Question

Taskbar, desktop icons keep disappearing and reloading

Asked by: mickn66

It happens every minute.  The icons disappear from the desktop, the taskbar disappears and then they all reappear.  If I'm using an application like IE, the applications still run seemingly unaffected by the problem except a) they lose focus and b) I usually have to re-login to whatever website I was using (including this one).  We ran spybot but it found nothing.  The IT guys here at work temporarily solved the problem by creating a new windows profile for me.  The problem came back when I created new folders for Outlook - in addition to the problem coming back, I also now have the Microsoft Office Customer Experience Improvement Program in my system tray.

The first time this problem started, it started when I logged onto our server from home, at which point windows acted as if I had never logged on before (actually I had never logged on to the server before but I had been using the computer at my desk for months) - i forget what it did exactly which made me think it was acting like I had never used it before, but it included getting the Office email that you get which says "Welcome to Office" when you first start using it.

Any ideas what this problem could be?  Thanks.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2007-01-10 at 14:30:41ID22118330
Tags

disappearing

,

desktop

,

icons

,

keeps

,

taskbar

Topic

Windows XP Operating System

Participating Experts
7
Points
500
Comments
25

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Taskbar tray items disappear.
    When I start Win 2000 Pro, I can see few items in the taskbar tray area. I have time/date, language switch, volume control, ms bookshelf, WinDVD, etc. However, the minute I touch the tray with my mouse (mouseover, not mouseclick!) most of the items disappear and I am left on...
  2. Restoring the taskbar
    Hi, It appears as though my taskbar has disappeared off the screen's viewable area somewhere and I don't know how to restore it. I've tried Ctrl-Esc but nothing pops up. I've tried Ctrl-Esc-R and nothing pops up but if I then type "CMD" and press enter it opens a ...
  3. Taskbar icon disappearing
    It happens on random occasions. When I reboot my comp, if I don't drag my mouse to the taskbar (I have auto-hide on), the icons sometimes disappear on their own. I've already tried to go to properties, check and uncheck hide inactive taskbar icons, but it still doesn't work. ...
  4. SYSTEM TRAY malfunctions.
    Normally, when I boot up my computer, I would see 6 icons in the system tray at the lower right corner. Yes, 6 (not 10-15 or more). PROBLEM: 50% of the time I boot up only 1 or 2 icons appear. The rest have disappeared. If I reboot the system; suddenly, all 6 have been "...
  5. Why do these icons and taskbar keep disappearing?
    I looked at a friends Windows XP Home computer. It was running very slow to boot up. Once It fully did boot up I couldn't even get any programs to run. I went ahead and ran AdAware 2007 on it and it took alot off. However, it did not take off everything. When I selected ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: orangutangPosted on 2007-01-10 at 14:40:14ID: 18288224

Well, what's probably happening is explorer keeps crashing for some reason. Open your start menu > Control Panel > Administrative Tools > Event Viewer. Click the Application section, sort the list by type and scroll down until you see an error and send us what the message says.

 

by: orangutangPosted on 2007-01-10 at 14:45:14ID: 18288264

I have a feeling that it may be a DLL loaded in explorer that's crashing it. Download and open Process Explorer (http://download.sysinternals.com/Files/ProcessExplorer.zip), click explorer.exe, click the View DLLs icon at the top and list the DLLs that it mentions for us.

 

by: mickn66Posted on 2007-01-10 at 14:52:54ID: 18288343

You are quite right, the log shows constant crashes.  It's tough for me to read what it says because everytime it crashes the control panel and administrative tools disappear.  The error message said:

The shell stopped unexpectedly and Explorer.exe was restarted.

The source listed is always winlogin.  It happens almost every 30 seconds.  I'll try to download process explorer.

Thanks.

 

by: orangutangPosted on 2007-01-10 at 14:56:48ID: 18288389

Yeah, try Process Explorer and list the DLLs loaded in explorer.

 

by: mickn66Posted on 2007-01-10 at 14:58:33ID: 18288411

I have downloaded and run ProcessExplorer and it is showing NO dlls (I did set it to show dlls in the lower pane).

 

by: mickn66Posted on 2007-01-10 at 14:59:55ID: 18288429

Whoops - I was wrong about the no dlls thing, I didn't notice that I needed to click on explorer first.  I'll be right back with the correct info.

 

by: johnb6767Posted on 2007-01-10 at 15:04:10ID: 18288473

If you get PE to load, double click Explorer.exe as well, and look at the threads tab. Might see something odd in there also....

 

by: mickn66Posted on 2007-01-10 at 15:13:22ID: 18288591

Ok, it's showing a million dlls for explorer.  They are:
AcrolEFavClient.dll
AcrolEFavClient.dll (it's listed twice)
AcrolEHelper.dll
actpxprxy.dll
advapi32.dll
apphelp.dll
atl.dll
browselc.dll
browseui.dll
c_28951.nls
cabinet.dll
clbcatq.dll
comctl32.dll (listed twice)
comres.dll
cryp32.dll
cryptnet.dll
cryptui.dll
cscdll.dll
cscui.dll
ctype.nls
davclnt.dll
dciman32.dll
ddraw.dll
ddrawex.dll
dispex.dll
dnsapi.dll
drprov.dll
dssenh.dll
dxtmsft.dll
dxtrans.dll
Flash8.ocx
Flash8.ocx
gdi32.dll
hnetcfg.dll
iepeers.dll
iepeers.dll
iexplorer.exe
imagehlp.dll
imgutil.dll
imm32.dll
index.dat (listed 3 times)
idhlpapi.dll
javacypt.dll
javart.dll
jit.dll
jscript.dll
kernel32.dll
linkinfo.dll
locale.nls
mfc42.dll
midimap.dll
mlang.dll
mpr.d;;
msacm32.dll
mscacm32.drv
msasn1.dll
msawt.dll
msctf.dll
mshtml.dll
mshtml.tlb
mshtmled.dll
MSIMGSIZ.DAT
msimtf.dll
msjava.dll
msls31.dll
MSOHEV.DLL
msc1_0.dll
msvcp60.dll
msvcrt.dll
mswsock.dll
msxml3.dll (twice)
msxml3r.dll
netapi32.dll
netrap.dll
netui0.dll
netui1.dll
ntdll.dll
ntlanman.dll
ntshrui.dll
ole32.dll
oleaut32.dll
olepro.dll
plugin.ocx
pngfilt.dll
R000000000007.clb
rasadhlp.dll
rasapi32.dll
rasman.dll
rpcrt4.dll
rsawnh.dll
rtutils.dll
samlib.dll
schannel.dll
SDHelper.dll
secur32.dll
sensapi.dll
setupapi.dll
shdoclc.dll
shdocvw.dll (twice)
shell32.dll
shlwapi.dll
softpub.dll
sortkey.nls
sorttbls.nls
stdole2.tlb
sxs.dll
tapi32.dll
unicode.nls
urlmon.dll
user32.dll
userenv.dll
uxtheme.dll
vbscript.dll
version.dll
vmhelper.dll
wdmaud.drv
winhttp.dll
wininet.dll
winmm.dll
winrnr.dll
winspool.drv
wintrust.dll
wldap32.dll
ws2_32.dll
ws2help.dll
wshtcpip.dll
wsock32.dll
xpsp2res.dll

Phew! That's it.

 

by: johnb6767Posted on 2007-01-10 at 15:18:38ID: 18288643

assuming this was a typo?

mpr.d;;

 

by: mickn66Posted on 2007-01-10 at 15:21:58ID: 18288673

The threads tab shows:
iexplorer.exe+0x2451
WININET.dll!InternetSetStatusCallback+0x1ca
ntdl.dll!RtlQueueWorkItem+0x2b5
ntdll.dll!RtlAllocateHeap+0x18c
wdmaud.drv!midMessage+0x306
WINMM.dll!PlaySoundW+0x77f
ntdll.dll!RtlDowncaseUnicodeString+0x75
USERENV.dll!UnregisterGPNotification+0x100
dxtrans.dll+0xad26 (listed twice)
msjava.dll!DllGetClassObject+0x164d
msjava.dll!DllGetClassObject+0x2b1d
msjava.dll!java_lang_Thread_onSetName+0x574 (listed twice)
mshtml.dll+0xe6c9b
BROWSEUI.dll!Ordinal107+0xbece
kernel32.dll!CreateThread+0x27

Thanks again everyone

 

by: mickn66Posted on 2007-01-10 at 15:23:08ID: 18288687

Yes, mpr.d;; was a typo, it should have been mpr.dll

 

by: mickn66Posted on 2007-01-10 at 15:24:51ID: 18288700

BY the way, the problem has gotten worse and it looks like the desktop is just plain gone - although the applications are still running (I'm using gotomypc right now and hooking up with my home computer, which I have logged into EE which is how I'm communicating with you right now.)  I'll have to reboot.

 

by: johnb6767Posted on 2007-01-10 at 15:44:33ID: 18288852

iexplorer.exe+0x2451

Internet explorer doesnt use a file by that name....

I would search for it, pull up a rt click>properties, and verify it is not a vaild needed app and delete it....

Any chance you can get us a Hijack This Log ?

 

by: johnb6767Posted on 2007-01-10 at 15:46:07ID: 18288866

Also, in the registry

start>run>regedit

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Take a look at the Shell= Value on the right. Make sure it is only (no qoutes) "Explorer.exe"

Sometimes applications piggyback "explorer.exe;badfilename.exe" etc....

 

by: orangutangPosted on 2007-01-10 at 15:50:09ID: 18288894

Also try running the contents of the batch file in http://www.experts-exchange.com/Operating_Systems/WinXP/Q_22105442.html

 

by: orangutangPosted on 2007-01-10 at 15:53:07ID: 18288920

Yeah, iexplore.exe seems to be acting as a DLL which is kind of weird. Copy and paste the properties of the DLL from the DLL View.

 

by: mickn66Posted on 2007-01-10 at 15:56:30ID: 18288940

Thanks a lot guys - unfortunately (or fortunately I should say) I am no longer at work in front of that computer.  I half hope we can't fix it so they'll get me a new computer, but I like trying to solve problems like this.  Also they probably won't get me a new computer so....I'll post the requested information tomorrow.  Thanks again!

 

by: rpggamergirlPosted on 2007-01-10 at 16:21:17ID: 18289188

iexplorer.exe <-- no this shouldn't be there.

Can we look at a hijackthis log as already suggested. The bad entries that shows up in the log can tell us if it is a part of an infection or just a lone virus.

Please download HijackThis 1.99.1
http://www.cyberanswers.org/forum/uploads/HijackThis1991.exe
http://danborg.org/spy/hjt/alternativ.exe
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.

Please download HijackThis 1.99.1
http://www.cyberanswers.org/forum/uploads/HijackThis1991.exe
http://danborg.org/spy/hjt/alternativ.exe
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.

You can upload the log at any hosting sites or these below:
1. http://www.ee-stuff.com

2. http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here.

3.  http://www.hijackthis.de/
and click "Analyse", click "Save".  Then post the link to the saved list here.

 

by: mickn66Posted on 2007-01-11 at 05:52:54ID: 18292431

I want to thank everybody for their help.  Unfortunately, my office has "solved" the problem by giving me a different machine (not a new one as I had hoped, but a different machine) which does not have the problem.  Consequently we can't work any more on solving this problem.  Since we did get somewhere, which may help others if they have a similar problem, I'll distribute the points anyway.

 

by: dwaynehenryPosted on 2007-11-04 at 21:50:46ID: 20214061

Logfile of HijackThis v1.99.1
Scan saved at 12:48:59 AM, on 11/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\V2VnZ29uIFNtYWxs\command.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Monitor\netmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Zune\ZuneNss.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\mrofinu1188.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\explorer.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\WinAble\winable.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\HijackThis 1.99.1\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.imesh.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: Mirar - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\version69ie7fix.dll
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SeekmoToolbar] C:\Program Files\SeekmoToolbar\Bin\4.8.4.0\${HOOKOE_FILE}
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Optimum Online net guide] "C:\Program Files\Optimum Online\Netsurf.exe" -trayicon
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135715071\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Words] C:\Program Files\Words\Words.exe
O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\Weggon Small\Application Data\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Super Utilities] C:\Program Files\SuperLogix\Super Utilities\SuperUtil.exe /min
O4 - HKCU\..\Run: [Poke Dead] C:\DOCUME~1\WEGGON~1\APPLIC~1\GLOBAL~1\Liveshow.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [License Manager] "C:\Program Files\License_Manager\license_manager.exe " /silent
O4 - HKCU\..\Run: [Insider] C:\Program Files\Insider\Insider.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: EarthLink Google Search - res://C:\Program Files\Bank Of America\Toolbar\SearchUI.dll/search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://connect.jpmorganchase.com/dana-cached/setup/JuniperSetupSP1.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/winantispyware.com/www/download/2006/WinAntiSpyware2006FreeInstall.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\geebxxy.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\V2VnZ29uIFNtYWxs\command.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qwerty12.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

 

by: dwaynehenryPosted on 2007-11-04 at 21:51:22ID: 20214063

this seems to be my issue, can someone please help me with a solution?
Thank you

 

by: orangutangPosted on 2007-11-04 at 22:50:17ID: 20214282

These seem suspicious:

C:\WINDOWS\V2VnZ29uIFNtYWxs\command.exe
C:\WINDOWS\mrofinu1188.exe
Also, the 6 "explorer.exe"s seem suspicious

I'm kind of confused on if you still need the problem solved or not but try SUPERAntispyware (http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE)

 

by: fedrich519Posted on 2007-11-13 at 09:11:28ID: 20273092

Wanted to throw in my two cents on this one.  This thread is the reason I joined this site because I was having the EXACT same problem, right down to the last detail.  When my computer would boot up, Explorer would refresh the taskbar and icons every 15 to 20 seconds, this would go on for about 10 minutes and then Explorer would just vanish completely.  I would then have to run all commands thru Task Manager, just like the original problem in this thread, I could run applications just fine like everything was normal, save for the fact that Explorer was unaccessible.

I can tell you with certainty the cause of the problem:

Smitfraud and Virtumonde (aka Vundo)

The problem started with SpyGuardPro (a variant of Smitfraud)  trying to install itself at startup, I fought to stop the install and kill the processes and delete temp files and other measures.  I was able to stop the install but the damage was done.

I ran the following programs with no results...

Spybot SD
Ad-Aware
Spysweeper
PC Tools Anti-Virus

Spybot would at least find Vundo and delete it, but would still be on the computer at reboot. I used VundoFix and it found Vundo and after a reboot Vundo was gone. (I should also note I first used FxVMonde and it found nothing)  I used the online scanner House Call from Trend Micro.  It was successful it cleaning up the computer but it turned out to be a temporary fix, the same problem reared its ugly head again three days later.  Vundo showed up again and so did Smitfraud.

This time around I was more successful.  

Like a dummy I realized I had System Restore enabled on ALL my hard drives, internal and external.  Once I found the same hidden adware folder on every single hard drive I also realized that like a dummy I hadn't scanned any of the hard drives other than the C drive.  So obviously my first step was to disable System Restore and remember to include all the hard drives in future scans.

I rebooted into Safe Mode and ran SDFix (for Smitfraud).  I then did the same for SmitFraudFix in Safe Mode. Once that was done, I again rebooted into Safe Mode and ran ComboFix (I realize the author of that program suggests not running it because of a rootkit, but Spysweeper was running when I ran the program and picked up the problem).  I should also note that running Spysweeper in conjunction with these programs was helpful because when they attempted to delete files, several hidden DLLs would pop up and try to change the registry at startup, Spysweeper was able to stop all of them from doing so.

Once all three of those ran I the computer booted up normally and everything seemed fine but I still had all the hard drives that hadn't been scanned for threats.  That made me nervous and fearful that the problem would came back after a couple of days so I had to do something.  

The answer to all my problems was found in a wonderful program that I can't believe I had never heard of.  This program was suggested in this thread and in many other threads on this board relating to the similar issues.

SUPERAntispyware.

Wow, what an amazing program.  It did what the combined efforts of Spybot, Ad-Aware, and Spysweeper could not do.  I scanned every hard drive on my system and it appeared that SmitFraudFix and SDFix did their jobs because Smitfraud was gone, but the nasty that is Vundo was still going very strong, it was all over the place.  SUPERAntispyware found over 50 problems, around 40 of those problems were Vundo.  After a cleaning and reboot, the computer worked fine.  Just to be safe, I ran a full scan with SUPERAntispyware again and it came up with no problems.

Just wanted to be helpful to anyone out there that might be experiencing the same problems.




 

by: adamjcPosted on 2007-11-17 at 13:20:00ID: 20305421

I have been seeing this problem in IE 6.0 for the past week, pretty much whenever I open a content-rich page.  It's especially bad on foxnews.  After the page first displays, there's about a two-second delay before the page refreshes (not quite a reload) and I can navigate the page.  When I pop up Process Explorer (from sysinternals.com) during the delay, the thread "iexplore+0x2451" is chomping CPU time.

 

by: Ron_WellsPosted on 2008-06-09 at 11:38:15ID: 21745463

fedrich519 gave me all the clues that I needed to fix the same problem in Vista.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...