cant start windows explorer, my computer or recycle bin

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

beth4joe

Thread Starter
Joined
Jan 11, 2003
Messages
4
In the last 2-3 days I have been unable to open the Windows Explorer, My Computer, or recycle bin from my desktop. I found a "dialer" virus today and cleaned it. The problem still exists.
All I see is "illegal operation" notice and it shuts down the program. I inherited this computer and dont have the win98 disc for reload. What now???:confused:

Here is the reading from the details:

EXPLORER caused an invalid page fault in
module INEB.DLL at 015f:01057eed.
Registers:
EAX=00000000 CS=015f EIP=01057eed EFLGS=00010202
EBX=0048ed68 SS=0167 ESP=00a4b150 EBP=00a4b168
ECX=00490e4c DS=0167 ESI=00490e4c FS=0e57
EDX=00000000 ES=0167 EDI=0048f340 GS=373e
Bytes at CS:EIP:
8b 52 04 89 11 c2 08 00 8b 44 24 04 8b 4c 24 08
Stack dump:
7113fec7 01620bec 00490e4c 00a4b180 0048f340 01620bec 00a4b1a4 71142cdb 00000000 00000007 0048f094 71169e44 01620bec 00000007 00000000 0048ed68
 

TonyKlein

Malware Specialist
Joined
Aug 26, 2001
Messages
10,392
Hi, and welcome to the board. :)

Please do this:

Go to http://www.spywareinfo.com/downloads.php#det , and download 'Hijack This!'.
Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log somewhere, and please show us its contents.
 

TonyKlein

Malware Specialist
Joined
Aug 26, 2001
Messages
10,392
When you've saved the log, doubleclick it, so it opens in Notepad.

Go to Edit > Select All, then to Edit > Copy.

Now you've copied the entire text to the Windows Clipboard (this happens behind your back.)

Next, go back to the forum thread, and click "Post Reply".

In an empty area click your RIGHT mouse button, and choose 'Paste' from the context menu.

And voila, there's your Hijack This log.
 

beth4joe

Thread Starter
Joined
Jan 11, 2003
Messages
4
viola!

joe

Logfile of HijackThis v1.90.0
Scan saved at 2:03:24 PM, on 1/11/2003
Platform: Windows 9x 4.10.1998
MSIE version: 5.50.4134.0600

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL=http://toolbar.i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://toolbar.i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://toolbar.i-lookup.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.i-lookup.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL=http://fastmetasearch.com/bar.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://toolbar.i-lookup.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.aol.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://toolbar.i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title=Microsoft Internet Explorer provided by America Online
O1 - Hosts: 66.40.16.234 auto.search.msn.com
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: ineb Helper - {61D029AC-972B-49FE-A155-962DFA0A37BB} - C:\WINDOWS\SYSTEM\INEB.DLL
O2 - BHO: SmartPops - {D5C778F1-CF13-4E70-ADF0-45A953E7CB8B} - C:\PROGRAM FILES\NETWORK ESSENTIALS\V11\NE.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: I-Lookup.com Bar - {8E4C16F3-45C8-4B24-99E6-F55082B7C4F1} - C:\WINDOWS\SYSTEM\INEB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [WinPoET] C:\Program Files\iVasion\WinPoET\WinPPPoverEthernet.exe
O4 - HKLM\..\Run: [Perry] C:\WINDOWS\SYSTEM\Perry.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
O4 - HKLM\..\Run: [AmazingTens] "C:\Program Files\AmazingTens\AmazingTens.exe" /H
O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [Launcher] "C:\Program Files\KFH\cl\launcher.exe" /P
O4 - HKLM\..\Run: [Desire] c:\program files\dialers\desire\desire.exe /noconnect
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKCU\..\Run: [LiquidArtPlayerTrayIcon] C:\PROGRA~1\LIQUID~1\ARTPLA~1\ARTPLA~1\ARTPLA~2.EXE
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O15 - Trusted Zone: http://free.aol.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E87A6788-1D0F-4444-8898-1D25829B6755} (MSN Chat Control 4.0) - http://fdl.msn.com/public/chat/msnchat4.cab
O16 - DPF: {A45F39DC-3608-4237-8F0E-139F1BC49464} - http://64.157.10.150/diallerfiles/034891.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.ordertire.com/CFIDE/classes/CFJava.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {FC89F9FA-0FEF-43DA-AE71-5C7897DC000D} (XLiteInstall Class) - http://www.cabcconnection.com/CABCXInstall_Full.cab
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/Browser_Plugin.cab
O16 - DPF: {D35A69A7-7A34-4C67-814A-3F508C0BF371} (Inst Class) - http://toolbar.i-lookup.com/ineb.cab
O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C} (NSUpdateLiteCtrl Class) - http://204.177.92.201/quickdl/action/NSupd9x.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
 

TonyKlein

Malware Specialist
Joined
Aug 26, 2001
Messages
10,392
OK, please do this:

Run Hijack this and check ALL of the following items.
Subsequently shut down ALL Internet Explorer windows, and have Hijack This fix all checked.

Reboot when you're done:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL=http://toolbar.i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://toolbar.i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://toolbar.i-lookup.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.i-lookup.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL=http://fastmetasearch.com/bar.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://toolbar.i-lookup.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://toolbar.i-lookup.com/search.html

O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: ineb Helper - {61D029AC-972B-49FE-A155-962DFA0A37BB} - C:\WINDOWS\SYSTEM\INEB.DLL
O2 - BHO: SmartPops - {D5C778F1-CF13-4E70-ADF0-45A953E7CB8B} - C:\PROGRAM FILES\NETWORK
O3 - Toolbar: I-Lookup.com Bar - {8E4C16F3-45C8-4B24-99E6-F55082B7C4F1} - C:\WINDOWS\SYSTEM\INEB.DLL

O4 - HKLM\..\Run: [Perry] C:\WINDOWS\SYSTEM\Perry.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
O4 - HKLM\..\Run: [AmazingTens] "C:\Program Files\AmazingTens\AmazingTens.exe" /H
O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [Launcher] "C:\Program Files\KFH\cl\launcher.exe" /P
O4 - HKLM\..\Run: [Desire] c:\program files\dialers\desire\desire.exe /noconnect

O16 - DPF: {A45F39DC-3608-4237-8F0E-139F1BC49464} - http://64.157.10.150/diallerfiles/034891.exe
O16 - DPF: {FC89F9FA-0FEF-43DA-AE71-5C7897DC000D} (XLiteInstall Class) - http://www.cabcconnection.com/CABCXInstall_Full.cab
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/Browser_Plugin.cab
O16 - DPF: {D35A69A7-7A34-4C67-814A-3F508C0BF371} (Inst Class) - http://toolbar.i-lookup.com/ineb.cab

Doublecheck so as not to forget a single one of the above items.

After rebooting, do this:

Download Spybot - Search & Destroy

It looks for spyware, but also targets dialers, keyloggers, and other nasties, and it's freeware.

After installing, press Online, and search for, put a check mark at, and install all updates.

Next, go to the Settings tab > File Sets, and uncheck 'System Internals' and 'Tracks' .
These aren't needed for our present purpose, and you can always experiment with them later on.

Finally, after closing down Internet Explorer, hit 'Check for Problems', and have SpyBot remove all it finds.

When you've done all that, test your system, and see whether your problem is gone.

Good luck,
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Members online

Top