HiJack log - Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by VickieQ1, Jun 30, 2005.

  1. VickieQ1

    VickieQ1 Private E-2

    Hi. Here is a HiJack log from my Brother's computer. I think he may have a virus of some sort, but I'm just not :confused: computer literate enough to tell you anything for sure. If someone could tell me what I can remove or what I need to do so I don't seriously screw up his computer, that would be great. He's running WinXP. I've already run AdAware & SpyBot and deleted everything those found. Originally noticed a problem when ALL of his desktop icons & startbar disappeared! I can get to most things through the task manager, but I'm just pretty clueless about anything else. Any help would be greatly appreciated!!
    Thank you.

    [EDIT] Inline, unrequested log removed. [/EDIT]
     
    Last edited by a moderator: Jun 30, 2005
  2. AbbySue

    AbbySue MajorGeeks Administrator

    We require our full clean procedure be run (ALL steps) in the order written before we will look at HijackThis logs. Please follow the steps below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above if you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. VickieQ1

    VickieQ1 Private E-2

    Did Guidelines....Still Broken - HiJack Log attached - hopefully

    Okay, I did all of the things that were on the "Do Not Post Until" link that this wonderous computer would let me do. All of the scanning downloads worked and were run. The "trend micro's free online virus scan" would access my computer, let me mark Drive C, but pressing the "scan" button did nothing. Also "Symantec Security Check" would let me on the site, but the "Go" button wouldn't "go" anywhere. Stinger worked. Tried the "optional" scans. Online scans didn't work except "TrojanScan" which told me I had to use A2 to clean it, but A2 required that I set up an account which I tried to do, but I need to access my email to get the code, which I can't do because Outlook refuses to open.....I'm pretty sure I'm nearly insane now. AdAware found 1 & Spybot found 2...other than that, the TrojanScan seemed to find a lot, but I couldn't do anything with them.

    After all that, I still have no icons, no start bar, and have to copy the link under properties and paste it into my address bar to get the i-net to go to the next page.

    So, here's that HiJack log, hopefully I can attach it. OKAY...can't seem to attach it either (it's one of those days!) I get "attach files" down below the post, but no way to click it...sorry

    Any advice would be greatly appreciated!!!

    Thank you
     

    Attached Files:

    Last edited by a moderator: Jun 30, 2005
  4. jak3y

    jak3y Guest

    Vickie, 2 things
    1) you running hijackthis from your C:\program files\hijacthis (folder)?
    2) attach the log versus pasting it in the thread.
    underneath the Submit Reply button there's another window titled "Additional Options", you'll see a button called "manage attachments", click that, find your hijack this log and upload it, then you'll come back to this page and THEN hit Submit Reply :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There's nothing wrong with running it from there. In fact this is where we prefer it to be.

    One of your problems (you have a few) is that your explorer.exe shell is not loading at startup. That is why you have no desktop. There are 2 registry keys that sometimes cause this problem. We are going to look for and delete these keys (if found).

    Press CTRL-ALT-DEL to bring up Task Manager. And click File, New Task (Run..) and enter regedit and click OK. This will run the registry editor. Now look for the below registry keys (navigate thru the registry). Make sure you only look for and delete the exact keys listed below.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplorer.exe

    After deleting this keys the desktop and explorer.exe should reappear. You may need to reboot after doing this. Let me know the results. After getting this problem fixed will will look at your remaining problems so post a new HJT log at this point.
     
  6. VickieQ1

    VickieQ1 Private E-2

    Re: HiJack log - Please Help Again

    Didn't find either of those keys. I'm attaching a HiJack log .Well...not I'm not, I can copy & paste, but I seriously do not have anything that says "manage attachments". I have "Additional Options", with a sub saying "attachements", but I can't click it...it list the valid types, but that's it. Sorry,

    Thanks

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Jul 2, 2005
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HiJack log - Please Help Again

    Well you still have something preventing explorer.exe from loading.

    First look in Control Panel, Add/Remove programs for AntivirusGold and uninstall if found.

    Did you have the below items running when you ran HijackThis?
    C:\WINDOWS\System32\taskmgr.exe
    C:\WINDOWS\regedit.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    I can understand having Task Manager running because of your problem getting explorer.exe to run. But why do you have regedit and iexplore running?

    Have you tried just running explorer.exe from Task Manager.


    Download Pocket Killbox and save it to its own folder where you can find it. Do not run it yet. Will will use it later in my next message.
     
    Last edited: Jul 2, 2005
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HiJack log - Please Help Again

    Print the below steps or save them locally. Stay disconnected from the internet while doing them.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    If taskmgr.exe, regedit.exe, and iexplore.exe were not being run by you, use the below step to kill those processese. If you were running them, you must end them before continuing to use HijackThis below.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\taskmgr.exe
    C:\WINDOWS\regedit.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\uvzuuu.exe reg_run
    O4 - HKLM\..\Run: [AntivirusGold] C:\Program Files\AntivirusGold\AntivirusGold.exe /h
    O4 - HKCU\..\Run: [lmrt] C:\WINDOWS\System32\lmrt.exe
    O4 - Global Startup: rnar.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\AntivirusGold <--- the whole folder
    C:\WINDOWS\System32\lmrt.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Killbox by double clicking on the killbox.exe file.

    Check the following boxes:

    Standard File Kill
    End Explorer Shell While Killing file

    Copy & paste (you must use copy & paste - typing will give an error) the full path of each of the files below (one at a time - see directions after the list) into the Full Path of File to Delete box (note some of these may not exist on your PC)
    C:\WINDOWS\icont.exe
    C:\WINDOWS\toolbar.exe
    C:\WINDOWS\system32\andpd.dll
    C:\WINDOWS\system32\nrimin.exe
    C:\WINDOWS\system32\vqwbw.dat
    C:\WINDOWS\system32\winup2date.dll
    C:\WINDOWS\system32\wmconfig.cpl
    C:\WINDOWS\System32\uvzuuu.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rnar.exe

    With the full path to the file name in the Full Path of File to Delete textbox. The filename will appear under the box in a blue color to indicate it was found. Now Click the Red X and for the confirmation message that will appear, you will need to click Yes. If the file is successfully delete you will get a message of confirmation. Just click OK!
    Do this for each of the files listed. Some will not be deleted. Make sure you keep a list of them.

    Now for any files not deleted properly above (the ones you wrote down), do the below (if all of them deleted, skip these steps):
    - in Killbox select the option to Delete on Reboot
    - uncheck the option to End Explorer Shell While Killing file

    Copy & paste the full path of each of the files you could not delete above into the box and then click the Red X and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? You will need to click No (since you are not finished adding all related files in yet).

    When you do enter the last file name that needs to be deleted, click Yes on the last file.
    Note: Killbox will let you know if the file does not exist.

    Okay so now your PC should be reboot. If you get an error message about Pending Operations, just reboot your PC yourself.

    After reboot continue doing the below before you do anything else.
    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot one more time in normal mode and get a new HJT log.
    Now reconnect to the internet and come back and post your new log. And tell us how things are working.

    Do not reboot or power down at this point because if you are still infected it can mutate making any steps I would post a waste of time.
     
  9. VickieQ1

    VickieQ1 Private E-2

    Re: HiJack log - Please Help 1 more time :)

    Sorry, still isn't giving me a desktop (no icons, no startbar). The only file I could find when I did Killbox was "C:\Windows\Sytem32\uvzuuu.exe" and it did delete it. Also, when it rebooted from safe mode after I ran Killbox, I got the following error:
    Windows could not start because the following file is missing or corrupt
    <Windows Root>\system32\hal.dll
    Please reinstall a copy of the above file
    I hit "enter" and it let me go on to the welcome screen. Didn't know if that was important, but I thought I should let you know. I also tried running explorer.exe from Task Manager - the back ground flashes, but the icons or start bar never come up.

    I know this must be a huge pain for you and I really appreciate the help. Sorry, I'm sure you've realized by now that I'm not the most computer literate person on the Earth, but the scary thing is....I'm the most computer literate one in my family, so I'm at least trying to help my brother get this thing going again :)

    Again, I REALLY appreciate you taking the time to look at all of this for me.

    I'm posting the latest HJT log...hope it's revealing??? I know it's a pain for me to copy & paste it, but unless I am unbelievably blind (which would not surprise me!), I still don't have an option to attach it.

    Thank you
     

    Attached Files:

    Last edited by a moderator: Jul 2, 2005
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Jul 2, 2005
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HiJack log - Please Help Again

    After doing what is in my previous message, follow the steps below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder - C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.


    You did not answer whether you can run explorer.exe from Task Manager.

    Just in case you don't know how.

    If you press CTRL-SHIFT-ESC to bring up Task Manager and then click File and select New Task (Run ...) and enter c:\windows\explorer.exe , what happens? Does your Desktop come back?


    You may want to check the below registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell

    and see if the values for Shell is explorer.exe

    To do that , use Task Manager again (like you did above) and enter regedit and click OK!

    Then navigate your way to and select Winlogon


    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

    then find the Shell in the right window pane and see what the Data entry is.


     
    Last edited: Jul 2, 2005
  12. VickieQ1

    VickieQ1 Private E-2

    Re: HiJack log - Please Help--Logs x3

    Me again.... If I run explorere.exe, the background sort of flashes, but the icons/start bar don't come up. I checked the registry key & it is set to explorer.exe. Here is the HiJack This log (sorry) and the Qoologic log and the RKTOOL log.

    Again, I really do appreciate your help. Thank you

    I've seperated the logs with ******. Sorry, I still can't attach. Also noticed that under my I-Net Options, there is nothing under the "advanced" tab anymore....I mean NOTHING, it's completely blank with the exception of a scroll bar & a reset button?? Didn't know if that was relevent.

    *******************************

    Edit by chaslang: Inline HJT, Qoologic, & RKfiles logs attached
     

    Attached Files:

    Last edited by a moderator: Jul 6, 2005
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HiJack log - Please Help--Logs x3

    You must remember to exit browsers ( C:\Program Files\Internet Explorer\iexplore.exe ) before running HijackThis.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\hookdump.exe <--- if found! You may not find this running! Just continue to next steps.

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\hookdump.exe

    After clicking Fix, exit HJT.

    Run Killbox by double clicking on the killbox.exe file.

    Check the following boxes:

    Standard File Kill
    End Explorer Shell While Killing file

    Copy & paste (you must use copy & paste - typing will give an error) the full path of each of the files below (one at a time - see directions after the list) into the Full Path of File to Delete box (note some of these may not exist on your PC)
    C:\WINDOWS\System32\OPMOO.DLL
    C:\WINDOWS\System32\OZXOOON.DLL
    C:\WINDOWS\System32\SUPDATE.DLL
    C:\WINDOWS\System32\DBADDDX.EXE
    C:\WINDOWS\System32\REDIT.CPL
    C:\WINDOWS\System32\WI0499.EXE
    C:\WINDOWS\System32\1803.DLL
    C:\WINDOWS\System32\DELFIN.DLL
    C:\WINDOWS\SYSTEM32\goldnew2b.dll
    C:\WINDOWS\BUDDY.EXE
    C:\WINDOWS\62lyuzb1jr.exe
    C:\WINDOWS\del.tmp
    C:\WINDOWS\System32\hookdump.exe

    With the full path to the file name in the Full Path of File to Delete textbox. The filename will appear under the box in a blue color to indicate it was found. Now Click the Red X and for the confirmation message that will appear, you will need to click Yes. If the file is successfully delete you will get a message of confirmation. Just click OK!
    Do this for each of the files listed. Some will not be deleted. Make sure you keep a list of them.

    Now for any files not deleted properly above (the ones you wrote down), do the below (if all of them deleted, skip these steps):
    - in Killbox select the option to Delete on Reboot
    - uncheck the option to End Explorer Shell While Killing file

    Copy & paste the full path of each of the files you could not delete above into the box and then click the Red X and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? You will need to click No (since you are not finished adding all related files in yet).

    When you do enter the last file name that needs to be deleted, click Yes on the last file.
    Note: Killbox will let you know if the file does not exist.

    Okay so now your PC should be reboot. If you get an error message about Pending Operations, just reboot your PC yourself.

    After reboot continue with the below.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixgold.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixgold.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.
    Now reconnect to the internet and come back and post a new HJT log. And tell us how things are working.

    Do not reboot or power down at this point because if you are still infected it can mutate making any steps I would post a waste of time.
     
  14. VickieQ1

    VickieQ1 Private E-2

    Re: HiJack log - Please Help - Fixgold

    Everything went well until I tried to double click fixgold.reg that I had saved to my desktop. I got the following error message:

    "This file does not have a program associated with it for performing this action. Create an association in the Folder Options control panel."

    Sorry.

    I didn't know if you wanted a new HJT log until I was able to do the fixgold.

    Thanks
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HiJack log - Please Help - Fixgold

    Are you sure you saved it to a filename that ends with .reg

    Try this:

    Click Start, Run, and enter regedit then click OK. This will open the registry editor.
    Now in regedit, click File, Import . Now navigate to the fixgold.reg file you saved to your desktop and select it. Tell me if that works.
     
  16. VickieQ1

    VickieQ1 Private E-2

    Re: HiJack log - Please Help - Fixgold

    Okay. It let me do that. Said it added key. Here's the new HJT log:

    Thank You

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Jul 8, 2005
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HiJack log - Please Help - Fixgold

    Okay you're log is clean. Are you still have problems that you cannot attach files? Have you looked for the Go Advanced button and clicked it and then scrolled down to Manage Attachments?

    How are things working now?
     
  18. VickieQ1

    VickieQ1 Private E-2

    Well....I have no popups, but I still have no icons or start bar on the desktop, I'm accessing everything thru the Task Manager. And I seriously do not see anything that says manage attachments. Under additional options, it has an "attachments" area, but it just lists the types of files that can be attached. Also, if I go under tools, I-net options, advanced, there's nothing there. In the box that should list the "settings", it's empty???? I'm sorry to be such a pain to you, but I just don't have a clue what to do about the desktop. Strange things when I'm on the net....if there's a link to another site, I have to right click it, go properties, copy the destination and paste it in the address bar to make it go there. Don't know if these are related or what.

    Any ideas???

    Thanks again
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean additional options? Do you mean you clicked the Go Advanced button?

    Do you see the below?
    Code:
     
    Attach Files
    Valid file extensions: bmp doc gif jpe jpeg jpg log pdf png psd txt zip
    

    But right below the Valid file extensions text you do not see a Manage Attachments button? Move your mouse there and click anyway. Any luck?

    Are you logged in with Administrator priviledges?
    Can you see IE, Tools, Internet Options, Advance tab stuff if you boot in safe mode and log into the Administrator account.
     
    Last edited: Jul 9, 2005
  20. VickieQ1

    VickieQ1 Private E-2

    Re: HiJack log - Please Help - again

    Sorry, I don't even have the i-net options when I'm in safe mode under admin. As far as the attachments, I'll try to tell you what I see

    The top of the box says: Additional Options
    The next is a subheading: Miscellaneous Options which shows "Automatically Parse Links in Text" - which is marked : and "Disable Smilies" in text - which is not marked.
    Then I have a sub heading called:Attach files which shows like your post is, but no button to "Manage Attachments". And if I click under the list where that button should be, it doesn't do anything.
    I have one more sub heading: Thread subscription that shows Notification type with a drop down box showing Instant Email Notification.

    It's like various things have just disappeared?!?

    Sorry to be such a problem.

    Thank you for your help and time.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HiJack log - Please Help - again

    If you scroll down to the very bottom of this page (the one you are reading right now), there should be a box titled as below with the options shown. What are yours set to (you can see my settings in bold).

    Posting Rules
    You may post new threads
    You may post replies
    You may post attachments
    You may edit your posts
    vB code is On
    Smilies are On
    [/url] code is [b]On[/b]
    HTML code is [b]Off[/b]
     
  22. VickieQ1

    VickieQ1 Private E-2

    It looks just like the one you posted.

    Thanks
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what is causing this. I'll keep thinking about it. But since your log is clean, you need to follow the steps in the below thread. Step 8 mentions using Mozilla Firefox. When you get to that step, install FireFox and import your favorites from IE. Then try to make an attachment using FireFox.


    How to Protect yourself from malware!
     
  24. VickieQ1

    VickieQ1 Private E-2

    Oh! Cool!! I now get the "manage attachements" button & I have options under my advanced i-net tools! However, I still don't have a start bar or icons on my desktop & now my wallpaper is missing (not that I really care about that) & the screen is solid blue.

    ??????

    Thanks

    I'm hopefully attaching a new HJT log?!?!
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have any of the below folders on your PC:
    c:\i386
    c:\windows\i386
    c:\windows\Driver Cache\i386


    If so, look in them for a copy of explorer.exe and copy it to c:\windows and overwrite the explorer.exe file that is in c:\windows.
     
  26. VickieQ1

    VickieQ1 Private E-2

    I've got an explorer.ex_ in my c:\I386, but if I try to open it, it tells me there is no program associated with this file type to open it?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That copy is a compressed version. You need to uncompress it.

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the following commands each followed by the enter key:

    cd c:\i386
    expand explorer.ex_ explorer.exe
    exit

    Now you should have a copy of explore.exe in i386. Before copying it to c:\windows and overwriting one that may be there, let's rename the c:\windows\explorer.exe file to explorer.sav

    Then copy the c:\i386\explorer.exe file to c:\windows

    Now reboot your PC and tell me if there is any change.
     
  28. VickieQ1

    VickieQ1 Private E-2

    Sorry, still just a solid blue screen when I reboot...no icons, no start bar.
    I can copy the explorer.exe to a disc from another XP computer and try to put it on this one if you think that will help????

    Thanks
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should only do this if it is running the same version of Windows XP.
    Your PC had Windows XP SP1 (WinNT 5.01.2600).

    We have tried a variety of typical procedures to get explorer.exe to load again. I'm not sure right now what else we can try.

    You could also try running sfc /scannow from a command prompt window. Not sure if that will fix the problem.

    I think you are going to have to discuss this issue further in the Software Forum. It looks like you may have some other issues with your Windows OS installation. A boot to recovery console (from your WinXP CD) may be necessary to repair your installation.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well we can try another item my friend Matacumbie pointed out. It adds a few more registry patches to some of the ones already tried. Perhaps we will have better luck with this one.


    Download this VB script and save it to the root folder of your C drive.

    http://www.kellys-korner-xp.com/regs_edits/xp_taskbar_desktop_fixall.vbs

    Then with TaskManager running (and do not close TaskManager) click File, New Task(Run....) and in the open box type xp_taskbar_desktop_fixall.vbs and click OK. When it prompts you to run the fix click Yes.

    Once the edit is merged, in Task Manager's Process list look for explorer.exe to be running. If it is, right click it and select End Process.

    Leave the Task Manager open. click File, New Task(Run....) and in the open box type: explorer.exe

    Does your Desktop come back, do icons appear, does explorer.exe remain running?

    Check after a reboot too?
     
  31. VickieQ1

    VickieQ1 Private E-2

    Re: HiJack log - Please Help -=VBS File

    Sorry, It won't let me run that xp_taskbar_desktop_fixall.vbs file. Tells me there is no program associated with it????

    Thanks
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HiJack log - Please Help -=VBS File

    Save the below quoted text to a file somewhere that you can find it. Name it fixvbs.reg
    Press CTRL-ALT-DEL to bring up Task Manager. And click File, New Task (Run..) and enter regedit and click OK. This will run the registry editor. Now in regedit click File and select Import. Locat the fixvbs.reg file and select it. Answer yes about to any prompts about adding it to your registry.

    Now try to run that VBS script.
     
  33. VickieQ1

    VickieQ1 Private E-2

    Re: HiJack log - Please Help-VBS

    Sorry again....now I get a message that says:
    Windows cannot find "xp_taskbar_desktop_fixall.vbs". Make sure you typed the name correctly, and then try again. To search for a file, click the Start Button, and then click Search.

    Tried it 5 different times. Even downloaded the original link again.

    Sorry
     
  34. VickieQ1

    VickieQ1 Private E-2

    Also...don't know if it's important or not, but I checked the "processes" and explorer.exe is Not running???
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what we have been trying to fix since message number 5.

    Where did you save the VBS file to? If you saved it to the root of drive C try using the below in Task Manager's run box:

    C:\xp_taskbar_desktop_fixall.vbs
     
  36. VickieQ1

    VickieQ1 Private E-2

    It's saved under C, but I still get that error. Even if I "browse" for it thru new task and select it, I still get that error. If I right click & go to properties, under "opens with" it says Unknow Application???

    Sorry, I was trying to be helpful.....told you I didn't know what I was doing!?! :)

    Thanks
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did the registry merge from message 32 work? Were you able to save it to a file without any problems and merge it into the registry? Did you get any error messages? Try it again.
     
  38. VickieQ1

    VickieQ1 Private E-2

    The reg. from message 32 seemed to work fine. I imported it and it says it has been successfully entered into the registry. I didn't get any propts other than to hit okay when it told me it was successful.

    Did it all again.. Got the same error message about the file not existing.

    I'm so sorry. I really do appreciate all your help.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you see the c:\xp_taskbar_desktop_fixall.vbs file from Task Manager's browser. Make sure you select All Files for the Files of type selection box. Is it actually named correctly? Make sure it is not named xp_taskbar_desktop_fixall.vbs.txt

    You may want to open a command prompt window and type:

    cd c:\
    dir

    and look to see what the file is actually named.
     
  40. VickieQ1

    VickieQ1 Private E-2

    Ran a dir. Says it's xp_taskbar_destop_fixall.vbs Also browsed for it thru task manager & right clicked on it & it says its a VBScript Script File but under "opens with", it says Unknown.

    Sorry
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto back to task managed and try running the following command

    c:\windows\system32\cscript C:\xp_taskbar_desktop_fixall.vbs

    Tell me if that works. cscript is the program that should be getting called inorder to run the VBS script. It seems you may have lost a bunch of your Windows file associations.
     
  42. VickieQ1

    VickieQ1 Private E-2

    It flashes up what looks like a command prompt screen really quickly, but I can't tell what it says, it's too quick.

    Thanks
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay perhaps it actually worked. Have you rebooted and checked to see if there is any change in your Desktop? Can you run explorer.exe now?
     
  44. VickieQ1

    VickieQ1 Private E-2

    Sorry, still no start bar/icons on reboot :(

    Thanks
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you ever try what I posted in message # 29?

     
  46. VickieQ1

    VickieQ1 Private E-2

    Solved!!!!

    Thank you, thank you, thank you!!!! Actually ended up reinstalling Windows from the disk that came with the computer (shocked he still had it actually!!!). Icons are back, start bar is back! And I love this Mozilla Firefox!

    THANK YOU
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Solved!!!!

    You're welcome. Make sure you complete the steps in the below thread ASAP to help protect you from future problems. You have to make sure you check for Windows Updates. It is step 1.

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds