Unsolved

This post is more than 5 years old

8 Posts

311

October 5th, 2005 07:00

Explorer Crashes and Internet Explorer Burns!!

Hi,
 
I am posting to the forum in hopes that someone can help.  I have already reformatted my hard drive, and reinstalled XP home, which was not a pleasant experience.  However I am trying to move past it, but one of the reasons I even did the reinstall was due to explorer.exe crashes and it is still doing so.
 
I have attached my HJT log in hopes someone can help. 
 
Thanks!!
Mike
 
Logfile of HijackThis v1.99.1
Scan saved at 3:56:44 AM, on 10/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://pages.ebay.com/ebay_toolbar/app/congrats.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)
 

2 Intern

 • 

5.9K Posts

October 5th, 2005 20:00

Sorry, your log is clean.  Nothing running that shouldn't be.  Are you talking Windows Explorer (desktop and file/folder viewer) or Internet Explorer?
 
Start, Run, sigverif, OK
 
Then press Start.  When it finishes do you have a lot of files in the list or just omni.sys?  If not too many could you list them?
 
Start, Run, eventvwr.msc, OK and look in System for red marked events.  Open them and post the text (press the bottom of the three buttons to copy the text then move to a Reply and Edit, Paste.)
 
Ron

8 Posts

October 14th, 2005 22:00

Sorry it has taken so long to reply, i was out of town.  I was speaking of explorer.exe (taskbar) crashing all the time in my first post. I was also getting a Blue Screen which made me reboot.  When I did the Crash Analysis Tool it gave me some random AOL drivers that were causing this, so I removed AOL.  Seems to be a little better now, but I dont want to not be able to use AOL.  HAve you heard of this issue with AOL?
 
Here is what the sigverif came back with:
 
pcouffin.sys
j2gjkm40.dll
j2gjum40.dll
mdigrpah.dll
mdiui.dll
 
 
Thanks for your help~

2 Intern

 • 

5.9K Posts

October 15th, 2005 12:00

These files are probably malware:
 
j2gjkm40.dll
j2gjum40.dll
mdigrpah.dll
 
They will probably be in C:\Windows\System32\.
 
I'd try to delete them if I were you.  You can use killbox
 
 
Put in C:\Windows\System32\j2gjkm40.dll
where it says Full Path of File to Delete
 
Check the Delete on Reboot and Unregister.dll options.  Then press the red button.  Agree to delete the files but don't let it reboot until you have them all done.  Repeat for:
 
C:\Windows\System32\j2gjum40.dll
C:\Windows\System32\mdigrpah.dll
 
If you have a fast link you can get mwav.exe from:
http://www.spywareinfo.dk/download/mwav.exe
and install it.  It wants to use kaspersky as the folder name and normally wants to install on C:\.  Better to change it to kas - easier to remember and type.   Get the killbox from:
http://www.bleepingcomputer.com/files/killbox.php
extract it to your desktop
 reboot into Safe Mode (F8) and run the escan(mwav) program.  Start, Run, c:\kas\mwavscan.com, OK.  Select Drive and Scan All Files then Scan Clean.  Let it run until it finishes.  (might take 8 hours or so)  It will eventually create a log file.  It will remove anything it finds that it considers a virus or try to.  Adware it just flags in the log.  You have to go through the log for entries like:
Fri Jul 29 10:25:26 2005 => File C:\WINDOWS\System32\06wu29rd.exe tagged as not-a-virus:AdWare.F1Organizer.g. No Action Taken.
(hint use Notepad's  Edit, Find to  search for: virus)
then use killbox to clean the adware manually. Double-click Killbox.exe to run it.
Select "Delete on Reboot".
Place the full path  in the "Full Path of File to Delete" box in Killbox:
example:  C:\WINDOWS\System32\06wu29rd.exe
Press the red button, agree you want to delete the file but do not let it reboot yet.  Repeat for every virus or not-a-virus entry then let it reboot after the last one.
 
Never hurts to do one of the free on line scans from Panda or Trend.  They take a while (tho not as long as mwav)  but are pretty good.
www.pandasoftware.com/activescan/activescan.asp?
http://housecall.trendmicro.com/
 
 
 
 
 
Ron

8 Posts

October 15th, 2005 17:00

Ron,

Thanks for getting back with me.  I think both the j2...dll files are for my j2messenger efax service.  I am worried to delete them, as it may mess up my faxing abilities.  I guess I could try it, and then just reinstall messenger. 

Any ideas on my blue screen error?  DRIVR_SQL_NOT_EQUAL  it said something similiar to that!

Thanks,

M~

2 Intern

 • 

5.9K Posts

October 16th, 2005 11:00

The files do not show up in Google anywhere which is why I flagged them.  You'd think if they were part of a known process they would show up a few times.
 
You can check the files in Windows Explorer tho you will have to go into Tools,View, and uncheck the two Hides and check the Show Hidden FIles and Folders.  Navigate down to C:\Windows\System32 and find the folders.  If you hold the cursor over them you can see who makes them (or right click then Properties then Version).  Files without a maker are almost always malware.
 
If you really formatted and reinstalled XP did you get all of the Microsoft patches right away?  Was your firewall working while you did this?  Otherwise you can get reinfected in no time.
 
Look in the Event Log and see if you can get any clues there.
 
Task Manager, File, New Task, eventvwr.msc, OK  Then look under System and Application for entries with red marks that have dates and times since the last reboot.  Double click on them and press the bottom of the three buttons to copy it to your clipboard then start a reply and Edit Paste.
 
You might want to run a mem check. 
 
 
Ron
 
Ron
 
 

0 events found

No Events found!

Top