1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

cant start windows explorer, my computer or recycle bin

Discussion in 'Earlier Versions of Windows' started by beth4joe, Jan 11, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. beth4joe

    beth4joe Thread Starter

    Joined:
    Jan 11, 2003
    Messages:
    4
    In the last 2-3 days I have been unable to open the Windows Explorer, My Computer, or recycle bin from my desktop. I found a "dialer" virus today and cleaned it. The problem still exists.
    All I see is "illegal operation" notice and it shuts down the program. I inherited this computer and dont have the win98 disc for reload. What now???:confused:

    Here is the reading from the details:

    EXPLORER caused an invalid page fault in
    module INEB.DLL at 015f:01057eed.
    Registers:
    EAX=00000000 CS=015f EIP=01057eed EFLGS=00010202
    EBX=0048ed68 SS=0167 ESP=00a4b150 EBP=00a4b168
    ECX=00490e4c DS=0167 ESI=00490e4c FS=0e57
    EDX=00000000 ES=0167 EDI=0048f340 GS=373e
    Bytes at CS:EIP:
    8b 52 04 89 11 c2 08 00 8b 44 24 04 8b 4c 24 08
    Stack dump:
    7113fec7 01620bec 00490e4c 00a4b180 0048f340 01620bec 00a4b1a4 71142cdb 00000000 00000007 0048f094 71169e44 01620bec 00000007 00000000 0048ed68
     
  2. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    Hi, and welcome to the board. :)

    Please do this:

    Go to http://www.spywareinfo.com/downloads.php#det , and download 'Hijack This!'.
    Unzip, doubleclick HijackThis.exe, and hit "Scan".

    When the scan is finished, the "Scan" button will change into a "Save Log" button.
    Press that, save the log somewhere, and please show us its contents.
     
  3. beth4joe

    beth4joe Thread Starter

    Joined:
    Jan 11, 2003
    Messages:
    4
    How do I insert the log file into this message?
     
  4. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    When you've saved the log, doubleclick it, so it opens in Notepad.

    Go to Edit > Select All, then to Edit > Copy.

    Now you've copied the entire text to the Windows Clipboard (this happens behind your back.)

    Next, go back to the forum thread, and click "Post Reply".

    In an empty area click your RIGHT mouse button, and choose 'Paste' from the context menu.

    And voila, there's your Hijack This log.
     
  5. beth4joe

    beth4joe Thread Starter

    Joined:
    Jan 11, 2003
    Messages:
    4
    viola!

    joe

    Logfile of HijackThis v1.90.0
    Scan saved at 2:03:24 PM, on 1/11/2003
    Platform: Windows 9x 4.10.1998
    MSIE version: 5.50.4134.0600

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL=http://toolbar.i-lookup.com/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://toolbar.i-lookup.com/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://toolbar.i-lookup.com/search.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.i-lookup.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL=http://fastmetasearch.com/bar.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://toolbar.i-lookup.com/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.aol.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://toolbar.i-lookup.com/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title=Microsoft Internet Explorer provided by America Online
    O1 - Hosts: 66.40.16.234 auto.search.msn.com
    O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: ineb Helper - {61D029AC-972B-49FE-A155-962DFA0A37BB} - C:\WINDOWS\SYSTEM\INEB.DLL
    O2 - BHO: SmartPops - {D5C778F1-CF13-4E70-ADF0-45A953E7CB8B} - C:\PROGRAM FILES\NETWORK ESSENTIALS\V11\NE.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: I-Lookup.com Bar - {8E4C16F3-45C8-4B24-99E6-F55082B7C4F1} - C:\WINDOWS\SYSTEM\INEB.DLL
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [WinPoET] C:\Program Files\iVasion\WinPoET\WinPPPoverEthernet.exe
    O4 - HKLM\..\Run: [Perry] C:\WINDOWS\SYSTEM\Perry.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
    O4 - HKLM\..\Run: [AmazingTens] "C:\Program Files\AmazingTens\AmazingTens.exe" /H
    O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
    O4 - HKLM\..\Run: [Launcher] "C:\Program Files\KFH\cl\launcher.exe" /P
    O4 - HKLM\..\Run: [Desire] c:\program files\dialers\desire\desire.exe /noconnect
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKCU\..\Run: [LiquidArtPlayerTrayIcon] C:\PROGRA~1\LIQUID~1\ARTPLA~1\ARTPLA~1\ARTPLA~2.EXE
    O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
    O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: Yahoo! Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
    O15 - Trusted Zone: http://free.aol.com
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E87A6788-1D0F-4444-8898-1D25829B6755} (MSN Chat Control 4.0) - http://fdl.msn.com/public/chat/msnchat4.cab
    O16 - DPF: {A45F39DC-3608-4237-8F0E-139F1BC49464} - http://64.157.10.150/diallerfiles/034891.exe
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.ordertire.com/CFIDE/classes/CFJava.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {FC89F9FA-0FEF-43DA-AE71-5C7897DC000D} (XLiteInstall Class) - http://www.cabcconnection.com/CABCXInstall_Full.cab
    O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/Browser_Plugin.cab
    O16 - DPF: {D35A69A7-7A34-4C67-814A-3F508C0BF371} (Inst Class) - http://toolbar.i-lookup.com/ineb.cab
    O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C} (NSUpdateLiteCtrl Class) - http://204.177.92.201/quickdl/action/NSupd9x.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
     
  6. TonyKlein

    TonyKlein Malware Specialist

    Joined:
    Aug 26, 2001
    Messages:
    10,392
    OK, please do this:

    Run Hijack this and check ALL of the following items.
    Subsequently shut down ALL Internet Explorer windows, and have Hijack This fix all checked.

    Reboot when you're done:

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL=http://toolbar.i-lookup.com/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://toolbar.i-lookup.com/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=http://toolbar.i-lookup.com/search.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.i-lookup.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL=http://fastmetasearch.com/bar.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://toolbar.i-lookup.com/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=http://toolbar.i-lookup.com/search.html

    O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
    O2 - BHO: ineb Helper - {61D029AC-972B-49FE-A155-962DFA0A37BB} - C:\WINDOWS\SYSTEM\INEB.DLL
    O2 - BHO: SmartPops - {D5C778F1-CF13-4E70-ADF0-45A953E7CB8B} - C:\PROGRAM FILES\NETWORK
    O3 - Toolbar: I-Lookup.com Bar - {8E4C16F3-45C8-4B24-99E6-F55082B7C4F1} - C:\WINDOWS\SYSTEM\INEB.DLL

    O4 - HKLM\..\Run: [Perry] C:\WINDOWS\SYSTEM\Perry.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
    O4 - HKLM\..\Run: [AmazingTens] "C:\Program Files\AmazingTens\AmazingTens.exe" /H
    O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
    O4 - HKLM\..\Run: [Launcher] "C:\Program Files\KFH\cl\launcher.exe" /P
    O4 - HKLM\..\Run: [Desire] c:\program files\dialers\desire\desire.exe /noconnect

    O16 - DPF: {A45F39DC-3608-4237-8F0E-139F1BC49464} - http://64.157.10.150/diallerfiles/034891.exe
    O16 - DPF: {FC89F9FA-0FEF-43DA-AE71-5C7897DC000D} (XLiteInstall Class) - http://www.cabcconnection.com/CABCXInstall_Full.cab
    O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/Browser_Plugin.cab
    O16 - DPF: {D35A69A7-7A34-4C67-814A-3F508C0BF371} (Inst Class) - http://toolbar.i-lookup.com/ineb.cab

    Doublecheck so as not to forget a single one of the above items.

    After rebooting, do this:

    Download Spybot - Search & Destroy

    It looks for spyware, but also targets dialers, keyloggers, and other nasties, and it's freeware.

    After installing, press Online, and search for, put a check mark at, and install all updates.

    Next, go to the Settings tab > File Sets, and uncheck 'System Internals' and 'Tracks' .
    These aren't needed for our present purpose, and you can always experiment with them later on.

    Finally, after closing down Internet Explorer, hit 'Check for Problems', and have SpyBot remove all it finds.

    When you've done all that, test your system, and see whether your problem is gone.

    Good luck,
     
  7. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/112686

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice