I have a feeling that it may be a DLL loaded in explorer that's crashing it. Download and open Process Explorer (http://download.sysintern
Main Topics
Browse All TopicsIt happens every minute. The icons disappear from the desktop, the taskbar disappears and then they all reappear. If I'm using an application like IE, the applications still run seemingly unaffected by the problem except a) they lose focus and b) I usually have to re-login to whatever website I was using (including this one). We ran spybot but it found nothing. The IT guys here at work temporarily solved the problem by creating a new windows profile for me. The problem came back when I created new folders for Outlook - in addition to the problem coming back, I also now have the Microsoft Office Customer Experience Improvement Program in my system tray.
The first time this problem started, it started when I logged onto our server from home, at which point windows acted as if I had never logged on before (actually I had never logged on to the server before but I had been using the computer at my desk for months) - i forget what it did exactly which made me think it was acting like I had never used it before, but it included getting the Office email that you get which says "Welcome to Office" when you first start using it.
Any ideas what this problem could be? Thanks.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I have a feeling that it may be a DLL loaded in explorer that's crashing it. Download and open Process Explorer (http://download.sysintern
You are quite right, the log shows constant crashes. It's tough for me to read what it says because everytime it crashes the control panel and administrative tools disappear. The error message said:
The shell stopped unexpectedly and Explorer.exe was restarted.
The source listed is always winlogin. It happens almost every 30 seconds. I'll try to download process explorer.
Thanks.
Ok, it's showing a million dlls for explorer. They are:
AcrolEFavClient.dll
AcrolEFavClient.dll (it's listed twice)
AcrolEHelper.dll
actpxprxy.dll
advapi32.dll
apphelp.dll
atl.dll
browselc.dll
browseui.dll
c_28951.nls
cabinet.dll
clbcatq.dll
comctl32.dll (listed twice)
comres.dll
cryp32.dll
cryptnet.dll
cryptui.dll
cscdll.dll
cscui.dll
ctype.nls
davclnt.dll
dciman32.dll
ddraw.dll
ddrawex.dll
dispex.dll
dnsapi.dll
drprov.dll
dssenh.dll
dxtmsft.dll
dxtrans.dll
Flash8.ocx
Flash8.ocx
gdi32.dll
hnetcfg.dll
iepeers.dll
iepeers.dll
iexplorer.exe
imagehlp.dll
imgutil.dll
imm32.dll
index.dat (listed 3 times)
idhlpapi.dll
javacypt.dll
javart.dll
jit.dll
jscript.dll
kernel32.dll
linkinfo.dll
locale.nls
mfc42.dll
midimap.dll
mlang.dll
mpr.d;;
msacm32.dll
mscacm32.drv
msasn1.dll
msawt.dll
msctf.dll
mshtml.dll
mshtml.tlb
mshtmled.dll
MSIMGSIZ.DAT
msimtf.dll
msjava.dll
msls31.dll
MSOHEV.DLL
msc1_0.dll
msvcp60.dll
msvcrt.dll
mswsock.dll
msxml3.dll (twice)
msxml3r.dll
netapi32.dll
netrap.dll
netui0.dll
netui1.dll
ntdll.dll
ntlanman.dll
ntshrui.dll
ole32.dll
oleaut32.dll
olepro.dll
plugin.ocx
pngfilt.dll
R000000000007.clb
rasadhlp.dll
rasapi32.dll
rasman.dll
rpcrt4.dll
rsawnh.dll
rtutils.dll
samlib.dll
schannel.dll
SDHelper.dll
secur32.dll
sensapi.dll
setupapi.dll
shdoclc.dll
shdocvw.dll (twice)
shell32.dll
shlwapi.dll
softpub.dll
sortkey.nls
sorttbls.nls
stdole2.tlb
sxs.dll
tapi32.dll
unicode.nls
urlmon.dll
user32.dll
userenv.dll
uxtheme.dll
vbscript.dll
version.dll
vmhelper.dll
wdmaud.drv
winhttp.dll
wininet.dll
winmm.dll
winrnr.dll
winspool.drv
wintrust.dll
wldap32.dll
ws2_32.dll
ws2help.dll
wshtcpip.dll
wsock32.dll
xpsp2res.dll
Phew! That's it.
The threads tab shows:
iexplorer.exe+0x2451
WININET.dll!InternetSetSta
ntdl.dll!RtlQueueWorkItem+
ntdll.dll!RtlAllocateHeap+
wdmaud.drv!midMessage+0x30
WINMM.dll!PlaySoundW+0x77f
ntdll.dll!RtlDowncaseUnico
USERENV.dll!UnregisterGPNo
dxtrans.dll+0xad26 (listed twice)
msjava.dll!DllGetClassObje
msjava.dll!DllGetClassObje
msjava.dll!java_lang_Threa
mshtml.dll+0xe6c9b
BROWSEUI.dll!Ordinal107+0x
kernel32.dll!CreateThread+
Thanks again everyone
BY the way, the problem has gotten worse and it looks like the desktop is just plain gone - although the applications are still running (I'm using gotomypc right now and hooking up with my home computer, which I have logged into EE which is how I'm communicating with you right now.) I'll have to reboot.
Also try running the contents of the batch file in http://www.experts-exchang
Thanks a lot guys - unfortunately (or fortunately I should say) I am no longer at work in front of that computer. I half hope we can't fix it so they'll get me a new computer, but I like trying to solve problems like this. Also they probably won't get me a new computer so....I'll post the requested information tomorrow. Thanks again!
iexplorer.exe <-- no this shouldn't be there.
Can we look at a hijackthis log as already suggested. The bad entries that shows up in the log can tell us if it is a part of an infection or just a lone virus.
Please download HijackThis 1.99.1
http://www.cyberanswers.or
http://danborg.org/spy/hjt
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.
Please download HijackThis 1.99.1
http://www.cyberanswers.or
http://danborg.org/spy/hjt
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.
You can upload the log at any hosting sites or these below:
1. http://www.ee-stuff.com
2. http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here.
3. http://www.hijackthis.de/
and click "Analyse", click "Save". Then post the link to the saved list here.
I want to thank everybody for their help. Unfortunately, my office has "solved" the problem by giving me a different machine (not a new one as I had hoped, but a different machine) which does not have the problem. Consequently we can't work any more on solving this problem. Since we did get somewhere, which may help others if they have a similar problem, I'll distribute the points anyway.
Logfile of HijackThis v1.99.1
Scan saved at 12:48:59 AM, on 11/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\spools
C:\PROGRA~1\COMMON~1\AOL\A
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\WINDOWS\system32\cisvc.
C:\WINDOWS\V2VnZ29uIFNtYWx
C:\WINDOWS\System32\svchos
C:\Program Files\Network Monitor\netmon.exe
C:\PROGRA~1\TRENDM~1\INTER
C:\PROGRA~1\TRENDM~1\INTER
C:\PROGRA~1\TRENDM~1\INTER
C:\Program Files\Zune\ZuneNss.exe
C:\PROGRA~1\TRENDM~1\INTER
C:\WINDOWS\System32\alg.ex
C:\WINDOWS\system32\cidaem
C:\WINDOWS\system32\ctfmon
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\WINDOWS\system32\dla\tf
C:\WINDOWS\Fonts\svchost.e
C:\WINDOWS\mrofinu1188.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre1.6.0_03\bin
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Common Files\InstallShield\Update
C:\WINDOWS\explorer.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\WinAble\winable.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\HijackThis 1.99.1\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A
O3 - Toolbar: Mirar - {9A9C9B68-F908-4AAB-8D0C-1
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.e
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1188.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SeekmoToolbar] C:\Program Files\SeekmoToolbar\Bin\4.
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Optimum Online net guide] "C:\Program Files\Optimum Online\Netsurf.exe" -trayicon
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135715071\ee\AO
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\D
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.ex
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [Words] C:\Program Files\Words\Words.exe
O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\Weggon Small\Application Data\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
O4 - HKCU\..\Run: [Super Utilities] C:\Program Files\SuperLogix\Super Utilities\SuperUtil.exe /min
O4 - HKCU\..\Run: [Poke Dead] C:\DOCUME~1\WEGGON~1\APPLI
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [License Manager] "C:\Program Files\License_Manager\lice
O4 - HKCU\..\Run: [Insider] C:\Program Files\Insider\Insider.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.e
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\Yah
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.htm
O8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
O8 - Extra context menu item: EarthLink Google Search - res://C:\Program Files\Bank Of America\Toolbar\SearchUI.d
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.c
O15 - Trusted Zone: http://redirect.mirarsearc
O15 - Trusted Zone: http://awbeta.net-nucleus.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-0
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1
O16 - DPF: {F919FBD3-A96B-4679-AF26-F
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8
O20 - AppInit_DLLs: c:\windows\system32\geebxx
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-9
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\A
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.e
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\V2VnZ29uIFNtYWx
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qwerty
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\Freeze
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NC
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTER
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTER
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTER
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTER
These seem suspicious:
C:\WINDOWS\V2VnZ29uIFNtYWx
C:\WINDOWS\mrofinu1188.exe
Also, the 6 "explorer.exe"s seem suspicious
I'm kind of confused on if you still need the problem solved or not but try SUPERAntispyware (http://www.superantispywa
Wanted to throw in my two cents on this one. This thread is the reason I joined this site because I was having the EXACT same problem, right down to the last detail. When my computer would boot up, Explorer would refresh the taskbar and icons every 15 to 20 seconds, this would go on for about 10 minutes and then Explorer would just vanish completely. I would then have to run all commands thru Task Manager, just like the original problem in this thread, I could run applications just fine like everything was normal, save for the fact that Explorer was unaccessible.
I can tell you with certainty the cause of the problem:
Smitfraud and Virtumonde (aka Vundo)
The problem started with SpyGuardPro (a variant of Smitfraud) trying to install itself at startup, I fought to stop the install and kill the processes and delete temp files and other measures. I was able to stop the install but the damage was done.
I ran the following programs with no results...
Spybot SD
Ad-Aware
Spysweeper
PC Tools Anti-Virus
Spybot would at least find Vundo and delete it, but would still be on the computer at reboot. I used VundoFix and it found Vundo and after a reboot Vundo was gone. (I should also note I first used FxVMonde and it found nothing) I used the online scanner House Call from Trend Micro. It was successful it cleaning up the computer but it turned out to be a temporary fix, the same problem reared its ugly head again three days later. Vundo showed up again and so did Smitfraud.
This time around I was more successful.
Like a dummy I realized I had System Restore enabled on ALL my hard drives, internal and external. Once I found the same hidden adware folder on every single hard drive I also realized that like a dummy I hadn't scanned any of the hard drives other than the C drive. So obviously my first step was to disable System Restore and remember to include all the hard drives in future scans.
I rebooted into Safe Mode and ran SDFix (for Smitfraud). I then did the same for SmitFraudFix in Safe Mode. Once that was done, I again rebooted into Safe Mode and ran ComboFix (I realize the author of that program suggests not running it because of a rootkit, but Spysweeper was running when I ran the program and picked up the problem). I should also note that running Spysweeper in conjunction with these programs was helpful because when they attempted to delete files, several hidden DLLs would pop up and try to change the registry at startup, Spysweeper was able to stop all of them from doing so.
Once all three of those ran I the computer booted up normally and everything seemed fine but I still had all the hard drives that hadn't been scanned for threats. That made me nervous and fearful that the problem would came back after a couple of days so I had to do something.
The answer to all my problems was found in a wonderful program that I can't believe I had never heard of. This program was suggested in this thread and in many other threads on this board relating to the similar issues.
SUPERAntispyware.
Wow, what an amazing program. It did what the combined efforts of Spybot, Ad-Aware, and Spysweeper could not do. I scanned every hard drive on my system and it appeared that SmitFraudFix and SDFix did their jobs because Smitfraud was gone, but the nasty that is Vundo was still going very strong, it was all over the place. SUPERAntispyware found over 50 problems, around 40 of those problems were Vundo. After a cleaning and reboot, the computer worked fine. Just to be safe, I ran a full scan with SUPERAntispyware again and it came up with no problems.
Just wanted to be helpful to anyone out there that might be experiencing the same problems.
I have been seeing this problem in IE 6.0 for the past week, pretty much whenever I open a content-rich page. It's especially bad on foxnews. After the page first displays, there's about a two-second delay before the page refreshes (not quite a reload) and I can navigate the page. When I pop up Process Explorer (from sysinternals.com) during the delay, the thread "iexplore+0x2451" is chomping CPU time.
Business Accounts
Answer for Membership
by: orangutangPosted on 2007-01-10 at 14:40:14ID: 18288224
Well, what's probably happening is explorer keeps crashing for some reason. Open your start menu > Control Panel > Administrative Tools > Event Viewer. Click the Application section, sort the list by type and scroll down until you see an error and send us what the message says.