ok, I turned on my computer right right now, and i found a notepad file on my desktop..i opened it and it said:
An unexpected exception has been detected in native code outside the VM.
Unexpected Signal : EXCEPTION_ACCESS_VIOLATION (0xc0000005) occurred at PC=0x6D31200F
Function=[Unknown.]
Library=C:\Program Files\Java\j2re1.4.2_04\bin\jpiexp32.dll
NOTE: We are unable to locate the function name symbol for the error
just occurred. Please refer to release documentation for possible
reason and solutions.
Current Java thread:
at sun.plugin.services.WPlatformService.waitEvent(Native Method)
at sun.plugin.viewer.frame.IExplorerEmbeddedFrame.destroy(Unknown Source)
Dynamic libraries:
0x00400000 - 0x00419000 C:\Program Files\Internet Explorer\IEXPLORE.EXE
0x77F80000 - 0x77FFD000 C:\WINNT\system32\ntdll.dll
0x78000000 - 0x78045000 C:\WINNT\system32\msvcrt.dll
0x7C570000 - 0x7C623000 C:\WINNT\system32\KERNEL32.dll
0x77E10000 - 0x77E6F000 C:\WINNT\system32\USER32.dll
0x77F40000 - 0x77F7B000 C:\WINNT\system32\GDI32.dll
0x70A70000 - 0x70AD6000 C:\WINNT\system32\SHLWAPI.dll
0x7C2D0000 - 0x7C332000 C:\WINNT\system32\ADVAPI32.dll
0x77D30000 - 0x77DA1000 C:\WINNT\system32\RPCRT4.DLL
0x71700000 - 0x71849000 C:\WINNT\system32\SHDOCVW.dll
0x007A0000 - 0x00824000 C:\WINNT\system32\comctl32.dll
0x782F0000 - 0x78535000 C:\WINNT\system32\SHELL32.dll
0x77A50000 - 0x77B3F000 C:\WINNT\system32\ole32.dll
0x71500000 - 0x715FC000 C:\WINNT\system32\BROWSEUI.dll
0x71960000 - 0x71972000 C:\WINNT\system32\browselc.dll
0x775A0000 - 0x77630000 C:\WINNT\system32\CLBCATQ.DLL
0x779B0000 - 0x77A4B000 C:\WINNT\system32\OLEAUT32.dll
0x63000000 - 0x63096000 C:\WINNT\system32\WININET.dll
0x7C740000 - 0x7C7C7000 C:\WINNT\system32\CRYPT32.dll
0x77430000 - 0x77440000 C:\WINNT\system32\MSASN1.DLL
0x77840000 - 0x7787E000 C:\WINNT\system32\cscui.dll
0x770C0000 - 0x770E3000 C:\WINNT\system32\CSCDLL.DLL
0x10000000 - 0x10008000 C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
0x01450000 - 0x0150B000 C:\PROGRA~1\SPYBOT~1\SDHelper.dll
0x77820000 - 0x77827000 C:\WINNT\system32\version.dll
0x759B0000 - 0x759B6000 C:\WINNT\system32\LZ32.DLL
0x695E0000 - 0x69609000 C:\WINNT\system32\olepro32.dll
0x1A400000 - 0x1A47D000 C:\WINNT\system32\urlmon.dll
0x718C0000 - 0x71944000 C:\WINNT\system32\shdoclc.dll
0x70440000 - 0x704CF000 C:\WINNT\system32\mlang.dll
0x75050000 - 0x75058000 C:\WINNT\system32\wsock32.dll
0x75030000 - 0x75044000 C:\WINNT\system32\WS2_32.DLL
0x75020000 - 0x75028000 C:\WINNT\system32\WS2HELP.DLL
0x74FD0000 - 0x74FEE000 C:\WINNT\system32\msafd.dll
0x774E0000 - 0x77513000 C:\WINNT\system32\RASAPI32.DLL
0x774C0000 - 0x774D1000 C:\WINNT\system32\RASMAN.DLL
0x77530000 - 0x77552000 C:\WINNT\system32\TAPI32.DLL
0x77830000 - 0x7783E000 C:\WINNT\system32\RTUTILS.DLL
0x75010000 - 0x75017000 C:\WINNT\System32\wshtcpip.dll
0x75AB0000 - 0x75AB5000 C:\WINNT\system32\sensapi.dll
0x7C0F0000 - 0x7C151000 C:\WINNT\system32\USERENV.DLL
0x75170000 - 0x751BF000 C:\WINNT\system32\netapi32.dll
0x7C340000 - 0x7C34F000 C:\WINNT\system32\Secur32.dll
0x77BF0000 - 0x77C01000 C:\WINNT\system32\NTDSAPI.dll
0x77980000 - 0x779A4000 C:\WINNT\system32\DNSAPI.DLL
0x77950000 - 0x7797A000 C:\WINNT\system32\WLDAP32.DLL
0x751C0000 - 0x751C6000 C:\WINNT\system32\NETRAP.dll
0x75150000 - 0x7515F000 C:\WINNT\system32\SAMLIB.dll
0x782C0000 - 0x782CC000 C:\WINNT\System32\rnr20.dll
0x77340000 - 0x77353000 C:\WINNT\system32\iphlpapi.dll
0x77520000 - 0x77525000 C:\WINNT\system32\ICMP.DLL
0x77320000 - 0x77337000 C:\WINNT\system32\MPRAPI.DLL
0x773B0000 - 0x773DF000 C:\WINNT\system32\ACTIVEDS.DLL
0x77380000 - 0x773A3000 C:\WINNT\system32\ADSLDPC.DLL
0x77880000 - 0x7790E000 C:\WINNT\system32\SETUPAPI.DLL
0x77360000 - 0x77379000 C:\WINNT\system32\DHCPCSVC.DLL
0x777E0000 - 0x777E8000 C:\WINNT\System32\winrnr.dll
0x777F0000 - 0x777F5000 C:\WINNT\system32\rasadhlp.dll
0x63580000 - 0x63833000 C:\WINNT\system32\mshtml.dll
0x75E60000 - 0x75E7A000 C:\WINNT\system32\IMM32.DLL
0x75AC0000 - 0x75AE8000 C:\WINNT\system32\MSLS31.DLL
0x35C50000 - 0x35C83000 C:\WINNT\system32\dxtrans.dll
0x773E0000 - 0x773F5000 C:\WINNT\system32\ATL.DLL
0x70F30000 - 0x70F9E000 C:\WINNT\system32\mshtmled.dll
0x039D0000 - 0x03A1E000 C:\WINNT\system32\inetcpl.cpl
0x719D0000 - 0x719ED000 C:\WINNT\system32\inetcplc.dll
0x6B700000 - 0x6B790000 C:\WINNT\system32\jscript.dll
0x6D440000 - 0x6D450000 C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
0x6D310000 - 0x6D327000 C:\Program Files\Java\j2re1.4.2_04\bin\jpiexp32.dll
0x6D380000 - 0x6D398000 C:\Program Files\Java\j2re1.4.2_04\bin\jpishare.dll
0x08000000 - 0x08138000 C:\PROGRA~1\Java\J2RE14~1.2_0\bin\client\jvm.dll
0x77570000 - 0x775A0000 C:\WINNT\system32\WINMM.dll
0x03D30000 - 0x03D37000 C:\PROGRA~1\Java\J2RE14~1.2_0\bin\hpi.dll
0x03D50000 - 0x03D5E000 C:\PROGRA~1\Java\J2RE14~1.2_0\bin\verify.dll
0x03D60000 - 0x03D79000 C:\PROGRA~1\Java\J2RE14~1.2_0\bin\java.dll
0x03D80000 - 0x03D8D000 C:\PROGRA~1\Java\J2RE14~1.2_0\bin\zip.dll
0x06410000 - 0x0651F000 C:\Program Files\Java\j2re1.4.2_04\bin\awt.dll
0x77800000 - 0x7781E000 C:\WINNT\system32\WINSPOOL.DRV
0x76620000 - 0x76630000 C:\WINNT\system32\MPR.DLL
0x06520000 - 0x06570000 C:\Program Files\Java\j2re1.4.2_04\bin\fontmanager.dll
0x51000000 - 0x51049000 C:\WINNT\system32\ddraw.dll
0x728A0000 - 0x728A6000 C:\WINNT\system32\DCIMAN32.dll
0x5C000000 - 0x5C0C8000 C:\WINNT\system32\D3DIM700.DLL
0x6D2F0000 - 0x6D304000 C:\Program Files\Java\j2re1.4.2_04\bin\jpicom32.dll
0x77920000 - 0x77943000 C:\WINNT\system32\imagehlp.dll
0x72A00000 - 0x72A2D000 C:\WINNT\system32\DBGHELP.dll
0x690A0000 - 0x690AB000 C:\WINNT\system32\PSAPI.DLL
Heap at VM Abort:
Heap
def new generation total 576K, used 31K [0x10010000, 0x100b0000, 0x10770000)
eden space 512K, 6% used [0x10010000, 0x10017c80, 0x10090000)
from space 64K, 0% used [0x100a0000, 0x100a0000, 0x100b0000)
to space 64K, 0% used [0x10090000, 0x10090000, 0x100a0000)
tenured generation total 1408K, used 387K [0x10770000, 0x108d0000, 0x16010000)
the space 1408K, 27% used [0x10770000, 0x107d0c40, 0x107d0e00, 0x108d0000)
compacting perm gen total 4096K, used 3476K [0x16010000, 0x16410000, 0x1a010000)
the space 4096K, 84% used [0x16010000, 0x163753d8, 0x16375400, 0x16410000)
Local Time = Sat Apr 09 06:30:09 2005
Elapsed Time = 10
#
# The exception above was detected in native code outside the VM
#
# Java VM: Java HotSpot(tm) Client VM (1.4.2_04-b05 mixed mode)
#
What is this? Just outta curiousity. In addition F-prot stoppped some "unknown virus" yesterday while i was on the net, and it said "cache something may be infected with an unknown virus". It could not delete the file or disinfect it, therefore i deleted it manually. I have submitted a HJT log below, just incase you need it or see anything STRANGE in there...
Ps. Everytime i run f-prot or ad-aware, it comes back empty. (which is good) But the computer is slower then it was before...any reason for this?
Thnx!
Logfile of HijackThis v1.99.1
Scan saved at 5:20:06 PM, on 10/04/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\FSI\F-Prot\F-StopW.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\AdsGone\adsgone.exe
C:\WINNT\system32\net.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijackthis-2\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.firefox.com/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvMixerTray] C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: AdsGone.lnk = C:\Program Files\AdsGone\adsgone.exe
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...nt.cab28578.cabO16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) -
http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cabO16 - DPF: {FDC7A535-4070-4B92-A0EA-D9994BCC0DC5} (IERPCtl Class) -
http://activex.microsoft.com/objects/ocget.dllO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe