Explorer.exe crashes when opening My COmputer and other FOlders

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Corbijn, Oct 27, 2004.

  1. Corbijn

    Corbijn Private E-2

    OK,

    I have read though and followed the directions in the tutorial yet my problem still persists.

    My op system is WINXP Pro SP1

    When I start the PC and open My COmputer, or a folder, or explorer (not IE) a message comes up saying Explorer has crashed. After a couple of times it restarts, I can then access these folders.

    After going through all the Scans and buster type things the problem, persists.

    If anyone can offer some help I would greatly appreciate it.

    Cheers

    Glyn
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or from a sub-folder of C:\Documents and Settings, or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HijackThis version 1.98.2
     
  3. Corbijn

    Corbijn Private E-2

    Attached is my HiJack this txt file. Thanks for your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions on where to place HijackThis. You currently still have it on your Desktop.
    C:\Documents and Settings\Glyn\Desktop\HijackThis.exe

    I working thru your log. I'll come back with info on what I find.
     
  5. Corbijn

    Corbijn Private E-2

    Thanks for that.

    Please don't waste anymore of your time. A friend had a look at it and it seems to be working now!

    I appreciate your time and I am sorry if I wasted it!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have some trojans in your system. I not sure if you have them fixed.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    C:\Documents and Settings\Glyn\Application Data\atao.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: BHO Class - {CBEFB350-ED5B-4115-B846-C1041676B377} - C:\WINDOWS\System32\CustomIE32.dll
    O4 - HKCU\..\Run: [Card] C:\Documents and Settings\Glyn\Application Data\mpot.exe
    O4 - HKCU\..\Run: [Esse] C:\Documents and Settings\Glyn\Application Data\atao.exe
    O16 - DPF: {07E9CDF4-20D2-46B1-B681-663968F527CE} - http://www.begin2search.com/toolbar/bar/winb2s32.cab

    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Glyn\Application Data\mpot.exe
    C:\Documents and Settings\Glyn\Application Data\atao.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.


    Are the proxy settings below something you require for you ISP? Is 10.1.1.1 your DNS server address?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy2.tpg.com.au:80
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.1;<local>
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C8179DC9-7F74-4403-AC31-0FFD9DFD523A}: NameServer = 10.1.1.1
     
  7. Corbijn

    Corbijn Private E-2

    Chaslang,

    Thanks for that, the problem is no longer occuring and the log is attached!

    I have a problem now that when I right click a folder, and select properties no properties option box comes up, however for a file or drive it works fine?

    COuld this be spyware, should I start a new thread?

    Cheers

    Glyn
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this log for the same PC? The log is okay. But I see changes since the last log.

    Where did this come from all of a sudden:
    :\Program Files\tcpIQ\Line Speed Meter\LineSpeedMeter.exe
    O4 - HKLM\..\Run: [Line Speed Meter V3.0] C:\Program Files\tcpIQ\Line Speed Meter\LineSpeedMeter.exe -minimized

    And why did the below line change:
    From: O17 - HKLM\System\CCS\Services\Tcpip\..\{C8179DC9-7F74-4403-AC31-0FFD9DFD523A}: NameServer = 10.1.1.1

    To: O17 - HKLM\System\CCS\Services\Tcpip\..\{C8179DC9-7F74-4403-AC31-0FFD9DFD523A}: NameServer = 203.12.160.35,203.12.160.36


    I'm not sure why you cannot see properties on a folder. It does not sound like spyware.
     
  9. Corbijn

    Corbijn Private E-2

    Line sped meter I installed, it monitors my BB speed

    I changed the DNS settings after some research. 10.1.1.1 seemed to work but I put them back to the ISP settings.

    I'll further for the proeprties problem cheers!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me know if anything else comes up.
     
  11. Corbijn

    Corbijn Private E-2

    Thank you so much for your help and patience.

    I will supply feddback if I get anywhere with the Right CLick problem!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    And please do send that feedback if you find a solution. Try the Software Forum.
     
  13. Corbijn

    Corbijn Private E-2

    Solution to right click problem

    Well, it seems that Norton Internet Security was causing the problem with the properties option.

    I read that some other Firewalls were causing similar problems, mainly Zone ALarm. First I just tried disabling the firewall, didn't help, then I tried removing it all together and voila! I have now reinstalled and all is fine!

    Thanks again for all your help!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Solution to right click problem

    Thanks for coming back and telling us what you found. Glad to see it all worked out.
     
  15. Corbijn

    Corbijn Private E-2

    OK,

    The problem returned, but this time I knew it was associated with Norton, so after a bit of googling I found a page that outlined the problem being with the 'World Wide Web Publishing Service' not starting properly. It has a work through that has now fixed my problem!

    Here is the link. The fix is almost at the bottom of the page.

    http://forums.majorgeeks.com/newreply.php?do=newreply&noquote=1&p=467997
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not insert the correct link. What you inserted was to start a new reply for the current thread here on MG's.
     
  17. Corbijn

    Corbijn Private E-2

    Sorry about that :)

    Here we go then!

    http://www.winportal.com/chat_sin.asp?ObjectID=5333

    Here is the actual help.

    1. Click 'Start' button from Task Bar and select 'Programs,' 'Administrative Tools,' 'Services.' 2. Select 'World Wide Web Publishing Service' from services list. From that you can notice that 'Status' of 'World Wide Web Publishing Service' is showing something like 'Starting'. It means the whole day it won't come up. 3. Double Click on that, you will see Properties Box of select service. 4. Click 'Startup Type' Combo box and select the type as 'Manual' and click 'OK' button. 5. And Re-start your machine. Then next time when you select 'World Wide Web Publishing Service' you can notice that nothing is showing as 'Status' of that 'World Wide Web Publishing Service'. Now if you want you can startup the service manually and once the service is trying to access LAN/WAN ZoneAlarm ask you to permit it. So if you permitted it'll work the way 'World Wide Web Publishing Service' earlier worked. This actually a work-around for this problem.

    Cheers
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the update! This may prove useful for other people.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds