Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 06-08-2005, 02:54 PM   #1 (permalink)
Apprentice
 
Join Date: Jan 2005
Location: mumbai
Posts: 74
Default problem in IE - igbppg32.exe


hey i use microsoft ie 6...

and the proble in tht... when ever i open my browser the cpu usage goes upto 100% and also i get error like virtual memory low...

i face this problem even for a very simple website with no graphics. say for tht matter google....

is there a bug or something and how do i remove it...

and yes gettin feed up with this , when i restart my system i get a message ending program "igbppg32.exe"

plz help
help_me is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 06-08-2005, 05:45 PM   #2 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default

well what OS u r useing?? if winXP then increase ur page file... right click on My Computer >>>> Properties >>>> Advence >>>>> Performance Option >>>> Change the virtual mem option.... change it to higher amount.... 768 MB is recomended.....



Scan ur system with a very good antivirus...
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 06-08-2005, 06:03 PM   #3 (permalink)
Apprentice
 
Join Date: Jan 2005
Location: mumbai
Posts: 74
Default

well m using windows 2000 pro.
help_me is offline  
Old 07-08-2005, 12:15 AM   #4 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default

well follow this guide to change ur page file...
  1. Log in as a system administrator.
  2. Open the system Control Panel, and double-click "Systemp"
  3. Now Select the "Advanced tab"
  4. Now Select the "Performance Options"
  5. Select "Change..."
  6. Select a drive, and change the size of the paging file.
  7. Press OK, and reboot ur system when asked.

by the way did u checked ur system with a good AVS like NAV05 or KAV 5.0??
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 07-08-2005, 12:22 AM   #5 (permalink)
Wise Old Owl
 
alib_i's Avatar
 
Join Date: Jun 2004
Location: omnipresent
Posts: 1,191
Default

can you post your HijackThis log. that'll tell the full story.

-----
alibi
__________________
What I've felt, What I've known; Never shined through in what I've shown
Never free, Never me; So I dub thee unforgiven
-Metallica
alib_i is offline  
Old 12-08-2005, 02:50 PM   #6 (permalink)
Apprentice
 
Join Date: Jan 2005
Location: mumbai
Posts: 74
Default

Quote:
Originally Posted by alib_i
can you post your HijackThis log. that'll tell the full story.

-----
alibi
hey as u saud heres my hijackthis log..
---------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 2:58:46 PM, on 8/12/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\YAHOO!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\pratik\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.zdnetindia.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 192.168.100.2:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.zdnetindia.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O21 - SSODL: Web Event Logger - {7CFBACFF-EE01-1231-ABDD-416592E5D639} - C:\WINNT\system32\Ofncei32.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: ServiceM - Unknown owner - C:\WINNT\System32\ServiceM.exe

------------------------------

hopin tht u find somethin..
help_me is offline  
Old 12-08-2005, 03:20 PM   #7 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

log file looks clean. dont know what Ofncei32.dll is though.
as suggested above, also do a good anti-virus and a anti-spy scan; preferably at boot-time or safe mode.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 12-08-2005, 04:27 PM   #8 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

pen NotePad, and copy the contents of the below "Code" box:-
Code:
cd %windir%
cd System32
attrib -s -r -h Ofncei32.dll
del Ofncei32.dll
sc stop ServiceM
sc config ServiceM start= disabled
sc delete ServiceM
attrib -s -r -h ServiceM.exe
del ServiceM.exe
Go to File Menu > Save As, and save the file with the name Test.bat and exit from NotePad.


Boot in SAFE mode.


Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-

O21 - SSODL: Web Event Logger - {7CFBACFF-EE01-1231-ABDD-416592E5D639} - C:\WINNT\system32\Ofncei32.dll
O23 - Service: ServiceM - Unknown owner - C:\WINNT\System32\ServiceM.exe


Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.


Double-Click on the file Test.bat, a small DOS type window should open and close immediately.


Reboot to normal mode, run HijackThis and post a fresh log again. Also, post back whether you are experiencing any problems with your PC.
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 22-08-2005, 04:16 PM   #9 (permalink)
Apprentice
 
Join Date: Jan 2005
Location: mumbai
Posts: 74
Default

hey i tried doing this and it worked.. i just deleted tht file from my system throught a search in safe miode... gr8 na!!
help_me is offline  
Old 22-08-2005, 04:23 PM   #10 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

Quote:
Originally Posted by help_me
hey i tried doing this and it worked.. i just deleted tht file from my system throught a search in safe miode... gr8 na!!
You did what?
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 22-08-2005, 05:30 PM   #11 (permalink)
Apprentice
 
Join Date: Jan 2005
Location: mumbai
Posts: 74
Default

i booted in safe mode gave a search for the file named "igbppg32.exe" and then when i found it .. i deleted it... ththz it
help_me is offline  
Old 22-08-2005, 09:24 PM   #12 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

But there are some other (atleast 2, as i can see from the HJT log) malware files to be deleted. Its better that you run that batch file as mentioned in my previous post.
__________________
http://swatrant.blogspot.com/
swatkat is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Sujeet
- by abhidev
- by Sarath
- by Krow

Advertisement




All times are GMT +5.5. The time now is 08:28 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2