Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Firefox 0.9 illegal operation in Windows 98 SE

Jun 17, 2004 8:59AM PDT

I've been using Mozilla Phoenix/Firebird/Firefox for the past few months. I recently upgraded to Firefox 0.9 and now when I try to start Firefox I get an illegal operation error. When I click details, I get the following:

FIREFOX caused an invalid page fault in
module FIREFOX.EXE at 019f:00424563.
Registers:
EAX=00000000 CS=019f EIP=00424563 EFLGS=00010246
EBX=00000000 SS=01a7 ESP=00c8f2c4 EBP=00c8f424
ECX=029ce3b0 DS=01a7 ESI=029ce3c0 FS=18f7
EDX=00000000 ES=01a7 EDI=00000000 GS=0000
Bytes at CS:EIP:
8b 08 ff 51 0c 8b 06 5e c3 33 c0 50 50 50 ff 74
Stack dump:
00000000 029ce3c0 00000000 004240ce 029ce370 00c8f460 03d00000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000

I'm running Windows 98 SE on a 500 MHz Celeron w/ 256 MB of RAM. I've updated my anti-virus software and scanned with it, nothing turned up. I did the same with Spybot. I've also tried uninstalling Firefox and then reinstalling it. Does anyone have any suggestions?

Discussion is locked

- Collapse -
Re: Firefox 0.9 illegal operation in Windows 98 SE
Jun 17, 2004 9:39AM PDT

There are neat hits on this one which note Compaqs, some Symantec Crashguard and video drivers.

A clean boot and a hijackthis log may reveal enough for me to pick it over if you want me to give it one shot?

As well as make/model machine, if Symantec/McAfee/whateve is installed, the contents of CONFIG.SYS, Autoexec.bat and basic machine information will help narrow it down.

Bob

- Collapse -
Re: Firefox 0.9 illegal operation in Windows 98 SE
Jun 17, 2004 11:05AM PDT

Here's the hijackthis log:

Logfile of HijackThis v1.97.7
Scan saved at 7:59:41 PM, on 06/17/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\EXECUTIVE SOFTWARE\DISKEEPER\DKSERVICE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\ACCESSRAMP\ARMON32.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\RAMBOOSTER\RAMBOOSTER.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAM FILES\FINEPIXVIEWER\QUICKDCF.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pottersschool.com/login2003
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\RDXPH.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\PROGRAM FILES\MYWAY\SRCHASTT\1.BIN\MYSRCHAS.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [AccessRampMonitor] C:\PROGRAM FILES\ACCESSRAMP\ARMon32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [DkService] C:\Program Files\Executive Software\Diskeeper\DkService.exe
O4 - HKCU\..\Run: [RamBooster] C:\PROGRAM FILES\RAMBOOSTER\RAMBOOSTER.EXE
O4 - Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AOL Instant Messenger (SM) (HKLM)
O9 - Extra button: PDFtypewriter (HKLM)
O9 - Extra button: MindSpring (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518} (ell Class) - http://www.ea.com/downloads/games/common/ieell.cab
O16 - DPF: {81361155-FAF9-11D3-B0D3-00C04F612FF1} (MSN Chat Control 3.0) - http://communities.msn.com/central/helium/en-us/uni/msnchat.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {8C285F85-0DBD-11D3-8B37-00A02459FA0F} (CuWeb CuWebConf) - http://ic2.cuseeme.com/packages/cuweb.cab
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.25.44/29ccad5fe132152b1e00/netzip/RdxIE.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (sys Class) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {E09F6B38-3A0D-11D3-B5E7-0008C7BF61F2} (DetectMN) - http://www.musicnotes.com/download/npmusicn.cab
O16 - DPF: {DBB2DE32-61F1-4F7F-BEB8-A37F5BC24EE2} (MozillaPluginHostCtrl Class) - http://www.musicnotes.com/download/adaptor.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/2069d318254b6b483200/netzip/RdxIE6.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {52A5CD24-64C6-4BAF-A4EC-4D13F451763F} (CU LiveUpdate Control) - http://204.119.241.146:8080/ctmexpress/runtime/pic/inner_pic/packages/liveupdate.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37879.4136458333
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4018/ftp.coupons.com/v3122/cpbrkpie.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab


The computer's an eMachine - etower 500i. It's got:

500 mhz celeron
256 mb ram
nVidia Riva TNT2 Model 64/Model 64 Pro
a sound card, not sure what kind
120 gb hard drive


Yes, Norton AntiVirus 2001 is installed. I'm also running Zone Alarm.


Config.sys:

REM [Header]



REM [CD-ROM Drive]
Device=C:\cdrom\oakcdrom.sys /d:gem001

REM [Miscellaneous]

REM [SCSI Controllers]

REM [Display]

REM [Sound, MIDI, or Video Capture Card]

REM [Mouse]
REM ------------------


Autoexec.bat:

REM [Header]
@ECHO OFF



REM [CD-ROM Drive]
REM c:\windows\command\mscdex /d:gem001

REM [Miscellaneous]

REM [Display]

REM [Sound, MIDI, or Video Capture Card]

REM [Mouse]

c:\windows\cwcdata\cwcdos.exe

PATH=%PATH%;"C:\Program Files\Mts";"C:\Program Files\Executive Software\Diskeeper\"


Also, as I was about to post this I accidently tried to run Firefox and it didn't crash, but gave a "page could not be found" error instead of an illegal operation error. I tried IE and got the same thing, apparently my ISP was down for a moment. I went ran Firefox again and got the same error. I clicked ok and everything else worked ok - I could open html docs from my hard drive, and the gui looked normal. Google is my home page, and I doubt connecting to that is causing the problem.

After noticing that Firefox's problems were internet related I unplugged my cable modem and a few minutes later plugged it back in. By that point (a couple minutes ago) my ISP was back up and now Firefox is working fine. However, my mom said that earlier in the day Firefox had worked for a little bit and then stopped. All this leads me to wonder if my computer's been cracked. What do you think?

- Collapse -
I read that log and ...
Jun 18, 2004 12:47AM PDT

You have the RAMBOOSTER which is a debateable item. If one needs to Optimize Windows, then the articles at http://www.aumha.org/articles.htm are better about that. Items like RAMBOOSTER often make more problems than they solve.

How can I write this. There are far too many addons and tasks running than I would on this OS and expect it to be dead stable. Nothing but one item stands out, but the total WEIGHT of all that can cause Windows 98 with it's measly 64 thousand byte resource pools to behave oddly.

As to "cracked", I don't know your definition of that is, but as to exploited, maybe!

http://reviews.cnet.com/5208-6132-0.html?forumID=32&threadID=24788&messageID=274257&tag=srch
is ABOUT BLANK which I see in your log file.

"R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank"

I'd read the above links and see if you caught the about blank parasite.

Bob