This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] explorer.exe restarting

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Everything was running fine on a very fresh installation, until I rebooted the PC. I noticed the taskbar dissapeared ever 5-10 secs and the tray icon for the control panel of my sound card wouldn't appear again after the taskbar dissapeared for the first time. I ran Avira Antivir Premium, with the latest updates and only found some keygens in some old partition that hasn't been used in more than a year. Then tried with Spy Sweeper, and the restarting of explorer.exe stopped after installation, once I've rebooted the PC, when I did a reboot again, the problem came back. Now the problem seems to come and go on each reboot.

In the Task Manager in the Process tab, I can see explorer.exe appearing and dissappearing and therefore I can't open any windows handled by the OS. The problem dissapears in Safe Mode. I ran a scan with Avira, Spy Sweeper with no results and also removed temporary files with Privacy Guardian. So I provide you here with this HiJackThis log.

Don't know if it matters, but I don't run any antispyware or av's in real time. This is the first time in more than 2 or 3 years that I picked such a nasty malware. Thanks in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:51:56 PM, on 2/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
K:\WINDOWS\System32\smss.exe
K:\WINDOWS\system32\winlogon.exe
K:\WINDOWS\system32\services.exe
K:\WINDOWS\system32\lsass.exe
K:\WINDOWS\system32\svchost.exe
K:\WINDOWS\System32\svchost.exe
K:\WINDOWS\system32\svchost.exe
K:\WINDOWS\system32\spoolsv.exe
K:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
K:\Program Files\Digidesign\Drivers\MMERefresh.exe
K:\Program Files\Java\jre6\bin\jqs.exe
K:\WINDOWS\system32\lxczcoms.exe
K:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
K:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
K:\WINDOWS\system32\svchost.exe
K:\WINDOWS\system32\ZuneBusEnum.exe
K:\WINDOWS\system32\hkcmd.exe
K:\WINDOWS\system32\igfxpers.exe
K:\WINDOWS\system32\DeltaIITray.exe
K:\WINDOWS\system32\igfxsrvc.exe
K:\Program Files\Microsoft IntelliPoint\ipoint.exe
K:\Program Files\Zune\ZuneLauncher.exe
K:\Program Files\Microsoft IntelliType Pro\itype.exe
K:\WINDOWS\system32\ctfmon.exe
K:\Program Files\Stardock\CursorFX\CursorFX.exe
K:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
K:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
K:\Program Files\Opera\Opera.exe
K:\Documents and Settings\Sorvino\Local Settings\Application Data\Opera\Opera\profile\cache4\temporary_download\HiJackThis.exe
K:\WINDOWS\explorer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - K:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - K:\Program Files\Real\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - K:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - K:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - K:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: QT TabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll (file missing)
O3 - Toolbar: QT Tab Standard Buttons - {D2BF470E-ED1C-487F-A666-2BD8835EB6CE} - mscoree.dll (file missing)
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - K:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [IgfxTray] "K:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "K:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [Persistence] "K:\WINDOWS\system32\igfxpers.exe"
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] "K:\WINDOWS\System32\DeltaIITray.exe"
O4 - HKLM\..\Run: [DeltaIITaskbarApp] "K:\WINDOWS\system32\DeltaIITray.exe"
O4 - HKLM\..\Run: [DigidesignMMERefresh] "K:\Program Files\Digidesign\Drivers\MMERefresh.exe"
O4 - HKLM\..\Run: [IntelliPoint] "K:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Zune Launcher] "K:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "K:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "K:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "K:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "K:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [itype] "K:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "K:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKCU\..\Run: [ctfmon.exe] K:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "K:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [CursorFX] "K:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = K:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://K:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - K:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - K:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - K:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - K:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - K:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - K:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - K:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1232993725140
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - K:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - K:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - K:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - K:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcz_device - - K:\WINDOWS\system32\lxczcoms.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - K:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - K:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - K:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe

–
End of file - 6968 bytes

Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI