1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Have to restart explorer.exe to go into My Computer (HJT log)

Discussion in 'Malware and Virus Removal Archive' started by MadCow, 2005/01/30.

Thread Status:
Not open for further replies.
  1. 2005/01/30
    MadCow

    MadCow Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    24
    Likes Received:
    0
    Have to restart explorer.exe to go into My Computer

    Hello,

    I've been spending the last few hours getting rid of spyware that hit my computer. The point I am at now has nothing being detected by Adaware, Spybot or AVG Antivirus, however I am not able to open My Computer.

    Everytime I try, I get an error asking me to Debug. The only way that I have found around this is to end the explorer.exe process, and run it again from the Windows directory. After I do that, it works fine.

    I have to do this everytime my computer is restarted now, which is a pain. I have searched on this site and haven't found anything related to my problem. Would any of you know how to fix this?

    Thanks.
     
  2. 2005/01/30
    BearNunya

    BearNunya Inactive

    Joined:
    2004/10/20
    Messages:
    39
    Likes Received:
    0
    Windows Version????????????
     

  3. to hide this advert.

  4. 2005/01/31
    MadCow

    MadCow Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    24
    Likes Received:
    0
    Windows XP Professional w/ SP2
     
  5. 2005/02/02
    MadCow

    MadCow Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    24
    Likes Received:
    0
    Has no one come across this problem before?
     
  6. 2005/02/02
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    It would seem not, but be patient.

    In the meantime it would not harm to run System File Checker ,,,,

    Start > Run > sfc /scannow - note the space and have your XP CD handy.

    SFC will run and exit without any closing dialogue. To see which files, if any, have been replaced look in Event Viewer.
     
  7. 2005/02/02
    Zander

    Zander Geek Member Alumni

    Joined:
    2002/01/07
    Messages:
    4,084
    Likes Received:
    5
    I don't know what the answer to your problem is but until somebody comes up with an answer I might have a quicker way for you to restart explorer. In Task Manager click file>new task and type explorer. Or, as an alternative to that, start>run>explorer will do it too if the start menu is available.
     
  8. 2005/02/02
    surferdude2

    surferdude2 Inactive

    Joined:
    2004/07/04
    Messages:
    4,009
    Likes Received:
    23
    Maybe some gremlin has hijacked your default shell program.

    Run HiJackThis and see what gives.
     
  9. 2005/02/08
    MadCow

    MadCow Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    24
    Likes Received:
    0
    I still haven't been able to come across any fix to the problem. I did, however, notice that when I go to some sites I'm automatically redirected to some "www.web-res.biz" site. This only happens to my computer, because it doesn't happen on my laptop.

    One example is when I try to search for items on eBay. It'll redirect to that site when I click the Search button... Adaware, Spytbot and my AVG Antivirus still does not find anything on my computer with the current updates to those programs.

    I've scanned my computer with HiJackThis, but I can't really determine what shouldn't be there. Here's the log:

    Logfile of HijackThis v1.99.0
    Scan saved at 1:15:47 PM, on 2/8/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    C:\Program Files\Sony Handheld\HOTSYNC.EXE
    C:\WINDOWS\system32\devldr32.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    D:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\Ian\LOCALS~1\Temp\Rar$EX00.772\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: BHO Class - {F6053709-5723-454E-AB9D-7FC7E681AFA5} - C:\WINDOWS\system32\WinTitle.dll
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe "
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
    O23 - Service: Adobe LM Service - Unknown - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    Hopefully someone can help me out with this.

    Thanks.
     
  10. 2005/02/08
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    use hjt to remove:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    O2 - BHO: BHO Class - {F6053709-5723-454E-AB9D-7FC7E681AFA5} - C:\WINDOWS\system32\WinTitle.dll
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
     
  11. 2005/02/09
    MadCow

    MadCow Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    24
    Likes Received:
    0
    Thanks, TonyT. Removing the line
    did the trick for both problems.

    Thank you to all who responded!
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.