Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Illegal Operation appears randomly


  • This topic is locked This topic is locked

#1
ashish

ashish

    Member

  • Member
  • PipPip
  • 39 posts
Now one more problem has started teasing me.

Anytime without any specific reason the puter returns following types of different errors. Most of the times it appears when i start or close any programs. The program i am starting or closing is different everytime.

At first the errors were occuring so frequently that i hardly could work for 5-10 minutes. As i click on the close button of the error window only the explorer.exe file use to shut and restart without even closing any of the programs running at the time of error. it was like logging off and on without restarting ur puter fully.

I was so fed up that i started Hijackthis,scanned and fixed all of the entries it showed. After that the puter was a little stable but still not perfect.

Pls help or this time i m thinking of switching to Windows 2000. Pls suggest if Win 2000 is a better option than 98.

My Hijackthis log is included.

Following are the errors that occurs.
1)EXPLORER caused an invalid page fault in
module <unknown> at 0000:028af9d8.
Registers:
EAX=02710fe2 CS=0167 EIP=028af9d8 EFLGS=00010283
EBX=0136ed32 SS=016f ESP=0136eb60 EBP=0136eb74
ECX=02710fe7 DS=016f ESI=0136ecb0 FS=364f
EDX=0136ebc0 ES=016f EDI=00000000 GS=0000
Bytes at CS:EIP:

Stack dump:
bfb742fa 00000444 0000001c 00000000 fff0d339 0136eb90 bfb742de 02710fe2 00000444 0000001c 00000000 fff0d339 0136ebec bfb741ff 00000444 0000001c

2)EXPLORER caused an invalid page fault in
module <unknown> at 0000:028af9d8.
Registers:
EAX=02710fe2 CS=0167 EIP=028af9d8 EFLGS=00010283
EBX=0136fa8e SS=016f ESP=0136f8bc EBP=0136f8d0
ECX=02710fe7 DS=016f ESI=0136fa0c FS=364f
EDX=0136f91c ES=016f EDI=00000000 GS=0000
Bytes at CS:EIP:

Stack dump:
bfb742fa 00000444 0000001c 00000000 fff0d339 0136f8ec bfb742de 02710fe2 00000444 0000001c 00000000 fff0d339 0136f948 bfb741ff 00000444 0000001c

3)EXPLORER caused an invalid page fault in
module KERNEL32.DLL at 0167:bff9db61.
Registers:
EAX=c00309c4 CS=0167 EIP=bff9db61 EFLGS=00010212
EBX=0258ff88 SS=016f ESP=0254ff7c EBP=02550218
ECX=00000000 DS=016f ESI=02550368 FS=23a7
EDX=bff76855 ES=016f EDI=0258ff74 GS=0000
Bytes at CS:EIP:
53 8b 15 e4 9c fc bf 56 89 4d e4 57 89 4d dc 89
Stack dump:

4)EXPLORER caused an invalid page fault in
module <unknown> at 0000:00e8f9d8.
Registers:
EAX=010c0fe2 CS=0167 EIP=00e8f9d8 EFLGS=00010283
EBX=0059f70c SS=016f ESP=0059f538 EBP=0059f54c
ECX=010c0fe7 DS=016f ESI=0059f688 FS=0e57
EDX=0059f598 ES=016f EDI=00000000 GS=0000
Bytes at CS:EIP:

Stack dump:
bfb742fa 00000c08 0000001c 00000001 00000000 0059f568 bfb742de 010c0fe2 00000c08 0000001c 00000001 00000000 0059f5c4 bfb741ff 00000c08 0000001c

Edited by ashish, 19 July 2004 - 12:39 PM.

  • 0

Advertisements


#2
admin

admin

    Founder Geek

  • Administrator
  • 24,489 posts

I was so fed up that i started Hijackthis,scanned and fixed all of the entries it showed.

<_< You don't want to do that. Many of the entries are required for the proper operation of your computer. Please restart Hijack This and restore the backups.
  • 0

#3
ashish

ashish

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
O.K i have restored all the items i had fixed and i m attaching the fresh hijckthis log file made after restoration.

And pls if u could tell me some of the important entries and their functions that appear in Hijackthis scan would be very helpful for me in future.
  • 0

#4
admin

admin

    Founder Geek

  • Administrator
  • 24,489 posts
Can we please see your current log?
  • 0

#5
ashish

ashish

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Logfile of HijackThis v1.97.7
Scan saved at 12:05:23 AM, on 7/22/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ELITECORE\CYBEROAM CLIENT FOR 24ONLINE\CYBEROAMCLIENT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\OPERA7\OPERA.EXE
D:\VIMP SOFTWARES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRAM FILES\NOVOSOFT\HANDY BACKUP\hbagent.exe -logon
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRAM FILES\FLASHGET\jc_link.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
  • 0

#6
admin

admin

    Founder Geek

  • Administrator
  • 24,489 posts
This is a strange log <_< Have you tried Ad-aware?

Download the latest version of Ad-Aware from here (if you already have Ad-Aware installed, make sure that it is the latest version and always go online and update it before you run it).

After installing AAW, and before running the program, you must FIRST update the reference file following these instuctions. (and you must always do this before you run the program at any later date).

Now do the following:

Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."

Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."

Press "Scan Now"

- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:

Now press "Next" to let Ad-aware scan your drives. It will find a number of spyware files and registry keys. Right-click in that pane and choose "select all"

Now press "Next" again. It will ask you whether you'd like to remove all checked items. Click OK.

Finally, close Ad-Aware, and reboot.

Run Hijack This again and post back a fresh log.
  • 0

#7
ashish

ashish

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Ok i have done every thing as u told. I m using ad-aware since very long time and scan my puter with it after every internet session and delete any adaware components installed. I updated it and its reference file.

I have posted my Hijackthis log.

Can u pls tell me what was so strange about my log file.

Logfile of HijackThis v1.97.7
Scan saved at 11:48:57 PM, on 7/22/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
D:\VIMP SOFTWARES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKCU\..\Run: [Handy Backup 3.9] C:\PROGRAM FILES\NOVOSOFT\HANDY BACKUP\hbagent.exe -logon
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRAM FILES\FLASHGET\jc_link.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
  • 0

#8
admin

admin

    Founder Geek

  • Administrator
  • 24,489 posts
Closed. Duplicate post. Continued here: http://www.geekstogo...opic=2510&st=0
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP