I am having major issues with my computer. I keep getting a message,,,
EXPLORER caused an invalid page fault in
module CAGWIZ.DLL at 017f:10016e94.
Registers:
EAX=00000000 CS=017f EIP=10016e94 EFLGS=00010246
EBX=0000000c SS=0187 ESP=01a1da60 EBP=01a1da6c
ECX=00000008 DS=0187 ESI=011c7ffc FS=3777
EDX=7efefeff ES=0187 EDI=011c8000 GS=0000
Bytes at CS:EIP:
f2 ae f7 d9 03 cb 8b fe 8b 75 0c f3 a6 8a 46 ff
Stack dump:
0000018c 10035d38 01a1eca0 01a1e860 1000c61b 011c7ffc 10035d38 0000000c 10035d38 00000000 000000ff 01a1eca0 02020101 536e6957 206b636f 00302e32
I have run adaware,spysweeper,registry mechanic, cwshredder....
When I run adaware, I know that VX2.betterinternet is there, I delete it, but the cagwiz.dll can't be removed because it says it is in use. I tried to remove it in safe mode, no luck, I tried renaming it, no luck. I am sending you the log from Hijack this:
Logfile of HijackThis v1.97.7
Scan saved at 11:54:04 AM, on 6/19/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\HPZTSB06.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.ca
O1 - Hosts: auto.search.msn.com
O1 - Hosts:
O1 - Hosts: ieautosearch
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Canada Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_18_0.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb06.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {C7932801-AF0C-11D6-8137-0050DA5F0293} (RdxIE Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} -
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Canada Companion) -
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {023A3744-EA13-4C8A-8B23-ABF98974A9F5} (JoyOnPack Control) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} -

If anyone can help me, I would be forever grateful. Thanks!!

Dani AI

Generated

Explorer crashing with an invalid page fault inside a third‑party DLL usually means code from an add‑on is running inside the Explorer process (shell extension, toolbar/BHO, appinit/image hijack, etc.). Those in‑process components can bring Explorer down when they misbehave or are damaged, so deleting the DLL without first identifying what loaded it risks leaving the system unstable or missing the real entry points to remove. (winhelponline.com)

A focused diagnostic workflow is recommended: capture which process actually has the module loaded (and the DLL full path, company/version and digital signature), then catalog any autorun/hook registrations that reference it. Process viewers that show handles and loaded DLLs make this straightforward; autorun/auto‑start scanners can expose BHOs, shell extensions and AppInit/ImageHijack entries for removal or disablement. Record the DLL hash for later lookup (VirusTotal or other repositories) before removing anything. (docs.microsoft.com)

If the DLL is a shell extension, disable shell extensions in groups and restart the shell (bisect) until the offending item is found; ShellExView is built for that exact isolation task. If the module is a registered COM/OCX DLL, unregister it first (regsvr32 /u) so Explorer won’t try to load it after deletion. For files locked by the running shell, either stop the hosting process (then delete) or remove the file from an offline environment (boot/rescue media) to avoid in‑use errors. Always back up the registry and system files before editing or deleting. (nirsoft.net)

The community advice in this thread is on the right track: as recommended, cleaning hijacked hosts/startup entries and keeping HijackThis backups is a sensible early move, and ’s suggestion to run a targeted detector can help find family‑specific components. Combine those steps with the diagnostic/removal sequence above; if the DLL cannot be safely isolated and removed, an image backup and clean OS reinstall should be considered as the reliable recovery option.

Recommended Answers

All 5 Replies

To delete CAGWIZ.DLL ,You could us a win98 boot disk and at the dos prompt type '
DEL c:\windows\CAGWIZ.DLL or whatever the full path to the dll file is .like it could be something like c:\wimdows\system\ or system32\CAGWIZ.DLL

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.

O1 - Hosts: auto.search.msn.com
O1 - Hosts:
O1 - Hosts: ieautosearch


Unless you want a fist full of Spyware don't use this program .fix this .
O16 - DPF: {C7932801-AF0C-11D6-8137-0050DA5F0293} (RdxIE Class) -

Reboot and post a fresh log .

also might be a good idea to get SPY-BOT in my signature also che the how to use it .

On top of what caperjack has instructed, please Can you download the following app & run it, making sure to have one internet exploder window open. Save the log & paste the results back here.

This is just a test i will be editing my message after i fininsh the test .thanks

edited .

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.