Jump to content

Windows Explorer has Encountered a Problem, Please help with a Highjac


Artlee
 Share

Recommended Posts

Hello, this is my first post. I needed some help with my Windows PC as this problem has been bugging me for months already. The problem goes like this: error messages like "WINDOWS EXPLORER HAS ENCOUNTERED A PROBLEM AND NEEDS TO CLOSE" randomly appears regardless of what action I was doing with the computer at that moment.

I've got Avira Premium Security Suite installed with firewall enabled and also have A-Squared Anti-malware installed. Both have not detected any viruses, worms, trojans, etc.. What exactly is the problem causing this error message to appear again and again? I have also ran CCleaner and fixed all issues, still the problem persists.

I shall show you all the HijackThis Logfile below:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 2:21:48 PM, on 10/1/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\Avira Premium Security Suite\sched.exe

C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe

C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\a2guard.exe

C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\Lee Tai Meng\Local Settings\Application

Data\Google\Update\GoogleUpdate.exe

C:\Program Files\Nikon\PictureProject\NkbMonitor.exe

C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe

C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe

C:\Program Files\a-squared Anti-Malware\a2service.exe

C:\Program Files\ActiveFax\Server\ActSrvNT.exe

C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe

C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe

C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\PSIService.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\WINDOWS\System32\Tablet.exe

C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe

C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE

C:\WINDOWS\System32\alg.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://www.dell.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL

= http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157

O1 - Hosts: 127.0.0.0 traffstats.biz

O1 - Hosts: 127.0.0.0 ybbwxlxytz.biz

O1 - Hosts: 126.0.0.0 traffstats.biz

O1 - Hosts: 126.0.0.0 ybbwxlxytz.biz

O1 - Hosts: 127.0.0.0 tongji123.com

O1 - Hosts: 126.0.0.0 tongji123.com

O2 - BHO: (no name) - {0000AC13-3487-1583-C4BE-BE6A839DB000} - (no

file)

O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-

FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-

784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} -

C:\PROGRA~1\FlashGet\jccatch.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -

C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no

file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -

C:\PROGRA~1\FlashGet\fgiebar.dll

O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} -

C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll

O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no

file)

O4 - HKLM\..\Run: [Nitro PDF Printer Monitor] "C:\Program Files\Nitro

PDF\Professional\NitroPDFPrinterMonitor.exe"

O4 - HKLM\..\Run: [a-squared] "C:\PROGRAM FILES\A-SQUARED ANTI-

MALWARE\a2guard.exe" /d=60

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Avira Premium

Security Suite\avgnt.exe" /min

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1

\YAHOOM~1.EXE" -quiet

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Lee Tai

Meng\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program

Files\Nikon\PictureProject\NkbMonitor.exe

O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32

\WTablet\TabUserW.exe

O8 - Extra context menu item: &eBay Search - res://C:\Program

Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html

O8 - Extra context menu item: Download All by FlashGet - C:\Program

Files\FlashGet\jc_all.htm

O8 - Extra context menu item: Download using FlashGet - C:\Program

Files\FlashGet\jc_link.htm

O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-

AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -

C:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-

0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-

4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-

0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-

B5C9-0050045C3C96} - C:\Program Files\Yahoo!

\Messenger\YahooMessenger.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-

BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} -

http://download.ebay.com/turbo_lister/US/install.cab

O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class)

- http://www.symantec.com/techsupp/activedata/nprdtinf.cab

O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner

Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab

O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download

Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} -

https://a248.e.akamai.net/f/248/5462/2h/www...store.com/v2.0-

img/operations/symbizpr/xcontrol/SymDlBrg.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{B8D3EE64-20C0-4B6B-9354-

80A68666B73F}: NameServer = 202.188.0.133 202.188.1.5

O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi

Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe

O23 - Service: ActiveFax-Server-Service (ActiveFaxServiceNT) - ActFax

Communication - C:\Program Files\ActiveFax\Server\ActSrvNT.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program

Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Avira Premium Security Suite Firewall

(AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\Avira

Premium Security Suite\avfwsvc.exe

O23 - Service: Avira Premium Security Suite MailGuard

(AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\Avira

Premium Security Suite\avmailc.exe

O23 - Service: Avira Premium Security Suite Scheduler

(AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\Avira Premium

Security Suite\sched.exe

O23 - Service: Avira Premium Security Suite Guard (AntiVirService) -

Avira GmbH - C:\Program Files\Avira\Avira Premium Security

Suite\avguard.exe

O23 - Service: Avira Premium Security Suite WebGuard

(antivirwebservice) - Avira GmbH - C:\Program Files\Avira\Avira Premium

Security Suite\AVWEBGRD.EXE

O23 - Service: Avira Premium Security Suite MailGuard helper service

(AVEService) - Avira GmbH - C:\Program Files\Avira\Avira Premium

Security Suite\avesvc.exe

O23 - Service: BCL easyPDF SDK 5 Loader (bepldr) - Unknown owner -

C:\Program Files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe

O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown

owner - C:\Program Files\FileZilla Server\FileZilla Server.exe (file

missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050

\Intel 32\IDriverT.exe

O23 - Service: Intel NCS NetService (NetSvc) - IntelĀ® Corporation -

C:\Program Files\Intel\NCS\Sync\NetSvc.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32

\PSIService.exe

O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft -

C:\Program Files\ReaConverter 5.0 Pro\rcp_scheduler.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental)

(rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program

Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: TabletService - Wacom Technology, Corp. -

C:\WINDOWS\System32\Tablet.exe

O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-

nt.exe (file missing)

--

End of file - 9829 bytes

Does the above logfile help in any way? Do you need me to supply any other information about my PC?

Oh, by the way, I should let you all view the screenshot of the windows explorer error message, though it doesn't signify anything in my opinion.

post-12717-1222843269_thumb.jpg

post-12717-1222843300_thumb.jpg

I am not a computer expert, so please help me in every single step you can. Thanks in advance to this forum and all the members.

Link to comment
Share on other sites

Welcome to the Windows Forum.

We currently do not have the capacity to analyze HJT logs, so your posting of the log doesn't help here.

However, can you open the Event Viewer and see if there are any entries/details for the time when it happened last? (See here how to use the Event Viewer.)

Link to comment
Share on other sites

I'm not a HJT specialist - but nothing obviously wrong except that your Java is 4 releases out of date.

BTW - the original plain text formatting of your HJT log has been somewhat messed about in copying/pasting ?

e.g.

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-

4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

really needs to look like this :-

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
Link to comment
Share on other sites

Hello, any Hijack This Specialist here?? I am desperately in need of an expert's help now... Anyone, please offer me some advice? Or perhaps give me a couple links to some special guide? Awaiting good news......

I gave you a link to a site which can handle such logs. As Pat says have you read the replies? :D

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy