• Welcome to Tux Reports: Where Penguins Fly. We hope you find the topics varied, interesting, and worthy of your time. Please become a member and join in the discussions.

IE8 Crashing Severley

S

shawnLane01

Flightless Bird
I uninstalled IE8 [it goes back to IE7] still no luck!! Whenever I launch IE
it crashes and opens the VS JIT Debugger!!!
Unhandled exception at 0x035ab82b in iexplore.exe: 0xC0000005: Access
violation reading location 0x035ab82b.
OS:Win2k3 R2
Please advice what shoudl I do...Tried launching Windbg but got error
CommandLine: "C:/Program Files\Internet Explorer\iexplore.exe"
Symbol search path is: C:/WINDOWS\Symbols\exe
Executable search path is:
ModLoad: 00400000 0049c000 iexplore.exe
ModLoad: 7c800000 7c8c2000 ntdll.dll
ModLoad: 77e40000 77f42000 C:/WINDOWS\system32\kernel32.dll
ModLoad: 7d1e0000 7d27c000 C:/WINDOWS\system32\ADVAPI32.dll
ModLoad: 77c50000 77cef000 C:/WINDOWS\system32\RPCRT4.dll
ModLoad: 76f50000 76f63000 C:/WINDOWS\system32\Secur32.dll
ModLoad: 77380000 77411000 C:/WINDOWS\system32\USER32.dll
ModLoad: 77c00000 77c49000 C:/WINDOWS\system32\GDI32.dll
ModLoad: 77ba0000 77bfa000 C:/WINDOWS\system32\msvcrt.dll
ModLoad: 77da0000 77df2000 C:/WINDOWS\system32\SHLWAPI.dll
ModLoad: 7c8d0000 7d0cf000 C:/WINDOWS\system32\SHELL32.dll
ModLoad: 77670000 777a9000 C:/WINDOWS\system32\ole32.dll
ModLoad: 5dca0000 5de88000 C:/WINDOWS\system32\iertutil.dll
ModLoad: 1a400000 1a532000 C:/WINDOWS\system32\urlmon.dll
ModLoad: 77d00000 77d8b000 C:/WINDOWS\system32\OLEAUT32.dll
(1138.160c): Break instruction exception - code 80000003 (first chance)
eax=77e00000 ebx=7ffff000 ecx=00000005 edx=00000020 esi=7c8897f4 edi=00141f38
eip=7c81a3e1 esp=0012fb70 ebp=0012fcb4 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
ntdll.dll -
ntdll!DbgBreakPoint:
7c81a3e1 cc int 3
 
P

PA Bear [MS MVP]

Flightless Bird
Uninstalling IE8 will not resolve the hijackware infection plaguing your
computer (nor ur broke spiel chukker).

WTF is a anyone browsing the internet in Windows Server 2000 R2 in the first
place?


shawnLane01 wrote:
> I uninstalled IE8 [it goes back to IE7] still no luck!! Whenever I launch
> IE
> it crashes and opens the VS JIT Debugger!!!
> Unhandled exception at 0x035ab82b in iexplore.exe: 0xC0000005: Access
> violation reading location 0x035ab82b.
> OS:Win2k3 R2
> Please advice what shoudl I do...Tried launching Windbg but got error
> CommandLine: "C:/Program Files\Internet Explorer\iexplore.exe"
> Symbol search path is: C:/WINDOWS\Symbols\exe
> Executable search path is:
> ModLoad: 00400000 0049c000 iexplore.exe
> ModLoad: 7c800000 7c8c2000 ntdll.dll
> ModLoad: 77e40000 77f42000 C:/WINDOWS\system32\kernel32.dll
> ModLoad: 7d1e0000 7d27c000 C:/WINDOWS\system32\ADVAPI32.dll
> ModLoad: 77c50000 77cef000 C:/WINDOWS\system32\RPCRT4.dll
> ModLoad: 76f50000 76f63000 C:/WINDOWS\system32\Secur32.dll
> ModLoad: 77380000 77411000 C:/WINDOWS\system32\USER32.dll
> ModLoad: 77c00000 77c49000 C:/WINDOWS\system32\GDI32.dll
> ModLoad: 77ba0000 77bfa000 C:/WINDOWS\system32\msvcrt.dll
> ModLoad: 77da0000 77df2000 C:/WINDOWS\system32\SHLWAPI.dll
> ModLoad: 7c8d0000 7d0cf000 C:/WINDOWS\system32\SHELL32.dll
> ModLoad: 77670000 777a9000 C:/WINDOWS\system32\ole32.dll
> ModLoad: 5dca0000 5de88000 C:/WINDOWS\system32\iertutil.dll
> ModLoad: 1a400000 1a532000 C:/WINDOWS\system32\urlmon.dll
> ModLoad: 77d00000 77d8b000 C:/WINDOWS\system32\OLEAUT32.dll
> (1138.160c): Break instruction exception - code 80000003 (first chance)
> eax=77e00000 ebx=7ffff000 ecx=00000005 edx=00000020 esi=7c8897f4
> edi=00141f38 eip=7c81a3e1 esp=0012fb70 ebp=0012fcb4 iopl=0 nv up
> ei
> pl nz na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
> efl=00000202 *** ERROR: Symbol file could not be found. Defaulted to
> export symbols for ntdll.dll -
> ntdll!DbgBreakPoint:
> 7c81a3e1 cc int 3
 
R

rob^_^

Flightless Bird
Hi,

You obviously have VS installed... what version?

Are you launching IE from the VS IDE and/or using ISS or a personal web
server instance.

Have you rebooted since? The VS debugger still has a hook into the
Iexplore.exe process. Closing VS and restarting it should clear the debugger
hooks.

Regards.

"shawnLane01" <shawnLane01@discussions.microsoft.com> wrote in message
news:531A8DBA-C884-4FE3-B42C-AF0F48B9329C@microsoft.com...
> I uninstalled IE8 [it goes back to IE7] still no luck!! Whenever I launch
> IE
> it crashes and opens the VS JIT Debugger!!!
> Unhandled exception at 0x035ab82b in iexplore.exe: 0xC0000005: Access
> violation reading location 0x035ab82b.
> OS:Win2k3 R2
> Please advice what shoudl I do...Tried launching Windbg but got error
> CommandLine: "C:/Program Files\Internet Explorer\iexplore.exe"
> Symbol search path is: C:/WINDOWS\Symbols\exe
> Executable search path is:
> ModLoad: 00400000 0049c000 iexplore.exe
> ModLoad: 7c800000 7c8c2000 ntdll.dll
> ModLoad: 77e40000 77f42000 C:/WINDOWS\system32\kernel32.dll
> ModLoad: 7d1e0000 7d27c000 C:/WINDOWS\system32\ADVAPI32.dll
> ModLoad: 77c50000 77cef000 C:/WINDOWS\system32\RPCRT4.dll
> ModLoad: 76f50000 76f63000 C:/WINDOWS\system32\Secur32.dll
> ModLoad: 77380000 77411000 C:/WINDOWS\system32\USER32.dll
> ModLoad: 77c00000 77c49000 C:/WINDOWS\system32\GDI32.dll
> ModLoad: 77ba0000 77bfa000 C:/WINDOWS\system32\msvcrt.dll
> ModLoad: 77da0000 77df2000 C:/WINDOWS\system32\SHLWAPI.dll
> ModLoad: 7c8d0000 7d0cf000 C:/WINDOWS\system32\SHELL32.dll
> ModLoad: 77670000 777a9000 C:/WINDOWS\system32\ole32.dll
> ModLoad: 5dca0000 5de88000 C:/WINDOWS\system32\iertutil.dll
> ModLoad: 1a400000 1a532000 C:/WINDOWS\system32\urlmon.dll
> ModLoad: 77d00000 77d8b000 C:/WINDOWS\system32\OLEAUT32.dll
> (1138.160c): Break instruction exception - code 80000003 (first chance)
> eax=77e00000 ebx=7ffff000 ecx=00000005 edx=00000020 esi=7c8897f4
> edi=00141f38
> eip=7c81a3e1 esp=0012fb70 ebp=0012fcb4 iopl=0 nv up ei pl nz na po
> nc
> cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
> efl=00000202
> *** ERROR: Symbol file could not be found. Defaulted to export symbols
> for
> ntdll.dll -
> ntdll!DbgBreakPoint:
> 7c81a3e1 cc int 3
>
>
 
R

Robert Aldwinckle

Flightless Bird
"shawnLane01" <shawnLane01@discussions.microsoft.com> wrote in message
news:531A8DBA-C884-4FE3-B42C-AF0F48B9329C@microsoft.com...
> I uninstalled IE8 [it goes back to IE7] still no luck!! Whenever I launch
> IE
> it crashes and opens the VS JIT Debugger!!!


> Unhandled exception at 0x035ab82b in iexplore.exe: 0xC0000005: Access
> violation reading location 0x035ab82b.
> OS:Win2k3 R2
> Please advice what shoudl I do...Tried launching Windbg but got error



You could run ProcMon to see if that address is significant in some way.
E.g. sometimes you will see that a module was loaded at 0x035a0000 but has
now been removed from memory.


Good luck

Robert Aldwinckle
---
 
S

shawnLane01

Flightless Bird
Its Windows 2003 by the way...also its a dev box needed for staging and
testing purposes. Could you help on what type of malware/grayware I should be
looking at? I have McAfee AV+ASpyware installed.
Also a twist is I can open an IE Instance inside the VS 2008 IDE

"PA Bear [MS MVP]" wrote:

> Uninstalling IE8 will not resolve the hijackware infection plaguing your
> computer (nor ur broke spiel chukker).
>
> WTF is a anyone browsing the internet in Windows Server 2000 R2 in the first
> place?
>
>
> shawnLane01 wrote:
> > I uninstalled IE8 [it goes back to IE7] still no luck!! Whenever I launch
> > IE
> > it crashes and opens the VS JIT Debugger!!!
> > Unhandled exception at 0x035ab82b in iexplore.exe: 0xC0000005: Access
> > violation reading location 0x035ab82b.
> > OS:Win2k3 R2
> > Please advice what shoudl I do...Tried launching Windbg but got error
> > CommandLine: "C:/Program Files\Internet Explorer\iexplore.exe"
> > Symbol search path is: C:/WINDOWS\Symbols\exe
> > Executable search path is:
> > ModLoad: 00400000 0049c000 iexplore.exe
> > ModLoad: 7c800000 7c8c2000 ntdll.dll
> > ModLoad: 77e40000 77f42000 C:/WINDOWS\system32\kernel32.dll
> > ModLoad: 7d1e0000 7d27c000 C:/WINDOWS\system32\ADVAPI32.dll
> > ModLoad: 77c50000 77cef000 C:/WINDOWS\system32\RPCRT4.dll
> > ModLoad: 76f50000 76f63000 C:/WINDOWS\system32\Secur32.dll
> > ModLoad: 77380000 77411000 C:/WINDOWS\system32\USER32.dll
> > ModLoad: 77c00000 77c49000 C:/WINDOWS\system32\GDI32.dll
> > ModLoad: 77ba0000 77bfa000 C:/WINDOWS\system32\msvcrt.dll
> > ModLoad: 77da0000 77df2000 C:/WINDOWS\system32\SHLWAPI.dll
> > ModLoad: 7c8d0000 7d0cf000 C:/WINDOWS\system32\SHELL32.dll
> > ModLoad: 77670000 777a9000 C:/WINDOWS\system32\ole32.dll
> > ModLoad: 5dca0000 5de88000 C:/WINDOWS\system32\iertutil.dll
> > ModLoad: 1a400000 1a532000 C:/WINDOWS\system32\urlmon.dll
> > ModLoad: 77d00000 77d8b000 C:/WINDOWS\system32\OLEAUT32.dll
> > (1138.160c): Break instruction exception - code 80000003 (first chance)
> > eax=77e00000 ebx=7ffff000 ecx=00000005 edx=00000020 esi=7c8897f4
> > edi=00141f38 eip=7c81a3e1 esp=0012fb70 ebp=0012fcb4 iopl=0 nv up
> > ei
> > pl nz na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
> > efl=00000202 *** ERROR: Symbol file could not be found. Defaulted to
> > export symbols for ntdll.dll -
> > ntdll!DbgBreakPoint:
> > 7c81a3e1 cc int 3

>
> .
>
 
S

shawnLane01

Flightless Bird
https://docs.google.com/leaf?id=0B93pSYLUcl4cYWY2ZGEwMmQtOGM2My00NWMxLTk3NmYtMDUxMTJlMGI1M2U5&hl=en

"Robert Aldwinckle" wrote:

>
> "shawnLane01" <shawnLane01@discussions.microsoft.com> wrote in message
> news:531A8DBA-C884-4FE3-B42C-AF0F48B9329C@microsoft.com...
> > I uninstalled IE8 [it goes back to IE7] still no luck!! Whenever I launch
> > IE
> > it crashes and opens the VS JIT Debugger!!!

>
> > Unhandled exception at 0x035ab82b in iexplore.exe: 0xC0000005: Access
> > violation reading location 0x035ab82b.
> > OS:Win2k3 R2
> > Please advice what shoudl I do...Tried launching Windbg but got error

>
>
> You could run ProcMon to see if that address is significant in some way.
> E.g. sometimes you will see that a module was loaded at 0x035a0000 but has
> now been removed from memory.
>
>
> Good luck
>
> Robert Aldwinckle
> ---
>
>
> .
>
 
P

PA Bear [MS MVP]

Flightless Bird
Apologies for typo.

What's the full name of this McAfee app? Has another McAfee app or a Norton
app ever been install on the computer?

Were all McAfee processes running in the background when IE8 was installed?


shawnLane01 wrote:
> Its Windows 2003 by the way...also its a dev box needed for staging and
> testing purposes. Could you help on what type of malware/grayware I should
> be looking at? I have McAfee AV+ASpyware installed.
> Also a twist is I can open an IE Instance inside the VS 2008 IDE
>
> "PA Bear [MS MVP]" wrote:
>> Uninstalling IE8 will not resolve the hijackware infection plaguing your
>> computer (nor ur broke spiel chukker).
>>
>> WTF is a anyone browsing the internet in Windows Server 2000 R2 in the
>> first place?
>>
>>
>> shawnLane01 wrote:
>>> I uninstalled IE8 [it goes back to IE7] still no luck!! Whenever I
>>> launch
>>> IE
>>> it crashes and opens the VS JIT Debugger!!!
>>> Unhandled exception at 0x035ab82b in iexplore.exe: 0xC0000005: Access
>>> violation reading location 0x035ab82b.
>>> OS:Win2k3 R2
>>> Please advice what shoudl I do...Tried launching Windbg but got error
>>> CommandLine: "C:/Program Files\Internet Explorer\iexplore.exe"
>>> Symbol search path is: C:/WINDOWS\Symbols\exe
>>> Executable search path is:
>>> ModLoad: 00400000 0049c000 iexplore.exe
>>> ModLoad: 7c800000 7c8c2000 ntdll.dll
>>> ModLoad: 77e40000 77f42000 C:/WINDOWS\system32\kernel32.dll
>>> ModLoad: 7d1e0000 7d27c000 C:/WINDOWS\system32\ADVAPI32.dll
>>> ModLoad: 77c50000 77cef000 C:/WINDOWS\system32\RPCRT4.dll
>>> ModLoad: 76f50000 76f63000 C:/WINDOWS\system32\Secur32.dll
>>> ModLoad: 77380000 77411000 C:/WINDOWS\system32\USER32.dll
>>> ModLoad: 77c00000 77c49000 C:/WINDOWS\system32\GDI32.dll
>>> ModLoad: 77ba0000 77bfa000 C:/WINDOWS\system32\msvcrt.dll
>>> ModLoad: 77da0000 77df2000 C:/WINDOWS\system32\SHLWAPI.dll
>>> ModLoad: 7c8d0000 7d0cf000 C:/WINDOWS\system32\SHELL32.dll
>>> ModLoad: 77670000 777a9000 C:/WINDOWS\system32\ole32.dll
>>> ModLoad: 5dca0000 5de88000 C:/WINDOWS\system32\iertutil.dll
>>> ModLoad: 1a400000 1a532000 C:/WINDOWS\system32\urlmon.dll
>>> ModLoad: 77d00000 77d8b000 C:/WINDOWS\system32\OLEAUT32.dll
>>> (1138.160c): Break instruction exception - code 80000003 (first chance)
>>> eax=77e00000 ebx=7ffff000 ecx=00000005 edx=00000020 esi=7c8897f4
>>> edi=00141f38 eip=7c81a3e1 esp=0012fb70 ebp=0012fcb4 iopl=0 nv up
>>> ei
>>> pl nz na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
>>> efl=00000202 *** ERROR: Symbol file could not be found. Defaulted to
>>> export symbols for ntdll.dll -
>>> ntdll!DbgBreakPoint:
>>> 7c81a3e1 cc int 3

>>
>> .
 
R

Robert Aldwinckle

Flightless Bird
"shawnLane01" <shawnLane01@discussions.microsoft.com> wrote in message
news:B18131B7-FDB0-4017-9CCC-8B11709C8C7F@microsoft.com...
> https://docs.google.com/leaf?id=0B93pSYLUcl4cYWY2ZGEwMmQtOGM2My00NWMxLTk3NmYtMDUxMTJlMGI1M2U5&hl=en



Focusing on Buffer Overflow from RegQueryValue? That's unlikely to be
significant IMO.

To see what I was suggesting you would only need Process and Thread
activity (e.g. for the load image event at least; I'm not sure about the
crash event report.)

BTW I hadn't realized how usable the .CSV save format from ProcMon could be.

Also, Excel 2010 couldn't open that from the web (bogus error message). I
had to save it first. ; )


HTH

Robert
---


>
> "Robert Aldwinckle" wrote:
>
>>
>> "shawnLane01" <shawnLane01@discussions.microsoft.com> wrote in message
>> news:531A8DBA-C884-4FE3-B42C-AF0F48B9329C@microsoft.com...
>> > I uninstalled IE8 [it goes back to IE7] still no luck!! Whenever I
>> > launch
>> > IE
>> > it crashes and opens the VS JIT Debugger!!!

>>
>> > Unhandled exception at 0x035ab82b in iexplore.exe: 0xC0000005: Access
>> > violation reading location 0x035ab82b.
>> > OS:Win2k3 R2
>> > Please advice what shoudl I do...Tried launching Windbg but got error

>>
>>
>> You could run ProcMon to see if that address is significant in some way.
>> E.g. sometimes you will see that a module was loaded at 0x035a0000 but
>> has
>> now been removed from memory.
>>
>>
>> Good luck
>>
>> Robert Aldwinckle
>> ---
>>
>>
>> .
>>
 
Top