No announcement yet.

Explorer.exe Crashes and re-starts upon startup of laptop

  • Filter
  • Time
  • Show
Clear All
new posts

  • Explorer.exe Crashes and re-starts upon startup of laptop

    Hi, I have found a couple of threads mentioning this problem but none seemed relevant so I started this!

    I'm trying to help a friend out, his laptop (Gateway Mx3101b on XP home) was experiencing problems so he scanned using a new version of Mc Afee nothing was found! He installed symantec corporate edition and found a trojan, removed the threat but upon re-starting of the computer explorer keeps crashing and re-starting itself! In task manager the process svchost has 6 or 7 processes running also! I'm not sure if the problem was from the trojan or if its a conflict between Mc Afee and Symantec?? Any help would be appreciated! sorry but he did'nt note the name of the trojan!!!

    Thanks Kev.

  • #2
    Re: Explorer.exe Crashes and re-starts upon startup of laptop

    If he has had a trojan there could be anything on the laptop. Have you tried an online scanner (to supplement the symantec)?
    I would also run Spybot and AdAware as well to check for spyware etc.
    It would be handy to know more about the errors etc

    Multiple svchost is fine (assuming they are legitimate).

    Run Hijack This from Trend Micro and post the result and we may be able to pick out any suspicious entries.

    Please read this before you post:

    Quis custodiet ipsos custodes?


    • #3
      Re: Explorer.exe Crashes and re-starts upon startup of laptop

      Here's the Hi-jack log:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:29:00, on 14/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\Program Files\Symantec AntiVirus\DefWatch.exe
      C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
      C:\Program Files\Symantec AntiVirus\Rtvscan.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Symantec AntiVirus\DoScan.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! UK & Ireland
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKCU\..\Run: [Spyware Begone] "C:\spywarebegone\SpywareBeGone.exe" -FastScan
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites -
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
      O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
      O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
      O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
      O23 - Service: Wireless Adapter Configurator - Unknown owner - C:\Program Files\BT Home Hub\Wireless Configuration\WirelessDaemon.exe (file missing)

      End of file - 5898 bytes

      SpyBot would'nt update and could'nt install? AdAware found a couple of things but removed them no prob, on reboot it did'nt find anything else and My mate also downloaded Super Anti Spyware and found "Adware Vundo Variant"
      The infection is:

      HKCR\CLSID\{0335D0C9-412C-4E5C-BCD4-E3856EB40132} (Name-(Default) Type-REG_SZ Data-C:\WINDOWS\Sytem32\fccCuRii.dll-{also value}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{0335D0C9-412C-4E5C-BCD4-E3856EB40132}

      Have tried to remove these items through Super Anti Spyware but to no avail as they are still there when you reboot and scan again.

      Tried to reboot in safe mode but the problem still occurs!

      Would be thankful if you'd have a look! Cheers, Kev


      • #4
        Re: Explorer.exe Crashes and re-starts upon startup of laptop

        Vundo - try these:

        From a quick look I didn't see anything specifically wrong with the list.

        Please read this before you post:

        Quis custodiet ipsos custodes?


        • #5
          Re: Explorer.exe Crashes and re-starts upon startup of laptop

          Vundo? My sister had it (her computer, anyway), and she went crazy, until I sent her the tools few days ago.
          There is a Removal Tool and instructions for Manual Removal.
          Try to remove it again and see if there's any change.
          Good luck.

          Sorin Solomon

          In order to succeed, your desire for success should be greater than your fear of failure.


          • #6
            Vundo is gone!! Cheers ppl, for all the help!!


            Got rid of vundo finally!! It had been using a .dll file to kinda rezurrect itself or had d/l'd something to!!!!! Got the path using superantispyware, And used unlocker 1.8.6 to allow me get rid of the file, Have checked all the paths in the manual removal guide( Thanks Again for that!!) An' all seems clear!!

            But I found a couple of pages saying vundo variant can I.D. Hijackthis and corrupt it, Dont know if it's true but would explain the clear log-file?!?!?

            But many thanks for all the help much appreciated!!

            Thanks, Kev


            • #7
              Re: Explorer.exe Crashes and re-starts upon startup of laptop

              Splendid. I didn't know about the Hijackthis thing so will bear in mind for next time. Thanks for letting us know.

              Please read this before you post:

              Quis custodiet ipsos custodes?