Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] explorer.exe no disk and winfixer pop-up

[Fixed] Hijackthis! Logs - [Fixed] explorer.exe no disk and winfixer pop-up posted in the Security & Safety forums; I have been expriencing a problem with a pop-up window on start-up that mentions explorer.exe no disk...etc. I usually just close this box, it opens once more. After I close ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-31-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 7
TomPNW - See this Members User comments on their Profile page
Default [Fixed] explorer.exe no disk and winfixer pop-up

I have been expriencing a problem with a pop-up window on start-up that mentions explorer.exe no disk...etc. I usually just close this box, it opens once more. After I close it a second time the system starts up without any other problems.

Once that works the system eventually has a problem (usually while I am on the internet) during which the taskbar and the icons on the desktop dissappear, leaving behind only my desktop background image. After this I obviously have to restart and the whole cycle starts all over again.

Just within the last few days I also have a problem with a winfixer pop-up that appears during times of internet browsing. I have run adaware several times although it never detects anything besides the temporary internet files. Any help with these problems would be appreciated.

I attached a HJT log and a image of the pop-up for winfixer.
Attached Images
File Type: jpg 31122005-011719-2422.jpg (32.9 KB, 7 views)
Attached Files
File Type: log hijackthis.log (6.9 KB, 5 views)


  #2  
Old 12-31-2005
Hengis's Avatar
PCHF Head Honcho
My PC
 
Join Date: Jan 2004
Location: Southern England
Posts: 11,593
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default

Welcome to PCHF

I can see that there is quite a bit of infection in your log. A Security Analyst will be along soon to look at this for you.


__________________

Pre-Work
/ System File Checker / Help promote PCHF! / What's inside your PC? / Did we help you? If we did, please consider A Donation
  #3  
Old 01-01-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 7
TomPNW - See this Members User comments on their Profile page
Default

Thank you for the welcome. I was figured the results weren't pretty. I know some of the items are related to all of the hp software that came with the computer but others I have no idea about. I figured it was best to play it safe and have someone more knowledgable take a look.

Happy New Year everyone!


  #4  
Old 01-01-2006
ladygreenwitch's Avatar
HR Director
My PC
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 5,778
PC Experience: PC Illiterate
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

:smiley: Hi Tom,

a warm welcome from me as well.

Before we start fixing your computer with HijackThis, will you please do the following;

Download To Your Desktop
Please download Process Explorer by Systernals, KillBox by Option^Explicit, CCleaner, and ewido Security Suite


Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.
Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Please print these instructions, and boot into Safe Mode where you will need to stay for the entirety of this fix. (Continually tap on your F8 key while booting up, until either a beep sounds or a menu pops up. Use your arrow keys to navigate to Safe Mode, and hit Enter)

Clean up unneccesary files and folders
Install and launch CCleaner
  • Click on check for updates.
  • Under Cleaner Settings, make sure that everything is checked, including Advanced.
  • Answer yes to all warnings.
  • Click Analyze, when it is finished, click Run Cleaner, then OK.
  • Allow the program to finish and exit application.
Remove any malware using Ewido
Install Ewido Security Suite.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu
  • Launch Ewido, there should be a big "E" icon on your desktop, double-click it.
  • The program will prompt you to update click the "OK" button
  • The program will now go to the main screen
  • You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
  • The update will start and a progress bar will show the updates being installed.*
  • After the updates are installed, exit ewido.
Once the updates are installed do the following:
  • If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Reboot into Safe Mode, restart your computer, tap the F8* key. Use your up arrow key to highlight Safe Mode, then hit enter.
Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
  • Click on Scanner , Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK, Complete system scan
  • Let the program scan the machine
  • If ewido finds anything, it will pop up a notification.*
NOTE:* We have been finding some cases of false positives with the new version of Ewido, so you need to step through the fixes one-by-one.* If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged.* In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action.*

DO NOT check "Perform action with all infections."* If you are unsure of an entry, select "none" for the time being.* We will see that in the log when you post it later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.

Click Save report. Save the report to your desktop, exit ewido


Note:

If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and run a new scan.

Next
Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of jkhfe.dll once and then click the kill button.

After you have killed all of the jkhfe.dll under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of jkhfe.dll then click the kill button.

Once you have done that click OK again.

Next run HijackThis and place a check beside each of the following.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost;<local>
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\jkhfe.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKCU\..\Run: [UWICKCD] E:\AUTORUN\UWICK.EXE E:\AUTORUN
O4 - Startup: Organize.lnk = ?
O20 - Winlogon Notify: ddayx - C:\WINDOWS\system32\jkhfe.dll
Now click fix checked and close HijackThis.

Please copy the text in the quote below, and paste it into a blank notepad window. Save it as vundo.reg and in the Save As Type box choose All Files.

Once you have saved it double click it and allow it to merge with the registry.


REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B5527 4-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB 5-BD7D-4D49-A1AA-8AB0F3D3CB44}] [-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}] [-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] [-HKEY_CLASSES_ROOT\MSEvents.MSEvents]
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEve nts.1]

Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full Path of File to Delete box

C:\WINDOWS\system32\jkhfe.dll


Click the red circle with the white x and allow your computer to reboot.

After your computer has rebooted please run Hijackthis again and post a new HijackThis log.

Look forward to your reply,

TTFN

LGW


  #5  
Old 01-01-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 7
TomPNW - See this Members User comments on their Profile page
Default

Here is the new HJT log
Attached Files
File Type: log hijackthis.log (6.7 KB, 2 views)


  #6  
Old 01-02-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

All the nasty's are gone. , but these "minor" probs can be fixed with hjt:

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
Do you still have any problems?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 01-02-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 7
TomPNW - See this Members User comments on their Profile page
Default Problem solved

Thank you for the help from all of you. The problems appear to be gone and all is back to normal. I will perform the minor fixes suggested by joe5 and turn on the system restore feature again.

Is there any recommendation as to leave the hidden files on or off?



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 05:59 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com