This is a read-only archive. No new posts or registrations. Privacy Page
Software

Explorer.exe failed to initialise

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I'm having a slightly annoying problem on about every third or fourth boot of my machine - Windows XP SP2, old Athlon 64 3500 with about 3GB of RAM.

After I type my password and hit return to login it sticks on the blue login screen for about 30 seconds and then when my desktop image finally appears there are no icons, no taskbar and an error dialog saying "Explorer.exe failed to initialise" and it also has one of those 0x0000 type of numbers at the end.

As I say, this happens on every third or fourth boot so when it happens I just reboot and the machine is fine again for a couple more boots/days until the problem happens again.

I've done some Googling and there are suggestions that it might be linked to a program's auto-update routine failing to run properly on startup and causing an error, but that tracking it down could be tricky.

I've been into MSCONFIG and disabled all of the startup items apart from the bare essentials, which are my firewall, AV and maybe ActiveSync, I think. But the firewall and AV were actually installed after this problem began because I thought it might be my AV that was causing the problem so I changed. I was originally using Comodo AV & firewall (all-in-one) but when the problems began I switched to Avira and Outpost instead, however the problems persist.

One thing… When I ran ComboFix (one of the WTT guys helped me remove some malware a little while ago) it seemed to think Comodo AV was still running, even though I've uninstalled it and there's no active startup entry for it in MSCONFIG. I do have Comodo system cleaner installed so perhaps it was picking up on that instead.

Anyway, I'm not really sure what the next steps are in tracking down which application might be causing the error I'm getting so any advice is appreciated.

Malware Thread
Hi fingerz. Explorer problems on startup are often caused by malware. You mentioned you recently had some malware removed. Can you please tell us how long ago this was and about when this problem started occuring in reference to that?

The error number provided and any further information that may have been provided could be useful to us in diagnosing your problem. Please open your event viewer and find the error related to this windows explorer problem. You may double click the entry in event viewer and press the small paper icon to copy and paste the error information to the forum. To open event viewer, click start -> run -> type eventvwr and press ENTER. This particular error should be listed in your application log.

EDIT: I just reviewed your malware removal thread. That is/was quite a mess you have there. Unfortunately, despite all the hard work of jpshortstuff, his best advice to you was probably to reformat your hard drive. When this type of mess gets on a computer, you can clean all day long, maybe or maybe not getting all the infection removed, and then be left behind with a never ending slew of problems. Its simply not even worth trying to clean these systems anymore nowadays in my opinion.

Lets take a look at those particular registry keys that were effected in your malware infection. Click start -> run -> type 'cmd' and press ENTER. At the command prompt copy and paste the following: reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" > postme.txt & notepad.exe postme.txt and press ENTER.

A file will open in notepad that you can copy and paste to the forum.

Secondly, open My Computer, navigate to C:\Windows and find the file called explorer.exe. Right-click it, click properties and tell me its size in bytes, and its date last modified time.

Lastly, please tell me what service pack level Windows XP is at. (Service Pack 2, service pack 3?) Find it in control panel -> system -> general tab.
Hi,

Thanks for coming to my aid. I agree that the reformat advice is probably the best path but if there's a way to fix this explorer problem that would basically mean my system is completely back to normal so I'd like to at least have a quick try, if that's ok.

I went into Event Viewer and went through a load of the errors but there's nothing there that relates to the Explorer error, at least not that I can see, so I took a screenshot for you in case anything stands out. It's quite large so rather than post the image here you can see it full-size here:
http://img684.imageshack.us/img684/239/eventviewer.gif

Explorer.exe in the C:\Windows folder has the following properties:

Size: 1,032,192 bytes
Last modified: 03 August 2004, 23:56:50

And here are the results of the registry query:

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
AutoRestartShell REG_DWORD 0x1
DefaultDomainName REG_SZ JAMEYS-PC
DefaultUserName REG_SZ Jamey
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\Bex\Application Data\msyqeu32.exe,C:\WINDOWS\system32\msqjgu32.exe,C:\WINDOWS\system32\msddky32.exe,C:\Documents and Settings\Bex\Application Data\msqmvu32.exe,C:\WINDOWS\system32\msuwhl32.exe,C:\WINDOWS\system32\msuslo32.exe,C:\WINDOWS\system32\msgike32.exe,C:\WINDOWS\system32\msyjqc32.exe,C:\WINDOWS\system32\mspavm32.exe,C:\WINDOWS\system32\mspaez32.exe,C:\Documents and Settings\Bex\Application Data\mspljj32.exe,C:\WINDOWS\system32\msxbqg32.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD 0xffffffff
allocatecdroms REG_SZ 1
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0x0
passwordexpirywarning REG_DWORD 0xe
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 0x1
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 0x1
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0x0
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 0x1
ShowLogonOptions REG_DWORD 0x0
AltDefaultUserName REG_SZ Jamey
AltDefaultDomainName REG_SZ JAMEYS-PC
Shell REG_SZ Explorer.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SCLogon

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Credentials
Oh, sorry, I just ran Malwarebytes before reading this (my net connection died for a little while just now) and did a quick scan. It found a few backdoor things so I removed them. Sorry, I won't do anything else until I hear back from you, apologies. Here is the log from the MBAM scan I did just now: Malwarebytes' Anti-Malware 1.44 Database version: 3556 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 16/01/2010 13:54:45 mbam-log-2010-01-16 (13-54-45).txt Scan type: Quick Scan Objects scanned: 132271 Time elapsed: 4 minute(s), 58 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 1 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi fingerz, just to follow up a bit … You had a nasty rootkit as well as a Backdoor Bot. BackdoorTrojan/Bots are known password and critical information stealer's.

I would highly suggest that you change all of your passwords using a known 'clean' computer. Do not use the one that was infected.

If you haven't done so, Download ATF Cleaner http://www.atribune.org/index.php?option=c…5&Itemid=25
Click "Main" > check 'select all' this first time using it, then click "Empty Selected". Do the same for FireFox or Opera if you use either of those browsers.

Finally go to Control Panel > Internet Options.
On the General tab under "Temporary Internet Files" Click "Delete Files".
Put a check by "Delete Offline Content" and click OK.
Click on the Programs tab then click the "Reset Web Settings" button. (if on your machine)
Click Apply then OK.

Next,
Download the HostsXpert 4.3 - Hosts File Manager.
  • Unzip HostsXpert 4.3 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert 4.3 - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper right corner (If available).
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

Just glancing through your logs, it looked like you need to update Java:
Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u18 allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.

See if you can get IE 7 (it's more secure than IE 6 ..
http://www.microsoft.com/downloads/details…;displaylang=en

Let appleoddity and me know if doing the above has helped.
Hi again, sorry for the delayed reply, I ended up being quite busy yesterday. I've done the things you asked above so I'll keep an eye on the machine this week to see if the problem is still occurring.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI