Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Invalid Syntax Error

Status
Not open for further replies.

countymounty

IS-IT--Management
Jan 24, 2003
60
US
I get an "Invalid Syntax Error" when I try starting IE 6. I can get into IE 6 when in Safe Mode and can brows the internet, do windows updates and the such but still unable to open browser when windows starts in regular mode. I recently removed some Viruses and Trojans from this particular computer and I think that has everything to do with this.

The computer is running windows 2000

Thanks for any help.
 
A good run with faq608-4650 likely will help.

Also, Control Panel, Internet Options, Advanced
Place a check mark to disable script debugging.
Remove a check next to 'display a notification about every script error.'
 
OK I have done everything listed on faq608-4650, faq 760-4962 & faq760-4866. I ran both Norton & Panda Anti Virus scans and found trojan.noupdate.b, Download.Trojan, MHTMLRedir.Exploit, Trj/Dluca.D, Trj/Downloader.BK, Trj/Revop.D. I removed all viruses and Trojans, ran CWShredder, Spybot, Adware, ToolbarCop, LSPfix, Winsock Fix, and I still get the "Invalid Syntax Error" when starting IE 6 in normal mode, again I can get into IE 6 when the computer is in Safe Mode. Also sometimes when trying to get to certain websites the browser goes to a website that has a little dancing character with a text box that says "Worth a Vist :)and veiw by the text box. Down in the tool bar it says Any ideas on what that can be?

Also here is my Hijack This Log

Logfile of HijackThis v1.97.7
Scan saved at 4:52:41 PM, on 4/20/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\sysctl.exe
C:\WINNT\Explorer.EXE
C:\unzipped\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\sysctl.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Internet Washer Pro] C:\PROGRA~1\INTERN~3\iw.exe min
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Startup: BHODemon.lnk = C:\Program Files\BHODemon\BHODemon.exe
O4 - Global Startup: Printkey.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us
O19 - User stylesheet: C:\WINNT\system32\p406n2.06z

Thanks for all of your help!
 
You have a backdoor virus, represented by sysctl.exe being resident.

You also have: W32/Magistr.a@MM

This is a badly formed registry entry, not malware per se, but shows registry corruption:
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE


And I do not like these entries at all:
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\sysctl.exe
R3 - Default URLSearchHook is missing
O19 - User stylesheet: C:\WINNT\system32\p406n2.06z
 
Start by using Hijack to remove what I listed above in this section:

And I do not like these entries at all:
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\sysctl.exe
R3 - Default URLSearchHook is missing
O19 - User stylesheet: C:\WINNT\system32\p406n2.06z

Then follow the Google link above to manually remove the virus represented by sysctl.exe




 
I have remove the entries in Hijack this that you pointed out, I have followed the instructions to remove the virus represented by the sysctl.exe and I still get the "Invalid Syntax Error" when starting IE 6 when windows starts in Normal Mode. I can get to the pages that I could not get to before so we have done something right. Here is a new Hi-Jack This Log

Logfile of HijackThis v1.97.7
Scan saved at 11:31:52 AM, on 4/21/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\unzipped\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Internet Washer Pro] C:\PROGRA~1\INTERN~3\iw.exe min
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Startup: BHODemon.lnk = C:\Program Files\BHODemon\BHODemon.exe
O4 - Global Startup: Printkey.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us

THANKS AGAIN FOR ALL YOUR HELP!!
 
I wonder if the ad blocking feature of Internet Washer Pro
O4 - HKCU\..\Run: [Internet Washer Pro] C:\PROGRA~1\INTERN~3\iw.exe min
isn't breaking some of your script processing.

Just for fun, try resetting all your IE settings as well.

Tools>Internet Options>Programs<Reset Web Settings
Tools>Internet Options>Advanced>Restore Defaults


Jeff
The future is already here - it's just not widely distributed yet...
 
I still get the "Invalid Syntax Error" message when starting IE. I did the recomended changes and even used Hijack to remove the O4 - HKCU\..\Run: [Internet Washer Pro] C:\PROGRA~1\INTERN~3\iw.exe min


Any other ideas? Iam about ready to format and reinstall.

Thanks again.
 
I did load Netscape and that does work. So I am a little confused.
 
I would suggest setting your start page to something simple like Google, but I suspect no change. In Add/Remove Programs, try doing a repair on IE.

You could also try downloading EasyCleaner from and try its registry cleanup.


Jeff
The future is already here - it's just not widely distributed yet...
 
A guess is that the error message comes from:


A security update is available that modifies the default behavior of Internet Explorer for handling user nformation in HTTP and in HTTPS URLs
What You Should Know About the Windows Security Updates for February 2004
Wininet retries POST requests with a blank header

Use Hijack and remove:
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
 
OK I have tried all the suggestions, I downloaded and ran Registry Medic and did all the fixes that it recommended, I followed the instructions on MS support artical 834489 and 831167 and still get the "Invalid Syntax Error" message when starting IE 6. Is there anything else I can try before I throw this out the window?

Thanks Again for your your help & Suggestions

Here is the latest Hijack This Log

Logfile of HijackThis v1.97.7
Scan saved at 10:53:39 AM, on 4/23/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey.exe
C:\unzipped\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Printkey.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = co.ramsey.nd.us
 
In IE, Tools, Internet Options Advanced:
check to disable script debugging
uncheck to Display a notification on any script error
uncheck to disable Third-party Browser extensions.

Reboot and test again. I see nothing in your log that implies a called procedure or BHO that will involve a script element, but that is a short log from Hijack.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top