Internet Products
1847225 Members
2490 Online
110263 Solutions
New Discussion

I.E 6.0 hangs on each load, cant open new windows

 
SOLVED
Go to solution
Matt_283
New Member

I.E 6.0 hangs on each load, cant open new windows

Was wondering if anyone knows why i.e 6 is hanging when i load it, typically it will take about 10 seconds, once loaded i am unable to open any new browser windows (this makes reading emails and accessing some sites very difficult as i have to manually enter address links.)

The istsvc program was present, however i think i have removed it since, i am unsure if this is related in anyway.

I have attached a hijackthis report

I have noted that one member complained of the save problem in one of the istsvc posts, however no solution was researched or found.


Logfile of HijackThis v1.99.0
Scan saved at 17:40:23, on 22/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\system32\RadioSvr.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\S3tray2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe
C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
C:\Program Files\Hewlett-Packard\HP Mobile Printing Driver\HPBMOBIL.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Common Files\Nokia\Tools\NclTray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\MICROSTAR\Bluetooth Software\BTTray.exe
C:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Project\Office\OSA.EXE
C:\PROGRA~1\MI43DA~1\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Anyone Else\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.virgin.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\msgr.en-us.en-gb\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [HP Mobile Printing Driver] C:\Program Files\Hewlett-Packard\HP Mobile Printing Driver\HPBMOBIL.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Presentation Ready] C:\Program Files\Hewlett-Packard\HP Presentation Ready\PresRdy.exe -r
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\Tools\NclTray.exe
O4 - HKLM\..\Run: [OSc5Q6L1] C:\WINDOWS\rbmxtlig.exe
O4 - HKLM\..\Run: [nkhytoh] C:\WINDOWS\nkhytoh.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Project\Office\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E348BA17-1792-49D2-A5C5-A980E62C233A}: NameServer = 195.92.195.95 195.92.195.94
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Apache - Unknown - C:\Program Files\Apache Group\Apache\Apache.exe
O23 - Service: HP Configuration Interface Service - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HP RF Device Service - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown - C:/mysql/bin/mysqld-nt.exe
O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe (file missing)
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Sun App Server 7 Admin Server (domain1:admin-server) - Sun Microsystems, Inc. - C:/Sun/studio5u1_se/appserver7/bin/appservd-wdog.exe
O23 - Service: Sun App Server 7 (domain1:server1) - Sun Microsystems, Inc. - C:/Sun/studio5u1_se/appserver7/bin/appservd-wdog.exe

4 REPLIES 4
Pat
Honored Contributor

Re: I.E 6.0 hangs on each load, cant open new windows

Hello, Matt,


1)

That occurred with Windows 2000. Is a blank page displayed? Load a page and hit F5 to refresh. It may not be displayed properly. If so, you may need to download this patch.

http://support.microsoft.com/kb/824145

CAUSE
This behavior may occur when you load a page that contains frames and the Uniform Resource Locator (URL) contains a long query string.

2)

CAUSE
This problem may occur when the use of Federal Information Processing Standard (FIPS) encryption algorithms is enforced through the Computer Configuration Security Options policy.

Some Secure Sockets Layer (SSL) implementations send a zero-length packet as the first message over an SSL connection. This behavior occurs only when a block cipher such as Triple Data Encryption Standard (Triple DES) is used, and is intended as a workaround for a known block cipher chaining vulnerability. The Internet extensions for the Wininet.dll file does not interpret this zero-length packet correctly.

Solution:

To successfully connect to a secure Web site, disable the system policy that requires FIPS-compliant algorithms. To do this, follow these steps:1. Click Start, and then click Control Panel.
2. Click Performance and Maintenance.
3. Click Administrative Tools.
4. Double-click Local Security Policy.
5. Expand Local Policies.
6. Click Security Options.
7. In the Policy list, double-click System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing.
8. Click Disabled, and then click OK.
9. Restart your computer.


Let us know.

Pat

Ron Kinner
Honored Contributor
Solution

Re: I.E 6.0 hangs on each load, cant open new windows

Make sure you have a copy of Winsockxpfix.exe from

http://www.iup.edu/house/resnet/winfix.shtm

just in case you can't get on the internet afterwards.



Boot to Safe Mode and run HijackThis then check and Fix Checked the following:

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [OSc5Q6L1] C:\WINDOWS\rbmxtlig.exe
O4 - HKLM\..\Run: [nkhytoh] C:\WINDOWS\nkhytoh.exe

These three are not malware but are dead anyway.

O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe (file missing)

Reboot and post a new log so I can see if we got it all.

Ron
Matt_283
New Member

Re: I.E 6.0 hangs on each load, cant open new windows

Cheers, thanks so much!!! that sorted it, everything is working now.

As asked ive attached another log

Cheers again
Ron Kinner
Honored Contributor

Re: I.E 6.0 hangs on each load, cant open new windows

You still have two entries for istsvc left:

O4 - HKLM\..\Run: [¢⠰¸K0à @à à à ]§ú" ü⠰üžiC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\rbmxtlig.exe
O4 - HKLM\..\Run: [¢⠰¸K0¨4W
}ïà z î [ 8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\rbmxtlig.exe


While in Safe Mode delete the C:\Program Files\ISTsvc\ folder and all its contents or better yet, delete just the contents and then right click on the ISTsvc folder and select Properties then Security. Uncheck the box where it says Allow Inheritable Permissions... then select each user and down at the bottom where it says FULL CONTROL check the DENY box. Then after all users have been denied full control click on OK. This leaves the folder there but denies all users the possibility of writing to it or running any files in the folder. This should keep a new infection from taking root.

Good idea to remove C:\WINDOWS\rbmxtlig.exe
to.

If it comes back again you might want to try Symantec's istsvc removal tool (probably best in Safe Mode).

http://securityresponse.symantec.com/avcenter/FxIstbar.exe

or run Trend Micro's antivirus scan.