy is online now   Reply With Quote
Old 09-07-2004, 07:35 PM   #3
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
Thanks EZY,
no luck yet on the fix.Still working on it.
lovesranch is offline   Reply With Quote
Old 09-08-2004, 07:13 AM   #4
Member (10 bit)
 
Mesaeus's Avatar
 
Join Date: Aug 2004
Location: Belgium
Posts: 873
Could you post a HijackThis log ? It's possible there's still some spyware present that Spybot & Adaware didn't find, and this could be the cause of your problems.
Mesaeus is offline   Reply With Quote
Old 09-08-2004, 01:10 PM   #5
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
Quote:
Originally Posted by Mesaeus
Could you post a HijackThis log ? It's possible there's still some spyware present that Spybot & Adaware didn't find, and this could be the cause of your problems.

i'll try when i get home from work,
thanks
lovesranch is offline   Reply With Quote
Old 09-08-2004, 03:40 PM   #6
Barefoot on the Moon!
Staff
Premium Member
 
Force Flow's Avatar
 
Join Date: Aug 2002
Location: Northeastern USA
Posts: 13,385
What version of IE are you running?
__________________
There are two secrets to staying young, being happy, and achieving success. You have to laugh and find humor every day, and you have to have a dream.
Force Flow is offline   Reply With Quote
Old 09-08-2004, 07:35 PM   #7
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
Internet Explorer 6.0
lovesranch is offline   Reply With Quote
Old 09-08-2004, 08:02 PM   #8
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
HijackThisLog

Mesaeus,
As requested. It's all French to me!

Logfile of HijackThis v1.95.0
Scan saved at 5:56:24 PM, on 9/8/04
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\WINDOWS\APPPATCH\VBDOC.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\AIM\AIM.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\EXPLORER.EXE
C:\DWNLDEDZIPS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.weather.com/outlook/driving/local/93536?lswe=93536&lwsa=WeatherLocalDriving
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar=http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default)=http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=c:\windows\SYSTEM\blank.htm
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN3\YCOMP5_5_5_0.DLL
O2 - BHO: (no name) - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\WINDOWS\TEMP\GERPTF.DAT
O2 - BHO: (no name) - {F32F8ECD-6CF3-459D-82F2-9738392C85A8} - C:\WINDOWS\TEMP\GOLBV.DAT
O2 - BHO: (no name) - {BF755B85-EA69-4F58-9A59-D85F384A15FF} - C:\WINDOWS\TEMP\CODBV.DAT
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN3\YCOMP5_5_5_0.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\ROBOFORM.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
O4 - HKLM\..\Run: [ASHLT] C:\WINDOWS\Ashlt.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [*VBLOG] C:\WINDOWS\SPEECH\VBLOG.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [TASKFONT] C:\WINDOWS\FONTS\TASKFONT.EXE
O4 - HKLM\..\Run: [*VBDOC] C:\WINDOWS\APPPATCH\VBDOC.EXE
O4 - HKLM\..\Run: [ACKB] C:\WINDOWS\APPPATCH\ACKB.EXE
O4 - HKLM\..\Run: [*BASDB] C:\WINDOWS\MSAGENT\BASDB.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: RoboForm (HKLM)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 (HKLM)
O9 - Extra button: Fill Forms (HKLM)
O9 - Extra 'Tools' menuitem: Fill Forms &] (HKLM)
O9 - Extra button: Save (HKLM)
O9 - Extra 'Tools' menuitem: Save Forms &[ (HKLM)
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .bmp: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get...irector/sw.cab
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {68B632F6-FB2C-11D2-9AEA-DC27E1000000} - http://www.cyberworldcorp.com/downloads/CW4AJ19.exe
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...804.7415162037
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.originalicons.com/members/arrtv.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache...tup1.0.0.8.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
lovesranch is offline   Reply With Quote
Old 09-09-2004, 10:56 AM   #9
Member (10 bit)
 
Mesaeus's Avatar
 
Join Date: Aug 2004
Location: Belgium
Posts: 873
You have quite some spyware still present. First close down all running programs, especially Windows Explorer and Internet Explorer, otherwise some things may not be deleted. Then start deleting these entries :


O2 - BHO: (no name) - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\WINDOWS\TEMP\GERPTF.DAT
O2 - BHO: (no name) - {F32F8ECD-6CF3-459D-82F2-9738392C85A8} - C:\WINDOWS\TEMP\GOLBV.DAT
O2 - BHO: (no name) - {BF755B85-EA69-4F58-9A59-D85F384A15FF} - C:\WINDOWS\TEMP\CODBV.DAT
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
O4 - HKLM\..\Run: [ASHLT] C:\WINDOWS\Ashlt.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [*VBLOG] C:\WINDOWS\SPEECH\VBLOG.EXE
O4 - HKLM\..\Run: [TASKFONT] C:\WINDOWS\FONTS\TASKFONT.EXE
O4 - HKLM\..\Run: [*VBDOC] C:\WINDOWS\APPPATCH\VBDOC.EXE
O4 - HKLM\..\Run: [ACKB] C:\WINDOWS\APPPATCH\ACKB.EXE
O4 - HKLM\..\Run: [*BASDB] C:\WINDOWS\MSAGENT\BASDB.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029
O16 - DPF: {68B632F6-FB2C-11D2-9AEA-DC27E1000000} - http://www.cyberworldcorp.com/downloads/CW4AJ19.exe
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.originalicons.com/members/arrtv.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocach...etup1.0.0.8.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yah...nst20040510.cab

After doing this, reboot and post a new HijackThis log (preferably with only HijackThis running). I can't guarantee it will solve your problem, but I cannot believe how many times cleaning out spyware has solved IE crashing such as yours.
Mesaeus is offline   Reply With Quote
Old 09-09-2004, 01:05 PM   #10
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
I will do that when i get home tonight (4pm PST)and post results.
Thanks
lovesranch is offline   Reply With Quote
Old 09-09-2004, 07:24 PM   #11
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
HijackThisLog after fix

O.K. Mesaeus,
Here's the logfile after deleting those items.

Logfile of HijackThis v1.95.0
Scan saved at 5:00:35 PM, on 9/9/04
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\APPPATCH\VBDOC.EXE
C:\DWNLDEDZIPS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.weather.com/outlook/driving/local/93536?lswe=93536&lwsa=WeatherLocalDriving
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar=http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default)=http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=c:\windows\SYSTEM\blank.htm
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN3\YCOMP5_5_5_0.DLL
O2 - BHO: (no name) - {BF755B85-EA69-4F58-9A59-D85F384A15FF} - C:\WINDOWS\TEMP\CODBV.DAT
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN3\YCOMP5_5_5_0.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\ROBOFORM.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [*VBDOC] C:\WINDOWS\APPPATCH\VBDOC.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: RoboForm (HKLM)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 (HKLM)
O9 - Extra button: Fill Forms (HKLM)
O9 - Extra 'Tools' menuitem: Fill Forms &] (HKLM)
O9 - Extra button: Save (HKLM)
O9 - Extra 'Tools' menuitem: Save Forms &[ (HKLM)
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .bmp: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get...irector/sw.cab
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...804.7415162037
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab

The one in bold came back after deleting it twice. While i was runnilng Hijackthis, I tried to use "ctrl,alt,delete" to end IE program but it was still running, even though the browser window was not open. I also closed Zone alarm & disconnected from the internet. When re-booting i got the following error messages: (before it shutdown)
Mprexe,Mmtask,Msgsrv32
Caused an Invalid page fault
Kernel32 .dll at 0257:bff9dba7
hope this gives you a clue.
lovesranch is offline   Reply With Quote
Old 09-09-2004, 08:24 PM   #12
Member (10 bit)
 
Mesaeus's Avatar
 
Join Date: Aug 2004
Location: Belgium
Posts: 873
Try to kill vbdoc.exe by booting in Safe Mode (press F8 repeatedly when your pc starts booting), going to C:\Windows\AppPatch\ and renaming the file (add a "2" to the name for example), this way it won't get loaded and you can undo it if it turns out to be beneficial after all.

Make sure HijackThis doesn't report more running processes from C:\Windows\AppPatch. That directory is for installation files, but on both my Windows Me and XP installations, it only contains .dll and .sdb files, not exe's. We already got rid of three of them, but one returned.

This also came back or wasn't fully deleted :

O2 - BHO: (no name) - {BF755B85-EA69-4F58-9A59-D85F384A15FF} - C:\WINDOWS\TEMP\CODBV.DAT

Delete it when HijackThis has no more running processes from C:\Windows\AppPatch, otherwise that VBDOC.exe process may set it back (if they're related).

Try all this and tell me if VBDOC keeps returning. Also, if you don't do anything, can you still reboot and shutdown without all those error messages ? Just making sure we're not messing with the internal workings of W98

Edit : and make sure IExplore.exe is gone from the taskmanager before using HijackThis, all those "BHO" entries are loaded whenever IE is, and there was at least one left.

