Hi folks,
Today my computer came up blank when windows started. Hunting around on the net I've seen many people having this problem, but I did not find a generic solution to try, just many custom ones. The folks here helped a few people with this issue so I thought I'd see if we can figure this one out together. I'd be grateful to have some assistance.
Here's the data:
SYSTEM: Windows XP Professional (OEM) SP2 on an Acer TM633 laptop
HISTORY/SURROUNDING EVENTS:
Two days ago computuer working fine. Did not use it yesturday.
Today, after logging into Windows the desktop is blank. No taskbar. Basically Explorer.exe did not load.
Tried loading it manually. The process starts, then after a few seconds it stops. Nothing appears on desktop.
Restarted. Desktop and taskbar appeared, all icons in place. Then it vanished (explorer.exe died). Further attempts, exploere dies right away or does not even attempt to load.
Tried it in Safe Mode. Same story.
I note that much of the startup process does not complete. I am thinking that something in the startup rountine is hanging the rest of the routine, including explorer.exe. Although that does not explain why I can't run it manually.
Only changes made to PC between weekend and today was that one the weekend (the last time I was using the computer) I installed thje open source programme EasyTag 2.1. I also installed the GTK+-2.10.13 support files for EasyTag.
I have now uninstalled both of these. Problem remains.
Further history. A few weeks ago nearly every application in the startup rountine (all the registry based user defined/installed apps) had a "-" in front of it's file name. Hence none of these things would start when I started XP. I fixed this by removing the "-" from the front of the file names. I am not sure what caused that to occur. It may or may not be related. I did do a virus scan at that time and it came up clean (NOD32).
Another thing I note is that I've taken a look into the Event Log. The following errors have been occuring every time I start up the PC for as long back as I have a record (which is only the 11th of July). These services not starting are:
1) The HID Input Service service terminated with the following error: The system cannot find the file specified. (The path for HID in Services.msc is "C:\WINDOWS\System32\svchost.exe -k netsvcs")
2) The server could not bind to the transport \Device\NetBT_Tcpip_{E4E61D70-53BF-4283-8718-DA138BC8C01B} because another computer on the network has the same name. The server could not start.
3) The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
Another thing I note in Service Control Manager is this service at the top:
Service Name: Bonjour Service
Display Name: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# #
Description: ##Id_String2.6844F930_1628_4223_B5CC_5BB94B879762# #
Path to executable: "C:\Program Files\Bonjour\mDNSResponder.exe"
I disabled this service a month or more ago when I found the mDNSResponder.exe running every time I started my PC.
I know the startup rountine is not completing because I ran SDFix and when it rebooted back into standard XP mode, the RunOnce trigger in the Registry (to complete the SDFix process) did not run. I ran it manually though. The Report.txt data is at the end of this message (in case it is of any use):
In the Application Event log I note the following (three times) from the first time I turned my computer on today. There are no subsequent occurances of this today (although I've restarted the PC many times). It just happened the first time the PC started today.
Quote:
Event Type: Information
Event Source: Winlogon
Event Category: None
Event ID: 1002
Date: 1/08/2007
Time: 9:09:14 a.m.
User: N/A
Computer: INSPIRED01
Description:
The shell stopped unexpectedly and Explorer.exe was restarted.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
|
If I should post a HJT log please let me know.
Below is also the results of running the Xoftspy 4.22 scanner, and SB S&D.
S7D says the Virtuemode trojan is on my computer.
Your help is greatly appreciated

. So far I've lost most of the day of work.
Regards,
Jonathan
SDFix Report.txt
Quote:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0"
"E:\\Internet Tools\\P2P Clients\\utorrent 1.4.exe"="E:\\Internet Tools\\P2P Clients\\utorrent 1.4.exe:*:Enabled:æTorrent"
"E:\\Internet Tools\\P2P Clients\\utorrent 1.6.exe"="E:\\Internet Tools\\P2P Clients\\utorrent 1.6.exe:*:Enabled:æTorrent"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr .exe"="C:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\h elpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\IBP 9\\IBP.exe"="C:\\Program Files\\IBP 9\\IBP.exe:*:Enabled:Internet Business Promoter (IBP)"
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5"
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"="C:\\Program Files\\Orbitdownloader\\orbitdm.exe:*:Enabled:Orbi t"
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"="C:\\Program Files\\Orbitdownloader\\orbitnet.exe:*:Enabled:Orb it"
"C:\\Program Files\\Mail Direct Pro\\madypro.exe"="C:\\Program Files\\Mail Direct Pro\\madypro.exe:*:Enabled:MADYPRO"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
Remaining Files:
---------------
Files with Hidden Attributes:
C:\COMMAND.COM
C:\Documents and Settings\All Users\Application Data\Data\LicenseManager2007.dll
C:\Program Files\SUPER\cygwin1.dll
C:\Program Files\SUPER\cygz.dll
C:\Program Files\SUPER\mencoder\14_43260.dll
C:\Program Files\SUPER\mencoder\28_83260.dll
C:\Program Files\SUPER\mencoder\atrc3260.dll
C:\Program Files\SUPER\mencoder\cook3260.dll
C:\Program Files\SUPER\mencoder\ddnt3260.dll
C:\Program Files\SUPER\mencoder\dnet3260.dll
C:\Program Files\SUPER\mencoder\drv13260.dll
C:\Program Files\SUPER\mencoder\drv23260.dll
C:\Program Files\SUPER\mencoder\drv33260.dll
C:\Program Files\SUPER\mencoder\drv43260.dll
C:\Program Files\SUPER\mencoder\dspr3260.dll
C:\Program Files\SUPER\mencoder\ivvideo.dll
C:\Program Files\SUPER\mencoder\qtmlClient.dll
C:\Program Files\SUPER\mencoder\raac.dll
C:\Program Files\SUPER\mencoder\rnco3260.dll
C:\Program Files\SUPER\mencoder\rnlt3260.dll
C:\Program Files\SUPER\mencoder\rv103260.dll
C:\Program Files\SUPER\mencoder\rv203260.dll
C:\Program Files\SUPER\mencoder\rv303260.dll
C:\Program Files\SUPER\mencoder\rv403260.dll
C:\Program Files\SUPER\mencoder\sipr3260.dll
C:\Program Files\SUPER\mencoder\tokr3260.dll
C:\WINDOWS\neoqaz2.dll
C:\WINDOWS\system32\flvDX.dll
C:\WINDOWS\system32\msfDX.dll
C:\Program Files\Helium 2007\UserDataRemove.exe
C:\Program Files\SUPER\Setup.exe
C:\WINDOWS\system32\B5E7A712E7.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\Documents and Settings\Jonathan\Application Data\Microsoft\Word\~WRL0795.tmp
Finished
|
SB S&D Scan results:
Quote:
Virtumonde: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{6ED63687-EB85-4687-A8D0-17E9792B20CA}
Virtumonde: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{6ED63687-EB85-4687-A8D0-17E9792B20CA}
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
Tradedoubler: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
|
Here are the FIX results from S&D (one item not fixed)
Quote:
Virtumonde: Class ID (Registry key, fixing failed)
HKEY_CLASSES_ROOT\CLSID\{6ED63687-EB85-4687-A8D0-17E9792B20CA}
Virtumonde: Browser helper object (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{6ED63687-EB85-4687-A8D0-17E9792B20CA}
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixe
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixed
Tradedoubler: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixed)
Tradedoubler: Tracking cookie (Firefox: Jonathan Evatt) (Cookie, fixed)
|
I am still waiting for Xoftspy to finish. Will post results when it's done.