Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Runtime Error in IE 6

Jun 2, 2005 10:44PM PDT

Anytime I click on IE, I recieve a dialog box that states:
Microsoft Visual C++ Runtime Library
Runtime Error.
it's with internet explorer/iexplore.exe
and says abnormal program termination.
When I close out of this box and click on IE it opens but on the inital try it doesn't.
My os is Windows XP.
I would appreciate any help.
Thank you.

Discussion is locked

- Collapse -
Typical of a spyware infection.
Jun 2, 2005 10:53PM PDT

What are you doing about spyware?

- Collapse -
Spybot
Jun 2, 2005 11:12PM PDT

I use spybot, ad-adware SE personal,a-squared.

When I use firefox, I don't have any problems but I would like to correct the problem with IE.

- Collapse -
Time to move it up a notch.
Jun 2, 2005 11:20PM PDT

Read about Hijackthis logs and how to use them to find out what has attached itself to IE.

Bob

- Collapse -
hijack this
Jun 2, 2005 11:54PM PDT

Thank you. Where would I find this information?

- Collapse -
Link to...
Jun 3, 2005 12:09AM PDT
- Collapse -
Link to
Jun 3, 2005 1:17PM PDT

I've clicked on this link several times and it doesn't bring up anything.

- Collapse -
go to Google
Jun 5, 2005 2:14AM PDT

type in Hijack This.

it will takew you to the site with instructions.

note there are forums specific to Hijack This.

Posting in our V&S will not provide you with the response.

- Collapse -
Hijack this
Jun 6, 2005 1:01PM PDT

I installed and scanned with hijack this but I have no idea what if anything is malware.

- Collapse -
hijack this
Jun 6, 2005 9:09PM PDT

on the hijack this, it doesn't show any malware etc. it looks fine.
Any other suggestions on solving the problem with IE?

- Collapse -
Hijackthis logs.
Jun 6, 2005 10:58PM PDT

Take a keen eye to spot what could be amiss.

Did you email it?

Did you post it in a Hijackthis Forum?

If not, you may never know.

Bob

- Collapse -
hijackthislogs.
Jun 7, 2005 1:24AM PDT

I had a computer tech look at it and he said everything looked fine.
Where would I e-mail the log
?

- Collapse -
Look at my profile.
Jun 7, 2005 1:26AM PDT

Even I won't claim to find all things.

Bob

- Collapse -
email
Jun 7, 2005 9:07AM PDT

Bob,
You mentioned I should e-mail it. Whom should I email it to for another opinion?
Thank you.

- Collapse -
I'd look if I could.
Jun 7, 2005 12:27PM PDT

You have choices. Drop me a copy, post it on the hijackthis forums and wait.

Bob

- Collapse -
Copy
Jun 7, 2005 9:36PM PDT

Logfile of HijackThis v1.99.1
Scan saved at 9:48:50 PM, on 6/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\PROGRA~1\VCOM\SYSTEM~1\mxtask.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\3M\PSN2Lite\PsnLite.exe
C:\Program Files\United Devices\UD.EXE
C:\PROGRA~1\3M\PSN2Lite\PSNGive.exe
C:\Program Files\United Devices\ud_7657531.exe
C:\Program Files\United Devices\ud_7657531_0.dir\WCGrid_Rosetta.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\DOCUME~1\Kay\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: Handy Password - {B2DE56E2-907A-4080-AE06-5C2A7BD4364E} - C:\Program Files\Handy Password\HandyPasswordToolbar.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe


Thanks Bob.

- Collapse -
completed copy
Jun 7, 2005 10:01PM PDT

Bob,
I realize now that I didn't copy the complete log. I hope this comes through okay this time. thank you.
Logfile of HijackThis v1.99.1
Scan saved at 9:48:50 PM, on 6/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\PROGRA~1\VCOM\SYSTEM~1\mxtask.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\3M\PSN2Lite\PsnLite.exe
C:\Program Files\United Devices\UD.EXE
C:\PROGRA~1\3M\PSN2Lite\PSNGive.exe
C:\Program Files\United Devices\ud_7657531.exe
C:\Program Files\United Devices\ud_7657531_0.dir\WCGrid_Rosetta.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\DOCUME~1\Kay\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: Handy Password - {B2DE56E2-907A-4080-AE06-5C2A7BD4364E} - C:\Program Files\Handy Password\HandyPasswordToolbar.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\VCOM\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE /A "C:\WINDOWS\system32\E_SF4.tmp"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: UD Agent.lnk = C:\Program Files\United Devices\UD.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Post-it

- Collapse -
I'd fix it...
Jun 7, 2005 10:23PM PDT

Use http://www.help2go.com/modules.php?name=HJTDetective and at least fix the minimum items it noted.

However, I see multiple BHO's in use and as such your machine is unsupportable. These are your choice and it is unlikely anyone will be able to fix your Internet Explorer with all these installed.

Bob

- Collapse -
Sorry I don't quite understand
Jun 8, 2005 2:07AM PDT

Bob,
I'm sorry but lot of this stuff is new to me. What do you mean that my machine is unsupportable? I know i installed the Adobe 7 and the google bar but I'm not sure what the other BHO's are. They are something I had to installed?
Thanks for your help.

- Collapse -
With so many BHOs....
Jun 8, 2005 2:26AM PDT

A BHO is a browser helper object. Looking at your report and the hijack test results, your configuration is one that is "very heavy" on BHO entries.

This is your choice to try such things, but I wouldn't expect it to be stable. To make matters more fun, it could be just one BHO causing the issue or some "toxic combo."

Such things are left to us, as owners to sort out.

In closing, did you fix, at a minimum the bad items noted by my last link? If not, please tell why.

Bob

- Collapse -
Get Firefox?
Jun 8, 2005 10:17AM PDT

Why not just switch to Firefox? It's just so much trouble to bother with IE. Life is short, don't waste it with IE... ^_____^

- Collapse -
run time error in IE6(Browser)
Jul 2, 2005 1:23PM PDT

When I open my IE6 browser and surf any site a message comming in a dialog box after few minutes
run time error(debug***yes or No****)

- Collapse -
Yes or No.
Jul 2, 2005 11:29PM PDT

Did you do the fixes (spyware removal) noted in the discussion?