Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cannot start IE 6 - 0xc0000005 error


  • Please log in to reply
2 replies to this topic

#1 Bralijo

Bralijo

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 23 May 2005 - 06:49 AM

Good day...

My installation of IE 6 stopped working last Wednesday. I have tried a myriad of activities, all of which end with the same situation. IE 6, immediately upon invocation, returns a dialog box with the message "The application failed to initialize properly (0xc0000005). Click on OK to terminate the application."

I have uninstalled / reinstalled multiple times. I am able to get back to a working IE 5, and, from there, I have executed the Windows updates from microsoft.com. I am completely up-to-date on security patches.

I have followed the directions in the BC post "http://www.bleepingcomputer.com/forums/t/19135/cannot-start-ie/" and removed a couple of offending BHOs. I did have the iasada.dll issue, which led me to BC (through a google search).

I am reaching a point of desparation as I have a demo to do tomorrow (!) that requires IE 6 to function. (I work for a software company and the solution I'm showing does not work with IE 5.)

Here is the latest HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 7:32:32 AM, on 5/23/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\avantgoserver\ASA\win32\dbsrv8.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
C:\WINNT\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
C:\WINNT\system32\Hummingbird\Connectivity\7.10\Jconfig\hjavaw.exe
C:\AvantGoServer\bin\httpd.exe
C:\AvantGoServer\bin\agd.exe
c:\program files\sybase\manage anywhere\marchost.exe
C:\Program Files\Java\j2re1.4.2_03\bin\javaw.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
c:\program files\sybase\manage anywhere\rstate.exe
C:\AvantGoServer\bin\agd.exe
C:\WINNT\System32\QCONSVC.EXE
C:\AvantGoServer\bin\httpd.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\vnxserv.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\Hummingbird\Connectivity\7.10\NFSClient\expserv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\system32\RunDll32.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINNT\system32\PRPCUI.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINNT\SM1BG.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\sybase\MANAGE~1\rstate.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Sybase\Shared\Sybase Central 4.2\scjview.exe
C:\Program Files\Sybase\SQL Anywhere 9\win32\dbisqlg.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
c:\program files\sybase\manage anywhere\rsstatus.exe
C:\Program Files\SYBASE\Pylon Anywhere\Clients\ClientShell.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Network Associates\Common Framework\McScript_InUse.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\jpearl\My Documents\My Downloads\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://syberspace/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = p5web.nielsenmedia.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
N1 - Netscape 4: user_pref("browser.startup.homepage", ""); (C:\Program Files\Netscape\Users\jpearl\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QCWLIcon] C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINNT\SM1BG.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Mobile Automation Agent] c:\PROGRA~1\sybase\MANAGE~1\rstate.exe /LOGON
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SybaseCentral42] "C:\Program Files\Sybase\Shared\Sybase Central 4.2\scjview.exe" -preload
O4 - HKCU\..\Run: [DBISQL9] "C:\Program Files\Sybase\SQL Anywhere 9\win32\dbisqlg.exe" -preload
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Startup: Pylon Anywhere Client.lnk = C:\Program Files\SYBASE\Pylon Anywhere\Clients\ClientShell.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Pylon Anywhere Client.lnk = C:\Program Files\SYBASE\Pylon Anywhere\Clients\ClientShell.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\system32\Shdocvw.dll
O15 - Trusted Zone: *.patch01.sybase.com (HKLM)
O16 - DPF: {0369528B-3082-11D2-9997-00A0C9B7A242} (PlaceWare Presentation-Upload Control) - http://scpwcc.ops.placeware.com/etc/place/...loadControl.cab
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://scpwla.ops.placeware.com/etc/place/...quicksilver.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp.com/rdq/downloads/msxml4.cab
O16 - DPF: {9B57C630-AA6E-440D-8D44-D34542E5531A} (SendMail Class) - http://www112.placeware.com/etc/static/SCL...MailObjects.cab
O16 - DPF: {BE5431D2-0F30-11D4-89D9-00C04F509C0A} - http://www.stamps.com/download/us/cab/stam...file=stamps.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sybase.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{74465827-8C26-4BC8-B75B-423C05DCA1D9}: Domain = sybase.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sybase.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = sybase.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = sybase.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = sybase.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = sybase.com
O20 - Winlogon Notify: tphotkey - C:\WINNT\SYSTEM32\tphklock.dll
O23 - Service: Afaria Client Service - XcelleNet, Inc. - C:\Program Files\Afaria\TestHTML\Bin\XeService.exe
O23 - Service: Afaria Inventory Manager Server - XcelleNet, Inc. - C:\Program Files\Afaria\bin\IMServer.exe
O23 - Service: Afaria Server - XcelleNet, Inc. - C:\Program Files\Afaria\bin\XService.exe
O23 - Service: M-Business Relay Server for BlackBerry (AGComServiceForBlackBerry) - Unknown owner - C:\AvantGoServer\bin\agcomsvr.exe
O23 - Service: Agent Launcher - Unknown owner - C:\Sybase\IOruntime-4_0\bin\.bin\AgentLauncher.exe
O23 - Service: Agent Launcher 4.3 - Unknown owner - C:\Sybase\IO-4_3\bin\.bin\AgentLauncher.exe
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Adaptive Server Anywhere - AppeonDB (ASANYe_AppeonDB) - Sybase, Inc. - C:\Program Files\Sybase\SQL Anywhere 7\win32\dbeng7.exe
O23 - Service: Adaptive Server Anywhere - AGDB (ASANYs_AGDB) - iAnywhere Solutions, Inc. - c:\avantgoserver/ASA\win32\dbsrv8.exe
O23 - Service: Adaptive Server Anywhere - AlertManagementSystem42 (ASANYs_AlertManagementSystem42) - Unknown owner - C:\Sybase\IO-4_3\asa\dbsrv8.exe" -hvASANYs_AlertManagementSystem42 (file missing)
O23 - Service: Adaptive Server Anywhere - BT56dashboard (ASANYs_BT56dashboard) - Unknown owner - C:\Sybase\BizTracker-5_6\asa\dbsrv8.exe" -hvASANYs_BT56dashboard (file missing)
O23 - Service: Adaptive Server Anywhere - BT56JMS (ASANYs_BT56JMS) - Unknown owner - C:\Sybase\BizTracker-5_6\asa\dbsrv8.exe" -hvASANYs_BT56JMS (file missing)
O23 - Service: Adaptive Server Anywhere - BT56rulfmt (ASANYs_BT56rulfmt) - Unknown owner - C:\Sybase\BizTracker-5_6\asa\dbsrv8.exe" -hvASANYs_BT56rulfmt (file missing)
O23 - Service: Adaptive Server Anywhere - BT56Runtime (ASANYs_BT56Runtime) - Unknown owner - C:\Sybase\BizTracker-5_6\asa\dbsrv8.exe" -hvASANYs_BT56Runtime (file missing)
O23 - Service: Adaptive Server Anywhere - BT58rulfmt (ASANYs_BT58rulfmt) - Unknown owner - C:\Sybase\IO-4_3\asa\dbsrv8.exe" -hvASANYs_BT58rulfmt (file missing)
O23 - Service: Adaptive Server Anywhere - BT58Runtime (ASANYs_BT58Runtime) - Unknown owner - C:\Sybase\IO-4_3\asa\dbsrv8.exe" -hvASANYs_BT58Runtime (file missing)
O23 - Service: Adaptive Server Anywhere - Io40DirectoryServices (ASANYs_Io40DirectoryServices) - Unknown owner - C:\Sybase\IOdirsvs-4_0\asa\dbsrv8.exe" -hvASANYs_Io40DirectoryServices (file missing)
O23 - Service: Adaptive Server Anywhere - Io43DirectoryServices (ASANYs_Io43DirectoryServices) - Unknown owner - C:\Sybase\IO-4_3\asa\dbsrv8.exe" -hvASANYs_Io43DirectoryServices (file missing)
O23 - Service: Adaptive Server Anywhere - IO43JMS (ASANYs_IO43JMS) - Unknown owner - C:\Sybase\IO-4_3\asa\dbsrv8.exe" -hvASANYs_IO43JMS (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Hummingbird Export (HCLExport) - Hummingbird Ltd. - C:\WINNT\system32\Hummingbird\Connectivity\7.10\NFSClient\expserv.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINNT\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\system32\ibmpmsvc.exe
O23 - Service: IO_Jaguar - Unknown owner - C:\Sybase\IO-4_3\EAServer\bin\jagsrv.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINNT\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
O23 - Service: M-Business Admin Server - Unknown owner - C:\AvantGoServer\bin\httpd.exe
O23 - Service: M-Business Soap Server - Unknown owner - C:\AvantGoServer\bin\agsoap.exe
O23 - Service: M-Business Sync Server - Unknown owner - C:\AvantGoServer\bin\agd.exe
O23 - Service: Live Support Host (marchost) - Unknown owner - c:\program files\sybase\manage anywhere\marchost.exe" -service (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Manage Anywhere Studio Agent (MobileAutmationAgentService) - Mobile Automation, Inc. - c:\program files\sybase\manage anywhere\rstate.exe
O23 - Service: Multi-user Cleanup Service - Unknown owner - C:\Program Files\Notes\ntmulti.exe
O23 - Service: PatchLink Update - Unknown owner - C:\Program Files\Patchlink\Update Agent\GRAVITIXSERVICE.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINNT\System32\QCONSVC.EXE
O23 - Service: Radia Notify (RADEXECD) - Novadigm - C:\PROGRA~1\Novadigm\RADEXECD.exe
O23 - Service: Radia Scheduler (RADSCHED) - Novadigm - C:\PROGRA~1\Novadigm\RADSCHED.exe
O23 - Service: Radia MSI Redirector (RADSTGMS) - Novadigm - C:\PROGRA~1\Novadigm\RADSTGMS.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sybase ASIQ Agent (SybASIQ-Agent) - Sybase, Inc. - C:\Program Files\Sybase\ASIQ-12_5\Win32\ASIQagent.exe
O23 - Service: Sybase Central Agent for the ASIQ Multiplex (SybASIQ_SCJ_Agent) - Unknown owner - C:\PROGRAM FILES\SYBASE\ASIQ12\WIN32\MPXService.exe
O23 - Service: SYSAM - Unknown owner - C:\Sybase\WorkSpace\DevRuntimes\ASE\SYSAM-1_0\bin\lmgrd (file missing)
O23 - Service: Vsclient Service (VnxService) - Unknown owner - C:\WINNT\system32\vnxserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

BC AdBot (Login to Remove)

 


#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:03:30 PM

Posted 23 May 2005 - 10:38 PM

Hi Bralijo and welcome to th BC forums. After reviewing your log I see no signs of viruses or malware at this time. The log is clean.

Here are some things to check:
  • Were there any hardware/software installed shortly before this started happening.
  • Were there any software updates shortly before this started happening.
  • Were there any configuration changes shortly before this started happening.
If any of the above are true have you tried to undo the changes?

Other than that I suggest that you post your issue in the forum below and see what they have to say:

http://www.bleepingcomputer.com/forums/Web...ations-f14.html

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 Bralijo

Bralijo
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 23 May 2005 - 10:46 PM

Thanks for the reply... The only software that I think I may have installed prior to this happening was AOL and I have since uninstalled it (and about 15 other software applications). I'll post in the other forum.

joe.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users