This is a read-only archive. No new posts or registrations. Privacy Page
Software

Explorer.exe not starting at power up/login

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there I wonder if any one can help me! I had a Trogean virus. (Trogan AN Agent, Fakealert Trogan & SVSCHOST.exe Issues) Which your malware team have helped me remove from my system. The only problem is whilst running the combofix.exe file it has caused the above error. When the desktop wallpaper has loaded I can press CTRL+ALT+DELETE and access Task manager. From there I can select new Task, browse to explorer.exe and the complete desktop returns, including Taskbar and icons. We have 4 users log on on this system 2 admin and 2 user. this happen on all users. The things i've tried are 1. Creating a new user(admin)…………..No Change 2. Opened Regedit and confirmed that HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\ Shell value is set to explorer.exe 3. Confirmed Explorer.exe is in c:\WINDOWS Can you Assist I'll attach the Hijack file incase it helps Cheers Lee
Hello Lee, welcome back. I'm guessing you also tried Safe Mode, right?

My guess is a registry problem.

I have RegSeeker installed and used it's Find in registry function to locate all instances of explorer.exe, then exported it as a .reg file, edited and renamed to .txt and zipped. I'll upload it here so you can look at it. If you do the same on your system, you can compare results and see if any of the registry entries on your computer are different. Some are very long hex strings so will be difficult to compare, but perhaps you'll see something obvious.

Before you make any change to the registry, please back it up. An excellent way to do this is to install ERUNT. Let it add an entry to your Start menu during the install process. That will allow ERUNT to backup your registry each time you boot. It only takes a few seconds and has no real impact on boot time. Run ERUNT immediately after installing it to create a full registry backup.

[attachment removed]
Hi there Just keeping you updated. I'm currently compairing the registrys.Its long and very boring. I will let you know when I've finnished Lee
Thanks for the update. I knew it would be a pain but it's all I can come up with right now. I sure hope you find something.

Hi there

I wonder if any one can help me!

I had a Trogean virus. (Trogan AN Agent, Fakealert Trogan & SVSCHOST.exe Issues) Which your malware team have helped me remove from my system. The only problem is whilst running the combofix.exe file it has caused the above error.

When the desktop wallpaper has loaded I can press CTRL+ALT+DELETE and access Task manager. From there I can select new Task, browse to explorer.exe and the complete desktop returns, including Taskbar and icons.

We have 4 users log on on this system 2 admin and 2 user. this happen on all users.

The things i've tried are
1. Creating a new user(admin)…………..No Change
2. Opened Regedit and confirmed that HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\ Shell value is set to explorer.exe
3. Confirmed Explorer.exe is in c:\WINDOWS

Can you Assist

I'll attach the Hijack file incase it helps



Cheers

Lee


Hi, in the registry, in the same location you mentioned above, there is also a userinit entry. It should say "C:\Windows\system32\userinit.exe," (note that there is a trailing comma, it has to be there). Is this the case?
Hi There Thankyou for the advice. The c:\windows\system32\userinit.exe, is in the above location. I have retyped it in but it is still the same The only differences I found Between the two registrys are as follows. 1. [HKEY_CLASSES_ROOT\Applications\WINWORD.EXE\TaskbarExceptionsIcons\WordMail\IconPath] @="explorer.exe,16" - t [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2} [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\explorer.exe] "0"=hex:52,04,F0,0A,00,00,06,00,00,00,28,0A,00,00,06,00,84,08,54,0B,00,00,06,0 0 "1"=hex:29,42,C2,B9,31,92,06,C3,B9,7F,AF,DF,59,F6,EE,CE,29,38,7B,C6,5D,11,37,B 1,08,E0,\ 7C,5A,04,AD,3C,E0,14,68,0F,A5,DF,72,82,CB,6E,2F,CC,DF,A3,68,69,3C This is in your reg but not mine 2. [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "@explorer.exe,-7024"="Internet" [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "@explorer.exe,-7025"="E-mail" [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "@explorer.exe,-7023"="&Run…" [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "@explorer.exe,-7020"="&Search" [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "@explorer.exe,-7021"="&Help and Support" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Nls\MUILanguages\RCV2\explorer.exe] "0"=hex:52,04,F0,0A,00,00,06,00,00,00,28,0A,00,00,06,00 "1"=hex:29,42,C2,B9,31,92,06,C3,B9,7F,AF,DF,59,F6,EE,CE,9C,01,A2,55,63,E5,0B,3 C,3F,E5,\ 8D,35,74,61,25,CB I have these, you dont Does any of this informatiom give you any clues, because i'm still lost All the best Lee
The only ones that looked interesting were the MUICache ones. Did some searching on muicache registry and found a good article on MUICache, what it is and how it's used but nothing that indicates not having those entries would cause the problem you are having.

http://ilostmynotes.blogspot.com/2008/05/m…mystery-de.html

One way to trouble shoot this is to create a new XP Account and see if the problem occurs there when you logon to it. If not, a solution would be to copy your data from the old, corrupted account to the new account. Try it for awhile and if all is well, delete the old account.

See here: http://support.microsoft.com/?kbid=811151

Or follow these directions posted in GeeksToGo.com:
  • Create a new Administrator level account. You can do this in Safe Mode logged in as Administrator.\ if necessary.
  • Reboot the computer.
  • Login with the new account so the folder structure under Documents and Settings gets created, then log off.
  • Login with an account that is neither the old or the new account. This prevents "file in use" errors while copying. (NOTE: If you don't have another account, you can create a third one or you can boot into Safe Mode and log with the ADMINISTRATOR account.)
  • Browse to c:\documents and settings\OldUserAccount
  • Select everything in that folder except the three files called ntuser.dat, ntuser.dat.log, and ntuser.ini. (These may be hidden files, so if you don't see them, open My Computer, Tools menu, View tab, check "Show Hidden Files/Folders")
  • Copy all those files into c:\documents and settings\NewUserAccount
  • Reboot the computer and login with your New user account.
  • Once you confirm that all your documents are located in My Documents of the New user, you can delete the old profile (And the third account you created in Step #3 if it was needed).
Hi there I tried crating a new Administrator account, when this first happened. I logged in, in both safe mode and normal mode. explorer.exe didn't work in either. I will try your suggestion tomorrow as it midnite here and i'm going to bed now. Will let you know how i get on Lee
Lee, if you already tried this I don't expect it to work any better this time.

Please check this registry key one more time:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

See if shell is set to explorer.exe
Hi There I have confirmed the Shell is set to "explorer.exe" One interesting thing.. I rerun a malware check using the malware software recommended by your malware team, and the userinit registry entry is showing as a trojan! Is that correct! Lee

Hi There

I have confirmed the Shell is set to "explorer.exe"

One interesting thing.. I rerun a malware check using the malware software recommended by your malware team, and the userinit registry entry is showing as a trojan! Is that correct!

Lee


Hi Enzo.. I browsed through your malware removal thread and I definitely see some issues there.

I'm curious as to why MBam is complaining about that userinit entry. I saw it in your malware thread also. Can you bring up your desktop by running explorer manually and then open My Computer and navigate to C:\windows\system32. Look for the file called userinit.exe. First, verify it does exist. Then, post back here with the file's size, and date last modified. I'm not a malware expert but it looks like Mbam either deleted the registry entry, or deleted the userinit.exe file all together. I've seen the userinit.exe file infected plenty of times and I suppose it is possible that it did delete that file. So, get back with on that information I asked for.

Again, I am no malware removal expert, but looking at your ComboFix logs appears to show a bunch of policies put in place by the malware that prevents your security center from monitoring things properly and also disables your windows firewall and opens up malicious ports. Its not an infection in itself, but it is some modifications made by the malware that was on your system. I'd like to make sure those were removed. Those policies can be removed with Dial-A-Fix. Please download dial-a-fix, and run it. The first thing it will do is open up a window listing several restrictive policies that have been put in place on your computer. Please remove them all and reboot your computer. Do not use any other features of dial-a-fix at this time. If it did not find any restrictive policies please let me know, because with my limited knowledge I didn't see anything in your malware removal thread about removing those policies, and I'm curious. Removing these policies will not make explorer.exe start up normally but it is one more step closer to having a properly functioning PC. Again, I am not offering malware removal advice, and am unqualified to tell you one way or another if your system is clean. But, your system has been marked clean by a malware expert in your previous thread and with that I am inclined to make sure that any other modifications or problems caused as a result of the malware are resolved.


The userinit data I requested is very important to me.

Hi, in the registry, in the same location you mentioned above, there is also a userinit entry. It should say "C:\Windows\system32\userinit.exe," (note that there is a trailing comma, it has to be there). Is this the case?


For F2, If you see UserInit=userinit.exe (notice no comma) that is still ok, so you should leave it alone. If you see another entry with userinit.exe, then that could potentially be a trojan or other malware. The same goes for F2 Shell=; if you see explorer.exe by itself, it should be fine, if you don't, as in the above example listing, then it could be a potential trojan or malware. You can generally delete these entries, but you should consult Google and the sites listed below.

Any time there's a rookit or backdoor involved, both were showing in the scans but appeared to be removed, it's impossible to be 100% sure that the machine is clean.

If that is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.
Hi All Sorry I have got back to you all. I've been working away Ok Userinit.exe size on disk 24.0KB, size 22KB created 3-8-2004 modified 18-02-2009 accessed 23-02-2009 I'll down load and run Dail a fix now Lee

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI