windows has encountered prob and needs to close !!!!! help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tichyboy, Oct 18, 2004.

  1. tichyboy

    tichyboy Private E-2

    hi there , i've followed advice on this site to clean my pc. used all suggested tools etc. thoroughly cleaned my pc but every time i try to access any of my files i am told that 'windows explorer has encountered a problem and needs to close'. any suggestions as i am near the end of my tether and my pc is about to take flying lessons
     
  2. Kodo

    Kodo SNATCHSQUATCH

    we require more information about your system.

    what OS..memory.. etc. etc.
     
  3. tichyboy

    tichyboy Private E-2

    right. using xp pro. as for the others not entirely sure how to find out? sorry bit of a novice in some respects. u tell me and i'll do it. please
     
  4. tichyboy

    tichyboy Private E-2

    176 MB of RAM. does that make sense?
     
  5. Kodo

    Kodo SNATCHSQUATCH

  6. tichyboy

    tichyboy Private E-2

    sorry to b a pain. how do i save it as a text file?
     
  7. tichyboy

    tichyboy Private E-2

    sorry done it, how do i post an attachment pls
     
  8. Kodo

    Kodo SNATCHSQUATCH

    start a reply (NOT QUICK REPLY.. click on POST REPLY).. scroll down below the message box and click on manage attachments button. The rest is self explanatory.
     
  9. tichyboy

    tichyboy Private E-2

    thank you. here's the log. hopefully
     

    Attached Files:

  10. Kodo

    Kodo SNATCHSQUATCH

    you didn't follow all of the directions 100%. You need to put HiJackThis in it's own folder like C:\program files\HiJackThis . Do not run it from any folder in documents and settings, the desktop or from an archive. When you're done, post another log.
     
  11. tichyboy

    tichyboy Private E-2

    here we go. this should be right. put hijack where u said. it doesn't matter where i save the text file does it?
     

    Attached Files:

  12. Kodo

    Kodo SNATCHSQUATCH

    Boot to safe mode and do the following

    Go to start...run type
    regsvr32 /u edm.dll hit enter and so OK to any prompt.
    Do the same for this one
    regsvr32 /u mspxs32.dll

    Now find the following files.
    C:\windows\sytem32\edm.dll
    C:\windows\sytem32\mspxs32.dll

    and delete them.
    I want you delete the following file as well but take note that there are TWO files in the system32 directory that are named winspool. One is winspool.exe and the other is winspool.drv.
    If you see ONLY those files, then do NOTHING.. don't delete ANYTHING.

    C:\WINDOWS\System32\w?nspool.exe




    Now load up HiJackThis. Put a check next to these items and and click fix.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    O2 - BHO: (no name) - {19AC672D-E711-789B-8756-6D550CF37846} - C:\WINDOWS\System32\edm.dll
    O4 - HKCU\..\Run: [Prc] C:\WINDOWS\System32\w?nspool.exe
    O9 - Extra button: AOL Instant Messenger (TM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE (file missing)
    O15 - Trusted Zone: *.windupdates.com

    Reboot your machine and post another log. Report any problems in finding the w?nspool.exe file.
     
  13. tichyboy

    tichyboy Private E-2

    ok did that , found and deleted first two files. did not find w?nspool.exe.
    ran hijackthis in safe mode and did not find all items to be fixed , ran it again in normal and did. here's the log. thank you for your help so far
     

    Attached Files:

  14. Kodo

    Kodo SNATCHSQUATCH

    go ahead and remove these from HJT

    O2 - BHO: BHO - {06CAD548-14DD-4fa3-9EA9-05F83C18CBD7} - C:\WINDOWS\System32\mspxs32.dll (file missing)
    O2 - BHO: (no name) - {19AC672D-E711-789B-8756-6D550CF37846} - C:\WINDOWS\System32\edm.dll (file missing)

    they are no longer needed now that you've deleted the files.

    Let us know how it works out for you
     
  15. tichyboy

    tichyboy Private E-2

    thank you, thank you. we have a result. what was wrong with the pc? if you're ever over in the uk i'll take u out for a pint
     
  16. monkeyg

    monkeyg Private E-2

    Reinstalling SP2 to repair Damaged DLLs

    If wanting to fix the user profile instead of scrapping and starting over this is probally worth a try.

    Scroll to the bottom of this post for what worked for me, keep reading if you like long-winded stories.

    I was getting a similar error, not when right clicking, but searching.

    Any search I attempted got the "Windows Explorer has encountered a problem and needs to close. We are sorry for the inconvenience." error myself only referencing a failure in Srchui.dll (Search User Interface Dynamic Link Library)

    As most .dll failures are due to a corruption of the dll itself I set off to overwrite my current Srchui.dll with the original.

    Thank you pklammer for the "Launch folder windows in a separate process" tip, it DID make my testing less painful!

    This was hindered by both the fact that I wanted the SP2 version and that I couldn't search to find the file on my harddrive.

    Microsoft shed some light with thier "A File That Is Required to Run Search Companion Cannot Be Found" article at http://support.microsoft.com/default.aspx?scid=kb;en-us;319949. I found this by searching Microsoft for just "Srchui.dll".

    The article recommended to (re)install Srchasst.inf, to replace the missing Srchui.dll. My hopes were that it would repair my damanged one.

    Doing so I was prompted for the SP2 CD, I didn't have one as I installined via Windows Update. I didn't seem to have a full unzipped directory in C:\WINDOWS\$NtServicePackUninstall$ either.

    I finally decided to try to reinstall SP2. I didn't wanna wait for CD and of course having it installed already it no longer appears in Windows Update. After some searching I DL'd the "Windows XP Service Pack 2 for IT Professionals and Developers" from http://www.microsoft.com/downloads/...BE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en (I search MS for "SP2 download")

    Some recommendations for (re)installing SP2 this way:
    Do a manual System Restore Checkpoint. Windows Update version will do one for you, this way won't.
    Restart when finished. The "Restart computer now" isn't grayed out like on the WU version. I didn't delay and wouldn't recommend you doing it either.

    I reinstalled it and held my breath during reboot. I got a "MSL Failed" (or something like that) error on login. I'm guessing that it was trying to migrate settings from SP1 but couldn't find any. I've rebooted once since and it's NOT reoccuring.

    My profile was in tact except a few arbitrary changes. I had to redelete the WMP shortcut from my quicklaunch. I had to redelete the "Set Program Access and Defaults" shortcut from the root of the start menu. I had to reuncheck the "Display detele confirmation dialog" in Recycling Bin properties. That's all I've found so far.

    I CAN SEARCH! Both local and network drive searches work like a charm.

    Things I have verified so far that were maintained in my profile are:
    Folder view preferences
    Custom Start Menu organization
    Favorites
    Firewall settings
    Both of my wireless NICs work.

    In short I had to click ok on one error message, reconfigure 3 settings and now i'm golden. I've been up for 25 minutes since reboot, no error, hangs, crashes, other problems, and still can search.

    I'll swing back by this topic if anything goes horribly wrong.

    Monkey G. =)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds