No desktop icons, taskbar, start button etc.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sbell16, Aug 14, 2005.

  1. sbell16

    sbell16 Private E-2

    Don't know how, but all of the sudden I've lost my desktop icons, taskbar, & start button. I can't right click on the desktop or make anything happen by typing explorer into task manager. I've searched through the Windows user groups, Google etc. & tried all of the utilities (Kelly's Korner etc.) but can't fix the problem. I've been through the virus steps on your website (couldn't access the online scan websites in safe mode, so I did this in normal mode). I appear to have cleaned out any viruses, but still no resolution. Would very much appreciate any help as this is very frustrating. Here is my HiJack log:
    [un-requested inline log removed]
     
    Last edited by a moderator: Aug 14, 2005
  2. sbell16

    sbell16 Private E-2

    Forgot to add. Windows XP Professional on Dell PC.
     
  3. Kodo

    Kodo SNATCHSQUATCH

  4. sbell16

    sbell16 Private E-2

    I have followed the instructions on the page you recommended twice (just to be sure) with the following exceptions:
    * I couldn't run Bit Defender & RavVirus in safe mode because I could find no way to connect to the internet in safe mode. I have run them twice in normal mode
    * I ran but could not get live updates for Ad-Aware SE (something about not being able to connect to the server - even though I was online at the time)
    * Could not run Spybot scan because I could not get an update to start things off
    * Same goes for a-squared
    * I have not yet followed the 'Only the Best' virus instructions

    The first run of the virus programs cleared a few virus' (mainly CWS & one or two Trojans). Second time round I appear to have a clean system with no virus reports.

    I still cannot see my desktop icons, the start button, taskbar or run explorer.exe from Task Manager (I can see the CPU usage increase when I try to open explorer but nothing happens).
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are 2 registry keys that sometimes cause this problem. We are going to look for and delete these keys (if found).

    Press CTRL-ALT-DEL to bring up Task Manager. And click File, New Task (Run..) and enter regedit and click OK. This will run the registry editor. Now look for the below registry keys (navigate thru the registry). Make sure you only look for and delete the exact keys listed below.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplorer.exe

    After deleting this keys the desktop and explorer.exe may reappear if this is your particular problem. There are many forms of problems with explorer.exe not loading at startup. You may need to reboot after doing this. Let me know the results.
     
  6. sbell16

    sbell16 Private E-2

    Firstly thanks for your help. I really appreciate it.

    Unfortunately I couldn't locate either file in the directory (Image File Execution Options). I also did a search for these file names (explorer.exe & iexplore.exe) in the Registry Editor without deleting any. In the HKEY_CLASSES_ROOT\applications\explorer.exe folder I found the following files.
    - (Default)
    - NoOpenWith
    - NoStartPage
    - TaskBarGroupIcon

    These wouldn't have anything to do with my problem would they (given my lack of knowledge I should stay away from diagnosis)?
    Thanks again.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No they have nothing to do with the problem and by the way there are many many more places where those filenames appear in the registry. They are valid Windows files.


    You may want to check the below registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell

    and see if the values for Shell is explorer.exe

    To do that , use Task Manager again (like you did above) and enter regedit and click OK!

    Then navigate your way to and select Winlogon


    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

    then find the Shell in the right window pane and see what the Data entry is.
     
  8. sbell16

    sbell16 Private E-2

    The data entry for Shell in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon is explorer.exe
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you boot in safe mode, do you get a Desktop and does explorer.exe run?

    How about if you login with a different user account?

    You could also try running sfc /scannow from a command prompt window. Not sure if that will fix the problem You may need to open the command prompt using Task Manager. In Task Manager just click File, New Task (Run...) and enter cmd and click OK. Yo may be asked to insert your original WinXP CD during this if it finds that files that are need are missing.

    If that does not help, follow the steps below:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
    Last edited: Aug 30, 2005
  10. sbell16

    sbell16 Private E-2

    Chaslang,
    Had nothing change with the sfc/scannow etc.

    Here's the HJT log file
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any major problems in your log that would cause explorer.exe not to load but let's fix the below lines using HJT. Make sure you close all browsers before clicking Fix.

    O2 - BHO: (no name) - {BC10DCCF-F6B8-4937-85EB-11B110552966} - blank (file missing)
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
    O4 - HKCU\..\Run: [Sonic RecordNow!] C:\freescan\freescan.exe -FastScan
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    Now for explorer not loading let's try this:
    - run msconfig (click Start,Run and enter msconfig and click ok)
    - click the Selective Startup radio button
    - uncheck the top four items under this button.
    - Click Apply and OK

    Now reboot. Let me now if explorer loads and you get a Desktop running this way.
     
  12. sbell16

    sbell16 Private E-2

    Chaslang,
    Firstly, I fixed the files using HJT.

    When I made the changes to msconfig & rebooted I did see my icons, start button & the taskbar. However in this mode I had no way of connecting to the internet so I had to go back to Normal startup in msconfig to get access to the internet again.

    Thanks again for your help. Very much appreciated.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! I should have told you that would happen. With the Services turned off many things will not work. Now let's try to zero in on the problem. Take a few iterations thru try the same steps but instead of uncheck the top four. Try to ID which one is causing the problem by only unchecking either one at a time.

    I would suggest we first try this first. Only uncheck Load System Services.
    If your Desktop appears, we have a problem with one of th Services.
    If you Desktop does not appear, re-check the Load Services and uncheck Load Startup Items....etc.

    Let me know which one seems to be the problem.
     
  14. sbell16

    sbell16 Private E-2

    More progress made today.

    I found by deselecting each of the 4 buttons in msconfig that your assumption was correct. When I deselected Load System Services the icons returned to the desktop (albeit again with limited functionality). When I deselected each of the other 3 tick boxes individually, there was no change.

    So the issue appears to have something to do with Load System Services.
    Thanks again.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download GetService.zip from here: Getservice.zip

    Extract the file to a folder where you can find it, then go to the folder and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad file as an attachment too. Call it service.txt.

    Then try using msconfig and just go to the Services tab and select Hide all Microsoft Services. Then select Disable All . This will disable all non MS services. Let's see what affect this has after a reboot.
     
  16. sbell16

    sbell16 Private E-2

    Hello again.
    I've attached the services.txt below.

    When I hid all Microsoft Services (ie. Disable All) & rebooted I could see all of my icons again (even with the Windows XP icon, Start Bar & Taskbar 'design/styling' this time). The feature set is limited again however under this option.

    Thanks.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me the names of the non-Microsoft Services that you disabled using my previous steps.
     
  18. sbell16

    sbell16 Private E-2

    I think this is what you are after. This is the list of non-MS in the Services tab of msconfig:

    Symantec Event Manager
    Symantec Network Proxy
    Symantec Password Validation
    Symantec Settings Manager
    Creative Service for CD ROM Access
    LexBce Server
    Norton Antivirus Auto Protect Service
    Intel NCS NetService
    SAVScan
    ScriptBlocking Service
    Symantec Network Drivers Service
    STOPzilla Local Service
    SymWMI Service
    WAN Miniport (ATW) Service
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this is going to sound strange but I have seen this happen before. What I want you to do is uninstall the Symantec software you have installed? And then enable all services and and see if you Desktop still appears. If so, it was something do to Symanted. If your Desktop disappears, uninstall StopZilla and see what happens.
     
  20. sbell16

    sbell16 Private E-2

    Today is a great day.

    I kept plugging away at Services in msconfig & identified that when I unclicked StopZilla & rebooted, that my icons (& everything else returned to normal). I have now uninstalled StopZilla & everything is back to normal again.

    You're a champion. Thanks so much for your time & effort, I really appreciate it. I am a very happy camper!!!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds