kristal79
asked on
How can I get my desktop back?
I am running Windows XP, when I start up, i get to the log on screen as normal, when I click on the icon to get into the desktop the error message "userinit.exe - Application Error The application failed to initialize properly (0xc0000005). Click on ok to terminate the application." If I push ok, the same message appears again. Click ok again and my desktop background appears, but with no icons or start menu (no taskbar at all). I have already run Spybot S&D, SUPERAntispyware and Avast Antivirus - lots of stuff found and quarantined or deleted. Problem still exists. Being a beginer in all of this, am looking for some advice. I am able to run programs though ctrl alt delete Task Manager,
ASKER
Hi, ok, downloaded Hijack This and here is the log file.
log1.txt
log1.txt
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Right, problems straight away, I tried to save the SDFix to the desktop - it asked if I wanted to open the folder after it had finished, so I clicked yes, it gave me this error message "rundll32.exe - Application Error The application failed to initialize properly (0xc0000005). Click ok to terminate application" , similar to the other one. So I clicked ok, then I got this message " Windows cannot find c:\Documents and Settings\Kristal\Desktop\S DFix.Zip. Make sure you typed the name correctly and then try again. To search for a file click the start button and then click search" .
So I thought I'd try to save it directly on the hardrive, seing how my desktop is a bit nonexistent at the moment, but I got the same message when I tried to open the folder, except obviously, the location was different. Any way you know of that I can get the application up and running?
So I thought I'd try to save it directly on the hardrive, seing how my desktop is a bit nonexistent at the moment, but I got the same message when I tried to open the folder, except obviously, the location was different. Any way you know of that I can get the application up and running?
Do you have another pc with internet access?
Try downloading SDFix from another pc and extracting it first before putting it into the infected pc and see if it runs.
If you don't have access to another pc, download it but rename it straightaway before extracting.
If it still won't run, try combofix and IF combofix also won't run, then rename combofix before saving it. Let us know how you go.
Try downloading SDFix from another pc and extracting it first before putting it into the infected pc and see if it runs.
If you don't have access to another pc, download it but rename it straightaway before extracting.
If it still won't run, try combofix and IF combofix also won't run, then rename combofix before saving it. Let us know how you go.
I dont feel this is due to spyware. Have you did a check disk or a memory scan? If you have a Dell you can boot up using F12 and boot into the diag mode and run it from there. If not go here http://memtest86.com
If the corruption was bad enuff from either a bad HDD or mem then the userinit.exe file might have to be replaced but we'll cross that bridge was you deem one of those defective.
let me know how you make out.
If the corruption was bad enuff from either a bad HDD or mem then the userinit.exe file might have to be replaced but we'll cross that bridge was you deem one of those defective.
let me know how you make out.
Can you check event viewer? and tell us if you have any error msgs marked with red or yellow marks.
Attach them here in a notepad (Text) file..
Attach them here in a notepad (Text) file..
Can you also disconnect any USB cable that's connected to your computer and restart with nothing connected to it.... See if the problem still persist?
Have you tried a system restore to an earlier point when the system was running?
kristal79,
How did you go?
You need to extract SDFix first from another pc before putting it in the infected PC as some nasties can prevent it from running, thus also with the "cannot find SDFix error" After it's been extracted, then it will run, it's only before it's been extracted that nasties can interfere with it.
If Bagle or a similar nasties is present, then combofix might not also run unless renamed.
NOTE: this is very important, while saving Combofix.exe to your desktop, you need to rename it to Combo-Fix.exe (see the difference?) you need to rename it before you actually download to your desktop otherwise Bagle or any nasties will jump in.)
Renaming Combofix when it is already in your desktop will not work....you need to rename it BEFORE it is actually downloaded to your desktop.(rename as you are saving it)
Disable your antivirus,
After Combo-fix is on your desktop,
From the run box type the following:
"%userprofile%\desktop\Com boFix.exe" /KillAll
How did you go?
You need to extract SDFix first from another pc before putting it in the infected PC as some nasties can prevent it from running, thus also with the "cannot find SDFix error" After it's been extracted, then it will run, it's only before it's been extracted that nasties can interfere with it.
If Bagle or a similar nasties is present, then combofix might not also run unless renamed.
NOTE: this is very important, while saving Combofix.exe to your desktop, you need to rename it to Combo-Fix.exe (see the difference?) you need to rename it before you actually download to your desktop otherwise Bagle or any nasties will jump in.)
Renaming Combofix when it is already in your desktop will not work....you need to rename it BEFORE it is actually downloaded to your desktop.(rename as you are saving it)
Disable your antivirus,
After Combo-fix is on your desktop,
From the run box type the following:
"%userprofile%\desktop\Com
ASKER
Hello again - sorry for leaving this so long, was out of town. Right, have had some success!! I managed to run both SDfix and Combo Fix. Have attached the logs, ran combofix twice as we had a power failure and wasn't sure if scan completed, looks like it did however. So here are the logs and hijack this log as well. Thanks to all for the advice. My icons are back on the desktop, however, I am still getting some strange error messages (Rundll Application error messages) when logging on. Also, not sure what happened, but my SUPERAntispyware will no longer open up. Couldn't even disable it to run the Combofix. Tried to uninstall so I could reinstall, but will not let me. Not sure what is happening there. Let me know how my logs look. It's all greek to me.
And in reply to some of the other posts, I did try system restore, didn't work.
I don't have a Dell computer, so i downloaded the memtest86 from the above link, not sure how to use it though, when I open it, it asks me to enter the target diskette drive?? I don't have a diskette drive, and when I put in a cdrom and told it the d drive, it didn't seem to do anything. Any advice on how to work it??
I have attached copies of my event viewer lists as there were heaps of red and yellow errors and warnings in the various places. Have attached all those lists. Thanks again for everyones advice on this.
Combofix-log1.txt
Combofix-Log2.txt
SDFix-Report1.txt
hijackthis2.txt
Event-Viewer---Applications.txt
Event-Viewer---Antivirus.txt
Event-Viewer---System.txt
And in reply to some of the other posts, I did try system restore, didn't work.
I don't have a Dell computer, so i downloaded the memtest86 from the above link, not sure how to use it though, when I open it, it asks me to enter the target diskette drive?? I don't have a diskette drive, and when I put in a cdrom and told it the d drive, it didn't seem to do anything. Any advice on how to work it??
I have attached copies of my event viewer lists as there were heaps of red and yellow errors and warnings in the various places. Have attached all those lists. Thanks again for everyones advice on this.
Combofix-log1.txt
Combofix-Log2.txt
SDFix-Report1.txt
hijackthis2.txt
Event-Viewer---Applications.txt
Event-Viewer---Antivirus.txt
Event-Viewer---System.txt
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Regarding the Memtest, you should burn an image copy to CD ... I believe that memtest offers a bootable CD so when you reboot with the CD inserted you will be redirected to their program upon restarting.
More information are available here:
http://www.playtool.com/pages/memtest/memtest.html
More information are available here:
http://www.playtool.com/pages/memtest/memtest.html
The rundll32.exe error messages is just a left over reg entry left behind. The SUPERAntispyware must've been corrupted, you can just reinstall that one and see if that fixes it.
You can also use Combofix CFScript to remove the leftovers instead of manually deleting them.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
-------------------------- ---------- ---------- ---------- ---------- ------
Folder::
C:\WINDOWS\VG9kZA
C:\Documents and Settings\Todd\!
C:\WINDOWS\system32\xnA
C:\WINDOWS\system32\3056v
Registry::
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"{4e49c2af-a419-4e58-b427- 18e9ffbb0a d9}"=-
"BM675c9811"=-
"{FA-AB-B2-22-DW}"=-
-------------------------- ---------- ---------- ---------- ---------- ------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
You can also use Combofix CFScript to remove the leftovers instead of manually deleting them.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
--------------------------
Folder::
C:\WINDOWS\VG9kZA
C:\Documents and Settings\Todd\!
C:\WINDOWS\system32\xnA
C:\WINDOWS\system32\3056v
Registry::
[HKEY_LOCAL_MACHINE\SOFTWA
"{4e49c2af-a419-4e58-b427-
"BM675c9811"=-
"{FA-AB-B2-22-DW}"=-
--------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
ASKER
Just want to thank everyone for their help. Seems to be running fine now. Error messages have gone, got SUPERAntivirus up and running again and as far as I can tell, all is well again. Again my appreciation, saved me from having to haul it in to the shop to be looked at. Never having done this before, I am going to try and give the points to the two of you who really took time out to help, hope it works. See Ya.
Hi Kristal,
Glad to know that the problem seems to be resolved.
When you're done with Combofix, please uninstall it.
Go to Start > Run and copy and paste next command in the field:
ComboFix /u
The procedure will delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Thanks!
Glad to know that the problem seems to be resolved.
When you're done with Combofix, please uninstall it.
Go to Start > Run and copy and paste next command in the field:
ComboFix /u
The procedure will delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Thanks!
we have had 7 computers in here with "userinit.exe the application failed to initialize properly (0xc0000005)"
System restore will not work as it will take out windows and it leads to a format.
There was no help on the net to fix it.
I have solved the problem with the following steps.
You need ERD commander or some other dos based program that will remove files from NTFS partitions and hijack this
1, remove any files from windows\system32
that start with __c00{five alphanumeric character}.dat
remove files from system restore c:\system volume information
remove all temp files
2, restart computer windows may or may not start normally,
if it does not Ctrl,alt,del to to run task manager
copy hijack this to the desktop.
run hijack this and remove any nasties.
namley "__c00{five alphanumeric character}.dat"
most *.dll in there in system32 should not be there.
3, Remove HDD place in another clean computer and scan for virus's
scan for adware,spyware etc.
System restore will not work as it will take out windows and it leads to a format.
There was no help on the net to fix it.
I have solved the problem with the following steps.
You need ERD commander or some other dos based program that will remove files from NTFS partitions and hijack this
1, remove any files from windows\system32
that start with __c00{five alphanumeric character}.dat
remove files from system restore c:\system volume information
remove all temp files
2, restart computer windows may or may not start normally,
if it does not Ctrl,alt,del to to run task manager
copy hijack this to the desktop.
run hijack this and remove any nasties.
namley "__c00{five alphanumeric character}.dat"
most *.dll in there in system32 should not be there.
3, Remove HDD place in another clean computer and scan for virus's
scan for adware,spyware etc.
Hijackthis:
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis
Open Hijackthis, click "Do a system scan and save a logfile" please don't fix anything yet.
Please attach the logfile.