jaymcptech
Beta member
- Messages
- 2
SYNTAX ERROR (never seen an error like this )!!!!!
well hello all,
To start, my name is jay and i am an mcp and a network administrator in maryland.
I encountered this abosolutely crippling but almost undetectable error in our network a few months ago, after extensive research i turn to the people here for one last cry for help.
heres the deal,
this is occuring in IE 6.0, NETSCAPE NAVIGATOR, AND FIREFOX, so whatever it is it sure isnt browser specific.
when the users go to a website all looks good UNTIL, they try to open a page linking, or maybe a java applet like calendar or a map or photo show, you know simple stuff (yet this error had actaully caused the office to lose money because it crippled the call tracking system used in IE)
the best way to describe it is to show it to you
this is obviously in IE , but in netscape if this happens its just like holding cntrl and getting a UNTITLED window WITH NOTHING IN IT.
things we have tried
admin removal of ALL JAVA
reinstall of ALL JAVA
complete scan of systems (40 pcs)
hijack this
ad aware
net pro (our system)
avg
sophos (commercial AV client)
registry mechanic (krappy software)
spybot
and multiple other attempts but unfortuantely this is here to stay
its strange how something so little could cripple us so badly, and even more bizarre how no one in their right mind knows how to fix this.
ill include a copy of the hijack log on this win2003 server, ALSO EXIBITING same symptoms
we are completely virus free, and have had our share of trojans on the network, so two things come to mind
something was severely damaged or destroyed in one or a few of our removals of the BAD GUYS, not browser specific (since it occurs multi platform and multi browser)
or something we are missing thats nested in our network causing this.
any help at all
email me at jay@NOSPAMitsyourmuzic.com IMMEDIATELY
or post here
thank you all and god bless
log is below from the server
i will post a client machine XP PRO as well
Jay
MCP
Citadel Broadcasting
Logfile of HijackThis v1.99.1
Scan saved at 4:35:51 AM, on 1/7/2006
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\Dfssvc.exe
E:\WINDOWS\System32\dns.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\ismserv.exe
E:\WINDOWS\system32\ntfrs.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\wuauclt.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\Program Files\Grisoft\AVG Free\avgemc.exe
E:\Program Files\Grisoft\AVG Free\avgcc.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\administrator profile\Start Menu\Programs\AV-removal\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = contoso.com
O17 - HKLM\Software\..\Telephony: DomainName = contoso.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{F07E9078-8929-4688-90D5-4B1D77EC7849}: NameServer = 127.0.0.1,68.87.73.242,68.87.71.226
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = contoso.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = contoso.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = contoso.com
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
well hello all,
To start, my name is jay and i am an mcp and a network administrator in maryland.
I encountered this abosolutely crippling but almost undetectable error in our network a few months ago, after extensive research i turn to the people here for one last cry for help.
heres the deal,
this is occuring in IE 6.0, NETSCAPE NAVIGATOR, AND FIREFOX, so whatever it is it sure isnt browser specific.
when the users go to a website all looks good UNTIL, they try to open a page linking, or maybe a java applet like calendar or a map or photo show, you know simple stuff (yet this error had actaully caused the office to lose money because it crippled the call tracking system used in IE)
the best way to describe it is to show it to you
this is obviously in IE , but in netscape if this happens its just like holding cntrl and getting a UNTITLED window WITH NOTHING IN IT.
things we have tried
admin removal of ALL JAVA
reinstall of ALL JAVA
complete scan of systems (40 pcs)
hijack this
ad aware
net pro (our system)
avg
sophos (commercial AV client)
registry mechanic (krappy software)
spybot
and multiple other attempts but unfortuantely this is here to stay
its strange how something so little could cripple us so badly, and even more bizarre how no one in their right mind knows how to fix this.
ill include a copy of the hijack log on this win2003 server, ALSO EXIBITING same symptoms
we are completely virus free, and have had our share of trojans on the network, so two things come to mind
something was severely damaged or destroyed in one or a few of our removals of the BAD GUYS, not browser specific (since it occurs multi platform and multi browser)
or something we are missing thats nested in our network causing this.
any help at all
email me at jay@NOSPAMitsyourmuzic.com IMMEDIATELY
or post here
thank you all and god bless
log is below from the server
i will post a client machine XP PRO as well
Jay
MCP
Citadel Broadcasting
Logfile of HijackThis v1.99.1
Scan saved at 4:35:51 AM, on 1/7/2006
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\Dfssvc.exe
E:\WINDOWS\System32\dns.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\ismserv.exe
E:\WINDOWS\system32\ntfrs.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\wuauclt.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\Program Files\Grisoft\AVG Free\avgemc.exe
E:\Program Files\Grisoft\AVG Free\avgcc.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\administrator profile\Start Menu\Programs\AV-removal\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = contoso.com
O17 - HKLM\Software\..\Telephony: DomainName = contoso.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{F07E9078-8929-4688-90D5-4B1D77EC7849}: NameServer = 127.0.0.1,68.87.73.242,68.87.71.226
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = contoso.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = contoso.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = contoso.com
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe