browser shut down

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hi all please help this newbie
i have pent 3 comp with xp home installed oem
service pack 1 ,zone alarm,avg all updates and current
My problem is lately while on the internet my explorer ie6 closes suddenly
closes no warning, but i stay connected to internet.
there appears on my desktop this new icon hs_er_pid 1660
Can anyone shed some light on this strange and annoying problem.
i can go right back and open ie again no problem this seems random,i`ve
scanned with ad- aware se,avg free net scans and nothing.
Thankyou all in advance for any and all help
 
Hi Don Thankyou for the suggestion, I ran numorus scans then even highjack
this here is the log
Logfile of HijackThis v1.99.1
Scan saved at 9:31:35 AM, on 3/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Documents and Settings\Computer\My Documents\special\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://sympatico.msn.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType
Pro\type32.exe"
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe"
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1106190280296
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
(MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://playweb14.pogo.com/game/deluxe/insaniquarium/popcaploader_v6.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe

This is what it found but don`t understand if theres a problem,the shut
downs seem random and it always put the new icon on the desktop,but leaves me
connected to the net.Thank You for any help.
Don Varnau said:
Hi,
This sounds like a malware problem. Sometimes you have to use a number of
different removal tools- including analysis of a HijackThis log.

Read the message at http://forum.aumha.org/viewtopic.php?t=4075 Then go to
http://www.aumha.org/a/quickfix.htm Work through the preliminary cleaning
steps and post a HijackThis log to the forum at
http://forum.aumha.org/viewforum.php?f=30

Don
[MS MVP- IE/OE]

leee said:
Hi all please help this newbie
i have pent 3 comp with xp home installed oem
service pack 1 ,zone alarm,avg all updates and current
My problem is lately while on the internet my explorer ie6 closes suddenly
closes no warning, but i stay connected to internet.
there appears on my desktop this new icon hs_er_pid 1660
Can anyone shed some light on this strange and annoying problem.
i can go right back and open ie again no problem this seems random,i`ve
scanned with ad- aware se,avg free net scans and nothing.
Thankyou all in advance for any and all help
 
leee,
Sorry for the delay. It appears that PA Bear has declared your log to be
clean.
http://aumha.net/viewtopic.php?t=12213
If the reinstall of Java (Sun) isn't the fix (it's what I would have
suggested- after some research) post back. We'll see if another idea comes
out.

Don
[MS MVP- IE/OE]

"leee" wrote in message
Hi Don Thankyou for the suggestion, I ran numorus scans then even highjack
this here is the log
[snip]
This is what it found but don`t understand if theres a problem,the shut
downs seem random and it always put the new icon on the desktop,but leaves me
connected to the net.Thank You for any help.

Don Varnau said:
Hi,
This sounds like a malware problem. Sometimes you have to use a number of
different removal tools- including analysis of a HijackThis log.

Read the message at http://forum.aumha.org/viewtopic.php?t=4075 Then go to
http://www.aumha.org/a/quickfix.htm Work through the preliminary cleaning
steps and post a HijackThis log to the forum at
http://forum.aumha.org/viewforum.php?f=30
 
My deepest apologies.I mispelled the error.it is hs_err_pid
Eyesight and confusion failing me.Here is a copy of error.
Hope for your forgiveness and understanding,and any help would be greatly
appreciated.Reloaded sun java still happens,
seems totally random,have found it does it playing pogo if that any help.
Thankyou Kindly
#
# An unexpected error has been detected by HotSpot Virtual Machine:
#
# EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x6d0e75d9, pid=672, tid=3872
#
# Java VM: Java HotSpot(TM) Client VM (1.5.0_01-b08 mixed mode, sharing)
# Problematic frame:
# C [awt.dll+0xe75d9]
#

--------------- T H R E A D ---------------

Current thread (0x07e04e60): JavaThread "AWT-EventQueue-7"
[_thread_in_native, id=3872]

siginfo: ExceptionCode=0xc0000005, reading address 0x00000004

Registers:
EAX=0x00000000, EBX=0x0764d168, ECX=0x07e04f1c, EDX=0x0849f7cc
ESP=0x0849f7d4, EBP=0x0849f838, ESI=0x07e04f1c, EDI=0x00000000
EIP=0x6d0e75d9, EFLAGS=0x00010246

Top of Stack: (sp=0x0849f7d4)
0x0849f7d4: 0764d168 07e04f1c 00000000 6d0c7a0d
0x0849f7e4: 20ae4238 20ae4238 07e04e60 0764d168
0x0849f7f4: 00000200 00000000 008d00a2 0145381a
0x0849f804: 000000a2 0000008d 2386fce0 00000000
0x0849f814: 04de5d15 00000000 23870238 23870390
0x0849f824: 04d98d4a 0849f7e4 0849fb64 6d0f2eb8
0x0849f834: 00000000 0849f850 04e00192 000001f7
0x0849f844: 0849f85c 0849f858 2386fc70 0849f878

Instructions: (pc=0x6d0e75d9)
0x6d0e75c9: 56 8b 0e ff 51 68 85 c0 7d 06 5f 33 c0 5e 59 c3
0x6d0e75d9: 8b 47 04 85 c0 74 15 8b 0d a8 fa 12 6d 8b 16 51


Stack: [0x083a0000,0x084a0000), sp=0x0849f7d4, free space=1021k
Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native
code)
C [awt.dll+0xe75d9]
J sun.awt.windows.WComponentPeer.nativeHandleEvent(Ljava/awt/AWTEvent;)V
J sun.awt.windows.WComponentPeer.handleEvent(Ljava/awt/AWTEvent;)V
J java.awt.Component.dispatchEventImpl(Ljava/awt/AWTEvent;)V
J java.awt.Container.dispatchEventImpl(Ljava/awt/AWTEvent;)V
J java.awt.EventQueue.dispatchEvent(Ljava/awt/AWTEvent;)V
J
java.awt.EventDispatchThread.pumpOneEventForHierarchy(ILjava/awt/Component;)Z
J
java.awt.EventDispatchThread.pumpEventsForHierarchy(ILjava/awt/Conditional;Ljava/awt/Component;)V
v ~RuntimeStub::alignment_frame_return Runtime1 stub
j java.awt.EventDispatchThread.pumpEvents(ILjava/awt/Conditional;)V+4
j java.awt.EventDispatchThread.pumpEvents(Ljava/awt/Conditional;)V+3
j java.awt.EventDispatchThread.run()V+9
v ~StubRoutines::call_stub
V [jvm.dll+0x8176e]
V [jvm.dll+0xd481d]
V [jvm.dll+0x8163f]
V [jvm.dll+0x8139c]
V [jvm.dll+0x9c05c]
V [jvm.dll+0xfeece]
V [jvm.dll+0xfee9c]
C [msvcrt.dll+0x27fb8]
C [kernel32.dll+0x1d28e]

Java frames: (J=compiled Java code, j=interpreted, Vv=VM code)
J sun.awt.windows.WComponentPeer.nativeHandleEvent(Ljava/awt/AWTEvent;)V
J sun.awt.windows.WComponentPeer.handleEvent(Ljava/awt/AWTEvent;)V
J java.awt.Component.dispatchEventImpl(Ljava/awt/AWTEvent;)V
J java.awt.Container.dispatchEventImpl(Ljava/awt/AWTEvent;)V
J java.awt.EventQueue.dispatchEvent(Ljava/awt/AWTEvent;)V
J
java.awt.EventDispatchThread.pumpOneEventForHierarchy(ILjava/awt/Component;)Z
J
java.awt.EventDispatchThread.pumpEventsForHierarchy(ILjava/awt/Conditional;Ljava/awt/Component;)V
v ~RuntimeStub::alignment_frame_return Runtime1 stub
j java.awt.EventDispatchThread.pumpEvents(ILjava/awt/Conditional;)V+4
j java.awt.EventDispatchThread.pumpEvents(Ljava/awt/Conditional;)V+3
j java.awt.EventDispatchThread.run()V+9
v ~StubRoutines::call_stub

--------------- P R O C E S S ---------------

Java Threads: ( => current thread )
0x074fbff8 JavaThread "Direct Clip" daemon [_thread_blocked, id=3624]
0x074fef98 JavaThread "Direct Clip" daemon [_thread_blocked, id=1976]
0x0762dbf8 JavaThread "poppit-jackpot-increment-timer" daemon
[_thread_blocked, id=2120]
0x07644920 JavaThread "Client" [_thread_in_vm, id=3200]
0x075c0e88 JavaThread "Thread-6376" daemon [_thread_blocked, id=4028]
0x07504450 JavaThread "thread
applet-com.pogo.game.client.poppit.PoppitApplet" [_thread_blocked, id=1404]
0x075045d0 JavaThread "TimerQueue" daemon [_thread_blocked, id=3920]
0x0756ec88 JavaThread "ClockTicker" daemon [_thread_blocked, id=3980]
0x07672ae0 JavaThread "React-game1.pogo.com:6045-1" [_thread_in_native,
id=3900]
0x075cf298 JavaThread "Direct Clip" daemon [_thread_blocked, id=3916]
0x074e8b58 JavaThread
"InvalQueue-1-com.pogo.ui.l[panel18,0,0,252x398,invalid]" daemon
[_thread_blocked, id=3704]
0x076d2940 JavaThread "EmoticonAnimThread" [_thread_blocked, id=3888]
0x075d5dc8 JavaThread "Thread-2697" daemon [_thread_blocked, id=3876]
0x076196b0 JavaThread "CasinoArenaAppletIntermissionTimer" daemon
[_thread_blocked, id=3840]
0x074f2fd8 JavaThread "IconMenu close timer" daemon [_thread_blocked,
id=3868]
0x07e058d8 JavaThread "ScrollbarButtonRepeater" daemon [_thread_blocked,
id=3852]
0x075fe008 JavaThread "TextFieldCaretBlinker" daemon [_thread_blocked,
id=3788]
=>0x07e04e60 JavaThread "AWT-EventQueue-7" [_thread_in_native, id=3872]
0x074f2338 JavaThread "thread
applet-com.pogo.game.arena.poppit.PoppitArenaApplet" [_thread_blocked,
id=3836]
0x075cc630 JavaThread "Thread-2682" [_thread_in_native, id=3720]
0x074eef08 JavaThread "Java Sound Event Dispatcher" daemon
[_thread_blocked, id=276]
0x07500668 JavaThread "TimerQueue" daemon [_thread_blocked, id=492]
0x0755b880 JavaThread "AWT-EventQueue-0" [_thread_blocked, id=804]
0x0753d058 JavaThread "traceMsgQueueThread" [_thread_blocked, id=1904]
0x07537720 JavaThread "AWT-Windows" daemon [_thread_in_native, id=212]
0x075372f0 JavaThread "AWT-Shutdown" [_thread_blocked, id=184]
0x07536268 JavaThread "Java2D Disposer" daemon [_thread_blocked, id=272]
0x020e9208 JavaThread "Low Memory Detector" daemon [_thread_blocked,
id=2000]
0x020e7e38 JavaThread "CompilerThread0" daemon [_thread_blocked, id=532]
0x020e7178 JavaThread "Signal Dispatcher" daemon [_thread_blocked, id=152]
0x0204ecb8 JavaThread "Finalizer" daemon [_thread_blocked, id=1920]
0x0204e020 JavaThread "Reference Handler" daemon [_thread_blocked, id=404]

Other Threads:
0x020e6758 VMThread [id=1392]
0x020ea418 WatcherThread [id=1600]

VM state:not at safepoint (normal execution)

VM Mutex/Monitor currently owned by a thread: None

Heap
def new generation total 5056K, used 885K [0x20a60000, 0x20fd0000,
0x211c0000)
eden space 4544K, 14% used [0x20a60000, 0x20affb18, 0x20ed0000)
from space 512K, 48% used [0x20ed0000, 0x20f0db18, 0x20f50000)
to space 512K, 0% used [0x20f50000, 0x20f50000, 0x20fd0000)
tenured generation total 66084K, used 40390K [0x211c0000, 0x25249000,
0x26a60000)
the space 66084K, 61% used [0x211c0000, 0x23931a68, 0x23931c00,
0x25249000)
compacting perm gen total 8192K, used 3054K [0x26a60000, 0x27260000,
0x2aa60000)
the space 8192K, 37% used [0x26a60000, 0x26d5ba88, 0x26d5bc00, 0x27260000)
ro space 8192K, 62% used [0x2aa60000, 0x2af67d30, 0x2af67e00, 0x2b260000)
rw space 12288K, 46% used [0x2b260000, 0x2b7ec8a0, 0x2b7eca00,
0x2be60000)

Dynamic libraries:
0x00400000 - 0x00419000 C:\Program Files\Internet Explorer\IEXPLORE.EXE
0x77f50000 - 0x77ff7000 C:\WINDOWS\System32\ntdll.dll
0x77e60000 - 0x77f46000 C:\WINDOWS\system32\kernel32.dll
0x77c10000 - 0x77c63000 C:\WINDOWS\system32\msvcrt.dll
0x77d40000 - 0x77dd0000 C:\WINDOWS\system32\USER32.dll
0x7f000000 - 0x7f041000 C:\WINDOWS\system32\GDI32.dll
0x77dd0000 - 0x77e5d000 C:\WINDOWS\system32\ADVAPI32.dll
0x78000000 - 0x78087000 C:\WINDOWS\system32\RPCRT4.dll
0x70a70000 - 0x70ad6000 C:\WINDOWS\system32\SHLWAPI.dll
0x71700000 - 0x71849000 C:\WINDOWS\System32\SHDOCVW.dll
0x71950000 - 0x71a34000
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1612_x-ww_7c379b08\comctl32.dll
0x7cd00000 - 0x7d512000 C:\WINDOWS\system32\SHELL32.dll
0x77340000 - 0x773cb000 C:\WINDOWS\system32\comctl32.dll
0x4fec0000 - 0x4fff6000 C:\WINDOWS\system32\ole32.dll
0x5ad70000 - 0x5ada4000 C:\WINDOWS\System32\uxtheme.dll
0x71500000 - 0x715fc000 C:\WINDOWS\System32\BROWSEUI.dll
0x72430000 - 0x72442000 C:\WINDOWS\System32\browselc.dll
0x75f40000 - 0x75f5f000 C:\WINDOWS\system32\appHelp.dll
0x7c890000 - 0x7c911000 C:\WINDOWS\System32\CLBCATQ.DLL
0x77120000 - 0x771ab000 C:\WINDOWS\system32\OLEAUT32.dll
0x77050000 - 0x77115000 C:\WINDOWS\System32\COMRes.dll
0x77c00000 - 0x77c07000 C:\WINDOWS\system32\VERSION.dll
0x63000000 - 0x63096000 C:\WINDOWS\system32\WININET.dll
0x762c0000 - 0x76348000 C:\WINDOWS\system32\CRYPT32.dll
0x762a0000 - 0x762b0000 C:\WINDOWS\system32\MSASN1.dll
0x76f90000 - 0x76fa0000 C:\WINDOWS\System32\Secur32.dll
0x76620000 - 0x7666e000 C:\WINDOWS\System32\cscui.dll
0x76600000 - 0x7661c000 C:\WINDOWS\System32\CSCDLL.dll
0x76670000 - 0x76757000 C:\WINDOWS\System32\SETUPAPI.dll
0x10000000 - 0x1000e000 C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
0x7c340000 - 0x7c396000 C:\WINDOWS\System32\MSVCR71.dll
0x1a400000 - 0x1a47d000 C:\WINDOWS\system32\urlmon.dll
0x75e90000 - 0x75f3d000 C:\WINDOWS\System32\SXS.DLL
0x76170000 - 0x761f8000 C:\WINDOWS\System32\shdoclc.dll
0x74770000 - 0x747ff000 C:\WINDOWS\System32\mlang.dll
0x71ad0000 - 0x71ad8000 C:\WINDOWS\System32\wsock32.dll
0x71ab0000 - 0x71ac5000 C:\WINDOWS\System32\WS2_32.dll
0x71aa0000 - 0x71aa8000 C:\WINDOWS\System32\WS2HELP.dll
0x71a50000 - 0x71a8b000 C:\WINDOWS\system32\mswsock.dll
0x71a90000 - 0x71a98000 C:\WINDOWS\System32\wshtcpip.dll
0x76ee0000 - 0x76f17000 C:\WINDOWS\System32\RASAPI32.DLL
0x76e90000 - 0x76ea1000 C:\WINDOWS\System32\rasman.dll
0x71c20000 - 0x71c6e000 C:\WINDOWS\System32\NETAPI32.dll
0x76eb0000 - 0x76edb000 C:\WINDOWS\System32\TAPI32.dll
0x76e80000 - 0x76e8d000 C:\WINDOWS\System32\rtutils.dll
0x76b40000 - 0x76b6c000 C:\WINDOWS\System32\WINMM.dll
0x5cd70000 - 0x5cd77000 C:\WINDOWS\System32\serwvdrv.dll
0x5b0a0000 - 0x5b0a7000 C:\WINDOWS\System32\umdmxfrm.dll
0x76f20000 - 0x76f45000 C:\WINDOWS\System32\DNSAPI.dll
0x76d60000 - 0x76d77000 C:\WINDOWS\System32\iphlpapi.dll
0x76fb0000 - 0x76fb7000 C:\WINDOWS\System32\winrnr.dll
0x76f60000 - 0x76f8c000 C:\WINDOWS\system32\WLDAP32.dll
0x722b0000 - 0x722b5000 C:\WINDOWS\System32\sensapi.dll
0x75a70000 - 0x75b15000 C:\WINDOWS\system32\USERENV.dll
0x014c0000 - 0x016c1000 C:\WINDOWS\System32\msi.dll
0x0ffd0000 - 0x0fff3000 C:\WINDOWS\System32\rsaenh.dll
0x76fc0000 - 0x76fc5000 C:\WINDOWS\System32\rasadhlp.dll
0x63580000 - 0x63833000 C:\WINDOWS\System32\mshtml.dll
0x6b700000 - 0x6b790000 C:\WINDOWS\System32\jscript.dll
0x746f0000 - 0x74716000 C:\WINDOWS\System32\msimtf.dll
0x74720000 - 0x74764000 C:\WINDOWS\System32\MSCTF.dll
0x76390000 - 0x763ac000 C:\WINDOWS\System32\IMM32.DLL
0x73300000 - 0x73375000 C:\WINDOWS\System32\vbscript.dll
0x02740000 - 0x028e7000 C:\WINDOWS\System32\macromed\flash\Flash.ocx
0x763b0000 - 0x763f5000 C:\WINDOWS\system32\comdlg32.dll
0x72d20000 - 0x72d29000 C:\WINDOWS\System32\wdmaud.drv
0x72d10000 - 0x72d18000 C:\WINDOWS\System32\msacm32.drv
0x77be0000 - 0x77bf4000 C:\WINDOWS\System32\MSACM32.dll
0x77bd0000 - 0x77bd7000 C:\WINDOWS\System32\midimap.dll
0x6bdd0000 - 0x6be03000 C:\WINDOWS\System32\dxtrans.dll
0x76b20000 - 0x76b35000 C:\WINDOWS\System32\ATL.DLL
0x65000000 - 0x65009000 C:\WINDOWS\System32\ddrawex.dll
0x51000000 - 0x51049000 C:\WINDOWS\System32\DDRAW.dll
0x73bc0000 - 0x73bc6000 C:\WINDOWS\System32\DCIMAN32.dll
0x6be10000 - 0x6be65000 C:\WINDOWS\System32\dxtmsft.dll
0x746c0000 - 0x746e7000 C:\WINDOWS\System32\MSLS31.DLL
0x03650000 - 0x0368c000 C:\WINDOWS\System32\iepeers.dll
0x73000000 - 0x73023000 C:\WINDOWS\System32\WINSPOOL.DRV
0x74cb0000 - 0x74d1f000 C:\WINDOWS\System32\mshtmled.dll
0x71d40000 - 0x71d5b000 C:\WINDOWS\System32\actxprxy.dll
0x6cc60000 - 0x6cc6b000 C:\WINDOWS\System32\dispex.dll
0x6d590000 - 0x6d5a1000 C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
0x5edd0000 - 0x5edea000 C:\WINDOWS\System32\OLEPRO32.DLL
0x6d400000 - 0x6d417000 C:\Program Files\Java\jre1.5.0_01\bin\jpiexp32.dll
0x6d450000 - 0x6d468000 C:\Program Files\Java\jre1.5.0_01\bin\jpishare.dll
0x6d640000 - 0x6d7c5000 C:\PROGRA~1\Java\JRE15~1.0_0\bin\client\jvm.dll
0x6d280000 - 0x6d288000 C:\PROGRA~1\Java\JRE15~1.0_0\bin\hpi.dll
0x76bf0000 - 0x76bfb000 C:\WINDOWS\System32\PSAPI.DLL
0x6d610000 - 0x6d61c000 C:\PROGRA~1\Java\JRE15~1.0_0\bin\verify.dll
0x6d300000 - 0x6d31d000 C:\PROGRA~1\Java\JRE15~1.0_0\bin\java.dll
0x6d630000 - 0x6d63f000 C:\PROGRA~1\Java\JRE15~1.0_0\bin\zip.dll
0x6d000000 - 0x6d166000 C:\Program Files\Java\jre1.5.0_01\bin\awt.dll
0x5c000000 - 0x5c0c8000 C:\WINDOWS\System32\D3DIM700.DLL
0x6d240000 - 0x6d27d000 C:\Program Files\Java\jre1.5.0_01\bin\fontmanager.dll
0x6d1f0000 - 0x6d203000 C:\Program Files\Java\jre1.5.0_01\bin\deploy.dll
0x6d5d0000 - 0x6d5ed000 C:\Program Files\Java\jre1.5.0_01\bin\RegUtils.dll
0x6d3e0000 - 0x6d3f4000 C:\Program Files\Java\jre1.5.0_01\bin\jpicom32.dll
0x6d4c0000 - 0x6d4d3000 C:\Program Files\Java\jre1.5.0_01\bin\net.dll
0x6d1c0000 - 0x6d1e3000 C:\Program Files\Java\jre1.5.0_01\bin\dcpr.dll
0x6d3c0000 - 0x6d3df000 C:\Program Files\Java\jre1.5.0_01\bin\jpeg.dll
0x6d470000 - 0x6d495000 C:\Program Files\Java\jre1.5.0_01\bin\jsound.dll
0x6d4a0000 - 0x6d4a7000 C:\Program Files\Java\jre1.5.0_01\bin\jsoundds.dll
0x51080000 - 0x510dd000 C:\WINDOWS\System32\DSOUND.dll
0x5ef80000 - 0x5ef84000 C:\WINDOWS\System32\KsUser.dll
0x6d4e0000 - 0x6d4e9000 C:\Program Files\Java\jre1.5.0_01\bin\nio.dll
0x69000000 - 0x6900e000 C:\WINDOWS\System32\Macromed\Common\SwSupport.dll

VM Arguments:
jvm_args:
-Xbootclasspath/a:C:\PROGRA~1\Java\JRE15~1.0_0\lib\deploy.jar;C:\PROGRA~1\Java\JRE15~1.0_0\lib\plugin.jar
-Xmx96m -Djavaplugin.maxHeapSize=96m -Xverify:remote
-Djavaplugin.version=1.5.0_01 -Djavaplugin.nodotversion=150_01
-Dbrowser=sun.plugin -DtrustProxy=true
-Dapplication.home=C:\PROGRA~1\Java\JRE15~1.0_0
-Djava.protocol.handler.pkgs=sun.plugin.net.protocol
-Djavaplugin.vm.options=-Djava.class.path=C:\PROGRA~1\Java\JRE15~1.0_0\classes
-Xbootclasspath/a:C:\PROGRA~1\Java\JRE15~1.0_0\lib\deploy.jar;C:\PROGRA~1\Java\JRE15~1.0_0\lib\plugin.jar
-Xmx96m -Djavaplugin.maxHeapSize=96m -Xverify:remote
-Djavaplugin.version=1.5.0_01 -Djavaplugin.nodotversion=150_01
-Dbrowser=sun.plugin -DtrustProxy=true
-Dapplication.home=C:\PROGRA~1\Java\JRE15~1.0_0
-Djava.protocol.handler.pkgs=sun.plugin.net.protocol vfprintf
java_command: <unknown>

Environment Variables:
PATH=C:\PROGRA~1\Java\JRE15~1.0_0\bin;C:\Program Files\Internet
Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;.
USERNAME=Computer
OS=Windows_NT
PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 1, AuthenticAMD


--------------- S Y S T E M ---------------

OS: Windows XP Build 2600 Service Pack 1

CPU:total 1 family 6, cmov, cx8, fxsr, mmx, sse

Memory: 4k page, physical 458224k(130760k free), swap 1084040k(818332k free)

vm_info: Java HotSpot(TM) Client VM (1.5.0_01-b08) for windows-x86, built on
Dec 6 2004 19:51:00 by "java_re" with MS VC++ 6.0


Don Varnau said:
leee,
Sorry for the delay. It appears that PA Bear has declared your log to be
clean.
http://aumha.net/viewtopic.php?t=12213
If the reinstall of Java (Sun) isn't the fix (it's what I would have
suggested- after some research) post back. We'll see if another idea comes
out.

Don
[MS MVP- IE/OE]

"leee" wrote in message
Hi Don Thankyou for the suggestion, I ran numorus scans then even highjack
this here is the log
[snip]
This is what it found but don`t understand if theres a problem,the shut
downs seem random and it always put the new icon on the desktop,but leaves me
connected to the net.Thank You for any help.

Don Varnau said:
Hi,
This sounds like a malware problem. Sometimes you have to use a number of
different removal tools- including analysis of a HijackThis log.

Read the message at http://forum.aumha.org/viewtopic.php?t=4075 Then go to
http://www.aumha.org/a/quickfix.htm Work through the preliminary cleaning
steps and post a HijackThis log to the forum at
http://forum.aumha.org/viewforum.php?f=30
"leee" <leee[at]discussions.microsoft.com> wrote in message
Hi all please help this newbie
i have pent 3 comp with xp home installed oem
service pack 1 ,zone alarm,avg all updates and current
My problem is lately while on the internet my explorer ie6 closes suddenly
closes no warning, but i stay connected to internet.
there appears on my desktop this new icon hs_er_pid 1660
Can anyone shed some light on this strange and annoying problem.
i can go right back and open ie again no problem this seems random,i`ve
scanned with ad- aware se,avg free net scans and nothing.
Thankyou all in advance for any and all help
 
i have a similar probem i think, i have uninstalled and re installed Java
and the site says i have the latest version. but if i go to yahoo chat i only
get a blank screen for a while then the browser closes, but im still
connected. please tell me what i need to reinstall
 
Back
Top