Last edited by Mesaeus; 09-09-2004 at 08:26 PM.
Mesaeus is offline   Reply With Quote
Old 09-09-2004, 08:57 PM   #13
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
I couldn't rename vbdoc.exe in safe mode. A pop up said it was in use so i couldn't rename.Also I'm still getting the errors when i reboot.Didn't get them shutting down from safe mode though.I am still getting the original error in IE "Invalid page fault"BROWSEUI.dll at 0257:711678a9. I think i'm giong to do an"over the top"Reinstall of my Win98. What do you think?
lovesranch is offline   Reply With Quote
Old 09-10-2004, 10:00 AM   #14
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,787
You are using a very out of date version of HJT - current version is 1.98.2.
glc is online now   Reply With Quote
Old 09-10-2004, 10:31 AM   #15
Resident Intel Fanboy
 
Redfallon's Avatar
 
Join Date: Mar 2004
Location: Cincinnati
Posts: 1,669
Also make sure you've got the newest (don't forget to update DAT files after downloading too!) of adware (1.04 SE i think is the newest, if you've got 6.0 it's quite outdated) and 1.3 of spybot (no new updates for 1.2 have been released in a long while). Also try CWshredder from the author of HJT (although i didn't see any cool web search entries in your log, it won't hurt to run it as well).
__________________

...wide is the gate, and broad is the way, that leadeth to destruction, and many there be which go in thereat...
Redfallon is offline   Reply With Quote
Old 09-10-2004, 11:18 AM   #16
Member (10 bit)
 
Mesaeus's Avatar
 
Join Date: Aug 2004
Location: Belgium
Posts: 873
Instead of "Safe Mode", next time get "Command Prompt only". This will dump you in straight DOS, then type the following two commands, pressing after each line :

cd Windows\AppPatch
ren vbdoc.exe vbdoc2.exe

and then press alt-ctrl-del to reboot

You're still getting the error messages, so either the spyware is still conflicting, or we accidentally removed something the system needs. In any case, a reinstall on top should fix everything. You can also restore individual items we deleted in HijackThis, by going in HijackThis to "Config..." and then the "Backups" tab. You might want to try restoring each line one for one, and checking each time if that line makes the error messages go away. I'm curious about which line does it, but if that's too much work, an install over the top should work too.
Mesaeus is offline   Reply With Quote
Old 09-10-2004, 07:23 PM   #17
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
The site for HJT is not up so i can't get the latest for that yet. I updated Adaware, and Spyware is up to date.
lovesranch is offline   Reply With Quote
Old 09-11-2004, 07:10 AM   #18
Member (10 bit)
 
Mesaeus's Avatar
 
Join Date: Aug 2004
Location: Belgium
Posts: 873
Incidentally, the HJT site being down is rumored to be due to a Distributed Denial Of Service attack by spyware makers or their cronies. HJT is a thorn in the spyware maker's side. There are even some forms of spyware who will prevent you from visiting the HJT site In any case, here's a mirror for the latest version, 1.98.2.
Mesaeus is offline   Reply With Quote
Old 09-12-2004, 02:18 PM   #19
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
Boom HJT Link & "over the top reinstall win98"

thanks for the HJT link mesaeus,
I downloaded that.Sorry i've been away, i was doing the "over the top reinstall" which went O.K. except for a few gliches. I'm not sure if i did something wrong or if my problems were because of having a restore cd and not a regular win98 cd. I won't get into details as everything is working fine now (no more error messages) but i do still have one problem. The reinstall wiped out my mail setting and address book. I have a backup cd (CDRW disk) but I can't access it. If i go to Start, Programs, Accessorys,system tools,backup (which is how i created my backups) and go to the disk to restore, it doesn't show any files on the disk. If i go to win explorer it says the disk is full (which it isn't) but also doesn't show any files on the disk. GRRRRRRRRRRRRRRRRR!!!!!!!!! I know the files are on the disk 'cause i put it in my friends PC and it shows them! How do i get my drive to read this disk?????????
lovesranch is offline   Reply With Quote
Old 09-12-2004, 02:48 PM   #20
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,787
Reinstall all your CD burning software including the packet writing software.
glc is online now   Reply With Quote
Old 09-12-2004, 04:44 PM   #21
Member (8 bit)
 
lovesranch's Avatar
 
Join Date: Apr 2001
Location: Lancaster, Ca.
Posts: 155
I reinstalled the software for my burner and now i can access the files for OE.Thanks glc.Sorry about the "over-the-top-reinstall'.Guess i jumped the gun as i was getting frustrated and wanted to get it over with.
lovesranch is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 05:34 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2