Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

iexplorer hangtime error

Status
Not open for further replies.

Drizzt7

Technical User
Dec 13, 2005
4
US
Hi, I'm having this problem where iexplorer will stay running in the task manager even when you exit out of it. This will prevent the computer from shutting down sometimes or even lock up the whole system. The version of iexplorer is 6.0.2900.2180. Any suggestions of what can be done to prevent this from happening? Thanks
 
ok it found a file called "KEYL_SE.72938" which is a trojan
 
Ok if it didnt remove it let me know but it should have. If it did run internet explorer for a bit and see if it happens again if it does I have an actual computer antivirus that will help you and in the mean time heres something else. Download hijackthis from the link below. Extract it to desktop or prefered folder, then open the program, choose do a system scan and save a logfile. Post the logfile results on here and unless your sure of what your doing dont check anything on it for not all items are bad.

 
ok i thought the problem was done because it didn't act up for a few days, but then the problem start to happen again. here is my logfile:

Logfile of HijackThis v1.99.1
Scan saved at 9:42:10 AM, on 1/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\MiaSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\WINDOWS\system32\3dlTB.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\lp\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.1.5.101:3128
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [3Dlabs Taskbar Display Manager] C:\WINDOWS\system32\3dlTB.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = workgroup.com
O17 - HKLM\Software\..\Telephony: DomainName = workgroup.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{266FF55C-3F2F-468B-B7B7-6B8B5957F41C}: NameServer = 10.1.5.238
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = workgroup.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{266FF55C-3F2F-468B-B7B7-6B8B5957F41C}: NameServer = 10.1.5.238
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = workgroup.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{266FF55C-3F2F-468B-B7B7-6B8B5957F41C}: NameServer = 10.1.5.238
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\\lic98rmt.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Inter-Tel Call Processing (ICP) - Unknown owner - C:\Icp\Icp.exe (file missing)
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: 3Dlabs LMM (miasvc) - Unknown owner - C:\WINDOWS\system32\MiaSvc.exe
 
Looks clean, all except im curious about this one.
O23 - Service: 3Dlabs LMM (miasvc) - Unknown owner - C:\WINDOWS\system32\MiaSvc.exe

If you have hardware that is 3dlabs then I wouldnt worry about it. If not I would remove it.
 
alright thank you much, i'll keep you posted if the problem continues to happen
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top